Dynamic Security Service Chain Orchestration in NFV
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security appliances struggle to dynamically and adaptively meet the diverse security requirements of applications in NFV and SDN environments, as they are typically hardware-based and deployed at fixed locations, making it difficult to provide customized security services effectively.
Innovation Solution
A method and system that involve a first controller receiving a request to create a service chain, obtaining configuration information, generating a request for a sequence of user-oriented security functions, and deploying these functions in a predetermined order within the service chain, including authentication and authorization, to create a customized security service chain dynamically in the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional hardware-based security appliances are deployed at fixed locations, then network security protection is provided, but the system cannot dynamically adapt to different security requirements of applications in NFV and SDN environments
Solution Approach 1:
The patent transforms static hardware-based security appliances into dynamic virtual security functions that can be deployed, moved, and configured programmatically. The service chain orchestrator dynamically creates and manages service chains composed of virtual security functions, allowing the system to adapt to different security requirements of various applications while maintaining a unified management framework.
Solution Approach 2:
The patent creates virtual copies of security functions that can be instantiated multiple times across the network. Instead of relying on single physical security appliances, the system deploys virtual security function instances that can be replicated and distributed according to security policy requirements, enabling flexible adaptation without proportionally increasing physical hardware complexity.
2Adaptability or versatility
If customized security services are provided dynamically for different applications, then security adaptability is improved, but the complexity of managing and deploying security functions increases
Solution Approach 1:
The patent implements a universal service chain orchestrator that can manage diverse security functions through a single interface and unified workflow. The orchestrator provides multi-functional capabilities including service chain creation, security function selection, deployment management, and policy enforcement, allowing customized security services to be provisioned without proportionally increasing management complexity.
Solution Approach 2:
The service chain orchestrator acts as an intermediary between application requirements and security function deployment. It translates high-level security requirements into concrete service chain configurations, automatically selecting and orchestrating appropriate security functions from available resources, thereby reducing the complexity burden on operators while enabling customized security services.
3Adaptability or versatility
If security functions are deployed in a service chain architecture, then flexibility and dynamicity are improved, but the time required to establish security service chains increases
Solution Approach 1:
The patent pre-configures service chain templates with commonly used security function sequences and policies. When a new security service is required, the orchestrator can instantiate from these pre-prepared templates rather than building service chains from scratch, significantly reducing establishment time while maintaining the ability to dynamically customize security functions as needed.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Embodiments of the present disclosure relate to method and device for providing a security service. For example, a method comprises: in response to receiving, at a first controller, a first request to create a first service chain for an application in a network, obtaining configuration information associated with the security service from the first request; generating, based on the configuration information, a second request to create a sequence of security functions associated with the first service chain; sending the second request to a second controller so as to create the sequence of security functions in the network; and in response to receiving from the second controller an acknowledgement for the sequence of security functions, creating the first service chain based on the sequence of security functions. Embodiments of the present disclosure further provide a device capable of implementing the above method.