NFV MANO Hardware Trust Validation for VNF Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Function Virtualization (NFV) infrastructures face challenges in integrating general-purpose systems with hardware-trusted systems and efficiently sharing Virtual Network Functions (VNFs) across these boundaries, leading to inefficiencies in security management and resource utilization.

Innovation Solution

The NFV Management and Orchestration (MANO) system exchanges hardware trust data with a hardware-trusted subsystem to maintain trust and efficiently execute VNFs in both general-purpose and hardware-trusted environments, using secret hardware-embedded keys for validation and enabling seamless sharing of VNFs between these systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If general-purpose NFVI systems and hardware-trusted NFVI systems operate separately, then each system can be optimized independently, but integration and resource sharing between them becomes inefficient

Engineering Contradiction:
Improveintegration capabilityVSAvoidresource sharing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent introduces a hardware-trust validation mechanism as an intermediary layer between general-purpose NFVI systems and hardware-trusted NFVI systems. This validation mechanism uses hardware-trusted subsystems to verify the integrity of VNFs before executing them, enabling secure integration and efficient resource sharing while maintaining the benefits of both system types operating independently

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If VNFs are executed separately in general-purpose and hardware-trusted NFVI systems, then system flexibility is maintained, but security management becomes complex

Engineering Contradiction:
Improvesystem flexibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal VNF execution model where the same VNF can be executed in both general-purpose and hardware-trusted NFVI systems. The hardware-trusted subsystems provide multi-functional capability by validating VNF integrity and enabling secure execution across different system types, thereby simplifying security management while maintaining flexibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware-trusted subsystems are deployed throughout the NFVI, then security and trust are enhanced, but system cost increases

Engineering Contradiction:
Improvehardware trustVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies hardware-trusted subsystems selectively at specific locations within the NFVI where security validation is most critical, rather than deploying them throughout the entire system. This localized approach enhances hardware trust where needed while minimizing the overall system cost and complexity

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3314816B1Network function virtualization (NFV) hardware trust in data communication systems
Publication Date: 2019.07.31 SPRINT COMMUNICATIONS CO LP
  • EP3314816B1 patent drawingFigure 1
  • EP3314816B1 patent drawingFigure 2
  • EP3314816B1 patent drawingFigure 3

AI summary

A Network Function Virtualization (NFV) Management and Orchestration (MANO) data communication system (120, 220) drives an NFV Infrastructure (NFVI) (101, 201) to support a Network Service (NS). The NFV MANO system (120, 220) exchanges hardware trust data with a hardware-trusted subsystem in the NFVI (104, 204, 510) to maintain hardware trust with the NFVI subsystem. The NFV MANO system (120, 220) exchanges NS data with an operations system (110, 210) and responsively exchanges network data to drive the NFVI (101, 201) to execute a Virtual Network Function (VNF) (102, 202) externally to the hardware-trusted subsystem (104, 204, 510) to support the NS. The NFV MANO system (120, 220) also exchanges trust data for the NS with the operations system (110, 210) and responsively exchanges network data with the hardware-trusted subsystem (104, 204, 510) to drive the subsystem to execute the VNF (102, 202) to support the NS.