NFV Certificate Configuration via Initial Credential Installation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network function virtualization (NFV) scenarios, conventional certificate configuration methods are inadequate due to the dynamic and software-generated nature of virtualized network function entities, leading to security risks such as mutual attacks between virtual machines and unauthorized access, as they cannot ensure unique certificates for each instance, thereby compromising communication security.
Innovation Solution
A method where a virtualized network management entity obtains and installs initial credential information for virtualized network function entities during instantiation, enabling them to obtain formal certificates from a certificate authority, ensuring unique certificates for each instance and enhancing security by configuring initial credential information, such as certificates, pre-shared keys, or tokens, to establish secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If conventional entity certificate configuration method is used, then certificate configuration is performed by provider of virtualized network function entity, but same certificate is installed for multiple instances causing severe security risk
Solution Approach 1:
The patent applies preliminary action by embedding initial credential information (such as initial certificates and private keys) into the virtualized network function entity's installation package before deployment. This allows each instance to automatically possess unique cryptographic credentials upon instantiation, eliminating the security risk of shared certificates while maintaining ease of configuration through automated deployment processes.
Solution Approach 2:
The patent segments the certificate management process by providing separate initial credential information for each virtualized network function entity instance within the installation package. Instead of using a single shared certificate, each instance receives its own unique credential set, enabling individual identification and authentication while preserving the simplicity of automated deployment.
2Productivity
If conventional entity certificate configuration method is used, then installation package is deployed to multiple instances, but unique certificate identification cannot be achieved
Solution Approach 1:
The patent applies preliminary action by pre-configuring unique initial credential information for each virtualized network function entity instance within the installation package. This enables automated deployment across multiple instances while ensuring each instance possesses unique cryptographic identifiers, thereby achieving both high deployment efficiency and precise instance identification simultaneously.
Solution Approach 2:
The patent applies local quality by providing customized initial credential information tailored to each specific virtualized network function entity instance. Each instance receives credential information with unique identifiers specific to its identity, enabling precise local identification while maintaining consistent automated deployment processes across the network.
3Adaptability or versatility
If virtualized network function entity is dynamically generated, then flexibility and adaptability are improved, but conventional certificate configuration becomes inapplicable
Solution Approach 1:
The patent applies preliminary action by embedding initial credential information directly into the virtualized network function entity's installation package before dynamic deployment. This approach maintains the flexibility and adaptability of dynamic virtualization while simplifying certificate management, as each instance automatically receives its unique credentials during instantiation without requiring complex post-deployment configuration.
Solution Approach 2:
The patent applies self-service by enabling virtualized network function entities to automatically obtain and utilize their initial credential information upon instantiation. Each instance independently uses its embedded credentials for authentication and secure communication without requiring external certificate management intervention, thereby maintaining virtualization flexibility while reducing management complexity.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The present invention discloses a network function virtualization-based certificate configuration method, apparatus, and system. A virtualized network management entity obtains initial credential information of a virtualized network function entity; and installs the initial credential information onto the virtualized network function entity during or after instantiation of the virtualized network function entity, so that the virtualized network function entity obtains, from a certificate authority by using the initial credential information, a formal certificate issued by a network operator of the virtualized network function entity. The present invention not only can apply to a network function virtualization scenario, but also can resolve a problem of a security risk in network function virtualization.