NFV Certificate Authority for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network Function Virtualization (NFV) systems face security challenges such as data leakage, sensitive information compromise, and trust management issues due to vulnerabilities in Hardware Isolated Secure Execution Environment (HISEE) and traditional authentication mechanisms, which threaten the confidentiality, integrity, and privacy of network and subscriber activities.
Innovation Solution
A network function virtualization system that includes a request receiving unit, a private key generator, a public key extractor, and a verifying unit to generate and verify private key information within a hardware-based isolated secure execution environment, ensuring secure authentication and data protection by using public key cryptography and secure storage mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication mechanisms are used in NFV systems, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities in HISEE and data leakage risks
Solution Approach 1:
The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to authenticate entities in the NFV system. The CA acts as a trusted mediator between communicating parties, verifying identities and providing cryptographic proof of authenticity through certificates, thereby enhancing security without complicating the authentication process for end users
Solution Approach 2:
The patent replaces traditional mechanical or software-based authentication mechanisms with public key cryptography and digital certificate verification. Instead of relying on vulnerable software authentication or physical credentials, the system uses mathematical cryptographic principles embedded in hardware security modules (HSM) and trusted platform modules (TPM) to provide unbreakable authentication based on cryptographic key pairs
2Reliability
If hardware-based isolated secure execution environment (HISEE) is used for secure credential storage, then security reliability is improved, but vulnerability to power analysis attacks and collusion threats increases
Solution Approach 1:
The patent implements different security levels and authentication methods for different components and operations within the NFV system. Critical credential storage uses hardware-based security with enhanced protection against power analysis, while other operations use appropriate authentication mechanisms. The system applies security measures locally where needed rather than uniformly across all components
Solution Approach 2:
The patent performs security verification and authentication in advance before critical operations occur. Digital certificates are pre-issued and verified before entities engage in sensitive operations. The system proactively checks cryptographic signatures and validates credentials beforehand, preventing unauthorized access before it can cause harm rather than reacting to attacks after they occur
3Reliability
If digital certificates are used for authentication, then security reliability is improved, but device complexity increases due to certificate management requirements
Solution Approach 1:
The patent creates a universal certificate authority infrastructure that serves multiple functions across the entire NFV ecosystem. The CA system provides authentication, authorization, and credential verification for diverse entities including virtual network functions, physical infrastructure, management systems, and third-party vendors through a single unified certificate management framework, eliminating the need for separate authentication systems for each component
Solution Approach 2:
The patent implements automated certificate issuance, renewal, and revocation processes that operate without manual intervention. The certificate authority system automatically manages the lifecycle of digital certificates, including generating key pairs, issuing certificates to requesting entities, monitoring certificate expiration, and revoking compromised certificates. This automation eliminates the need for manual certificate administration and reduces operational complexity
4Reliability
If public key cryptography is implemented for secure authentication, then confidentiality and integrity are improved, but processing time increases due to cryptographic operations
Solution Approach 1:
The patent divides the cryptographic authentication process into distinct segments: asymmetric cryptography (public key) is used for initial identity verification and key exchange, while symmetric cryptography is used for subsequent data encryption and authentication. This segmentation allows the computationally intensive public key operations to be limited to essential authentication steps, while faster symmetric operations handle bulk data protection, reducing overall processing time
Data Source
AI summary
A network function virtualization system, comprises a request receiving unit that receives a request to a certificate of at least one of data exchanging parties; a private key generator that generates a first private key information using a second private key information stored in a hardware-based isolated secure execution environment, in response to the request; a public key extractor that extracts a public key information of the first private key information; a public key information storage unit that stores the public key information; and a verifying unit that is accessible from the request receiving unit and verifies the certificate using the public key information corresponding to the certificate.


