Sign In to Follow Application
View All Documents & Correspondence

Network Function Virtualization System And Verifying Method

Abstract: The present invention provides a virtualized environments which has an improved function for protecting sensitive authentication data. A network function virtualization system, comprises a request receiving unit that receives a request to certificate of at least one of data exchanging parties ; a private key generator that generates a first private key information using a second private key information stored in the hardware-based isolated secure execution environment, in response to a request; a public key extractor that extracts a public key information of the first private key information; a public key information storage unit that stores the public key information; and a verifying unit that is accessible from the request receiving unit and the verifying unit verifies the certificate using the public key information corresponding to the certificate.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
08 September 2016
Publication Number
10/2018
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 108-8001, Japan

Inventors

1. SINGARAVELU Pradheepkumar
c/o NEC Mobile network Excellence Centre, NEC India Pvt Ltd, SP Infocity, Block-A, 9th floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennnai - 600 096, India
2. ARUMUGAM Sivabalan
c/o NEC Mobile network Excellence Centre, NEC India Pvt Ltd, SP Infocity, Block-A, 9th floor, Module-2A, 40, MGR Salai, Kandanchavadi, Perungudi, Chennnai - 600 096, India
3. PRASAD Anand
c/o NEC CORPORATION, 7-1, Shiba 5-chome, Minato-ku, Tokyo 108-8001, Japan
4. ITO Hironori
c/o NEC CORPORATION, 7-1, Shiba 5-chome, Minato-ku, Tokyo 108-8001, Japan

Specification

[DESCRIPTION]
[Title]
NETWORK FUNCTION VIRTUALIZ ATION SYSTEM AND VERIFYING
METHOD
[Technical Field]
[0001]
The present invention relates to a network function v i r t u a l i z a t i on
system and a verifying method.
[Background]
[0002]
Network functions v i r t u a l i z a t i o n (NFV) is proposed as described
in Non Patent Literatures 1 and 2. Network functions v i r t u a l i z a t i on
(NFV) is a unified orchestration platform that introduces unique
opportunities of addressing security problems due to unprecedented
scale, complex and disjointed virtual environment, flexibility and
central control management. Resources for virtual nodes (like
compute, storage and network) have to be dynamically allocated in a
controlled environment, which requires dynamic security mechanism.
A novel approach is required to solve this NFV related security problem,
which should have the capability to address the security requirements
across all layers such as platform level, virtualized network level and
application levels. The dynamic nature of NFV system demands
security mechanism, policies, processes and practices that should be
embedded in the genetic fabric of NFV. The proposed framework
should provision confidentiality, integrity and privacy for NFV
operation and also should f a c i l i t a t e strong authentication mechanism to
secure the services and credentials of the systems.
[0003]
NFV system brings new security challenges which are listed
below
Exploit or violation due to native v u l n e r a b i l i t i e s of VNFs
Exploit or violation due to vulnerabilities of virtualization
software
Exploit or violation due to v u l n e r a b i l i t i e s of VNF images
Exploit or violation due to administrative errors
Malicious tenant or neighbor
Rogue insider
Exploit or violation due to vulnerabilities of hardware and
firmware
Information leakage during VM (Virtual machine) crashing
Privilege escalation and verify the i d e n t i t i e s of each service at a
given layer
Verify the security patches which are required for upgradation
without disturbing the NFV services
Handling of zero-day v u l n e r a b i l i t i es
Managing the trust for third party vendors or users
[0004]
In a cloud environment, multi -tenancy drives the need for logical
separation of virtual resources among tenants. Through NFV
orchestration, certain VNFs can be deployed on separate compute nodes,
and they can be further segregated by using separate networks. In
addition, the use of security zones allows VNFs to be deployed on or
migrated to hosts that satisfy security-pertinent criteria such as
location and level of hardening for example, some hosts will employ the
trusted computing technology i.e., Hardware Isolated Secured
Execution Environment(HISEE). HISEE provides a safe environment
for secure data on the chip. With HISEE, full bus-bandwidth access is
provided to all storage areas to provide fast memory access speeds. It
provides flexibility to allow customization and upgrades to the secure
system even after the SoC (Systems on Chip) is finalized. HISEE
defines a secured environment within the embedded system.
The HISEE are designed to protect against or mitigate the potential
damage caused by a variety of threats and attacks.
[0005]
Patent L i t e r a t u r e s 1 to 3 describe existing solutions related to the
present invention.
[Citation List]
[Patent Literature]
[ 000 6]
[PTL 1] US 9043604 B2
[PTL 2] US 2013/0339739 A1
[PTL 3] US 8925055 B2
5 [ Non Pa te nt Lit e rat ure ]
[ 000 7]
[NPL 1]
E urop ea n Te le c omm un ic a t i on s St a nda r d s I nst i tut e (ETSI) , " Ne tw ork
F u n c t i on s Vi r tu al i sa ti on - U pda te Wh i te Paper " , [o n l i ne ], [ Sea rc he d o n
10 Au gu s t 2 5, 20 16], I n te rnet ,
[NPL 2]
E urop ea n Te le c omm un ic a t i on s St a nda r d s I nst i tut e (ETSI) , " Ne tw ork
Functions Virtualisation ; Architectural Framework (ETSI GS NFV
15 002)", [Searched on August 25, 2016], Internet
[Summary]
[ Tech n ic a l Prob le m]
20 [0008]
T he disc lo s u re s of Pat ent Lit e ra t u re s 1 t o 3 a nd N on Paten t
L i t e r a t u r e s 1 and 2 given above are hereby incorporated in their e n t i r e ty
by refere nc e in to t hi s sp ecif ic a t i on . T he f ol lo wi ng a nal ys is is mad e b y
t he in ve nt or of t he pre s ent in ve n t i on .
25 [0009]
Ac co r d i ng t o i nve nt or ' s o f p re se n t disc lo s u re ana l ys i s, foll ow i ng
prob le ms t o b e s olve d are r e ma i ne d.
Problem 1: Gaps in HISEE for NFV Environment
Da t a s uc h a s a sec u r e c re de nt ia l, co nf i de n t i a l da ta , prof i le o f ne tw ork
30 an d su bsc ri ber ac t i v i t ie s, c a n be leake d t o a th i rd part y in a n u nse c u re
manner if a third party and secure mechanism collude . It has been
a rgu e d tha t HISEE wo n ' t c omp romi s e, bu t ca n not gu a ra n te e that
colluding will never happen. It has to s a c r i f i c e s e c u r i t y and privacy in
order to de t e c t i nva l i d HISEE 's a tt es ta ti on s . It s ho uld a l so be n o te d
4
t ha t t he H I S EE c an no t p r o t e c t a ga in st ma n y of a t ta c ks t ha t t h r e a t en
s e c u r i t y and privacy of network or subscriber a c t i v i t i e s . For instance,
most viruses nowadays exploit the s c r i p t i n g languages in many products .
I n such a ca s e , the a pp l i ca t io n w i l l be tru s te d by HISEE s yst e m;
5 ho wever ne tw ork an d su b s c r i be r a c t i vit ie s or d at a c o uld ac tua ll y be
co m p ro mi se d co ve r tl y. Al s o th e HI S E E do es no t re du ce t he th rea t f r om
t he lik e s o f s pyw a re s th a t c oul d mo nit or net wo r k a nd e ve nt se r vi c es
ac t i v i ti e s, su c h a s as s ign in g VM (Vir tua l Mac hi ne) to a vi r t ual ne t work,
co nnec t in g VM to e x te r n a l ne t wo r k, at ta ch i ng n e tw ork servi c e s be tw ee n
10 V M ' s, te na nt m i g r a t i on, sha r in g th e reso u rc e, VNF pa c ka ge up gr a dat io n,
o n - boa r d i ng pa c ka ge s, e tc . A dd it i onal ly, it i s vul ne ra b le t o po we r
an a l y s i s w h i ch ca n bre ak ta m pe r - e v i de n t pro pe rt y of the HISE E b y
be i ng ab le t o ex t ra ct i nfo r ma ti on fro m pro t e c t ed st ora ge wit hou t bei ng
de t e c t e d .
15 [0010]
P r obl e m 2: Sen s i t i ve dat a l ea ka ge
As il lu st r a t ed in t he bo x # 3 of Fi g . 3 8, N FV r out i ne l y p os s e s s se nsi t i ve
da ta (su c h as passw ord s, p r iva te ke ys , c r ypt og r a ph ic c e rtif ica te s,
t o ken s, e tc ) wh ic h a r e use d f o r au t he n t ic at io n of p r o c e s s , se r v i c e ,
20 a gent s a nd users . T he se da ta s ho ul d be pro te c te d du r in g a l l ph a se s of
the NFV lifecycle management and should be considered highly dynamic
i n natu r e, wi th u pda t es like l y d u r in g in s t an t ia ti on,
hi bern at io n/ s u sp e nsi on, a nd VN F ret i re me n t . Fo r e xa m p l e , le t 's
di sc u s s a b ou t th e im port a nce of pro te ct in g t he p r iv a te k e y. If t he
25 private ke y i s com p ro mi s e d i. e . , att ac ke r m igh t ha ve o bta i ned t he
private ke y a nd ha d re ad all t he e ncryp te d s en t/ r ec e i ve d me s sa ge s un de r
the corresponding public key and forged the signatures . The
se r io usne ss of the se c on seq ue nc es e nsu re s t he im po r t ance of p ro t e c t in g
t he pri va te key wi th se c u re mec ha ni sm s . Rece n t l y a n a t ta c k was
30 pe rf orme d a nd dem on st r a t ed the vi ab il i ty of co -l oca ti on an d re su lt e d
f i rs t c onc re t e p r oof f or sen si t i ve in f orm a t i on le a ka ge o n a c omm e r c ia l
cl oud en v i ro nmen t . T he c o - l oc a t i on dete c t io n ca n be e na b le d a n d
de t e c t e d b y reso u rc e sh a r in g bet wee n te na nt vi r t u al ma c hin es . Under
ce r ta in c on d i t i on s, t he s am e me ch a n i sm c a n a l so be e xpl oit e d t o ex t ra ct
5
se nsi t i v e info rma t io n fro m a c o - l oc a t e d vi c t im VM s, re sul t in g i n
s e c u r i t y and priva cy breaches. They have presented the f u l l - f l e d g ed
at t a ck tha t ex pl oit s s ubt le le a kages to reco ve r RSA decryp ti on ke ys
from a co-located i n s t a n c e . As i l l u s t r a t e d in the box #2 of Fi g. 38,
5 Prime and Probe attack was performed to recover noisy keys from a
ca ref u l l y m oni to r ed c lo ud V M runn in g t he a f o re men ti one d vul nera b le
l i b r a r i e s.
[ 0011 ]
P r obl e m 3: Ma nag in g t h e tru s t of t r u s t e d t h i rd pa rt y ow ne r
10 The problem for all the authentication mechanism in NFV system is
ba sed on t he le ve l of t rust on a ut hent ica ti on se r ve rs (f or e . g. : pu b l i c
ke y c ryp to gra p hy ( P KC ) ) . I n t ra dit io na l cryp to syste m , the re is a n
as s um p t i on t ha t a ut he n t i c a ti on ser v e r s a re tru st e d s uc h th at t he y ne ve r
f a i l an d d i fficul t t o c omp r om i se . Ho we ve r, i n re al t i m e scen a r i o , th is
15 as s um p t i on doe s n' t oc cu r.
Although such servers a re kept in physically secured environments,
there is still a chance for an attacker to hijack the secure operations
r emo te l y . The s e cu r it y p r ob le m a r i s e s o nly if t he p r i va te ke y of a
dedicated authentication server is compromised . In PKC system, an
20 at t a ck er c a n c re a te va li d cre dent ia ls by sp oof i ng ce r t i f i c a t e s a nd
ge t ti ng t he s ecu re c re dent ia ls of a Ce r tif ica te Au t h o r i ty ( C A ) , an d c an
impersonate any user which trusts the compromised CA by using the
ce r t i f i ca te s. Onc e th is c om prom i se i s ide n t i f i ed , a l l o f t he c e r ti fica te s
t ha t a r e i s sued by thi s CA mu s t be re vo ke d rec u r s i ve l y. If the p ri va te
25 ke y of t he t op le ve l a u th o r i ty i s c om p ro mi s e d, the n a ll o f th e
ce r t i f i ca te s of th e s yst e m sh ou l d b e re vo ke d . Th e re vo ked c e r ti fica te s
ca n c r e a t e a s ec u r i ty bot t le ne c k f or t he NFV syst e m .
[0012]
As descri be d a bo v e , s e c u r i t y i s c ri ti cal f o r NF V s ys te m, si nc e
30 network services and data protection are especially important for
t r u s t ed th i rd p a r ty a re u nsu re , w he t he r th e y w a nt t o m ove the se c u re
c re de nt ia ls a n d n et wo r k f u nct io na l i t i e s int o t he cl ou d. Wi th out t he
ob li ga to r y a ssu ra nc e s, t r u s t e d t hi r d pa r ty ve nd or wil l be rel uc ta nt to
ad opt N FV b as e d se r v i c e s . T he refo r e, N F V s ho uld p ro vid e a d di ti onal
6
se c u r i t y a nd p rot e ct ion f or t he se nsi t i v e data a nd t he ir se r vi c e s .
[0013]
S o the p r op os e d fra me wo rk sh ou ld a dd re ss the sec u r i t y the
prob le ms s uch as se n s i ti ve da ta l e ak a ge a nd mana gi n g t he t r ust of
5 t r u s t ed t hi rd p a r ty by the s am e way it s ho ul d c on s t r uc t se c u r i ty syst em
wh i ch s up po rt s au t he n t ic i t y , in t e g r i t y a nd n on - r ep udi a ti o n by
m i ni mi zi ng th e risk s a nd m a na gi n g t he tru st amo ng t he tru s te d th i rd
pa rt y se r ve rs . NFV s ys tems ha ve w i de va r i e t i e s of th r ea t which mi ght
be known or unknown. Threats like networking attack from a VM like
10 ad d re s s re sol u t i on pro t oc ol ( AR P) po i so ni n g, man in t he m id d le ,
co nfid e n t ia li ty an d i n te g r i t y of traff i c , aut hent ic a t i on a nd a uth ori za t i on
( i nc lu di ng du r in g i ni t i a l de pl oymen t ) , a ut hen t ic a ti on a nd a u t h o r i z a t io n
of API ( App li ca ti on Prog r a mm i ng I nt e rfa c e ) , m i sc onfi gu r at i on, s te a li ng
a VM, pa tc hi n g , ap p l ic a t io n l a ye r at t ac k, au th o r i za ti on an d
15 au t he nt ic at i on o f c o nf igu ra ti on, unau th o r i ze d s to ra ge ac ce s s ,
du p l i c a ti ng VM i ma ge en c rypt io n a nd ta m pe ri ng e nc r yp t e d se nsi t i ve
i nfo rma ti on .
