Security Slice Attestation for Network Element Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods for managing security assurance levels in network elements and security slices, particularly in network function virtualization environments.

Innovation Solution

An apparatus and method for determining the security status of network elements within security slices by sending requests to an attestation server for security attributes, processing these attributes to assess the security status, and ensuring that network elements meet required integrity levels before being added to the slice.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security attributes are verified for each network element before adding to security slice, then security assurance level is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs security attribute verification in advance before network elements are added to the security slice. The security status determination apparatus evaluates integrity levels, security configurations, and other attributes of network elements prior to their inclusion, ensuring that only elements meeting the required security thresholds are admitted. This preliminary action prevents security compromises while maintaining systematic control over the verification process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security attributes are verified for each network element before adding to security slice, then security assurance level is improved, but processing time increases

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security verifications are performed in advance during the network element onboarding process, before the element becomes operational in the security slice. This ensures that security checks are completed as part of the setup phase rather than during runtime operations, minimizing the impact on system performance and operational timing.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network elements with inadequate integrity are prevented from being added, then security status is improved, but network element availability decreases

Engineering Contradiction:
Improvesecurity statusVSAvoidnetwork element availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements differentiated security requirements for different network elements based on their specific integrity levels and security attributes. Rather than applying a uniform security threshold to all elements, the system evaluates each element's characteristics and determines appropriate security classifications and requirements. This allows elements with varying integrity levels to be incorporated into the security slice according to their specific security capabilities, optimizing both security posture and resource utilization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3696700B1Security status of security slices
Publication Date: 2026.01.14 NOKIA TECHNOLOGIES OY
  • EP3696700B1 patent drawingFigure 1
  • EP3696700B1 patent drawingFigure 2~3
  • EP3696700B1 patent drawingFigure 4~5

AI summary

An apparatus, method and computer program is described comprising: sending one or more requests to an attestation server, wherein each request requests security attributes corresponding to one of one or more network elements of a security slice of a system; receiving the requested security attributes from the attestation server; and processing the received security attributes to determine a security status of the security slice.