NFV SDN Network-to-Network Interfaces for Secure Cross-Network Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The data interface between MANO orchestrators and SDN controllers in different data communication networks is rigid and insecure, limiting the flexibility and security of data communication services in NFV SDN systems.

Innovation Solution

Implementing Network Function Virtualization (NFV) Software-Defined Network (SDN) architecture that uses Network-to-Network Interfaces (NNIs) to transfer forwarding graphs and instructions across network boundaries, enabling secure and flexible communication between NFV orchestrators and SDN controllers through service, NFV, and SDN NNIs, and utilizing Hardware Trust (HWT) for secure validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rigid data interfaces are used between MANO orchestrators and SDN controllers in different networks, then system stability is maintained, but flexibility and security are reduced

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces Hardware Trust (HWT) modules as intermediary security components embedded in network devices. These HWT modules act as mediators that validate cryptographic keys and certificates between MANO orchestrators and SDN controllers across network boundaries, enabling secure communication without requiring rigid pre-configured interfaces. The HWT modules perform mutual authentication and key validation, providing both flexibility in network configuration and security in data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If rigid data interfaces are used between MANO orchestrators and SDN controllers in different networks, then system stability is maintained, but flexibility and security are reduced

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the security parameters from static, pre-configured interface credentials to dynamic cryptographic validation using HWT modules. Instead of relying on fixed interface definitions, the system uses changing cryptographic parameters including public key infrastructure (PKI), digital certificates, and dynamic key exchange mechanisms. This allows the interface to adapt to different network configurations while maintaining security through continuous cryptographic validation.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If traditional data interfaces are used across network boundaries, then implementation simplicity is maintained, but security and flexibility are limited

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The HWT modules perform self-validation and self-authentication without requiring complex external security infrastructure. Each HWT module automatically validates its own cryptographic credentials and the credentials of communicating partners using embedded trust anchors and public key verification. This self-service approach simplifies implementation by eliminating the need for centralized security management systems while providing robust security validation across network boundaries.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10164914B2Network function virtualization (NFV) software-defined network (SDN) network-to-network interfaces (NNIs)
Publication Date: 2018.12.25 T MOBILE INNOVATIONS LLC
  • US10164914B2 patent drawing
  • US10164914B2 patent drawing
  • US10164914B2 patent drawing

AI summary

A Network Function Virtualization (NFV) Software-Defined Network (SDN) communicates across network boundaries with other NFV SDNs to support a data communication service. An NFV orchestrator transfers forwarding graphs for service, NFV, and SDN Network-to-Network Interfaces (NNIs) to an SDN controller. The SDN controller converts the forwarding graphs into forwarding instructions and transfers the forwarding instructions for the service, NFV, and SDN NNIs to an NFV SDN switching system. The NFV orchestrator uses the NFV NNI to transfer its forwarding graphs over the NFV SDN switching system across the network boundary to another NFV orchestrator. The SDN controller uses the SDN NNI to transfer its forwarding instructions over the NFV SDN switching system across the network boundary to another SDN controller. The NFV SDN switching system uses the service NNI to transfer user data across the network boundary to another NFV SDN switching system.