[0014]
NFV syst e m c on ta in sec u r i ty c re de n t i a ls , su c h a s s e c r e t keys,
20 pa s s word s , e tc th at ca n be u se d to ga in ac c e ss by c om promi s in g t he
ne t wo r k s / se r v e r s or can be us e d t o pe rfo rm di s t r i but ed a t ta ck suc h a s
DHCP (Dynamic Host Configuration Protocol ) attacks, DDoS
( D i st r ib u te d De nia l of Se r v i ce ) a t ta c k s , e t c . T he s e secre ts ke ys c ou ld
al so be use d t o de c r ypt se nsi t i v e inf orma ti on, ste a l a d i g i ta l i dent it y, or
25 f orge si gna t u r e s .
[0015]
To s olve al l th e se prob le m, d em a rc a t io n t echn ol og y need s to be
de si gne d to p ro vid e s ec u r i ty - ha r de ned au t he n t i c a t i on f u nct io ns .
Tam pe r - re s i s t an t st o ra ge of c re de n t i al s, s uch as e nc rypt io n k e ys an d
30 ot her pa s s wo rd s , i s a m on g the key feat u re s re qu i re d f or im p le me n t i ng
s uch f un ct io nal it y.
[0016]
I n view of t he f or e goin g, t he p r e se n t in ve n t i on h as be e n ma de .
Na m el y, i t is a n obj ec t of the pre s e nt i nve nt io n t o p rovi de a ne t wo rk
7
f u n c t i on vi rt ua li za ti on syst e m which c a n c on t r i bu te to i mp r ove t he
f u n c t i on f or pro te c ti ng se n s i t i ve a uthe n t i c a t io n da ta .
[ Sol u t i on to Pro bl em]
[0017]
5 According to a first aspect, there is provided a network function
vi r tu a li za t i on s ys te m com p r i s in g: a r e qu es t rece i v i ng u nit t ha t rece i ve s
a re que st t o cert if i ca t e of a t le a st on e o f da ta ex c ha ngi n g pa r t i e s . Th e
ne t wo rk f un c t i on vi r tu al i z a t io n s ys t em f u rt he r c o mp ri s in g a private ke y
ge ne rat or t hat ge n e ra te s a f i r s t p r iv a te key inf orma ti on usi ng a s ec o nd
10 private ke y i nfo r ma ti on s to re d i n t he ha r dware -ba se d i s ola t ed se c u re
ex ec u t i on e n v i ro nme n t , i n re sp ons e t o a r e que s t. Th e ne tw ork f unc ti on
vi r tu a li za t i on s ys te m f urt he r c om p r i si ng a pu b l i c ke y e x t r a c t o r t ha t
ex t r a c t s a pub l ic ke y i nfo r ma ti on of t he f i rs t pri va t e ke y i nf ormat io n .
T he ne tw ork fu nc ti on virt ua li za t io n s ys te m f urt he r co mp r i s in g a pu bl ic
15 key information storage unit that stores the public key information .
T he net wo r k fu n c t i on virt u a l i za ti o n system f u r t he r com p r i s i ng a
ve ri fyi ng unit t ha t i s acc e s s i b le fro m the re qu est rece iv in g un it a nd t he
ve ri fyi ng uni t ve r i f ie s t he c e r t i f i ca te u si ng t he p ubl ic ke y inf orm a t io n
co r r e sp on d i ng to t he cert if i c a t e a s d e p i c t ed in fi gure 1.
20 [0018]
Ac co r d i ng t o a se co nd a s pe c t of t he pre sen t i nve n t i on, the re i s
provi de d a n ve rifyi n g me th od i n a ne t wo rk f unc ti on vi r tua li z a t i on
s yst e m, c om p r i s i ng th e step s of: rece i v i n g a re que st t o ce r t i f i c a t e o f at
l ea s t one of da ta exc ha n gin g part ie s ; ge n e r a t i ng a first p r iva te ke y
25 i nfo rma ti on u s in g a se co nd p r iva te key i nf ormat io n sto re d i n t he
hardware -based isolated secure execution environment, in response to a
r e que s t; e x t r a c t in g e x t ra c ts a p ubl ic ke y inf orma t i o n of th e f i rs t pri vat e
ke y i nf orma t io n; a nd verif yin g t he cert if ic a te or r e que s t u s in g the
public key information correspond i ng to the certificate by an
30 authentication unit that is accessible from an a p p l i c a t i o n programming
i nterface .
[ Advan ta ge o us Eff e ct s of In ve n t io n]
[0019]
According to the present invention, a network function
8
vi r tu a li za t i on s ys te m havi ng i mpro ve d pe rf orm a nce f or pro te c t i ng
se nsi t i v e a ut he n t i ca t i on data i s p rov i de d .
[ B rief De sc r ip ti on of Draw in gs ]
[0020]
5 [ Fi g. 1 ]
Fig. 1 is a block diagram showing a configuration of an
exemplary embodiment according to the present invention .
[ Fi g. 2 ]
F i g. 2 is a bl oc k d ia gr a m sho wi ng a n arc hi t ec t u re of p r opo sed
10 method.
[ Fi g. 3]
F i g. 3 is a b l oc k dia gra m sh owi ng a p r iva te ke y h ie r a rc hy of a
ne t wo rk f u nc t io n virt ua li za ti on s ys t em of a n exem pla ry e mbo di me nt 1
according to the present invention .
15 [ Fi g. 4]
F i g. 4 i s a dia gra m sho wi ng a r e p re se nt a ti ve f unc t ion of Sof tw a re
Private Key Generator used in present disclosure .
[ Fi g. 5]
F i g. 5 is a d ia gram sh ow in g a re p re sen t a t i ve fu nc ti on of
20 Re ke yin g - So f twar e Pri v a t e Ke y Ge ne ra t or use d i n pre s en t di scl o s u r e .
[ Fi g. 6]
Fig. 6 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he P KI c e rtif ica t e .
[ Fi g. 7]
25 Fig. 7 is a diagram showing a behavior of NFV system of the
present disclosure which verifies the PKI c e r t i f i c a t e.
[ Fi g. 8]
Fig. 8 is a diagram showing a message format sent between
HISE E a nd NFV f o r ve r if yin g t he P KI ce r tif ic a te .
30 [ Fi g. 9]
Fig. 9 is a diagram showing a message format sent between
HISE E a nd NFV f o r ve r if yin g t he P KI ce r tif ic a te .
[Fig. 10]
Fig. 10 is a diagram showing a NFV system of the present
9
di sc lo su r e f o r Veri f yi ng t he On boa rd in g V NF pac ka ge s .
[ Fi g. 11 ]
Fig. 11 is a diagram showing a behavior of NFV system of the
presen t di sc lo s u re w h ic h v e r i fi e s t he On bo a rd in g V NF package s .
5 [Fig. 12]
Fig. 12 is a diagram showing a message format sent between
HISEE and NFV for verifying the Onboarding VNF packages.
[Fig. 13]
Fig. 13 is a diagram showing a message format sent between
10 HISEE and NFV for verifying the Onboarding VNF packages.
[Fig. 14]
Fig. 14 is a diagram showing a NFV system of the present
di sc lo su r e f or Ve ri f yi ng t he tru s te d t hi r d pa r ty p r iva te key f or
a u t h e n t i c a t i o n .
15 [ Fi g. 1 5 ]
Fig. 15 is a diagram showing a behavior of NFV system of the
present disclosure which verifies the trusted third party private key for
a u t h e n t i c a t i o n .
[Fig. 16]
20 Fig. 16 is a diagram showing a message format sent between
HISE E a nd NFV f o r ve rif yin g t he tru s te d t h i rd p a r t y p r iva te key f o r
a u t h e n t i c a t i o n .
[Fig. 17]
Fig. 17 is a diagram showing a message format sent between
25 HISE E a nd NFV f o r ve rif yin g t he tru s te d t h i rd p a r t y p r iva te key f o r
a u t h e n t i c a t i o n .
[Fig. 18]
Fig. 18 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he S ca l i ng tri gge re d re qu e st b y V NF.
30 [ Fi g. 19 ]
Fig. 19 is a diagram showing a behavior of NFV system of the
presen t di s c lo s u re w h ic h v e r i f ie s the Sc al in g t r i g gere d r e que s t b y V NF.
[Fig. 20]
Fig. 20 is a diagram showing a message format sent between
10
HISEE and NFV for verifying the Scaling triggered request by VNF.
[ Fi g. 21 ]
Fig. 21 is a diagram showing a message format sent between
HISEE and NFV for verifying the Scaling triggered request by VNF.
5 [Fig. 22]
Fig. 22 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he S ca l i ng t r ig ge red re q ue s t by E M /V NF.
[Fig. 23]
Fig. 23 is a diagram showing a behavior of NFV system of the
10 presen t di sc l o su r e wh i ch v e rif ie s the Sca li ng t r i ggered re q uest b y
EM/VNF.
[Fig. 24]
Fig. 24 is a diagram showing a message format sent between
HISEE and NFV for verifying the Scaling triggered request by EM/VNF.
15 [ Fi g. 2 5 ]
Fig. 25 is a diagram showing a message format sent between
HISEE and NFV for verifying the Scaling triggered request by EM/VNF.
[Fig. 26]
Fig. 26 is a diagram showing a NFV system of the present
20 di sc lo su r e f o r Veri f yi ng t he S ca l i ng t r ig ge red re q ue s t by OSS/ B S S .
[Fig. 27]
Fig. 27 is a diagram showing a behavior of NFV system of the
presen t di sc l o su r e wh i ch v e rif ie s the Sca li ng t r i g g e r e d re quest b y
OSS/BSS.
25 [ Fi g. 2 8 ]
Fig. 28 is a diagram showing a message format sent between
HISE E a nd NFV fo r ve ri f yi ng t he Sc al in g t r i g ge red re qu est by
OSS/BSS.
[Fig. 29]
30 Fig. 29 is a diagram showing a message format sent between
HISE E a nd NFV fo r ve ri f yi ng t he Sc al in g t r i g ge red re qu est by
OSS/BSS.
[Fig. 30]
Fig. 30 is a diagram showing a NFV system of the present
11
di sc lo su r e f o r Veri f yi ng t he VN F C f a i lu r e req ue s t.
[Fig. 31]
Fig. 31 is a diagram showing a behavior of NFV system of the
presen t di sc lo s u re w h ic h v e r i fi e s t he V NFC f a il u re req ue s t.
5 [Fig. 32]
Fig. 32 is a diagram showing a message format sent between
HISEE and NFV for verifying the VNFC failure request.
[Fig. 33]
Fig. 33 is a diagram showing a message format sent between
10 HISEE and NFV for verifying the VNFC failure request.
[Fig. 34]
Fig. 34 is a diagram showing a NFV system of the present
d i s c l o s u r e for verifying and storing the VNFC failure service state in
secure storage .
15 [ Fi g. 3 5 ]
Fig. 35 is a diagram showing a behavior of NFV system of the
presen t di s c lo s u re w h ic h v e r if ie s an d st o re s the V NFC f a il u re servi ce
s t a te i n sec u re sto r a ge .
[Fig. 36]
20 Fig. 36 is a diagram showing a message format sent between
HISE E a nd NFV f o r ve r if yi n g a nd s to r in g the VN FC fa i l u re s e r v ic e state
i n secu r e sto ra ge .
[Fig. 37]
Fig. 37 is a diagram showing a message format sent between
25 HISE E a nd NFV f o r ve r if yi n g a nd s to r in g the VN FC fa i l u re se r v i ce s ta te
i n secu r e sto ra ge .
[Fig. 38]
F i gu re 3 8 i s a dia gra m fo r e xp la i ni ng pro blems in ex i s t i ng
s olut io n.
30 [Description of Embodiments]
[0021]
I n i t i a l l y , a su mma ry of an e xe mpl ary em bod i me nt o f the p r e s e n t
i n ven t io n w i ll be de s c r i be d wit h refere nc e t o the drawi ngs . It is noted
t ha t s ymb ol s f or re f e r e n c i ng the draw in gs a re e n te re d in t he s ummary
12
m e r e ly a s e xa mpl e s to assi s t i n und e rst a ndin g an d a re n ot in t en de d to
limit the present invention to the mode i l l u s t r a t e d.
[0022]
Re f e r r in g t o F i g . 1, an exe m pla ry emb od i me nt of t he prese nt
5 i n ven t io n may b e imp le men te d b y a ne tw ork fu nc ti on vi r tu al iz at i on
s yst e m 10 w hi c h is ma de up by a re qu est r ecei vin g unit 1 1 , a private ke y
ge ne rat or 1 5 , a pu b l i c key e xt ra c to r 14, a p ub l ic ke y i nf o r ma t io n
storage unit 13 and an verifying unit 12.
[0023]
10 S pecif ic al l y, t he r eq uest re c ei vi n g un it 11 rece i ve s a req ue s t to
ce r t i f i ca te of a t le as t one of da ta e xcha n gin g part ie s . T he p r iva te k e y
ge ne rat or 1 5 ge ne ra te s a fi r s t pri va te k e y i nf orma t io n u s in g a sec on d
private ke y i nfo r ma ti on s to re d i n t he ha r dware -ba se d i s o l a t ed se c u re
execution environment, in response to a request . The public key
15 ex t r a c t or 14 e xt r a ct s a p ub l ic key inf orm a t i on of t he fi r s t pri va te key
i nfo rma ti on . The pu bl ic ke y i nfo r ma t i on is st ored i n t he pu b l i c ke y
information storage unit 13 . The a u t h e n t i c a t i o n unit 12 is accessible
f rom th e re quest re c e i vin g u nit . A nd, the a ut he n t i c a ti on u nit 1 2
ve ri fie s t he cert if i cat e usi ng t he pu b l i c ke y i nf orma t io n c o r r e sp on ds t o
20 t he certi f ic a te .
[0024]
Wit h t he a b ove me n t i on ed co nf i gu ra ti on , it is p os s ib le to protect
NFV s ys te m a gai nst m a ny of at t ac k s t ha t th r ea te n se c u r i t y.
