Secure Inter-VNF Communication via NFVI Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized network environments, inter-virtual network function (VNF) and inter-virtual network function component (VNFC) communications over unprotected networks are vulnerable to security concerns such as unauthorized data snooping, data alteration, and privacy breaches, due to untrusted inter-platform communications.

Innovation Solution

A system that employs a network function virtualization infrastructure (NFVI) with a trusted execution environment (TEE) and cryptographic key management to establish secure communication channels between VNFs and VNFCs, ensuring encrypted communication without requiring vendors to modify their VNFs, thereby protecting against security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If inter-VNF and inter-VNFC communications are allowed over unprotected networks to enable flexible deployment, then adaptability and ease of operation are improved, but security and reliability deteriorate due to vulnerabilities to unauthorized data snooping, data alteration, and privacy breaches

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a network function virtualization infrastructure (NFVI) as an intermediary layer between VNFs and the underlying network. The NFVI includes a virtual switch that acts as a mediator to establish secure communication channels between VNFs, enabling them to communicate over unprotected networks while maintaining security through the intermediary's control and management of cryptographic keys and secure channel establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic key management and trusted execution environment are implemented to secure communications, then security and reliability are improved, but device complexity increases due to additional security infrastructure requirements

Engineering Contradiction:
Improvecommunication securityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the trusted execution environment (TEE) and cryptographic key management functions directly into the network function virtualization infrastructure, specifically within the virtual switch. This integration combines multiple security functions into a single unified component, reducing overall system complexity while maintaining strong security. The TEE provides a hardware-based secure environment for key management, eliminating the need for separate complex security infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If VNFs are required to be modified to implement security measures, then security is improved, but ease of manufacture and deployment deteriorate due to vendor modification requirements

Engineering Contradiction:
Improvesecurity protectionVSAvoidvendor implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Instead of modifying VNFs to implement security measures, the patent inverts the approach by implementing security measures in the NFVI layer that surrounds and protects the VNFs. The virtual switch and TEE provide security functionality without requiring any changes to the VNF code or implementation. This allows vendors to deploy their VNFs unchanged while still achieving strong security protection through the inverted security architecture.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUSRE48411E1Technologies for secure inter-virtual network function communication
Publication Date: 2021.01.26 INTEL CORP
  • USRE48411E1 patent drawing
  • USRE48411E1 patent drawing
  • USRE48411E1 patent drawing

AI summary

Technologies for secure inter-virtual network function communication include a computing device to determine a cryptographic key for secure communication over at least one of an inter-virtual network function (VNF) network, an inter-virtual network function component (VNFC) network, or a VNF-VNFC network based on a security policy of the computing device; and. The computing device securely communicates over at least one of the inter-VNF, inter-VNFC, or VNF-VNFC network based on the determined cryptographic key.