NFV MANO Hardware Trust Validation for VNF Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network Function Virtualization (NFV) infrastructures face challenges in integrating general-purpose systems with hardware-trusted systems and efficiently sharing Virtual Network Functions (VNFs) across these boundaries, leading to inefficiencies in security management and resource utilization.
Innovation Solution
The NFV Management and Orchestration (MANO) system exchanges hardware trust data with a hardware-trusted subsystem to maintain trust and efficiently execute VNFs in both general-purpose and hardware-trusted environments, using secret hardware-embedded keys for validation and enabling seamless sharing of VNFs between these systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If general-purpose NFVI systems and hardware-trusted NFVI systems operate separately, then each system can be optimized independently, but integration and resource sharing between them becomes inefficient
Solution Approach 1:
The patent introduces a hardware-trust validation mechanism as an intermediary layer between general-purpose NFVI systems and hardware-trusted NFVI systems. This validation mechanism uses hardware-trusted subsystems to verify the integrity of VNFs before executing them, enabling secure integration and efficient resource sharing while maintaining the benefits of both system types operating independently
2Adaptability or versatility
If VNFs are executed separately in general-purpose and hardware-trusted NFVI systems, then system flexibility is maintained, but security management becomes complex
Solution Approach 1:
The patent implements a universal VNF execution model where the same VNF can be executed in both general-purpose and hardware-trusted NFVI systems. The hardware-trusted subsystems provide multi-functional capability by validating VNF integrity and enabling secure execution across different system types, thereby simplifying security management while maintaining flexibility
3Reliability
If hardware-trusted subsystems are deployed throughout the NFVI, then security and trust are enhanced, but system cost increases
Solution Approach 1:
The patent applies hardware-trusted subsystems selectively at specific locations within the NFVI where security validation is most critical, rather than deploying them throughout the entire system. This localized approach enhances hardware trust where needed while minimizing the overall system cost and complexity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A Network Function Virtualization (NFV) Management and Orchestration (MANO) data communication system (120, 220) drives an NFV Infrastructure (NFVI) (101, 201) to support a Network Service (NS). The NFV MANO system (120, 220) exchanges hardware trust data with a hardware-trusted subsystem in the NFVI (104, 204, 510) to maintain hardware trust with the NFVI subsystem. The NFV MANO system (120, 220) exchanges NS data with an operations system (110, 210) and responsively exchanges network data to drive the NFVI (101, 201) to execute a Virtual Network Function (VNF) (102, 202) externally to the hardware-trusted subsystem (104, 204, 510) to support the NS. The NFV MANO system (120, 220) also exchanges trust data for the NS with the operations system (110, 210) and responsively exchanges network data with the hardware-trusted subsystem (104, 204, 510) to drive the subsystem to execute the VNF (102, 202) to support the NS.