NFV VNF Authentication via Element Manager Hash Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In NFV environments, managing and authenticating virtualized network functions (VNFs) is challenging, leading to potential contamination by malicious VNFs, and existing methods are inefficient and costly, lacking automated authentication and traffic control mechanisms.

Innovation Solution

A security communication method using hash chains for authentication between VNFs, where a Virtualized Infrastructure Manager generates and updates hash chains, and an Element Manager authenticates VNFs using these chains, generating secret keys for secure communication, with a VNF gateway controlling traffic based on security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the manager directly manages setting information of virtualized VNF using an element manager, then configuration control is achieved, but capital expenditure and operating expenses are high

Engineering Contradiction:
Improveconfiguration managementVSAvoidoperating expenses
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent implements self-service automation where the element manager automatically performs VNF configuration management, authentication, and traffic control without requiring manual manager intervention. The system uses automated hash chain verification and policy-based routing to enable self-configuring VNFs, eliminating the need for expensive manual management operations while maintaining security and control.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If the VNF loaded in the tenant does not undergo a separate authentication process, then loading is simple, but malicious users may load malicious VNF to contaminate the entire tenants

Engineering Contradiction:
ImproveVNF loadingVSAvoidtenant security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary authentication action by requiring VNFs to undergo hash chain verification before being loaded into the tenant environment. The element manager verifies the VNF's authenticity by comparing its hash chain against authorized templates, ensuring that only legitimate VNFs are deployed. This preliminary security check prevents malicious VNFs from contaminating the tenant while maintaining a streamlined loading process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If automated authentication and traffic control mechanisms are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary element manager that mediates between VNFs and the NFV infrastructure, centralizing authentication and traffic control functions. The element manager acts as a trusted intermediary that verifies hash chains, manages secret keys, and enforces traffic policies, thereby implementing robust security mechanisms without requiring complex security logic to be distributed across multiple VNFs, thus managing system complexity through centralized coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11146385B2Security communication method in NFV environment and system thereof
Publication Date: 2021.10.12 THE IND & ACADEMIC COOP IN CHUNGNAM NAT UNIV (IAC)
  • US11146385B2 patent drawing
  • US11146385B2 patent drawing
  • US11146385B2 patent drawing

AI summary

Provided is a security communication method in a NFV environment and a system thereof. A security communication method in the NFV environment according to an exemplary embodiment of the present invention is a security communication method between virtualized network functions (VNF) in a network function virtualization (NFV) environment including: performing authentication between a first VNF and a second VNF by an element manager using a hash chain; generating secret keys based on its own hash chains by the first VNF and the second VNF which are authenticated; and performing the communication by the first VNF and the second VNF using its own secret keys.