VNF Packet Security Verification During Instantiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security verification of VNF packets in network function virtualization increases instantiation delay and reduces performance, as it is typically performed before instantiation.

Innovation Solution

Performing security verification on VNF packets during the instantiation process and sending verification results to allow network connection only after successful verification, thereby integrating security verification into the instantiation procedure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security verification is performed on VNF packets before instantiation, then security of VNF packet is ensured, but VNF instantiation delay increases and performance decreases

Engineering Contradiction:
Improvesecurity of VNF packetVSAvoidVNF instantiation delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security verification by adding signature files to VNF packets during storage, so that the verification data is prepared in advance. This allows the actual verification to be integrated into the instantiation process without adding significant delay, as the verification components are already available when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges security verification operations with the VNF instantiation process by having the verification result directly determine whether to proceed with instantiation. This integration eliminates separate verification steps and reduces overall delay, as verification and instantiation become a unified workflow rather than sequential independent operations.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If security verification is performed on VNF packets before instantiation, then security of VNF packet is ensured, but VNF instantiation performance decreases

Engineering Contradiction:
Improvesecurity of VNF packetVSAvoidVNF instantiation performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Signature files and verification data are prepared and stored in advance with VNF packets, so that during instantiation the system can perform verification efficiently without time-consuming setup or data preparation, thus maintaining high instantiation performance while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process is merged with instantiation operations, allowing both security checking and instance creation to proceed in an integrated manner. This reduces overhead and improves performance by eliminating redundant operations and optimizing the workflow to handle verification as part of the instantiation pipeline rather than a separate bottleneck.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10757129B2Software security verification method, device, and system
Publication Date: 2020.08.25 HUAWEI TECH CO LTD
  • US10757129B2 patent drawing
  • US10757129B2 patent drawing
  • US10757129B2 patent drawing

AI summary

The present invention discloses a software security verification method, a device, and a system, and relates to the communications field, so as to resolve a problem in the prior art that security verification on a VNF packet increases a VNF instantiation delay and reduces VNF instantiation performance. In a specific solution, after a first device receives an instantiation request of a VNF, the first device performs security verification on a stored VNF packet of the VNF when or after starting to instantiate the VNF according to the instantiation request of the VNF, and the first device sends first result information to a second device when security verification on the VNF packet of the VNF succeeds. The first result information includes information that security verification on the VNF packet of the VNF succeeds. The present invention is applied to software security verification.