Network Service Header Security via Selective Authentication Tags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service Function Chaining (SFC) networks face challenges in securing Network Service Headers (NSH) due to unauthenticated and unencrypted metadata, which requires additional security measures like IPsec for transport encapsulation, but these solutions are not scalable for dynamic service function paths and credential management.
Innovation Solution
A network service packet header security system that includes an NSH imposer, a key management service, and service functions, which analyzes packets, identifies security functions, requests and applies encryption keys, and generates authentication tags to secure NSH data, using a ticket-based key management system to ensure only authorized service functions access encrypted metadata.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If transport encapsulation features like IPsec are used to secure NSH data, then security is improved, but scalability and adaptability to dynamic service function paths deteriorate
Solution Approach 1:
The patent segments the security mechanism into modular components: authentication tags are applied selectively to specific NSH fields rather than requiring full packet encryption. This allows individual fields to be secured based on their sensitivity and the specific service function path requirements, enabling scalable security that adapts to dynamic service chains without requiring comprehensive re-encryption of all data.
Solution Approach 2:
The patent applies different security treatments to different parts of the NSH structure. Critical fields such as service path identifier and metadata are authenticated using security tags, while other fields may remain unauthenticated. This local quality approach allows the system to provide security where needed while maintaining scalability and avoiding the overhead of encrypting entire packets, thus resolving the contradiction between security and adaptability.
2Reliability
If authentication and encryption are applied to NSH metadata, then security is improved, but processing complexity and overhead increase
Solution Approach 1:
The patent implements partial authentication by applying security tags only to critical NSH fields rather than authenticating the entire packet. This partial action approach provides sufficient security for the most important metadata fields while significantly reducing processing complexity and overhead compared to full packet authentication, thus resolving the contradiction between security and processing complexity.
3Reliability
If credentials are pre-distributed to service functions, then security is improved, but adaptability to dynamic service function paths deteriorates
Solution Approach 1:
The patent implements dynamic security tagging where authentication tags are applied to NSH fields based on the specific service function path being traversed. Rather than pre-distributing static credentials, the system dynamically determines which fields require authentication for each service function path, allowing the security mechanism to adapt to dynamic service chains while maintaining strong security through context-aware authentication tag application.
Data Source
AI summary
A network service packet (NSP) header security method includes receiving an NSP on a communication interface, analyzing, by a processor, the NSP in order to identify a plurality of service functions and an associated service function path for the plurality of service functions, identifying, by the processor, which security function or functions may be performed by each of the plurality of service functions on an NSP header to be generated for the NSP, requesting, by the processor, at least one key for securing at least part of the NSP header, receiving the at least one key on the communication interface, generating, by the processor, the NSP header for the NSP, securing, by the processor, the NSP header based on the at least one key, and sending, on the communication interface, the NSP with the NSP header to one of the plurality of service functions.