[0025]
25 Ne x t , va ri ou s e m bod iment s o f t he pre se nt i nve n ti o n wi ll be
de s c r i be d m o re in de t a i l be lo w wi th ref e re n ce t o t he dra win gs . The
f o l l ow in g di s c lo s u re f e atu re s P KC aut he nt ic at i on a s an a s s ump t io n, a
hi gh ly se c u re an d eff i c i en t m et hod o f p r o te ct in g t he s e cu r e c r eden t ia ls
s uch as pa ss wo r d s , p r i va te k e ys , cryp t ogra ph ic c e r t i fi c a t e s, t ok en s, e t c . ,
30 i n HISEE . U sin g thi s di sc lo s u re , NFV c om po ne nt s can a ut he n t i c a te
ea ch ot he r, en s u r i ng se c u re a u t he n t i c a t io n d u r in g i n s ta n t i at io n,
m i grat i o n , m on it ori ng a nd hi be r nat io n/ s us pe n s io n .
[0026]
5. 1 M o t i v a t io n s :
13
- S ec u r e l y st o r in g a nd a c c e s s i ng t he pri va te crede n ti a ls su ch a s
private k e y, passw ord s, t oke n s, e tc in HISEE .
- P r i v a t e ke ys a re use d fo r e nc rypt io n o r si gnat u re ve rif ica t io n i. e.
whe th e r the st ored im a ge s are e n c r yp ted an d i n te g r i t y pro t e c t ed ;
5 du ri ng PKI cert ifi ca te s va lid at i on ;
- T he p re sen t d i sc l osu re di s c l ose s the sc he me to p r o t e c t t he s ec u re
c r e d e n t i a l s and ho w they are accessed securely between NFV
components and HISEE.
[ 002 7]
10 5.2 Assumptions:
- HISEE is trusted environment for NFV system which is a
combination of both software and hardware components .
- Private key (PS ) is a software based private key which a re subset
of ori gin a l ha rdw a r e base d p r iva te keys(P H )
15 - Origi na l ha rdwa r e ba se d pri va te keys( P H) are h a rd ware ba se d
embedded private keys
- P r i vate ke ys ( P S ) a r e st ore d i n sec ure sto rage a n d Origi na l
ha rd ware privat e ke ys ( PH) a re kep t in sec u r e d en v i ro nm en t (i. e .
HISEE).
20 - PKC - Public Key Cryptography ( e . g . : assumptions are made
based on RSA Algorithm)
- Private keys will be shared to the trusted third
pa rt y/ ve nd o r s / su bsc r iber in a secu re ch a nne l
- Certification generation is done offline .
25 [0028]
As p refe r re d emb od ime n t s of the pres e nt di sc lo s u r e , foll ow in g
usecases are described.
- Us eca se 1 : Sec u r e l y ac c e s s i ng t he p ri va te ke y ( PS ) f ro m HISEE
f o r Ve rif yi n g the P KI c e r t i f ic a te
30 - Us eca se 2 : Secu re a cc e s s i ng t he p r iv a te ke y ( P S ) f ro m HISEE fo r
VNF Package verification
- Us eca se 3: Verif yi ng t he Tr uste d t hi r d pa r t y pri va t e key ( P S ) f or
a u t h e n t i c a t i on
- Us eca se 4 : Ve rifyi n g t he Sca li ng tri gge re d re qu e st by VNFM
14
- Us eca se 5 : Ve rifyi n g t he Sca li ng tri gge re d re qu e st by EM/ VN F
- Us eca se 6 : Ve rifyi n g t he S ca l in g t r ig ge r e d req ue st by OSS/ B S S
- Us eca se 7 : Ve rify i n g the V NFC fa il u re re que s t
- Us eca se 8: Ve rifyi n g t he VN FC f a i lu re se r vi ce st at e which ha s t o
5 be st o re d i n secu r e sto ra ge
[0029]
- Authentication mechanism
- Tr us t ed thi r d part y c a n be a uth ent i c a t e d by NFV p l atf orm usi ng
HISE E f or ac c e s s i ng t he sen s i t i ve data by usi ng o nl y pu b l i c c omp onen ts
10 an d mo du l u s fu nc ti on of pri va te key ( P S ) .
- Me s sage se q uence fo r vari ou s pu r pos es
- De r i v i ng th e p ub l ic c o m po ne nt s and mo du lu s f u n c t i on f rom the
provi de d pri v a t e k e y ( P S ) .
- Handshake between both Normal Environment Engine -HISEE and
15 Secured Environment Engine -HISEE.
- Message format
- Ac ce s s in g th e se n s i t i ve data in HISEE
- Ho w the a ut he n t i c a ti on re qu est f orw a r de d f rom no r ma l
- Ke y ge ne ra ti on
20 - NFV base d s yst e m a t t r ib ut es (U n iq ue iden t i f i e r li ke IMEI
( I n t e r n a t io nal Mo b i l e Eq u ip me nt Iden tif ie r ) nu mbe r, loca ti on
co ordi na ti on ' s, or an y in de x va lu e, etc), n o n e of t he hard ware privat e
ke y (PH ) a re used f or ge nera ti ng t he pri v a t e k e y ( P S ).
- The generated software private key (PS ) for authentication or
25 encryption mechanism required for NFV system .
[0030]
5.4 Benefits:
By using this idea one can protect the secure c r e d e n t i a l s from the
non-secured environment by any mean of a u t h e n t i c a t i o n process in NFV
30 s yst e m. E ven du r in g t he worst c a se sce na r io s, if th e p ubl ic
components and modulo functions of private key(P S ) are compromised,
that will not impact the whole private key c r e d e n t i a l s .
[0031]
6. Arc hit ec t ure of pr op osed me th od
15
F i g. 2 is a bl oc k d ia gr a m sho wi ng a n arc hi t ec t u re of pro pose d
method. As shown in Fig. 2, normal environment engine 130 and
HISE E a rc h i t e c t u re 1 40 can be dis po sed i n t he vi r tu a li zat io n l a yer i n
t he NFV I (N etwork f un ct io n virt u a l i za t io n in f ra s t r uc tu r e ) of NFV
5 pla tfo r m. Ea c h com po ne nt w i l l be de s c r i be d in the f ol lo win g
ex pla na ti on of use ca s e s .
[0032]
7. P r i v a t e Ke y Hiera r c hy
F i g. 3 is a dia gra m sh ow i ng pri va te ke y h i e ra r c hy. A s s ho wn i n
10 F i g. 3, pri va te keys (p sn ) a r e ge ne r a te d fro m a n ori gi na l p r i va te k e y
stored in the hardware - b a s ed isolated secure execution environment .
Ea c h p r iva t e key (p sn ) is used f or c e rt if ic a te ma na ge me n t , e nc r ypti n g
images and so on.
[0033]
15 7.1 Software Private Key Generator (PG)
F i g. 4 i s a dia gra m sho wi ng a r e p re se nt a ti ve f unc t ion of Sof tw a re
P r i v a t e Ke y Ge ne rat or. As sh own in Fi g. 4, Sof tw a re Pri va te Ke y
Ge ne rat or t akes as in put s uc h a s tru s te d t h i rd pa r t y pri va te ke y (P T T P ) ,
No nce of the hard wa r e pri va te k e y (P H ) , a se t of un i que at t r i b u t e s
20 ( Uni que i de n t i f i e r like IM E I n umb e r, lo ca t ion c oo r di na t io n ' s , or a ny
index value, e t c ) , in the authority 's zone (A1 , A2 , A3 , . . . , AN ) and
ou t put s t he sof tw a r e p ri va te ke y (P S ). We wi ll as s um e that t he se t of
at t r ib u te s i n the a ut h o r i t y ' s zo ne ha s b ee n ve r if ie d (su ch a s u ni que n e s s ,
l e vel of se c u r i ty st re n gt h, e tc . ) be f o re t hi s a l gori th m i s ru n . Soft wa re
25 private ke y gener at or (P G) is a se cu r e ran do miz e d based a l g o r i t hm
which must be run by a u t h o r i z a t i o n party. The a u t h o r i z a t i o n party can
select and use their private key generator base d on their security
r e q u i r e me n t s. The sec u re c r e den t ia ls w i ll be d i s t r i but e d t o th e
dependent services providers through a secure channel .
30 [0034]
7. 2 Re ke yin g S of t wa re Pri v a t e Ke y G e ne r a to r ( PRK ) :
F i g. 5 i s a d ia gram sh ow i ng a r e p re sen ta t i ve fun c t io n of Re ke yi ng
Software Private Key Generator. As shown in Fig. 5, Rekeying
Software Private KeyGenerator (PRK) takes as input such as third party
16
private ke y, n o nc e of the hard wa re private ke y (PH) , a se t of at t r i b u t e s
i n t he a u th o r i ty ' s zo ne ( A1 , A2 , A3 , . . . , AN ), m ono to nic c o unter val ue
( CM ) a nd o ld soft ware p r i va te ke y ( OP S ) . I t r e sul ts the ne w s of t wa re
private ke y (N P S ). T he ne w up da te d secu r e c re de nt ia ls wi ll be
5 di s t r i bu te d t o t he de p en de nt se rv i c e s pro vi d e r s th r ough a se c u re
ch an ne l.
[0035]
I t sh ou ld b e no te d th e fol lo wi ng matters . HI SE E ha s b ui lt i n
m o n o to n ic c o unter wh ose val ue i s n on - vol a t i le an d m on o to n ic c a n be
10 increased by 1, but it can never be reverted to an older value, even if
one has c om p le te ph ys i cal ac c e ss t o t he e nt i r e ma c h i n e h ost i ng an d
invoking the HISEE.
[0036]
8. Proposed protocol for NFV usecase
15 8. 1 Ve rif yin g t he P KI c e r t i fica te in NFV s ys te m
8. 1. 1 Bl oc k D ia gr a m f or Ve r if yin g t he PKI c e r t i f i ca te
Fig. 6 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he P KI c e rt i f i c a t e .
[0037]
20 8. 1. 2 De s c r i p t i on
As sh ow n i n Fi g. 6 , NFV s ys t em 10 0 al lo ws vari ou s virt ua li sa t io n
f u n c t i on s e rvi c e s li ke i n s ta n t ia ti on, hi bern at io n/ s usp e nsi on, reti r em e nt
an d mi gr a ti on . The se servi ce s r eq ui r e th e t r a nsfer of c ri t i ca l
information/data request among the NFV nodes . Therefore, it is
25 ex t rem e ly nece s s a ry t o pro vid e t he sec u r i t y s e r v ic e s like a u t he nt ica t io n .
P KI ce r tif ica te sy s te m s are u se d t o pro vi d e au t he n ti c a t i on se rvi c e f or
NFV s ys te m 1 0 0. T he objecti ve of t he use ca se is t o ve rify the
au t he nt ic it y of P KI c e rt i f ic a te re que st f or acc e s si ng t he N F V syst em b y
any internal or external user. Any malicious user may use duplicate or
30 malicious the c e r t i f i c a t e which may lead to compromise of NFV system .
S o the e x te r n a l o r inter na l use r s ha ve t o p r ove the V I M (Virt ua l i ze d
I nf ra s t r u c t u re M a na ge r ) 11 2 t ha t t hey a re not the ma li c io us o ne wh e n
t he y a re re q u e s t i ng t o ac c e s s NFV syst e m . One c a n easil y a c hi e ve
au t he nt ic it y u si ng t he pro pose d me ch a ni s m of t he pres e nt disclo s u re .
17
Be lo w we ha ve pr ovid e d t he step by s te p au t he n t ic at io n p r oced u re f or
ve ri fyi ng P KI ce r tif ica te by a ny in te r na l or ex te r na l user s.
[0038]
8 . 1 . 3 Procedure:
5 As s how n i n F i g . 6, t he N FV sys t em of t he p r e s e nt disc lo su r e
ve ri fie s th e PK I certif ic a te a s f o l l ow s .
- S t e p 1 : Ex te rna l use r or a ny c l oud se r ve r 21 0 req ue s t s NFV s ys te m
10 0 t o acce s s t he P KI ce rtif ic at e fo r an y ki nd of da ta e xch a nge betw ee n
the NFV system and external system.
10 - S t e p 2 : N F V O ( NF V orc he s t r a t o r ) 111 va l ida te s the a uthe nt ic it y of
t he e x te rna l u s e r usin g f ol l owi ng p ro po se d pro t oc ol . Na me ly, NFVO
111 c o r r e s po nds t o t he req ue st rec ei vi ng unit 11 in Fi g. 1.
- Step3: NFVO 111 forwards the request to VIM 112 for v a l i d a t i ng
t he au t he n t ic it y.
15 - S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
- Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
- S t e p 6 : N F VI 11 3 loc a te the si gn a tu r e a nd API's of pri va te
ke y(PS )in the se c ure st ora ge fo r va lid a t in g the aut he n t i ca ti on re que s t.
20 - S t e p 7 : API 's of the pri va t e key (P S ) f orward the ca l l t o the norm al
environment engine (NEE) 130 to get the public exponent and modulus
va l ue of t he p r i va t e ke y (P S ) .
- Step8: The normal environment engine 130 will map the request
t o secure d e nvi ro nme n t e ngi ne (SEE) 141 wh ic h i s l oc at e d i n se c u re d
25 environment.
- Step9: The secured environment engine (SEE) 141 read the
private ke y( P S ) w h ic h i s l oc at ed i n HISEE 1 4 0 an d e xt ra ct t he pu b l ic
ex pon e nt a nd mo du lu s va l ue of t he p r i va te ke y ( PS ). Nam el y, secu re d
en vi ron me n t e ngi ne (SEE) 14 1 co r re s po nd s t o th e pu bl ic ke y ex t ra c t o r
30 on 14 in Fi g. 1.
- S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p ub l ic
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y ( P S ) fo r a pa r t i c u la r
se s s io n a nd e ra s e s it p e rma ne nt l y.
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i a l s suc h as
18
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 140. Namely, PKC container 142 corresponds to the public key
i nfo rma ti on sto ra ge uni t 1 3 in Fi g. 1 .
- S t e p1 2: Sec ured en v i r on men t e n gi ne (SE E ) 14 1 fo rm ula te th e
5 pu b l i c e x p on e nt an d mo du lu s va l ue fo r t he give n a ut hen t ic a ti on req ue s t
an d f orw a r d the cre de n t i a l s to normal E nvi ro nm e nt e n g i n e (N E E ) 1 3 0 .
- S t e p1 3: N orm al E nvi r onm e nt e n gi ne 1 30 resp on se s the A P I 's call
wi t h p ubl ic ex pon en t a nd m od ul us v al ue of th e pri va te key( P S ) .
- S t e p 1 4 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
10 ex pon e nt a nd m od ul us val ue of t he p r i va te ke y (P S ), se c u re st ora ge 120
wi ll no tif y au t h en t ic a t io n wa s suc c essf u l to the N F VI 113. Namel y,
se c u re s to ra ge 12 0 co r re s po nd s to th e ve r if yi n g un it 12 i n Fig. 1.
