Virtualized Network Function Verification Using Decentralized Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing validation of virtualized network functions (VNFs) using universal unique identifiers (UUIDs) is fragmented, lacking proof of authenticity between network service orchestrators and VNF providers, and between tenants and VNF instances, leading to trust issues and challenges in licensing and deployment.

Innovation Solution

The use of Decentralized Identifiers (DIDs) based on distributed ledger technology, such as blockchain, for verifying the integrity and authenticity of VNF images and instances, enabling secure deployment and dynamic licensing without the need for a centralized license server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If universal unique identifiers (UUIDs) are used for verifying VNF instances, then the deployment process is simple, but the system lacks proof of authenticity and trust between network service orchestrators and VNF providers

Engineering Contradiction:
Improveauthenticity verificationVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a DID document as an intermediary that contains cryptographic verification information. This document acts as a mediator between the verification system and VNF images, providing proof of authenticity without requiring complex direct verification mechanisms. The DID document includes public keys and verification data that enable trusted verification while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by generating and storing DID documents and cryptographic verification information before VNF image deployment. The verification data is prepared in advance and associated with VNF images, allowing rapid authentication during deployment without complex real-time verification processes.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If centralized license servers are used for VNF licensing, then license management is centralized and controlled, but the system requires additional infrastructure and deployment complexity

Engineering Contradiction:
Improvelicensing operationVSAvoidinfrastructure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service licensing where VNF images contain embedded licensing information and verification data within their DID documents. The system performs self-verification using cryptographic proofs embedded in the VNF images themselves, eliminating the need for external license servers or centralized licensing infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the licensing functionality from centralized license servers and embeds it directly within the VNF images through DID documents. This extraction eliminates the need for separate licensing infrastructure while maintaining license management capabilities within the VNF deployment process.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cryptographic verification is implemented for VNF images, then security and authenticity are improved, but the verification process and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the verification parameter from complex multi-factor authentication to simplified cryptographic signature verification. By using digital signatures and DID documents with embedded public keys, the system achieves strong security through mathematically sound verification that is computationally efficient and easier to implement than traditional cryptographic protocols.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11695568B1Virtualized network functions verification using decentralized identifiers
Publication Date: 2023.07.04 EQUINIX INC
  • US11695568B1 patent drawing
  • US11695568B1 patent drawing
  • US11695568B1 patent drawing

AI summary

This disclosure describes techniques for verifying virtualized network functions (VNFs) using Decentralized Identifiers (DIDs). For example, a system includes an orchestrator configured to obtain, using a Decentralized Identifier (DID) that is associated with a virtualized network function (VNF) image for a VNF, a DID document associated with the DID, verify, based on the DID document associated with the DID, the VNF image, and deploy the VNF image as a VNF instance on a Network Functions Virtualization infrastructure (NFVi). The system also includes one or more consensus networks that store the DID document associated with the VNF image in a distributed ledger.