Dynamic Security Policy Deployment for Virtualized Network Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network systems utilizing NFV technology, manual configuration of security policies for virtualized network functions (VNFs) often fails to keep pace with changes in VNF lifecycles, leading to security policy bugs and compromised network security.

Innovation Solution

A method and apparatus for dynamically generating and deploying security policies by a management network element, such as a VNFM or NFVO, in response to changes in the lifecycle state of VNFs, ensuring timely adjustments to access control and isolation requirements between components and network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual configuration of security policies is used for VNFs, then initial security policy setup is simple, but security policies cannot keep pace with VNF lifecycle changes leading to security bugs

Engineering Contradiction:
Improveease of security policy configurationVSAvoidsecurity policy accuracy
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements dynamic security policy configuration that automatically adapts to VNF lifecycle changes. The system continuously monitors VNF states and dynamically generates updated security policies, transforming the static manual configuration process into a dynamic automated system that maintains security policy accuracy throughout the VNF lifecycle.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes a feedback mechanism where the system monitors VNF lifecycle events and automatically triggers security policy updates. This closed-loop feedback system ensures that security policies are continuously synchronized with actual VNF states, preventing security bugs caused by outdated policies.

Inventive Principle:
Principle #23Feedback

2Reliability

If security policies are manually updated for each VNF change, then security policy accuracy is maintained, but the complexity and time required for policy management increases

Engineering Contradiction:
Improvesecurity policy accuracyVSAvoidsecurity policy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the system automatically generates and updates security policies based on monitored VNF lifecycle events. This eliminates the need for manual security policy updates, reducing management complexity while maintaining high accuracy through automated policy generation tied to actual VNF state changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-defining security policy templates and rules that are automatically applied when VNF lifecycle events occur. This preparation work is done in advance, allowing the system to rapidly generate accurate security policies without complex manual configuration when changes occur.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If manual security policy configuration is used, then initial setup is straightforward, but timely detection and adjustment of security policies after VNF changes is difficult

Engineering Contradiction:
Improveease of initial security policy setupVSAvoidtime delay in security policy updates
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent implements real-time feedback monitoring of VNF lifecycle events that automatically triggers security policy updates. This immediate feedback mechanism eliminates time delays by detecting VNF changes as they occur and instantly generating corresponding security policy updates, maintaining continuous security protection.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent ensures continuous security policy maintenance through automated monitoring and update mechanisms that operate throughout the entire VNF lifecycle. This continuous action eliminates gaps in security policy protection that would occur with periodic manual updates, maintaining constant security alignment with VNF states.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11489873B2Security policy deployment method and apparatus
Publication Date: 2022.11.01 HUAWEI TECH CO LTD
  • US11489873B2 patent drawing
  • US11489873B2 patent drawing

AI summary

A security policy deployment method and apparatus are provided, and the method includes: when a lifecycle state of a virtualized network function VNF changes, generating, by a management network element, a security policy of the VNF, where the security policy of the VNF is used to perform access control on the VNF; and sending, by the management network element, the security policy of the VNF to a control device. The management network element is a network element configured to perform lifecycle management on the VNF. By using the method or apparatus provided in embodiments of this application, the security policy of the VNF can be adjusted in time when the lifecycle state of the VNF changes, thereby greatly reducing a possibility that a bug occurs in the security policy of the VNF because the VNF changes.