Management Virtual Machine for Secure NFV Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The ETSI MANO architecture for Network Function Virtualization (NFV) faces scalability issues and efficiency losses as the number of virtual machines grows, and it increases the attack surface for denial-of-service attacks due to required connectivity between the VNFM and VNFCI, necessitating improvements in security and efficiency.

Innovation Solution

A virtual network system with a management virtual machine that communicates between VNFCIs and a VNFM, using separate network interfaces to maintain separation between operator infrastructure and tenant VNFs, allowing the VNFM to learn and control VNFCI states without direct interaction, thereby enhancing security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the ETSI MANO architecture requires direct connectivity between VNFM and VNFCI, then control and management functions can be performed, but the attack surface increases and the system becomes vulnerable to denial-of-service attacks

Engineering Contradiction:
ImprovesecurityVSAvoidconnectivity structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management virtual machine as an intermediary component between the VNFM and VNFCI. This mediator handles all communication and control operations, so the VNFM never directly interacts with VNFCI. The management virtual machine receives requests from the VNFM, processes them, and executes appropriate operations on the VNFCI, thereby eliminating direct connectivity requirements while maintaining full control functionality and reducing the attack surface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the number of virtual machines grows in the ETSI MANO architecture, then more network functions can be virtualized, but scalability problems and efficiency losses occur

Engineering Contradiction:
Improvevirtualization capacityVSAvoidmanagement efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges the management and control functions into a single management virtual machine that handles operations for multiple VNFCI instances. Instead of having separate management channels for each virtual machine, one management virtual machine consolidates all control operations, reducing overhead and improving scalability as the number of virtualized network functions increases.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If direct interaction between VNFM and VNFCI is implemented, then control operations can be executed, but communication overhead and processing time increase

Engineering Contradiction:
Improvecontrol operation executionVSAvoidcommunication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The management virtual machine serves as an efficient intermediary that batches and processes control operations. By consolidating communication channels and using a single management instance to handle multiple VNFCI, the system reduces the total number of communication transactions required, thereby decreasing overall communication overhead and processing time despite the additional intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11822946B2Systems and methods for secure network management of virtual network functions
Publication Date: 2023.11.21 CABLE TELEVISION LAB INC
  • US11822946B2 patent drawing
  • US11822946B2 patent drawing

AI summary

A virtual network system for a computer network is provided. The system includes a first host executing a virtual network function manager. The system also includes a second host executing a management virtual machine. The management virtual machine is in communication with the virtual network function manager and with one or more virtual network function component instantiations. The management virtual machine is programmed to route messages between the one or more virtual network function component instantiations and the virtual network function manager.