- S t e p1 5: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112 .
15 - S t e p1 6: If au t h en t ic a t io n wa s s ucce s sf u l , a nd V I M s ack no wle d ge
the success PKI c e r t i f i c a t i o n authentication to NFVO 111, otherwise
reject the request.
- Step17: NFVO 111 notifies the NFV system.
[0039]
20 8. 1. 4 Us eca se f or Secu r in g acce s si ng the pri va te key(P S ) f ro m HISEE
f or Ve r if yi n g the P KI certi f ic a te
Fig. 7 is a diagram showing a behavior of NFV system of the
present disclosure which v e r i f i e s the PKI c e r t i f i c a t e.
[0040]
25 8. 1. 5 Me s sage f orma t Sec u r i ng acce s s in g the p r i va te ke y( P S ) f rom
HISEE fo r Ve r if yi ng the P KI certi f i c a te
Fig. 8 and 9 are diagrams showing a message format sent between
HISEE a nd NFV f o r ve r i f yin g t he P KI ce r tif i c a t e .
[0041]
30 8. 1. 6 Ope ra ti ons of Se c u re acce s s i ng t he p r i va te ke y f rom HIS EE fo r
VNF Package Verification
As shown in Figs. 8 and 9, HISEE and NFV send following
messages.
1) Validate_PKI_Certificate, NFVO->VIM
19
T h i s me s sa ge defi ne s t he va lid a t i on re q ue st f or P KI ce rtif ic a te
v e r i f i c a t i o n by NFVO 111 to VIM 112.
2) Validate_PKI_Certificate, VIM->NFVI
T h i s me s sa ge defi ne s t he va lid a t i on re q ue st f or P KI ce rtif ic a te
5 verification by VIM 112 to NFVI 113.
3) Validate_PKI_Certificate, Read_PrivateKeyAPI, NFVI->SS
T h i s m e ssa ge defi ne s t he va l i da ti on of PKI c e r t i f i ca te b y c a l l i ng t he
API's of the p r i va te key ( P S ) a n d lo ca te t he cre de n t ia ls i n t he secu re
s t ora ge ( S S ) .
10 4) Get_Public_Exponent, Get _ModulusValue, SS->NEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120 to NEE 130.
5) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
15 exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
6) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
20 va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
7) Store_Public_Exponent, Store _ModulusValue,
PKCCont<-HISEE(SW)
T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
of the p r iva te key in PKC co nta i ner 14 2 .
25 8) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of t he p r i va te ke y f ro m PKC C on ta i ne r 14 2 to t he se c u re d
environment engine SEE 1 4 1.
9) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
30 T h i s m e s sa ge d ef i ne s of f orm ula t in g the pu b l i c e x po nen t an d m od ul us
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t en gin e SE E 1 4 1 .
10) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y fro m secu re d e n v i ro nm e nt e ngi ne ( S E E ) 1 4 1 to
20
the normal Environment engine (NEE) 130.
11) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue o f t he p r i va te key f r om n orma l E nvi r onm e nt e ng i ne (N E E ) t o t he
5 secure storage (SS) 120.
1 2 ) Va li da te _ PKI_ C e r t i f i ca te (Pu b l i c _ E xp one n t , Mo dul usVal ue ) , SS
T h i s me s s a ge defi ne s t he va l id a t i on of PK I ce rtif ic a te usi ng pu bl ic
ex pon e nt a nd mo du lu s va lue of t he p r iva te k e y ( P S ) t o ac h ieve
au t he nt ic it y.
10 1 3 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S
T h i s me s sa ge de fine s th e va li da t io n s ta t us of the P KI ce rtif ic a te fro m
secure storage (SS) 120 to NFVI 113.
1 4 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s me s sa ge de fine s th e va li da t io n sta t us of the P KI ce r tif i c a t e f ro m
15 NFVI 113 to VIM 112.
15) Notify_Validation_Status(Success/Failure), NFVO <-VIM
T h i s me s sa ge de fine s th e va li da t io n sta t us of the P KI ce r tif i c a t e f ro m
VIM 112 to NFVO 111.
[0042]
20 8.2 Verifying the Onboarding VNF packages
8.2.1 Block Diagram for Verifying the Onboarding VNF packages
Fig. 10 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he On boa rd in g V NF pac ka ge s .
[ 00 43]
25 8. 2. 2 De s c r i p t i on :
As shown in Fig. 10, VNF Package on-boarding refers to the
process of submitting VNF Package to the NFVO 111 to be included in
t he ca ta lo gue ( Ca t Lo g) 16 0. Figu re dep ic ts t he bl oc k diagra m f or
ve ri fyi ng t he On - boa r d i ng V NF pack a ge s . Th e objecti ve of the u s ec a se
30 i s t o ve r if y th e a ut he n t i c i t y a nd in te gr i t y of on -b oard V NF pac ka ge
request by any internal or external user. Any malicious user may
r e que s t on -b oa rd V NF pac kage w it ho ut t he nece s s i t y , it ma y le a d to
co m p ro mi se o f NFV system 1 00a . So t he ext e r na l or i n te rn al use r s
have to prove VIM 112 that they are not malicious one when they are
21
requesting for on-board VNF package. One can easily achieve
au t he nt ic it y an d in te gri t y usi ng th e p r op osed me ch a ni sm of pre s e nt
di sc lo su r e . B el ow we ha ve pro vid e d th e s te p b y st ep a uthen t ic a t i on
proce du re f or veri f yi ng On - bo a r din g VN F pa c ka ge s b y any in te rn al o r
5 ex t e rn a l u se r.
[ 004 4]
8. 2. 3 P r oced u re :
As s ho wn i n Fig. 10, th e N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s th e O n -b oa r d in g V NF package s a s f o l l ow s .
10 - Step1: VNF package is submitted to NFVO 111 for on-boarding
VNFD using the operation On - b o a rd VNF Package of the VNF Package
Management interface.
- S t e p2 : NFV O 111 val i da te the a ut hent ic it y of t he e x t e rn al user
us in g f ol lo wi ng p r op osed pro t oc o l .
15 - Step3: NFVO 111 forward the request to VIM 112 for validating
t he au t he n t ic it y of t he ex te r na l user.
- S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
- Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
20 - S t e p 6 : NFV I 11 3 loc a t e t he VN F ce r t i f ic a te a nd API 's of private
ke y(PS )in t he se c ure st ora ge 12 0 f o r vali da ti ng th e a ut he n t i c a t i on
r e q u e s t .
- S t e p 7 : API 's of the pri va t e key (P S ) f orward t he c al l to t he no rma l
Environment engine (NEE) 130 to get the public exponent and modulus
25 value of the private key (PS ) .
- Step8: The normal Environment engine (NEE) 130 will map the
request to secured environment engine (SEE) 141 which is located in
secured environment.
- Step9: The secured environment engine (SEE) 141 read the
30 private ke y (P S ) wh i ch i s lo ca te d in H I SEE 14 0 an d e xt ra ct t he pu bl ic
ex pon e nt a nd m od ul us va l ue of t he pri va te k e y (P S ) .
- S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p ub l ic
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y (P S ) fo r a pa r t i c u la r
se s s io n a nd e ra s e s it p e rma ne nt l y.
22
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i al s suc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
- Step12: Secured environment engine (SEE) 141 formulated the
5 pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
and forward the c r e d e n t i a l s to normal Environment engine (NEE) 130.
- Step13: Normal Environment engine (NEE) 130 responses the
API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
(PS ).
10 - S t e p 1 4 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
ex pon e nt a nd m od ul us val ue of t he p r i va te ke y ( P S ), se cu r e sto r a ge 1 20
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l to t he N F VI 113.
- S t e p1 5: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112 .
15 - S t e p1 6: I f a ut he nt ica t i on w as s ucce s sf u l , VIMs 112 a c kn ow le dge
t he su cc e s sf ul up loa d i ng of the i ma ge t o N FVO 111 , o the rw i s e re je c t t he
r e q u e s t .
- S t e p1 7: N F VO 111 no ti f i e s th e c a t a l ogu e .
- Step18: NFVO 111 acknowledges the VNF Package on - b o a r d i n g to
20 t he sen de r.
[0045]
8.2.4 Usecase for Secure accessing the private key from HISEE for VNF
P ac kage Ve r i fica ti on
Fig. 11 is a diagram showing a behavior of NFV system of the
25 present disclosure which v e r i f i e s the On-boarding VNF packages.
[0046]
8.2.5 Message Format: Secure accessing the private key from HISEE for
VNF Package Verification
Fig. 12 and 13 are diagrams showing a message format sent
30 between HISEE and NFV for verifying the On-boarding VNF packages.
[ 00 47]
8. 2. 6 Ope r a t io ns of Se c u re a cce s s in g t he p r iva te key f ro m HISE E f or
VNF Package Verification
As shown in Figs. 12 and 13, HISEE and NFV send following
23
messages.
1) Validate_QueryImageRequest, NFVO ->VIM
T h i s messa ge def i ne s t he va lid a t i on re qu es t f or I ma g e veri f ic a t io n b y
NFVO 111 to VIM 112.
5 2) Validate_QueryImageRequest, VIM ->NFVI
T h i s messa ge def i ne s t he va lid a t i on re qu es t f or I ma g e veri f ic a t io n b y
VIM 112 to NFVI 113.
3) Validate_VNF_Certificate, Read_PrivateKeyAPI, NFVI->SS
T h i s m e s sa ge d ef i ne s t he val ida t i on of V NF cert if ic a t e by c a l l in g the
10 API's of the p r i va te key (P S ) a n d lo ca te t he cre de n t ia ls i n t he secu re
storage(SS) 120.
4) Get_Public_Exponent, Get _ModulusValue, SS->NEE
T h i s me s sa ge def i ne s t he f orw a r di ng of A PI c a l l to r e qu es t t he p ubli c
exponent and modulus value of the private key from SS 120 to NEE 130.
15 5) Get_Public_Exponent, Get_ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
6) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
20 SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e x po ne nt an d m od ul us
va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
7) Store_Public_Exponent, Store _ModulusValue, PKCCont
<-HISEE(SW)
25 T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
of the p r iva te key in PKC co nta i ner 14 2 .
8) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
30 environment engine SEE 1 4 1.
9) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
T h i s m e s sa ge d ef i ne s of f orm ula t in g the pu b l i c e x po nen t an d m od ul us
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
10) Send_Public_Exponent, Send _ModulusValue, NEE<-SEE
24
T h i s me s s a ge def i ne s of f orw a r di ng t he p u b l i c e xp one nt a nd mo dul us
va l ue of the pri va te key f r om se c u re d e n v i ro nm e nt e ngi ne ( SE E ) 1 4 1 to
the normal Environment engine(NEE) 130.
11) Send_Public_Exponent, Send _ModulusValue, SS <-NEE
5 This message defines of forwarding the public exponent and modulu s
value of the priva te key from normal Environment engine(NEE) 130 to
t he se c u re s to r ag e ( SS) 1 2 0 .
12) Validate_VNF_Certificate(Public _Exponent, ModulusValue),SS
T h i s me s sa ge de f i ne s t he va li da t io n of V NF cert if ic a te u s in g pub l ic
10 ex pon e nt a nd mo du lu s va lu e o f t he pri va te key (P S ) t o ac h ieve
au t he nt ic it y.
1 3 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S
T h i s messa ge defi ne s t he val ida ti on sta tu s of t he V NF cer tif i c a t e f r om
secure storage (SS) 120 to NFVI 113.
15 1 4 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s messa ge defi ne s t he val ida ti on sta tu s of t he V NF cer tif i c a t e f r om
NFVI 113 to VIM 112.
15) Notify_Validation_Status(Success/Failure), NFVO <-VIM
T h i s messa ge defi ne s t he val ida ti on sta tu s of t he V NF cer tif i c a t e f r om
20 VIM 112 to NFVO 111.
[0048]
8. 3 Ve r i f i ca t io n o f Tr u s t e d t h i rd pa r ty pri va te k e y f o r a ut he nt ica ti on
8. 3. 1 Bl oc k D ia gr a m fo r Ve r i f yin g the Tru s te d t h i rd pa rt y pri va te ke y
f or a uth e n t i ca t io n
25 Fig. 14 is a diagram showing a NFV system of the present
di sc lo su r e f or Verif ying t he Tru s te d thi r d pa r ty p r i va te ke y f or
a u t h e n t i c a t i o n .
[0049]
8. 3. 2 De s c r i p t i on
30 As s ho wn i n F i g . 14, t he re l ia b i l it y on som e d e d ic a t ed t hi r d pa r ty
se r ve rs w h ic h a re u se d fo r a c c e s s in g th e data a nd se r v i c e s wi t h th e NFV
system 100b. For accessing the data and s e r v i c e s , it requires trusted
t h i rd pa r ty c red en t ia ls lik e p r i v a t e ke y, to kens et c . If t he se
c re de nt ia ls are c o mp r omised it may cau se secu r it y p r ob le ms, be cau se
25
t he u na va i la bi l i t y of such re qu i r e s tru s t ed th i rd pa r ty se r ve rs cau s es t he
whole system blocked, and compromise of them means the compromise
of a ll of t he use r s who tru s t t he serve rs . T he r efo r e , it i s ex t re me l y
necessary to provide the security for trusted third party credentials .
5 T he o bje c ti ve of t he usec a se is to v e ri f y the au t he nt i c i t y of acc e s s i ng
t he tru s te d thi r d pa rt y cre de nt i al s wh ic h are sto r e d in NFV sys t em 1 00b .
An y malic i ous u ser m a y use du pl i c a t e o r ta m pe r t he t r u s t ed th i rd p a r ty
c r e d e n t i a l s which may lead to compromise of NFV system 100b. So the
ex t e rn a l o r i n te rn al u s e r s ha ve t o p r ove th e VIM 11 2 that the y a re no t
10 m a l ic io us o ne whe n the y a re r e que s t in g to access tru s t ed t h i rd part y
c re de nt ia ls in th e NFV syst em 1 0 0 b. O ne c an easi ly ac h i e ve
au t he nt ic it y u si ng t he p r op osed mec h a ni s m of pr e se nt di sc l os u re .
Be lo w we ha ve pr ovid e d t he step by s te p au t he n t ic at io n p r oced u re f or
verifying the TTP private key for authentication by any
15 i n t e r n a l /e x te r n a l u se r.
[0050]
8. 3. 3 P r oced u re :
As s ho wn i n Fig. 14, th e N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s t he Tr u s t e d t hi r d pa r ty pri va te k e y f o r a uthen t ic a ti on a s
20 follows.
