Security Slice Attestation for Network Element Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack effective methods for managing security assurance levels in network elements and security slices, particularly in network function virtualization environments.
Innovation Solution
An apparatus and method for determining the security status of network elements within security slices by sending requests to an attestation server for security attributes, processing these attributes to assess the security status, and ensuring that network elements meet required integrity levels before being added to the slice.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security attributes are verified for each network element before adding to security slice, then security assurance level is improved, but system complexity and processing time increase
Solution Approach 1:
The patent performs security attribute verification in advance before network elements are added to the security slice. The security status determination apparatus evaluates integrity levels, security configurations, and other attributes of network elements prior to their inclusion, ensuring that only elements meeting the required security thresholds are admitted. This preliminary action prevents security compromises while maintaining systematic control over the verification process.
2Reliability
If security attributes are verified for each network element before adding to security slice, then security assurance level is improved, but processing time increases
Solution Approach 1:
Security verifications are performed in advance during the network element onboarding process, before the element becomes operational in the security slice. This ensures that security checks are completed as part of the setup phase rather than during runtime operations, minimizing the impact on system performance and operational timing.
3Reliability
If network elements with inadequate integrity are prevented from being added, then security status is improved, but network element availability decreases
Solution Approach 1:
The patent implements differentiated security requirements for different network elements based on their specific integrity levels and security attributes. Rather than applying a uniform security threshold to all elements, the system evaluates each element's characteristics and determines appropriate security classifications and requirements. This allows elements with varying integrity levels to be incorporated into the security slice according to their specific security capabilities, optimizing both security posture and resource utilization.
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
An apparatus, method and computer program is described comprising: sending one or more requests to an attestation server, wherein each request requests security attributes corresponding to one of one or more network elements of a security slice of a system; receiving the requested security attributes from the attestation server; and processing the received security attributes to determine a security status of the security slice.