VNF Package Access Control via Scope Parameter Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VNF packages are targeted at all user equipment, leading to relatively poor information security as they cannot be restricted to only authorized users, making it difficult to implement secure access control.

Innovation Solution

A VNF package operation method and apparatus that determines whether a VNF package is of a private type, allowing only authorized users to access it by verifying a scope parameter in the request message, and rejecting requests from unauthorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a VNF package is made accessible to all user equipment, then the ease of operation and usage is improved, but information security deteriorates

Engineering Contradiction:
Improveaccessibility of VNF packageVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the user base into authorized and unauthorized users by introducing a scope parameter that divides access rights. The VNF package operation is segmented into different paths: one for authorized users who provide the scope parameter and another for unauthorized users who are rejected, thereby resolving the contradiction between universal accessibility and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a VNF package is restricted to authorized users only, then information security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidaccessibility of VNF package
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The scope parameter acts as an intermediary mechanism that mediates between security requirements and operational ease. It provides a standardized interface for authorization verification, allowing the system to maintain security while simplifying the access process for authorized users who automatically include this parameter in their requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a scope parameter verification mechanism is added to VNF package operations, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidoperation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a new parameter (scope parameter) to the existing VNF package operation framework. This parameter-based approach allows the system to maintain its existing structure while adding security functionality, avoiding the need for a completely new complex mechanism. The scope parameter can take different values to indicate different authorization levels, providing flexibility without increasing structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3249527B1Operation method and device for VNF package
Publication Date: 2022.11.02 HUAWEI TECH CO LTD
  • EP3249527B1 patent drawingFigure 1
  • EP3249527B1 patent drawingFigure 2
  • EP3249527B1 patent drawingFigure 3~4

AI summary

The present invention relates to the field of communications technologies, and in particular, to a VNF package operation method and apparatus, so as to resolve a technical problem of relatively poor information security because a current VNF package is targeted at all user equipments instead of only some user equipments. A private type is defined in embodiments of the present invention. If a type of a VNF package is the private type, only an authorized user is allowed to use this VNF package, so that the VNF package can be opened to only some user equipments. A specific authorization scope may be self-defined. Therefore, information security is improved, and the problem that cannot be resolved in the prior art is resolved, so as to provide a better service for a user.