Dynamic Security Service Chain Orchestration in NFV

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security appliances struggle to dynamically and adaptively meet the diverse security requirements of applications in NFV and SDN environments, as they are typically hardware-based and deployed at fixed locations, making it difficult to provide customized security services effectively.

Innovation Solution

A method and system that involve a first controller receiving a request to create a service chain, obtaining configuration information, generating a request for a sequence of user-oriented security functions, and deploying these functions in a predetermined order within the service chain, including authentication and authorization, to create a customized security service chain dynamically in the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional hardware-based security appliances are deployed at fixed locations, then network security protection is provided, but the system cannot dynamically adapt to different security requirements of applications in NFV and SDN environments

Engineering Contradiction:
Improveadaptability to different security requirementsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms static hardware-based security appliances into dynamic virtual security functions that can be deployed, moved, and configured programmatically. The service chain orchestrator dynamically creates and manages service chains composed of virtual security functions, allowing the system to adapt to different security requirements of various applications while maintaining a unified management framework.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates virtual copies of security functions that can be instantiated multiple times across the network. Instead of relying on single physical security appliances, the system deploys virtual security function instances that can be replicated and distributed according to security policy requirements, enabling flexible adaptation without proportionally increasing physical hardware complexity.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If customized security services are provided dynamically for different applications, then security adaptability is improved, but the complexity of managing and deploying security functions increases

Engineering Contradiction:
Improvecustomized security service capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal service chain orchestrator that can manage diverse security functions through a single interface and unified workflow. The orchestrator provides multi-functional capabilities including service chain creation, security function selection, deployment management, and policy enforcement, allowing customized security services to be provisioned without proportionally increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The service chain orchestrator acts as an intermediary between application requirements and security function deployment. It translates high-level security requirements into concrete service chain configurations, automatically selecting and orchestrating appropriate security functions from available resources, thereby reducing the complexity burden on operators while enabling customized security services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security functions are deployed in a service chain architecture, then flexibility and dynamicity are improved, but the time required to establish security service chains increases

Engineering Contradiction:
Improvedynamic deployment capabilityVSAvoidservice chain establishment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent pre-configures service chain templates with commonly used security function sequences and policies. When a new security service is required, the orchestrator can instantiate from these pre-prepared templates rather than building service chains from scratch, significantly reducing establishment time while maintaining the ability to dynamically customize security functions as needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3580910B1Method and device for providing a security service
Publication Date: 2024.07.10 ALCATEL LUCENT SA
  • EP3580910B1 patent drawingFigure 1
  • EP3580910B1 patent drawingFigure 2~3
  • EP3580910B1 patent drawingFigure 4

AI summary

Embodiments of the present disclosure relate to method and device for providing a security service. For example, a method comprises: in response to receiving, at a first controller, a first request to create a first service chain for an application in a network, obtaining configuration information associated with the security service from the first request; generating, based on the configuration information, a second request to create a sequence of security functions associated with the first service chain; sending the second request to a second controller so as to create the sequence of security functions in the network; and in response to receiving from the second controller an acknowledgement for the sequence of security functions, creating the first service chain based on the sequence of security functions. Embodiments of the present disclosure further provide a device capable of implementing the above method.