NFV Secure Domain Configuration via Role and Location

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network functions virtualization infrastructure, there is a challenge in preventing unauthorized access to sensitive data within secure domains, particularly in ensuring that sensitive data is visible only to legitimate parties and adhering to national regulations regarding data storage and location.

Innovation Solution

A method and apparatus that configure a secure domain by utilizing a network functions virtualization orchestrator and virtualized infrastructure manager to allocate virtual objects based on confidentiality levels and geographic location, ensuring that only authorized parties with specific roles can access and manage sensitive data, and enforcing strict access controls and location restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual objects are allocated without strict access controls and location restrictions, then ease of operation and deployment is improved, but security of sensitive data deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity of sensitive data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the NFVI into multiple secure domains based on geographic location and confidentiality levels. Virtual objects are allocated to specific secure domains rather than a single unified environment, creating isolated segments that prevent unauthorized access while maintaining operational efficiency within each domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control policies and security configurations to different secure domains based on their specific geographic location and confidentiality requirements. Each domain has tailored access controls, location restrictions, and management policies suited to its specific security needs rather than a one-size-fits-all approach.

Inventive Principle:
Principle #3Local quality

2Reliability

If strict access controls and location restrictions are enforced, then security of sensitive data is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of sensitive dataVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the NFVO automatically discovers geographic location information, determines appropriate secure domains, and allocates virtual objects without manual intervention. The system self-configures access controls and location restrictions based on predefined policies, reducing operational complexity despite enhanced security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces new parameters (geographic location, secure domain ID, confidentiality level) to the virtual object allocation process. By formalizing these parameters and integrating them into the existing NFV orchestration framework, the system manages complexity through structured parameter handling rather than unstructured security configurations.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If virtual objects are allocated based on geographic location and confidentiality levels, then compliance with national regulations is improved, but allocation time and processing duration increase

Engineering Contradiction:
Improvecompliance with regulationsVSAvoidallocation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by discovering and storing geographic location information of virtual objects during the initial allocation phase. The NFVO proactively identifies suitable secure domains before actual object deployment, and pre-configures access controls and location restrictions, avoiding time-consuming compliance checks during operational phases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the NFVO continuously monitors the locations of virtual objects and verifies compliance with secure domain requirements. The system receives feedback about object placement and automatically adjusts allocations to maintain regulatory compliance, enabling real-time compliance verification without significant time overhead through efficient feedback loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10897467B2Method and arrangement for configuring a secure domain in a network functions virtualization infrastructure
Publication Date: 2021.01.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10897467B2 patent drawing
  • US10897467B2 patent drawing
  • US10897467B2 patent drawing

AI summary

It is disclosed a method, an arrangement and a computer program for configuring a secure domain, SD, in a network functions virtualization infrastructure. The SD comprises virtual objects handling privileged information. NS instance information of a virtual object is obtained based on input from a party associated with the SD. The NS instance information is searched for a level of confidentiality and a geographic location information. When having identified the level of confidentiality and the geographic location information, the virtual object is allocated to the SD according to the geographic location information, based on the level of confidentiality and a specific role of the party. It is an advantage that access to a SD is allowed or granted based on the specific role of the party.