Zero-Touch VNF Provisioning via Secure Out-of-Band Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional approach to deploying and managing virtual network functions (VNFs) is hindered by the need for manual installation and configuration, leading to increased costs and delays in network service rollouts, as well as challenges in modifying or updating VNFs hosted by third-party developers.

Innovation Solution

The implementation of pre-configured universal customer premises equipment (uCPE) with a wireless interface that connects to an automatic configuration server (ACS) via a wireless access network, enabling secure, encrypted tunneling for VNF configuration and persistent management, allowing for zero-touch provisioning and management of VNFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual installation and configuration of VNFs is used, then device complexity is reduced, but productivity decreases and loss of time increases

Engineering Contradiction:
ImproveVNF deployment speedVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring VNF packages with all necessary configuration data before deployment. The configuration server prepares VNF configurations in advance, and the uCPE device receives pre-packaged VNFs that are ready for immediate deployment without requiring manual configuration during installation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The uCPE device automatically receives, installs, and configures VNFs through self-service mechanisms. The device can autonomously download VNF packages from the configuration server, extract configuration data, and apply settings without human intervention, enabling automated deployment and management of virtual network functions.

Inventive Principle:
Principle #25Self-service

2Loss of time

If manual configuration is used, then ease of operation is maintained, but loss of time increases

Engineering Contradiction:
Improvedeployment timeVSAvoidautomation level
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The system implements self-service automation where the uCPE device automatically receives VNF packages, installs them, and applies configurations without manual intervention. The configuration server automatically manages VNF deployment, updating, and modification processes, significantly reducing deployment time while maintaining operational simplicity through automated workflows.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The configuration server acts as an intermediary between the VNF provider and the uCPE device. It automatically manages the deployment process by receiving VNF requests, preparing configuration packages, transmitting them to the appropriate uCPE devices, and coordinating updates and modifications, thereby eliminating the need for manual configuration while streamlining the overall process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If third-party VNF hosting is used, then adaptability increases, but reliability decreases due to security challenges

Engineering Contradiction:
ImproveVNF provider flexibilityVSAvoidconfiguration security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The configuration server serves as a secure intermediary between third-party VNF providers and the uCPE infrastructure. It receives VNF configurations from external providers, validates and secures the configuration data, and then distributes it to authorized devices. This intermediary layer maintains security control while enabling flexible integration of VNFs from multiple providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service security mechanisms where the configuration server automatically authenticates VNF providers, validates configuration data integrity, and manages secure distribution. The uCPE device automatically verifies received configurations and applies them through secured processes, maintaining reliability while enabling adaptability to third-party VNFs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11588695B2Method and system for secure zero touch device provisioning
Publication Date: 2023.02.21 VERIZON PATENT & LICENSING INC
  • US11588695B2 patent drawing
  • US11588695B2 patent drawing
  • US11588695B2 patent drawing

AI summary

A customer premises device may include a memory configured to store day 0 configuration instructions, a first network interface to couple to an out-of-band network, a second network interface operatively coupled to a customer network, and at least one processor configured to automatically and without user input execute the day 0 configuration instructions. The at least one processor is configured to establish and maintain a secure tunnel connection with a security gateway device via the out-of-band network and to establish a connection with a configuration platform on the provider network via the secure tunnel connection. Orchestration instructions for configuring one or more VNFs are received from the configuration platform via the tunnel connection. The at least one processor is further configured to receive VNF management instructions via the secure tunnel connection, wherein the VNF management instructions include one of: updates, reconfigurations, or patches.