- S t e p 1 : Ex te rnal u se r or a ny cl ou d se r ve r re quest N F V syst em
10 0b to acce s s t he Tru st e d thi rd pa r t y p r i va te key 1 2 1 for a n y ki nd of
data exchange between the NFV system 100b and external system such
as cl o ud se r ve r 2 10
25 - S t e p 2 : NFV O 111 val i da te the aut hent ic it y of t he e x t e rn al us er
us in g f ol lo wi ng p r opo sed pro t oc ol .
- Step3: NFVO 111 forward the request to VIM 112 for validating
t he au t he n t ic it y.
- S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
30 - Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
- S t e p 6 : NFV I 11 3 loc at e t he s ignat u re an d API 's of pri v a t e ke y( P S )
i n th e se c u re st ora ge 1 20 f or vali da ti ng th e a u t he nt ic at io n req ue s t .
- S t e p 7 : API 's of the pri va t e key (P S ) f orward t he c al l to t he no rma l
26
Environment engine (NEE) 130 to get the public exponent and modulus
va l ue of t he p r i va t e ke y (P S ) .
- Step8: The normal Environment engine 130 will map the request
t o secure d e nvi ro nme n t e ngi ne (SEE) 141 wh ic h i s l oc at e d i n sec u re d
5 en vi ron me n t .
- Step9: The secured environment engine (SEE) 141 read the
private ke y( P S ) w h ich i s l oc ated i n HISEE 1 4 0 an d e xt ra ct t he pu b l ic
ex pon e nt a nd m od ul us va lue of t he pri va te k e y ( P S ) .
- S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p u b l ic
10 ex pon e nt a nd m od ul us val ue of t he p riva te ke y(P S ) f or a part ic ula r
se s s io n a nd e ra s e s it p e rma ne nt l y.
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i al s suc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
15 - Step12: Secured environment engine (SEE) 141 formulated the
pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
an d f orw a r d the cre de n t i a l s to normal E nvi ro nm e nt e n g i n e (N E E ) 1 3 0 .
- Step13: Normal Environment engine (NEE) 130 responses the
API' s call wi th p ub l ic e xpo ne nt a n d mo dul us va lu e o f p r i va te ke y ( P S ).
20 - S t e p 1 4 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
ex pon e nt a nd m od ul us val ue of t he p r i va te ke y (P S ), se cu r e sto r a ge 120
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l to t he NFV I 113.
- S t e p1 5: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112 .
25 - S t e p1 6: If au th en t ic a t io n wa s suc cessf u l, a nd V I M 11 2
ac kn ow le dge s t he suc c e ss of ac c e s s in g the t r u s t e d t h i rd p a r ty pri va te
ke y a uth e n t i c at io n t o NFVO 111, ot he r w i s e rej ect t he re ques t.
- Step17: NFVO 111 notifies the NFV system.
[0051]
30 8. 3. 4 Us eca se f o r Verif yin g the Tru s t e d thi r d p a rt y pri va t e key f or
a u t h e n t i c a t i on
Fig. 15 is a diagram showing a behavior of NFV system of the
presen t di sc lo s u re w h ic h v e r i fi e s t he Tru s te d t hi r d part y p r iva te ke y f or
a u t h e n t i c a t i o n .
27
[0052]
8. 3. 5 Me s sage Fo r m at f or Ve rifyi n g the Tru s te d t hi rd pa r ty pri va te key
f or a uth e n t i ca t io n
Figs. 16 and 17 are diagrams showing a message format sent
5 be t wee n H I S E E a n d NFV f or ve r if yi n g t he Tr u s t e d t hi r d part y private
key for a u t h e n t i c a t i o n.
[0053]
8. 3. 6 Ope ra ti ons of Sec u re accessi ng t he p r iva te key f ro m HISEE f or
VNF Package Verification
10 As shown in Figs. 16 and 17, HISEE and NFV send following
messages.
1) Validate_TTP_CertificateRequest, NFVO ->VIM
T h i s messa ge d e fine s the val ida ti on re q ue s t for T T P certi f ic a te
v e r i f i c a t i o n by NFVO 111 to VIM 112.
15 2) Validate_TTP_CertificateRequest, VIM ->NFVI
T h i s messa ge d e fine s the val ida ti on re q ue s t for T T P certi f ic a te
v e r i f i c a t i o n by VIM 112 to NFVI 113.
3) Validate_TTP_Certificate, Read_PrivateKeyAPI, NFVI->SS
T h i s me s sa ge def i ne s t he va lid at i on of TTP cert if ic at e b y ca l li ng the
20 API' s of the pri v a t e ke y (P S ) a n d lo ca te t he cre de n t ia ls i n t he secu re
storage (SS) 120a.
4) Get_Public_Exponent, Get _ModulusValue, SS->NEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120a to NEE
25 130.
5) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ue s t t he p ubli c
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
30 6) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
7) Store_Public_Exponent, Store _ModulusValue,
28
PKCCont<-HISEE(SW)
T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
of the p r iva te key in PKC co nta i ner 1 4 2 .
8) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
5 T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
environment engine (SEE) 1 4 1.
9) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
T h i s m e s sa ge d ef i ne s of f o r m u l a t i ng t he pu bl ic ex po ne nt a nd mo du lu s
10 va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
10) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y se c u re d e nvi r onm e nt e n gi ne (SEE) 1 4 1 to the
normal environment engine (NEE) 130.
15 11) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120 a.
1 2 ) Va li da te _ T T P _Ce r t i f i c a t e (Pu b l i c _Ex po ne n t , Mo dul us Val ue ) , SS
20 T h i s me s sa ge def i ne s t he va lid a t i on of T T P cert if ic a te usin g pu bl ic
ex pon e nt a nd mo du lu s va lue of t he p r iva te k e y ( P S ) t o ac h ieve
au t he nt ic it y.
1 3 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S
T h i s me s sa ge d ef i ne s t he va lid a t i on sta t us of t he TTP cert if i c a t e f ro m
25 secure storage (SS) 120a to NFVI 113.
1 4 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s me s sa ge d ef i ne s t he va lid a t i on sta t us of t he TTP cert if i c a t e f ro m
NFVI 113 to VIM 112.
15) Notify_Validation_Status(Success/Failure), NFVO <-VIM
30 T h i s me s sa ge d ef i ne s t he va lid a t i on sta t us of t he TTP cert if i c a t e f ro m
VIM 112 to NFVO 111.
[0054]
8.4 Verifying the Scaling triggered request by VNFM
8. 4. 1 Bl oc k D ia gra m fo r Ve r i f yin g the Scal in g t r i ggere d re ques t by
29
VNF
Fig. 18 is a diagram showing a NFV system of the present
di sc lo su r e f o r Veri f yi ng t he S ca l i ng t r ig ge red re q ue s t by VN F.
[0055]
5 8. 4. 2 De s c r i p t i on
F i g. 1 8 d e pi ct t he block d ia gra m fo r ve rif yin g t he scal in g
t r ig ge r e d re quest b y VNFM ' s . Th e o bj ect i ve of t he u s ec a se i s to ve rif y
t he a uth e nt i cit y of s ca li ng tri gge r re que st b y t he VNFM ' s. Any
m a l ic io us u ser ma y r ai se t he sc a le tri gge r wit ho ut t he n ec e s s i ty . So
10 the VNFM's have to prove VIM 112 that they are not malicious one when
t he y are re q ue st in g f or sc a l in g t r ig ge r. O ne c a n easi ly a chi e ve
a u t h e n t i c i t y using our proposed mechanism . Below we have provided
t he s te p b y s te p a ut he n t i c a t i on proc e du re fo r ve r if yin g t he scal in g
trigger request raised by VNFM ' s .
15 [0056]
8. 4. 3 P r oced u re :
As s ho wn i n Fig. 1 8, t he N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s t he Scali ng t r ig ge r e d req ue s t b y VN F 1 00c a s f ol lows .
- S t e p 1 : V NFM 's 118 de te ct s a c a pa cit y sh ort age wh i le mea s u r i ng
20 the performance of EM/VNF's.
- Step2: VNFM 118 and NFVO 111 coordinate each other for
scaling decision.
- Step3: VNFM 118 forward the request to VIM 112 for v a l i d a t i ng
t he au t he n t ic it y.
25 - S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
- Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
- S t e p 6 : NFV I 113 loc a te t he si gna tu r e a nd API ' s of p r i va te ke y
( P S ) in the se c u re s to ra ge 12 0 f o r va lid a t in g t he au t he n t i cat io n re quest .
30 - S t e p 7 : API 's of the pri va t e key (P S ) f orward t he c a l l to t he no r ma l
environment engine (NEE) 130 to get the public exponent and modulus
va l ue of t he p r i va t e ke y (P S ) .
- Step8: The normal Environment engine 130 will map the request
t o secure d e nvi ro nme n t e ngi ne (SEE) 141 wh ic h i s l oc at e d i n se c u re d
30
en vi ron m e n t .
- Step9: The secured environment engine (SEE) 141 read the
private ke y (P S ) wh i ch i s lo ca te d in H I SEE 14 0 an d e xt ra ct t he p ubl ic
ex pon e nt a nd m od ul us va l ue of t he pri va te k e y (P S ) .
5 - S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p ub l ic
ex pon e nt a n d mo du lu s valu e o f t he pri va te key ( P S ) fo r a pa r t i c u la r
se s s io n a nd e ra s e s it p e rma ne nt l y.
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i al s suc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
10 (SEE) 1 4 1.
- Step12: Secured environment engine (SEE) 141 formulated the
pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
an d f orw a r d the cre de n t i a l s to normal E nvi ro nm e nt e n g i n e (N E E ) 1 3 0 .
- Step13: Normal Environment engine (NEE) 130 responses the
15 API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
(PS ).
- S t e p 1 4 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
ex pon e nt a nd m od ul us val ue of t he p r i va te ke y (P S ), se cu r e sto r a ge 120
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l t o th e NFVI 113.
20 - S t e p1 5: N F VI 113 wi ll f orw a r d t he aut he nt i c a t i on sta tu s t o VIM
112 .
- S t e p1 6: I f a ut he nt ica t i on w as s ucce s sf u l , VIM 112 ac kn ow le dge s
t he stat us of all oc at i ng re s ou r ce s t o the VNFM 11 8, ot he r wise re j ec t the
r e q u e s t .
25 - Step17: VNFM 118 will coordinate with NFVO 111 and allocate
r es ou r ce f or sca li ng .
- Step18: VNFM 118 updates the status to EM/VNF ' s if the
a u t h e n t i c a t i o n request was successful .
- S t e p1 9: N F VO 111 no w is a wa re t ha t t he c onfi gura t i o n of t he
30 ne wly sc a le d VNF is in s t an t ia te d .
- Step20: NFVO 111 maps the VNF to the proper VIM 112 and
resource pool.
[0057]
8. 4 . 4 Us eca se f o r Ve rif yi ng th e Sca li ng t r ig ge r ed req ue st by VN FM
31
Fig. 19 is a diagram showing a behavior of NFV system of the
presen t di sc l o su r e wh i ch v e rif ie s the Sca li ng t r i ggered re q uest b y
VNFM.
[0058]
5 8. 4. 5 Me s sage f o r mat f o r Ve rifyi n g t he Sca li ng tri gge r e d r eq ue s t by
VNFM
Figs. 20 and 21 are diagrams showing a message format sent
between HISEE and NFV for verifying the Scaling triggered request by
VNFM.
10 [0059]
8. 4 . 6 Ope ra ti ons fo r Ver if yi ng t he Sc a li ng tri gge re d re que s t b y V NFM
As shown in Fig. 20 and 21, HISEE and NFV send following
messages.
1) Detect_Error_ResourceAllocation, VNFM
15 T h i s messa ge defi ne s the d e t ec t i on of e r ro r du r in g r e so u rc e all oca t io n
in VNFM 118.
2) Cordinates_Scaling_Descison, VNFM<->NFVO
T h i s messa ge def i ne s the co ord ina t io n of scali ng d ec i s io n b et ween
VNFM 118 and NFVO 111.
20 3) ScalingRequest, VNFM ->VIM
T h i s messa ge d ef i ne s t he sca l in g re que st of re s ou rc e al l oc a ti on fro m
VNFM 118 to VIM 112.
4) Va li da te _ Sc a l i ng Tri gge rR e q u e s t , VIM
T h i s mess a ge defi ne s t he va li da t io n of sc a l in g re q ue st by the VIM 11 2 .
25 5) Validate_ScalingTriggerRequest, VIM ->NFVI
T h i s messa ge d ef i ne s t he va lid at i on of sc a li ng r e que s t f ro m V I M 112 to
NFVI 113.
6) Validate_VNFM_Certificate, Read _PrivateKeyAPI, NFVI->SS
T h i s messa ge defi ne s the va lid a t i on of V NFM ce r tif ica te b y c a l l in g the
30 API's of the p r i va te key ( P S ) an d l oc at e t he c r e de n t i a l s in t he se c u re
storage(SS) 120.
7) Get_Public_Exponent, Get_ModulusValue, SS->NEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120 to NEE 130.
32
8) Get_Public_Exponent, Get_ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he p ubl ic
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
5 9) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
10) Store_Public_Exponent, Store _ModulusValue,
10 PKCCont<-HISEE(SW)
T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
of the p r iva te key in PKC co nta i ner 1 4 2 .
11) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
15 va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
environment engine SEE 1 4 1.
12) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
T h i s m e s sa ge d ef i ne s of f orm ula t in g th e pu bl ic ex po ne nt an d mo du l us
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e SEE 1 4 1 .
20 13) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y fro m secu re d e nvi r onm e nt e ng i ne ( SE E ) 1 4 1 to
the normal Environment engine (NEE) 130.
14) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
25 T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120.
15) Validate_VNFM_Certificate(Public _Exponent, ModulusValue),
SS
30 T h i s mess a ge defi ne s t he va li da t io n of VN FM ce r tif i c a te u s in g pu b l ic
ex pon e nt a nd mo du lu s va lue of t he p r iva te k e y ( P S ) t o ac h ieve
au t he nt ic it y.
1 6 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S ,
T h i s messa ge d ef i ne s t he va lid at i on s ta tu s of the V NFM c e r t i f i ca te f ro m
33
secure storage (SS) 120 to NFVI 113.
1 7 ) No t ify _Va l i da ti on _St atu s (Su c ce s s / F a i l ure ), VIM <-NF VI
T h i s messa ge d ef i ne s t he va lid at i on s ta tu s of t he VNF M c e r t i f i c a t e f ro m
NFVI 113 to VIM 112.
