NFV vSW Hardware Trust Verification via Mediator Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of hardware trust into Software Defined Network (SDN) virtual switches (vSWs) operating in Network Function Virtualization (NFV) systems is inefficient and ineffective, hindering the secure communication between Virtual Network Functions (VNFs).

Innovation Solution

A Network Function Virtualization (NFV) Software Defined Network (SDN) system maintains hardware trusted communications by using a source and target trust controller to establish hardware trust with a trust server, which verifies and transfers Virtual Data Units (VDUs) only through hardware trusted vSWs, ensuring secure data transfer across physical boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware trust integration is implemented in SDN vSWs for NFV systems, then security and reliability of VNF communications is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvehardware trust verificationVSAvoidtrust controller integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces trust controllers as intermediary components that mediate between the hardware trust server and vSWs. The trust controllers establish hardware trust relationships with the trust server and verify target vSW trust status, acting as intermediaries that simplify the integration complexity while maintaining security. This mediator layer handles the complex trust verification logic centrally, reducing the burden on individual vSWs and making the overall system more manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware trust verification is performed for each VDU transfer between VNFs, then communication security is improved, but data transfer efficiency and speed decrease

Engineering Contradiction:
Improvecommunication securityVSAvoiddata transfer rate
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary hardware trust verification where the source trust controller verifies the target vSW's hardware trust status before VDU transfer begins. By performing this verification in advance rather than during each data transfer operation, the system ensures security while minimizing impact on transfer speed. The trust verification relationship is established beforehand, allowing subsequent transfers to proceed efficiently without repeated verification overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If physical boundaries are enforced for hardware trust verification, then security against unauthorized transfers is improved, but system adaptability and flexibility decrease

Engineering Contradiction:
Improveunauthorized transfer preventionVSAvoidcross-physical-network communication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal hardware trust verification mechanism that works across multiple physical networks and vSWs. The trust server and trust controllers establish a universal trust relationship that can verify hardware trust status regardless of which physical network or vSW is involved. This universal approach allows VNFs to communicate securely across different physical boundaries while maintaining the security guarantees of hardware trust verification, thereby increasing system adaptability without sacrificing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3488587B1Virtual network function (VNF) hardware trust in a network function virtualization (NFV) software defined network (SDN)
Publication Date: 2022.06.08 T MOBILE INNOVATIONS LLC
  • EP3488587B1 patent drawingFigure 1
  • EP3488587B1 patent drawingFigure 2
  • EP3488587B1 patent drawingFigure 3

AI summary

A Network Function Virtualization (NFV) Software Defined Network (SDN) (100, 600, 700) maintains hardware trusted communications. A source trust controller (141, 142) and a target trust controller (141, 142) establish hardware trust with a trust server (150). The trust server (150) exchanges information with the source trust controller (141, 142) that indicates the hardware trust for a target vSW (131, 132). The source trust controller (141, 142) exchanges the information with the source vSW (131, 132) that indicates the hardware trust for the target vSW (131, 132). The source vSW (131, 132) receives a Virtual Data Unit (VDU) from the source VNF (121, 122) for delivery to the target VNF (121, 122) over the target vSW (131, 132), and before transfer, the source vSW (131, 132) verifies hardware trust of the target vSW (131, 132) based on the HT information. Responsive to the hardware trust verification, the source vSW (131, 132) transfers the VDU for the delivery to the target vSW (131, 132). The target vSW (131, 132) transfers the VDU to the target VNF (121, 122).