NFV vSW Hardware Trust Verification via Mediator Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of hardware trust into Software Defined Network (SDN) virtual switches (vSWs) operating in Network Function Virtualization (NFV) systems is inefficient and ineffective, hindering the secure communication between Virtual Network Functions (VNFs).
Innovation Solution
A Network Function Virtualization (NFV) Software Defined Network (SDN) system maintains hardware trusted communications by using a source and target trust controller to establish hardware trust with a trust server, which verifies and transfers Virtual Data Units (VDUs) only through hardware trusted vSWs, ensuring secure data transfer across physical boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware trust integration is implemented in SDN vSWs for NFV systems, then security and reliability of VNF communications is improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces trust controllers as intermediary components that mediate between the hardware trust server and vSWs. The trust controllers establish hardware trust relationships with the trust server and verify target vSW trust status, acting as intermediaries that simplify the integration complexity while maintaining security. This mediator layer handles the complex trust verification logic centrally, reducing the burden on individual vSWs and making the overall system more manageable.
2Reliability
If hardware trust verification is performed for each VDU transfer between VNFs, then communication security is improved, but data transfer efficiency and speed decrease
Solution Approach 1:
The patent implements preliminary hardware trust verification where the source trust controller verifies the target vSW's hardware trust status before VDU transfer begins. By performing this verification in advance rather than during each data transfer operation, the system ensures security while minimizing impact on transfer speed. The trust verification relationship is established beforehand, allowing subsequent transfers to proceed efficiently without repeated verification overhead.
3Reliability
If physical boundaries are enforced for hardware trust verification, then security against unauthorized transfers is improved, but system adaptability and flexibility decrease
Solution Approach 1:
The patent creates a universal hardware trust verification mechanism that works across multiple physical networks and vSWs. The trust server and trust controllers establish a universal trust relationship that can verify hardware trust status regardless of which physical network or vSW is involved. This universal approach allows VNFs to communicate securely across different physical boundaries while maintaining the security guarantees of hardware trust verification, thereby increasing system adaptability without sacrificing security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A Network Function Virtualization (NFV) Software Defined Network (SDN) (100, 600, 700) maintains hardware trusted communications. A source trust controller (141, 142) and a target trust controller (141, 142) establish hardware trust with a trust server (150). The trust server (150) exchanges information with the source trust controller (141, 142) that indicates the hardware trust for a target vSW (131, 132). The source trust controller (141, 142) exchanges the information with the source vSW (131, 132) that indicates the hardware trust for the target vSW (131, 132). The source vSW (131, 132) receives a Virtual Data Unit (VDU) from the source VNF (121, 122) for delivery to the target VNF (121, 122) over the target vSW (131, 132), and before transfer, the source vSW (131, 132) verifies hardware trust of the target vSW (131, 132) based on the HT information. Responsive to the hardware trust verification, the source vSW (131, 132) transfers the VDU for the delivery to the target vSW (131, 132). The target vSW (131, 132) transfers the VDU to the target VNF (121, 122).