5 1 8 ) C hec k _Va l idat io n _St at u s , Pe r f o r m _Sc al in g_Co nf igu r at io n, V I M
This message defines the check the validation status of VNFM 118
ce r t i f i ca te a nd pe rfo rm sc a l in g c on figu r a t io n f or VNFM 11 8 if the
va l i d a t io n sta tu s wa s s ucce s s ot herw i se r ej ec t t he re quest .
19) Ack_NewResourceAllocation, VNFM <-VIM
10 This message defines the acknowledgement status of the new resource
a l l o c a t i o n for VNFM 118 from VIM 112.
20) Update_Scaling_Configuration, VNFM
This message defines the updation of scaling configuration by VNFM
118 .
15 21) Update_Scaling_Configuration_Status, VNFM->NFVO
T h i s me s sa ge d ef i ne s t he u pda t e of s ca li ng c onf igu rat io n s ta t u s to
NFVO 111 by VNFM 118.
[0060]
8. 5 Ve rif yin g t he Scali ng tri gge re d req ues t b y E M/ VN F
20 8. 5. 1 Bl oc k D ia gra m fo r Ve r i f yin g the Scal in g t r i ggere d re ques t by
EM/VNF
Fig. 22 is a diagram showing a NFV system of the present
di sc lo su r e f o r Verif yin g the Sc a l in g t r igge re d re q ue s t by EM (E leme nt
Manager)/VNF.
25 [0061]
8. 5. 2 De s c r i p t i on
Fig. 22 depicts the block diagram for verifying the scaling
t r ig ge r e d re que s t b y EM /VNF ' s . The o bj e ct i ve o f the u s ec a se is t o
verify the authenticity of scaling trigger request by the EM/VNF ' s .
30 An y mali ci ous us e r ma y ra i se th e scal e tri gge r w it hou t t he ne c e s s i t y.
So the EM/VNF's have to prove VIM 112 that they are not malicious one
when they are requesting for scaling trigger. One can easily achieve
au t he nt ic it y u s in g p r opo sed mec h an i sm of pre sen t di s c lo s u re . Bel ow
we have pro vi ded th e s t ep b y s te p a ut he nt ica ti on p r oce d u re f or
34
verifying the scaling trigger request raised by EM/VNF ' s .
[0062]
8. 5. 3 P r oced u re :
As s ho wn i n Fig. 22, th e N FV sys t em of t he p re se n t disc lo su r e
5 ve ri fie s t he Scali ng t r ig ge r e d req ue s t b y EM/ VN F as f o l lo ws .
- Step1: EM/VNF 119 may send automatic or manual scaling
request to NFVO 111 to expand the capacity of a VNF. Automatic
sc al in g re q uest a r e r a i s ed f or so me ce rt a in c on di ti ons l i ke t r affic
overloaded or network resource failures .
10 - Step2: NFVO 111 and VNFM 118 coordinate each other for
sc al in g de c i s i on .
- Step3: NFVO 111 forward the request to VIM 112 for validating
t he au t he n t ic it y.
- S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
15 - Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
- S t e p 6 : NFV I 113 loc a te t he s i gn a t u re an d A PI ' s of p r i va te ke y
( P S ) in the se c u re s to ra ge 12 0 f o r va lid a t in g t he au t he n t i cat io n re quest .
- S t e p 7 : API 's of the pri va t e key (P S ) f orward t he c al l to t he no rma l
20 Environment engine (NEE) 130 to get the public exponent and modulus
va l ue of th e pri va t e key ( P S ) .
- Step8: The normal Environment engine 130 will map the request
t o secure d e nvi ro nme n t e ngi ne (SEE) 141 wh ic h i s l oc at e d i n se c u re d
en vi ron me n t .
25 - Step9: The secured environment engine (SEE) 141 read the
private ke y ( P S ) wh i ch i s lo ca te d in HISEE 1 4 0 an d e xt ra ct t he p ubl ic
ex pon e nt a nd m od ul us va lue of t he pri va te k e y ( P S ) .
- S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p ub l ic
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y (P S ) fo r a pa r t i c u la r
30 se s s io n a nd e ra s e s it p e rma ne nt l y.
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i al s suc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
- Step12: Secured environment engine (SEE) 141 formulated the
35
pu b l i c e x pon en t and m o dul us val ue for the gi ve n a ut hent ica t i on re que s t
an d f orw a r d the cre de n t i a l s to normal E nvi ro nm e nt e n g i n e (N E E ) 1 3 0 .
- Step13: Normal Environment engine (NEE) 130 responses the
API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
5 (PS ) .
- S t e p1 4: If va li da ti on wa s s uc ce s sf ul wit h t he e x t r a c te d pub l ic
ex pon e nt a nd m od ul us val ue of t he p r i va te ke y (P S ), se cu r e sto r a ge 1 2 0
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l to t he N F VI 113.
- S t e p1 5: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
10 112.
- Step16: If authenticat i on was successful, VIM 112 acknowledges
t he stat us of all oc at i ng re s ou r ce s t o the VNFM 11 8, ot he r wise re j ec t the
r e q u e s t .
- Step17: VNFM 118 will coordinate with NFVO 111 and allocate
15 r es ou r ce f or sca li ng .
- Step18: VNFM 118 reports the success of scaling to EM/VNF's
119 if t he a u t he nt i c a t io n re quest wa s succ e s sf ul .
- S t e p1 9: N F VO 111 no w is a wa re t ha t t he c onfi gura t i o n of t he
ne wly sc a le d VNF is in s t an t ia te d .
20 - Step20: NFVO 111 maps the VNF to the proper VIM 112 and
resource pool.
[0063]
8. 5. 4 Us eca se f or Ve rif yi ng t he Scali ng trig ge r e d req uest b y EM /V NF
Fig. 23 is a diagram showing a behavior of NFV system of the
25 presen t di sc l o su r e wh i ch v e rif ie s the Sca li ng t r i ggered re q uest b y
EM/VNF.
[ 00 64]
8. 5. 5 Me s sage f o r mat f o r Ve rifyi n g t he Sca li ng tri gge r e d req ue s t by
EM/VNF
30 Figs. 24 and 25 are diagrams showing a message format sent
between HISEE and NFV for verifying the Scaling triggered request by
EM/VNF.
[0065]
8. 5. 6 Ope ra ti ons f or Ve r if yi ng t he S c a l i ng t r ig gered re qu es t b y
36
EM/VNF
As shown in Figs. 24 and 25, HISEE and NFV send following messages .
1) ScalingRequest, EM/VNF->VNFM
T h i s messa ge defi ne s the d e t ec t i on of e r ro r du r in g r e so u rc e all oca t io n
5 in EM/VNF 119 and request VNFM 118 for scaling resource a l l o c a t i o n .
2) Cordinates_Scaling_Descison, VNFM<->NFVO
T h i s messa ge def i ne s the co ord ina t io n of scali ng d ec i s io n b et ween
VNFM 118 and NFVO 111.3)
3) Validate_ScalingTriggerRequest, VNFM ->VIM
10 This message defines validation of scaling request from VNFM 118 to
VIM 112.
4) Va li da te _ Sc a l i ng Tri gge rR e q u e s t , VIM
T h i s mess a ge defi ne s t he va li da t io n of sc a l in g re q ue st by the VIM 11 2 .
5) ValidateScalingTriggerRequest, VIM ->NFVI
15 T h i s messa ge d ef i ne s t he va lid at i on of sc a li ng r e que s t f ro m V I M 112 to
NFVI 113.
6) Validate_EM/VNF_Certificate, Read_PrivatekeyAPI, NFVI->SS
T h i s me s sa ge d ef i ne s t he val ida ti on of EM/VNF 11 9 cert if ic a te by
c a l l i n g the API's of the private key (P S ) and locate the c r e d e n t i a l s in the
20 secure storage (SS) 120.
7) Get_Public_Exponent, Get _ModulusValue, SS->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120 to NEE 130.
8) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
25 T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
9) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
SEE->HISEE(SW)
30 T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
10) Store_Public_Exponent, Store _ModulusValue,
PKCCont<-HISEE(SW)
T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
37
of the p r iva te key in PKC co nta i ner 1 4 2 .
11) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mod ulu s
va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
5 environment engine (SEE) 1 4 1.
12) Formulate _Public_Exponent, Formulate_ModulusValue , SEE
T h i s m e s sa ge d ef i ne s of f orm ula t in g the pu b l i c e x po nen t an d m od ul us
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
13) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
10 T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y fro m secu re d e n v i ro nm e nt e ngi ne ( S E E ) 1 4 1 t o
the normal Environment engine (NEE) 130.
14) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
15 value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120.
15) Validate_EM/VNF_Certificate(Public_Exponent, ModulusValue),
SS
T h i s me s sa ge def i ne s t he va l id a t i on of E M/ VNF 11 9 ce r t i f i ca te u s in g
20 pu b l i c e xp on ent a nd m od ul us va l ue of th e p r i v a t e k e y (P S ) t o a c hie ve
au t he nt ic it y.
1 6 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / F ai l u re ) , N F VI <- S S ,
T h i s messa ge de fine s th e va li da t io n sta t us of the EM / VNF 119
ce r t i f i ca te f rom s e cu re sto r a ge (S S) 1 2 0 to NFVI 113.
25 1 7 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s messa ge de fine s th e va li da t io n sta t us of the EM / VNF 119
c e r t i f i c a t e from NFVI 113 to VIM 112.
1 8 ) C hec k _Va l i d a t io n _St at u s , Pe r f o r m _Sc al in g _ C onf igu r at io n, V I M
This message defines the check the validation status of EM/VNF 119
30 ce r t i f i ca te an d pe rfo rm scali ng c on figu r a t io n f o r EM/VNF 119 if th e
va l i d a t io n s tat us w as s u c c e s s o t he rwi se rej ect the req ue s t .
19) Ack_NewResourceAllocation, VNFM <-VIM
T h i s me s sa ge de fine s th e ack no wle dgeme n t s t a tu s of t he new re so u r ce
a l l o c a t i o n for EM/VNF 119 from VIM 112.
38
20) Notifies_updates, EM/VNF<-VNFM
This message defines the updat ion of scaling configuration from VNFM
118 to EM/VNF 119.
21) Update_Scaling_Configuration, EM/VNF
5 This message defines the updation of scaling configuration by EM/VNF
119 .
22) Update_Scaling_Configuration, VNFM ->NFVO
T h i s me s sa ge d ef i ne s t he u pda t e of s ca li ng c onf igu rat io n s ta t u s to
NFVO 111 by VNFM 118.
10 [0066]
8. 6 Ve rif yin g t he Scali ng tri gge re d req ues t b y OSS/ B SS
8. 6. 1 Bl oc k D ia gra m fo r Ve r i f yin g the Scal in g t r i ggere d re ques t by
OSS/BSS
Fig. 26 is a diagram showing a NFV system of the present
15 di sc lo su r e f or Verif yi n g the S ca l i ng t r ig ge red re qu es t by O S S / B SS
Ope ra ti on S upp ort Syste m/ B us in es s Sup po r t Syst e m) .
[0067]
8. 6. 2 De s c r i p t i on
Fig. 26 depicts the block diagram for verifying the scaling
20 t r ig ge r e d re qu est b y OSS/BS S' s . The objecti ve of t he u s ec a se i s t o
verify the authenticity of scaling trigger request by the OSS/BSS ' s .
An y mali ci ous us e r ma y ra i se th e scal e tri gge r w it hou t t he ne c e s s i t y.
So the OSS/BSS's have to prove VIM 112 that they are not malicious o ne
when they are requesting for scaling trigger. One can easily achieve
25 au t he nt ic it y u si ng t he p r op osed mec h a ni s m of pr e se nt di sc l os u re .
Be lo w w e ha ve p r o vid e d the ste p by ste p a ut he nt ic at i on proc e d u re fo r
ve ri fyi ng the scali ng t r ig ge r r e que s t ra is e d by O SS/ B S S' s.
[0068]
8. 6. 3 P r oced u re :
30 As s ho wn i n Fig. 26, th e N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s t he Scali ng t r ig ge r e d req ue s t b y OSS/ B S S as f o l lo ws .
- Step1: OSS/BSS 122 sends scaling request to NFVO 111 for some
management demand.
- Step2: NFVO 111 and VNFM 118 coordinate each other for
39
scaling decision.
- Step3: NFVO 111 forward the request to VIM 112 for validating
t he au t he n t ic it y.
- S t e p 4 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
5 - Step5: VIM 112 forwards the request to NFVI 113 for signature
ve ri fic a t io n .
- S t e p 6 : NFV I 113 loc a te t he si gna tu r e a nd API ' s of p r i va te ke y
( P S ) in the se c u re s to ra ge 12 0 f o r va lid a t in g t he au t he n t i cat io n re quest .
- S t e p 7 : API 's of the pri va t e key ( P S ) f orw a rd t he c a l l to t he n ormal
10 Environment engine (NEE) 130 to get the public exponent and modulus
value of the private key (PS ) .
- Step8: The normal Environment engine 130 will map the request
t o secure d e nvi ro nme n t e ngi ne (SEE) 141 wh ic h i s l oc at e d i n se c ured
en vi ron me n t .
15 - Step9: The secured environment engine (SEE) 141 read the
private ke y ( P S ) wh i ch i s lo ca te d in H I SEE 1 4 0 an d e xt ra ct t he p ubl ic
ex pon e nt a nd m od ul us va lue of t he pri va te k e y ( P S ) .
- S t e p 1 0 : The P KC con ta i ner 1 42 st o re s the e xt ra ct ed p ub l ic
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y (P S ) fo r a pa r t i c u la r
20 se s s io n a nd e ra s e s it p e rma ne nt l y.
- S t e p 1 1 : The PKC con ta i ne r 14 2 f o r wa r d s t he c re de n t i al s suc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
- Step12: Secured environment engine (SEE) 141 formulated the
25 pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
an d f orw a r d the cre de n t i a l s to normal E nvi ro nm e nt e n g i n e (N E E ) 1 3 0 .
- Step13: Normal Environment engine (NEE) 130 responses the
API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
(PS ).
30 - S t e p 1 4 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
ex pon e nt a nd m od ul us val ue of t he p r i va te ke y ( P S ), se cu r e sto r a ge 120
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l to th e NFVI 113.
- S t e p1 5: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112.
40
- S t e p1 6: I f a ut he nt ica t i on w as s ucce s sf u l , VIM 112 ac kn ow le dge s
the status of allocating resources to the NFVO 111 and VNFM 118,
ot herw i se r ejec t t he req ue s t .
- Step17: NFVO 111 will coordinate with VNFM 118 and allocate
5 r es ou r ce f or sca li ng .
