NFV Secure Domain Configuration via Role and Location
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network functions virtualization infrastructure, there is a challenge in preventing unauthorized access to sensitive data within secure domains, particularly in ensuring that sensitive data is visible only to legitimate parties and adhering to national regulations regarding data storage and location.
Innovation Solution
A method and apparatus that configure a secure domain by utilizing a network functions virtualization orchestrator and virtualized infrastructure manager to allocate virtual objects based on confidentiality levels and geographic location, ensuring that only authorized parties with specific roles can access and manage sensitive data, and enforcing strict access controls and location restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual objects are allocated without strict access controls and location restrictions, then ease of operation and deployment is improved, but security of sensitive data deteriorates
Solution Approach 1:
The patent segments the NFVI into multiple secure domains based on geographic location and confidentiality levels. Virtual objects are allocated to specific secure domains rather than a single unified environment, creating isolated segments that prevent unauthorized access while maintaining operational efficiency within each domain.
Solution Approach 2:
The patent applies different access control policies and security configurations to different secure domains based on their specific geographic location and confidentiality requirements. Each domain has tailored access controls, location restrictions, and management policies suited to its specific security needs rather than a one-size-fits-all approach.
2Reliability
If strict access controls and location restrictions are enforced, then security of sensitive data is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the NFVO automatically discovers geographic location information, determines appropriate secure domains, and allocates virtual objects without manual intervention. The system self-configures access controls and location restrictions based on predefined policies, reducing operational complexity despite enhanced security requirements.
Solution Approach 2:
The patent introduces new parameters (geographic location, secure domain ID, confidentiality level) to the virtual object allocation process. By formalizing these parameters and integrating them into the existing NFV orchestration framework, the system manages complexity through structured parameter handling rather than unstructured security configurations.
3Reliability
If virtual objects are allocated based on geographic location and confidentiality levels, then compliance with national regulations is improved, but allocation time and processing duration increase
Solution Approach 1:
The patent performs preliminary actions by discovering and storing geographic location information of virtual objects during the initial allocation phase. The NFVO proactively identifies suitable secure domains before actual object deployment, and pre-configures access controls and location restrictions, avoiding time-consuming compliance checks during operational phases.
Solution Approach 2:
The patent implements feedback mechanisms where the NFVO continuously monitors the locations of virtual objects and verifies compliance with secure domain requirements. The system receives feedback about object placement and automatically adjusts allocations to maintain regulatory compliance, enabling real-time compliance verification without significant time overhead through efficient feedback loops.
Data Source
AI summary
It is disclosed a method, an arrangement and a computer program for configuring a secure domain, SD, in a network functions virtualization infrastructure. The SD comprises virtual objects handling privileged information. NS instance information of a virtual object is obtained based on input from a party associated with the SD. The NS instance information is searched for a level of confidentiality and a geographic location information. When having identified the level of confidentiality and the geographic location information, the virtual object is allocated to the SD according to the geographic location information, based on the level of confidentiality and a specific role of the party. It is an advantage that access to a SD is allowed or granted based on the specific role of the party.


