NFV VNF Authentication via Element Manager Hash Chains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In NFV environments, managing and authenticating virtualized network functions (VNFs) is challenging, leading to potential contamination by malicious VNFs, and existing methods are inefficient and costly, lacking automated authentication and traffic control mechanisms.
Innovation Solution
A security communication method using hash chains for authentication between VNFs, where a Virtualized Infrastructure Manager generates and updates hash chains, and an Element Manager authenticates VNFs using these chains, generating secret keys for secure communication, with a VNF gateway controlling traffic based on security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the manager directly manages setting information of virtualized VNF using an element manager, then configuration control is achieved, but capital expenditure and operating expenses are high
Solution Approach 1:
The patent implements self-service automation where the element manager automatically performs VNF configuration management, authentication, and traffic control without requiring manual manager intervention. The system uses automated hash chain verification and policy-based routing to enable self-configuring VNFs, eliminating the need for expensive manual management operations while maintaining security and control.
2Ease of manufacture
If the VNF loaded in the tenant does not undergo a separate authentication process, then loading is simple, but malicious users may load malicious VNF to contaminate the entire tenants
Solution Approach 1:
The patent implements preliminary authentication action by requiring VNFs to undergo hash chain verification before being loaded into the tenant environment. The element manager verifies the VNF's authenticity by comparing its hash chain against authorized templates, ensuring that only legitimate VNFs are deployed. This preliminary security check prevents malicious VNFs from contaminating the tenant while maintaining a streamlined loading process.
3Reliability
If automated authentication and traffic control mechanisms are implemented, then security is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary element manager that mediates between VNFs and the NFV infrastructure, centralizing authentication and traffic control functions. The element manager acts as a trusted intermediary that verifies hash chains, manages secret keys, and enforces traffic policies, thereby implementing robust security mechanisms without requiring complex security logic to be distributed across multiple VNFs, thus managing system complexity through centralized coordination.
Data Source
AI summary
Provided is a security communication method in a NFV environment and a system thereof. A security communication method in the NFV environment according to an exemplary embodiment of the present invention is a security communication method between virtualized network functions (VNF) in a network function virtualization (NFV) environment including: performing authentication between a first VNF and a second VNF by an element manager using a hash chain; generating secret keys based on its own hash chains by the first VNF and the second VNF which are authenticated; and performing the communication by the first VNF and the second VNF using its own secret keys.