- Step18: NFVO 111 reports the success of scaling to OSS/BSS 122
if the a u t h e n t i c a t i o n request was successful .
[0069]
8. 6. 4 Us eca se f or Veri f y in g t he Sc a li n g tri gge re d re qu e st by OSS/BS S
10 Fig. 27 is a diagram showing a behavior of NFV system of the
presen t di sc l o su r e wh i ch v e rif ie s the Sca li ng t r i ggered re q uest b y
OSS/BSS.
[0070]
8. 6. 5 Me s sage f o r mat f o r Ve rifyi n g t he Sca li ng tri gge r e d r eq ue s t by
15 OSS/BSS
Figs. 28 and 29 are diagrams showing a message format sent
between HISEE and NFV for verifying the Scaling triggered request by
OSS/BSS.
[0071]
20 8. 6. 6 Ope ra ti ons f or Ve r if yi ng t he S c a l i ng t r ig gered re qu es t b y
OSS/BSS
As shown in Figs. 28 and 29, HISEE and NFV send following
messages.
1) ScalingRequest, OSS/BSS->NFVO
25 T h i s messa ge defi ne s the d e t ec t i on of e r ro r du r in g r e so u rc e all oca t io n
in OSS/BSS 122 and request NFVO 111 for scaling resource a l l o c a t i o n.
2) Validate _ScalingTriggerRequest, NFVO ->VIM
T h i s messa ge d ef i ne s t he sc a li ng req ue s t of reso u r c e all oc at i on f r om
NFVO 111 to VIM 112.
30 3) Validate_ScalingTriggerRequest, VIM
T h i s mess a ge defi ne s t he va li da t io n of sc a l in g re q ue st by the VIM 11 2 .
4) Validate_ScalingTriggerRequest, VIM ->NFVI
T h i s messa ge d ef i ne s t he va lid at i on of sc a li ng r e que s t f ro m V I M 112 to
NFVI 113.
41
5) Validate_EM/VNF_Certificate, Read_PrivatekeyAPI, NFVI->SS
T h i s mes s a ge def i ne s t he va lid at i on of O S S / B SS 12 2 cert if i ca te by
c a l l i n g the API's of the private key (PS ) and locate the c r e d e n t i a l s in the
secure storage(SS) 120.
5 6) Get_Public_Exponent, Get _ModulusValue, SS->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120 to NEE 130.
7) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
10 exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
8) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
15 va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
9) Store_Public_Exponent, Store _ModulusValue,
PKCCont<-HISEE(SW)
T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du lu s va l ue
of the p r iva te key in PKC co nta i ner 1 4 2 .
20 10) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
environment en g i n e (SEE) 1 4 1.
11) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
25 T h i s m e s sa ge d ef i ne s of f orm ula t in g the pu b l i c e x po nen t an d m od ul us
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
12) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y fro m secu re d e n v i ro nm e nt e ngi ne ( S E E ) 1 4 1 to
30 the normal Environment engine (NEE) 130.
13) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120.
42
1 4 ) Va li da te _ OS S / B SS _Ce r t i f i ca te (Pu b l i c _ E xp on e n t , M od ul us Val ue ),
SS
T h i s mes s a ge defi ne s t h e va li da ti on of OSS/ B S S 12 2 certi f i c a t e u s in g
pu b l i c e xp on ent a nd m od ul us va l ue of th e p r i v a t e k e y (P S ) t o a c hie ve
5 au t he nt ic it y.
1 5 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S ,
This message defines the validation status of the OSS/BSS 122
ce r t i f i c a te fro m se c u re s t o ra ge (SS) 1 20 to NFVI 113.
1 6 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
10 This message defines the validation status of the OSS/BSS 122
c e r t i f i c a t e from NFVI 113 to VIM 112.
1 7 ) C hec k _Va l i d a t io n _St at u s , Pe r f o r m _Sc al in g _ C onf igu r at io n, V I M
T h i s me s sa ge d ef i ne s t he che c k t he vali da t io n s ta t u s of OS S /B SS 1 22
ce r t i f i ca te a nd pe r f orm sca li ng c on figu r a t io n f o r O S S/BSS 12 2 if th e
15 va l i d a t io n s tat us w as s ucce ss o t he rwi se rej ect the req ue s t .
18) Ack_NewResourceAllocation, NFVO <-VIM
T h i s me s sa ge de fine s th e ack no wle dgeme n t s t a tu s of t he new re so u r ce
a l l o c a t i o n for OSS/BSS 122 from VIM 112 to NFVO 111.
19) Cordinates_Scaling_Descison, VNFM<->NFVO
20 T h i s messa ge def i ne s the co ord ina t io n of scali ng d ec i s io n b et ween
VNFM 118 and NFVO 111.
20) Update_Scaling_Configuration, OSS/BSS <-NFVO
T h i s me s sa ge d ef i ne s t he u pda t e of s ca li ng c onf igu rat io n s ta t u s to
OSS/BSS 122 by NFVO 111.
25 [0072]
8. 7 Ve rif yin g t he VN FC fa il u re r e que s t
8. 7. 1 Bl oc k D ia gr a m f or Ve r if yin g t he VNFC f a i l u r e re qu e st
Fig. 30 is a diagram showing a NFV system of the present
di sc lo su r e f o r Verif yi n g t he VN F C (Virt ua l i z ed N e tw ork Funct io n
30 C om po ne nt ) fa il u re re que s t .
[0073]
8. 7. 2 De s c r i p t i on s
Fig. 30 depicts the block diagram for verifying the failure request
by VNFC ' s . Th e objec ti ve of th e use ca se i s to verif y t he aut he nt i c i ty
43
of fail u re requ e st b y t he V NFC ' s . A ny ma l i c i ou s u se r m a y ra i se t he
f a i l u re r e que s t wi th ou t t he n ec e s s i ty a nd to avo id dup l i c i t y of the r a i sed
r e q u e s t . So the VNFC ' s have to prove VIM 112 that they are not
malicious one when they are requesting for any failure request . One
5 ca n eas il y a c h i e v e a uthen t ic it y u s in g t he pro po se d me c ha n i sm of
presen t d i s c l os ur e . Be l ow w e ha ve pro vid e d the st e p b y s te p
a u t h e n t i c a t i o n procedure for verifying the failur e request by VNFC ' s .
[0074]
8. 7. 3 P r oced u re
10 As s ho wn i n Fig. 30, th e N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s t he VN FC f ai l u re re que s t as fo l lo w s .
- S t e p 1 : Du e t o tra ffi c o ve r loa d e d o r ne tw ork reso u rc e fa i lu r e s,
VNFC system may get interrupted or failed at any time. If VNFC1
12 31 got fai le d, it wi ll re po rt t o t he nearb y V NFC 2 1 23 2 rega rd in g the
15 VNFC1 s t a t u s.
- Step2: VNFC2 1232 will send failure request to VNFM 118 in
be hal f of VNFC1 12 31 re ga r d i n g th e fa i lu r e s tat us .
- Step3: NFVO (not shown in Fig. 30) and VNFM 118 coordinate
each other for decision making .
20 - Step4: VNFM 118 forward the request to VIM 112 for validating
t he au t he n t ic it y of t he f ai lu r e re quest by VNFC2 1 2 3 2 .
- S t e p 5 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
- S t e p 6 : V I M 112 f o r wa r d s t he r eq ue s t t o N FVI 11 3 f or si gna tu re
ve ri fic a t io n .
25 - S t e p 7 : NFV I 113 loc a te t he si gna tu r e a nd API ' s of p r i va te ke y
( P S ) in the se c u re s to ra ge 12 0 f o r va lid a t in g t he au t he n t i cat io n re quest .
- S t e p 8 : API 's of the pri va t e key ( P S ) f orward t he c al l to t he no rma l
Environment engine (NEE) 130 to get the public exponent and modulus
va l ue of t he p r i va t e ke y (P S ) .
30 - Step9: The normal Environment engine (NEE) 130 will map the
request to secured environment engine (SEE) 141 which is locate d in
secured environment.
- Step10: The secured environment engine (SEE) 141 read the
private ke y( P S ) w h ich i s l oc ated i n HISEE 1 4 0 an d e xt ra ct t he pu b l ic
44
ex pon e nt a nd m od ul us va lue of t he pri va te k e y ( P S ) .
- S t e p 1 1 : Th e PKC co nta i ner 14 2 s to re s the e xt ra c t ed pu b l ic
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y (P S ) fo r a pa r t i c u la r
se s s io n a nd e ra s e s it p e rma ne nt l y.
5 - S t e p1 2: T he PKC co nta i n e r 1 42 f o r wa r d s t he c r eden t ia ls such as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
- Step13: Secured environment engine (SEE) 141 formulated the
pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
10 and forward the c r e d e n t i a l s to normal Environment engine (NEE) 130.
- Step14: Normal Environment engine (NEE) 130 responses the
API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
(PS ).
- S t e p 1 5 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
15 ex pon e nt a nd m od ul us val ue of t he p r i va te ke y ( P S ), se cu r e sto r a ge 120
wi ll no tif y au t h en t ic at io n wa s s uc ce s sf ul to t he NFV I 113.
- S t e p1 6: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112 .
- S t e p1 7: I f a ut he nt ica t i on w as s ucce s sf u l , VIM 112 ac kn ow le dge s
20 the status of a l l o c a t i n g new VNFC 1231, 1232 resources to the VNFM
118 , ot he r wi s e rej ect the re q uest .
- Step18: VNFM 118 will coordinate with NFVO and updates the
s t at us of ne wly al l oc a t e reso u rc e fo r re c ove r y .
- S t e p 1 9 : V NFM 11 8 re po rt s t he s ucc e s s s ta t us of n e wly all oc a t e
25 resource to VNFC1 1231 and VNFC2 1232 if the a u t h e n t i c a t i o n request
was successful.
- Step20: NFVO now is aware that the configuration of the newly
scaled VNFC 1 1231 i n s t a n t i a t e d.
- Step 2 1 : NFVO maps the VNFC 1 2 3 1 , 1232 to the proper VIM 112
30 and resource pool.
[0075]
8. 7. 4 Us eca se f or Veri f y in g t he V NFC fa il u re re que s t
Fig. 31 is a diagram showing a behavior of NFV system of the
present disclosure which v e r i f i e s the VNFC failure request.
45
[0076]
8. 7. 5 Me s sage f orma t f o r Ve rif yin g t he VN FC f a il u re req ue st
Figs. 32 and 33 are diagrams showing a message format sent
between HISEE and NFV for verifying the VNFC failure request .
5 [0077]
8. 7. 6 Ope ra ti ons fo r Ver if yi ng t he V NFC fail u re re que st
As shown in Figs. 32 and 33, HISEE and NFV send following
messages.
1) Notify_FailureStatus, VNFC1<->VNFC2
10 This message defines the detection of failure status in VNFC1 1231 and
n o t i f i e s the status to the nearby VNFC ' s (VNFC2 1232).
2) Notify_FailureStatus, VNFC2->VNFM
T h i s me s s a ge defi ne s th e n ot if ic at io n of fa i lu r e st a t us f ro m VNFC2
1232 to VNFM 118.
15 3) Validate_FailureStatusRequest, VNFM ->VIM
T h i s messa ge d ef i ne s the req ue s t f or va l i da ti on of fa il u re s tat us f ro m
VNFM 118 to VIM 112.
4) Va li da te _ Fa i lu reSt a tu s Re q u e s t , VIM
T h i s messa ge def i ne s the val id a t i on of fa i l u re sta t us re que st by the VIM
20 112.
5) Validate_FailureStatusRequest, VIM ->NFVI
T h i s m e s sa ge d ef i ne s t he f orwa rd v al ida t io n of f a il u re s ta tu s re quest
from VIM 112 to NFVI 113.
6) Validate_VNFC1_Certificate, Read_PrivatekeyAPI, NFVI->SS
25 T h i s mess a ge def i ne s the val ida t io n of VN FC1 12 31 certi f i c a te b y
c a l l i n g the API's of the private key (PS ) and locate the c r e d e n t i a l s in the
secure storage(SS) 120.
7) Get_Public_Exponent, Get _ModulusValue, SS->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
30 exponent and modulus value of the pr i v a t e key from SS 120 to NEE 130.
8) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
46
9) E x t ra ct _ P ub l ic _Ex po nen t, E x t ra ct _Mo du lu s Va lu e,
SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
va l ue of t he p riva t e ke y fro m S E E 14 1 t o Pri va t e ke y 1 43 (P S ).
5 10) Store_Public_Exponent, Store _ModulusValue,
PKCCont<-HISEE(SW)
T h i s messa ge de fine s of st o r in g t he p ubli c ex po ne nt a n d m odu lu s va l ue
of the p r iva te key in PKC co nta i ner 1 4 2 .
11) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
10 T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of th e pri va te key f r om P KC Co nta i n e r 14 2 to t he se c u re d
environment engine (SEE) 1 4 1.
12) Formulate _Public_Exponent, Formulate_ModulusValue, SEE
T h i s m e s sa ge d ef i ne s of f orm ula t in g the pu b l i c e x po nen t an d m od ul us
15 va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
13) Send_Pu blic_Exponent, Send_ModulusValue, NEE<-SEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of the pri va te ke y fro m secu re d e n v i ro nm e nt e ngi ne ( S E E ) 1 4 1 to
the normal Environment engine (NEE) 130.
20 14) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120.
15) Validate_VNFC1_Certificate(Public_Exponent, ModulusValue),
25 SS
T hi s messa ge de fi ne s the va li da ti on of VN F C 1 12 31 certi f i c a te u s in g
pu b l i c e xp on ent a nd m od ul us va l ue of th e p r i v a t e k e y (P S ) t o a c hie ve
au t he nt ic it y.
1 6 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S ,
30 T h i s me s sa ge de f i ne s t he va li da t io n s ta tu s of t he V NFC1 c e rt i f i ca te
from secure storage (SS) 120 to NFVI 113.
1 7 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s me s sa ge de f i ne s t he va li da t io n s ta tu s of t he VNFC1 c e r t i f i c a te
from NFVI 113 to VIM 112.
47
1 8 ) C hec k _Va l idat io n _St at u s , Pe r f o r m _Sc al in g _ C onf igu r at io n, V I M
T h i s mess a ge defi ne s t he ch ec k t he va li da t ion s ta tu s of VN FC 1
ce r t i f i ca te a nd pe rfo r m scal in g c onfi gura t i on f o r VN FC 1 123 1 if t he
va l i d a t io n s tat us w as s ucce ss o t he rwi se rej ect the req ue s t .
