VNF Software Installation File Tamper Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software verification methods for virtualized network elements in cloud environments are prone to security risks due to manual verification reliance on personal skills and inability to ensure file integrity within installation packages.
Innovation Solution
A method and apparatus for automatically verifying installation files of VNF software using signature files to determine if the software has been tampered with, involving obtaining and verifying installation files and signature files, and performing integrity protection if modifications are detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual Hash verification method is used, then verification process is simple, but security risk increases due to personal factors and skill requirements
Solution Approach 1:
The verification system performs automatic verification without human intervention. The verification device autonomously obtains installation files, calculates Hash values, compares them with stored standard values, and generates verification results, eliminating dependency on operator skills and reducing security risks associated with manual verification.
Solution Approach 2:
The patent replaces the manual mechanical verification process with an automated electronic verification system. Instead of operators manually calculating Hash values and comparing them, the system uses automated software to perform these operations, substituting human actions with machine-based processes that are more reliable and consistent.
2Productivity
If Hash verification is performed on installation package, then package-level verification is achieved, but individual file integrity within package cannot be ensured
Solution Approach 1:
The verification system segments the verification process into two levels: package-level verification and individual file verification. The device first verifies the installation package as a whole, then extracts and verifies each individual file within the package separately. This segmentation allows comprehensive verification of all files while maintaining efficient automated processing.
3Reliability
If automated verification is implemented, then security risk is reduced, but verification system complexity increases
Solution Approach 1:
The verification device is designed with multi-functionality to handle various verification tasks within a single system. It can perform package-level verification, individual file verification, Hash value calculation, comparison with standard values, and result generation. This universality consolidates multiple functions into one device, managing complexity while providing comprehensive verification capabilities.
Data Source
AI summary
A software verification method and apparatus are disclosed, applied to the cloud computing field and the communications field, and can be used to automatically verify whether an installation file of VNF software has been tampered with. The method includes: obtaining installation files of VNF software and signature files of the installation files, where the signature files of the installation files are used to store verification information of the installation files; verifying the installation files according to the signature files of the installation files; and determining, if the verification of the installation files succeeds, that the VNF software has not been tampered with.


