NFV Certificate Authority for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Function Virtualization (NFV) systems face security challenges such as data leakage, sensitive information compromise, and trust management issues due to vulnerabilities in Hardware Isolated Secure Execution Environment (HISEE) and traditional authentication mechanisms, which threaten the confidentiality, integrity, and privacy of network and subscriber activities.

Innovation Solution

A network function virtualization system that includes a request receiving unit, a private key generator, a public key extractor, and a verifying unit to generate and verify private key information within a hardware-based isolated secure execution environment, ensuring secure authentication and data protection by using public key cryptography and secure storage mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication mechanisms are used in NFV systems, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities in HISEE and data leakage risks

Engineering Contradiction:
Improveauthentication mechanismVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to authenticate entities in the NFV system. The CA acts as a trusted mediator between communicating parties, verifying identities and providing cryptographic proof of authenticity through certificates, thereby enhancing security without complicating the authentication process for end users

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical or software-based authentication mechanisms with public key cryptography and digital certificate verification. Instead of relying on vulnerable software authentication or physical credentials, the system uses mathematical cryptographic principles embedded in hardware security modules (HSM) and trusted platform modules (TPM) to provide unbreakable authentication based on cryptographic key pairs

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based isolated secure execution environment (HISEE) is used for secure credential storage, then security reliability is improved, but vulnerability to power analysis attacks and collusion threats increases

Engineering Contradiction:
Improvesecure credential storageVSAvoidpower analysis attack and collusion threat
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements different security levels and authentication methods for different components and operations within the NFV system. Critical credential storage uses hardware-based security with enhanced protection against power analysis, while other operations use appropriate authentication mechanisms. The system applies security measures locally where needed rather than uniformly across all components

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs security verification and authentication in advance before critical operations occur. Digital certificates are pre-issued and verified before entities engage in sensitive operations. The system proactively checks cryptographic signatures and validates credentials beforehand, preventing unauthorized access before it can cause harm rather than reacting to attacks after they occur

Inventive Principle:
Principle #10Preliminary action

3Reliability

If digital certificates are used for authentication, then security reliability is improved, but device complexity increases due to certificate management requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal certificate authority infrastructure that serves multiple functions across the entire NFV ecosystem. The CA system provides authentication, authorization, and credential verification for diverse entities including virtual network functions, physical infrastructure, management systems, and third-party vendors through a single unified certificate management framework, eliminating the need for separate authentication systems for each component

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements automated certificate issuance, renewal, and revocation processes that operate without manual intervention. The certificate authority system automatically manages the lifecycle of digital certificates, including generating key pairs, issuing certificates to requesting entities, monitoring certificate expiration, and revoking compromised certificates. This automation eliminates the need for manual certificate administration and reduces operational complexity

Inventive Principle:
Principle #25Self-service

4Reliability

If public key cryptography is implemented for secure authentication, then confidentiality and integrity are improved, but processing time increases due to cryptographic operations

Engineering Contradiction:
Improveconfidentiality and integrityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the cryptographic authentication process into distinct segments: asymmetric cryptography (public key) is used for initial identity verification and key exchange, while symmetric cryptography is used for subsequent data encryption and authentication. This segmentation allows the computationally intensive public key operations to be limited to essential authentication steps, while faster symmetric operations handle bulk data protection, reducing overall processing time

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11463267B2Network function virtualization system and verifying method
Publication Date: 2022.10.04 NEC CORP
  • US11463267B2 patent drawing
  • US11463267B2 patent drawing
  • US11463267B2 patent drawing

AI summary

A network function virtualization system, comprises a request receiving unit that receives a request to a certificate of at least one of data exchanging parties; a private key generator that generates a first private key information using a second private key information stored in a hardware-based isolated secure execution environment, in response to the request; a public key extractor that extracts a public key information of the first private key information; a public key information storage unit that stores the public key information; and a verifying unit that is accessible from the request receiving unit and verifies the certificate using the public key information corresponding to the certificate.