5 19) Ack_NewResourceAllocation, VNFM <-VIM
T h i s me s sa ge de fine s th e ack no wle dgeme n t s t a tu s of t he new re so u r ce
a l l o c a t i o n for VNFC1 1231 from VIM 112 to VNFM 118.
20) UpdateStatus_NewVNFCAllocation, VNFM
T h i s me s sa ge defi ne s t he u pd at e s of ne w re so u r c e a l l oc at io n i. e . , ne w
10 VNFC in VNFM 118.
21) Notify_NewVNFCAllocation, VNFC2<-VNFM
T h i s mess a ge defi ne s t he no tif i ca ti on of the new re s ource a l locat io n i. e . ,
VNFC for VNFC1 1231 from VNFM to VNFC2 1232.
22) Notify_NewVNFCAllocation, VNFC1<-VNFM
15 T h i s mess a ge defi ne s t he no tif i ca ti on of the new re s o u r c e al l oc at io n i. e . ,
VNFC for VNFC1 1231 from VNFM to VNFC1 1 2 3 1.
[0078]
8. 8 Ve rif yin g a n d s to r in g the V NFC fail u re se r v i c e s ta t e i n se c u re
storage
20 8. 8. 1 Bl oc k Dia gra m fo r ve ri f yin g a nd s tor in g t he VNFC f a i lu re se r vi c e
s t a te i n sec u re sto r a ge
Fig. 34 is a diagram showing a NFV system of the present
d i s c l o s u r e for verifying and storing the VNFC failure service state in
secure storage .
25 [0079]
8. 8. 2 De s c r i p t i on
F i g. 3 4 de p ict s t he b l oc k di a gr am f or ve rifyi n g the VNFC f a il u re
se r v i c e sta te w h ic h ha s to b e s t o re d i n secu re s to ra ge . T he o bject i ve o f
t he usec a se is t o ve r i fy t he a u t he nt ic it y of fa i lu r e se r v ic e s t a t e w h ic h
30 ha s to be sto re d in secu re st orage . An y m a l ic io us use r may ra i se t he
m a l ic io us d a ta t o be s to red i n secu r e s to ra ge . So the VNFC 's ha ve to
prove V I M 112 tha t th e y a re no t ma li ci ous o ne whe n t he y a re re qu e st i ng
f or s to r in g the fa i lu re s e r v ic e state i n sec u re st orage . One ca n ea s i ly
ac h i e v e a ut hen t i c i t y us in g t he pro po se d mec ha n i sm of p re se nt
48
d i s c l o s u r e . Below we have provided the s t ep by step a u t h e n t i c a t i on
proce du re f or ver if yi ng the ve r if yi ng th e VNFC f a il u re se r vi ce s t a te
which has to be stored in secure storage .
[0080]
5 8.8. 3 Procedure:
As s ho wn i n Fig. 34, th e N FV sys t em of t he p re se n t disc lo su r e
ve ri fie s a nd st o re s th e VNFC f a il u re servi ce sta te i n se c u re sto r a ge a s
follows.
- S t e p 1 : Du e t o tra ffi c o ve r loa d e d o r ne tw ork reso u rc e fa i lu r e s,
10 VNFC 1233 system may get i n t e r r u p t e d or failed at any time .
- Step2: VNFC 1233 simultaneously send failure request to VNFM
118 a nd NF ( Net w ork Fu nc ti on ) 1 24 re ga r d i ng t he fa i lu r e sta t u s to a vo i d
ne t wo rk i n te r r up ti on se r v i c e .
- Step3: VNFC 1233 request VNFM 118 to store the NF status in SS
15 120.
- Step4: VNFM 118 request VIM 112 to validate the VNFC 1233
f a i l u re sta t us & re q ue st VIM 11 2 t o st o re t he NF s tat us i n SS 1 2 0 .
- S t e p 5 : VIM 112 va li d a t e s th e a ut he nt ica ti on re q ue st .
- Step6: VIM 112 forwards the request to NFVI 113 for signature
20 ve ri fic a t io n .
- S t e p 7 : NFV I 113 loc a te t he si gna tu r e a nd API ' s of p r i va te ke y
( P S ) in the se c u re s to ra ge 12 0 f o r va lid a t in g t he au t he n t i cat io n re quest .
- S t e p 8 : API 's of the pri va t e key ( P S ) f orward t he c al l to t he no rma l
Environment engine (NEE) 130 to get the public exponent and modulus
25 value of the private key (PS ) .
- Step9: The normal Environment (NEE) 130 engine will map the
request to secured environment engine (SEE) 141 which is located in
secured environment.
- Step10:The secured environment engine (SEE) 141 read the
30 private ke y ( P S ) wh i ch i s lo ca te d in H I SEE 14 0 an d e xt ra ct t he p ubl ic
ex pon e nt a nd m od ul us va lue of t he pri va te k e y ( P S )
- S t e p 1 1 : Th e PKC co nta i ner 14 2 s to re s the e xt ra ct ed pu b l i c
ex pon e nt a nd m od ul us val ue of t he p r iva te ke y (P S ) fo r a pa r t i c u la r
se s s io n a nd e ra s e s it p e rma ne nt l y.
49
- S t e p1 2: T he PKC co nta i n e r 1 42 f o r wa r d s t he c r eden t ia ls s uc h as
pu b l i c e xp one nt an d mo dul us va l ue t o th e s ecu re d e nv i ron me nt e ngi ne
(SEE) 1 4 1.
- Step13: Secured environment engine (SEE) 141 formulated the
5 pu b l i c e x pon en t and m o dul us val ue for the gi ve n a uthent ica t io n re que st
an d f orw a r d the cre de n t i a l s to normal E nvi r onm e nt e n g i n e (N E E ) 1 3 0 .
- Step14: Normal Environment engine (NEE) 130 responses the
API' s cal l w it h pu b l i c e xp on e nt an d mo du lu s val ue of th e p r i va te key
(PS ).
10 - S t e p 1 5 : If va li da ti on wa s s uc ce s sf ul wi th t he ext r ac t ed pu b l i c
ex pon e nt a nd m od ul us va l ue of t he private ke y (P S ), se cu r e sto r a ge 120
wi ll no tif y au t h en t ic at io n wa s s uc cessf u l to t he N F VI 113.
- S t e p1 6: NFV I 11 3 wil l f orwa rd t he au t he n t ic at io n s t at us to VIM
112 .
15 - S t e p1 7: I f a ut he nt ica t i on w as s ucce s sf u l , VIM 112 ac kn ow le dge s
t he st at us a n d al lo ws V NF to st o re t he f ai l u r e s e r v ic e state of NF 1 24 in
se c u re s to ra ge 12 0, o t he rwi se re j ect the re quest .
- Step18: VNFM 118 will coordinate with NFVO (not shown in Fig.
34 ) a n d up da te s t he s ta tu s of ne wl y al l o ca te reso u rc e f or reco ve r y.
20 - S t e p 1 9 : V N F M 11 8 re po rt s t he s ucc e s s s ta t us of n e wly all oc a t e
resource to VNFC 1233 and NF 124 if the a u t h e n t i c a t i o n request was
successful.
- Step20: NFVO now is aware that the configuration of the newly
scaled VNFC 1233 is i n s t a n t i a t e d.
25 - Step21: NFVO maps the VNFC 1233 to the proper VIM 112 and
resource pool.
[0081]
8. 8. 4 Us eca se f or Ve rif yi ng and st o r i ng t he V NFC fail u re se r v i c e sta te
i n secu r e sto ra ge
30 Fig. 35 is a diagram showing a behavior of NFV system of the
presen t di s c lo s u re w h ic h v e r if ie s an d st o re s the V NFC f a il u re servi ce
s t a te i n sec u re sto r a ge .
[0082]
8. 8. 5 Me s sage f o r m at f o r Ve rifyi n g a n d st o r i ng t he VN FC fa i lu re
50
se r v i c e sta te in se c u re s t o ra ge
Figs. 36 and 37 are diagrams showing a message format sent
between HISEE and NFV for verifying and storing the VNFC failure
se r v i c e sta te in se c u re s t o ra ge .
5 [0083]
8. 8. 6 Ope ra ti ons fo r Ve r if yi ng a nd s t o r in g t he V NFC f a il u re servi c e
s t a te i n sec u re sto r a ge
As shown in Figs. 36 and 37, HISEE and NFV send following
messages.
10 1) Notify_VNFCFailureStatus, VNF<-VNFC
T h i s me s sa ge d ef i ne s t he de t ec t i on of fa i lu re sta t us i n VN F C 12 33 a nd
n o t i f i e s the status to the NF 124.
2) Notify_VNFCFailureStatus, Request_Store_NFStatus,
VNFC->VNFM
15 T h i s me s sa ge de fine s t he no tif ica ti on t o t he VN FC f a i lu re sta t u s t o the
VNFM 118 and request VNFM 118 to store the network function (NF
s t a t u s ) in secure storage (SS) 120.
3) Validate_FailureStatusRequest, VNFM ->VIM
T h i s m essa ge def i ne s the r e que st f or va li dat io n o f VNFC f ai lu re st at us
20 from VNFM 118 to VIM 112.
4) Va li da te _ Fa i lu re S t atu s Req ue s t, VIM
T h i s messa ge defi ne s t he val ida t i on of V NFC fa il u re s ta tu s f a il u re
s t at us re que s t i n V I M 11 2 .
5) ValidateFailureStatusRequest, VIM ->NFVI
25 T h i s m e s sa ge d ef i ne s t he f orwa rd v al ida t io n of f a il u re s ta tu s re quest
from VIM 112 to NFVI 113.
6) Validate_VNFC_Certificate, Read _PrivatekeyAPI, NFVI->SS
T h i s me s sa ge defi ne s th e val id a t i on of V NFC 1 23 3 cert if ic at e b y ca ll in g
t he AP I 's of t he pri v a t e ke y ( P S ) a n d loca te the crede n ti a l s in the sec u re
30 storage(SS) 120.
7) Get_Public_Exponent, Get _ModulusValue, SS->SEE
T h i s me s sa ge def i ne s the f orw a r din g of A P I call to r eq ues t t he pu b l i c
exponent and modulus value of the private key from SS 120 to NEE 130.
8) Get_Public_Exponent, Get _ModulusValue, NEE->SEE
51
T h i s me s sa ge def i ne s the f orw a r din g of A P I c al l to requ est t he p ubl i c
exponent and modulus value of the private key from NEE 130 to SEE
1 4 1 .
9) E x t ra ct _ P ub l ic _Ex po nen t, E xt ra c t _Mo du lu s Va lu e,
5 SEE->HISEE(SW)
T h i s m e s sa ge defi ne s of ex t ra c t i ng t he p ubli c e xp one nt a nd mo dul us
value of the private key f rom SEE 141 to Private key 143 (PS ) .
10) Store_Public_Exponent, Store _ModulusValue, PKCCont
<-HISEE(SW)
10 T h i s messa ge de fine s of s to r in g the pu b l i c exp on e nt a nd mo du l us val ue
of the p r iva te key in PKC co nta i ner 1 4 2 .
11) Send_Public_Exponent, Send_ModulusValue, SEE<-PKCCont
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of th e pri va te key f r om P KC Co nta i ner 14 2 to t he se c u re d
15 environment engine (SEE) 1 4 1.
12) Formulate _Public_Exponent, Formulate_ModulusValue , SEE
This message defines of formulating the public exponent and modulus
va l ue of t he p r i va t e ke y in se c u re d en v i r on men t e ngin e (SE E ) 1 4 1 .
13) Send_Public_Exponent, Send_ModulusValue, NEE<-SEE
20 T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
va l ue of t he p r i va t e key f r om s ec ured e n vi ron men t e n g i n e (SEE) 1 4 1 to
the normal Environment engine (NEE) 130.
14) Send_Public_Exponent, Send_ModulusValue, SS <-NEE
T h i s me s s a ge def i ne s of f orw a r di ng t he pu bl ic e xp onen t a nd mo dulu s
25 value of the private key from normal Environment engine (NEE) 130 to
t he secu re sto rage ( S S ) 120.
1 5 ) Va li da te _ VN F C _C e rt if ic a te ( P ubl ic _Ex po ne n t , M od ul us Val ue ) ,
SS
T h i s messa ge def i ne s th e v a l ida ti on o f VNFC c e r ti f i c a t e u si ng p ub l ic
30 ex pon e nt a nd mo du lu s va lue of t he p r iva te k e y ( P S ) t o ac h ieve
au t he nt ic it y.
1 6 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ), NFVI <- S S ,
T h i s messa ge def i ne s t he va li da t ion sta t us of t he V NFC c e r t i f i ca te f ro m
secure storage (SS) 120 to NFVI 113.
52
1 7 ) No t ify _Va l i da ti on _St atu s (Suc c e s s / Fai lu re ) , VIM <-NF VI
T h i s messa ge def i ne s t he va li da t ion sta t us of t he V NFC c e r t i f i ca te f ro m
NFVI 113 to VIM 112.
1 8 ) C hec k _Va l idat io n _St at u s , Pe r f o r m _Sc al in g _ C onf igu r at io n, V I M
5 T h i s me s sa ge d e f i ne s t he c he ck t he va li da ti on s ta tu s of VNFC
ce r t i f i ca te an d pe rfo rm scali ng c on f igu r a t io n f o r VNFC 1 23 3 if t he
va l i d a t io n s tat us w as s ucce s s , o t he rwi se i t wil l re j ect the re quest .
19) Request_Store_NFStatus, VIM->NFVI
T h i s mes s a ge defi ne s of s to r in g t he NF s t a tu s i n s ecu r e sto rage (SS) 1 2 0
10 from VIM 112 to NFVI 113.
20) Request_Store_NFStatus, NFVI->SS
T h i s mes s a ge defi ne s of s to r in g t he NF st atu s in se c u re st ora ge (SS) 1 2 0
by NFVI 113.
21) Ack_Store_NFStatus, NFVI<-SS
15 T h i s mes s a ge def i ne s t he a c knowled ge me nt of s to r i ng t he NF s ta tu s in
secure storage (SS) 120.
22) Ack_Store_NFStatus, VIM<-NFVI
T h i s mes s a ge def i ne s t he ack now l e dgeme n t of st o r i ng the N F s tat us i n
secure storage (SS) 120 by NFVI 113 to VIM 112.
20 23) Ack_NewVNFCAllocation, Ack _Store_NFStatus, VNFM<-VIM
T h i s mes s a ge def i ne s t he ack now l e dgeme n t of st o r i ng the N F s tat us i n
secure storage (SS) 120 and new VNFC a l l o c a t i o n by VIM 112 to VNFM
118 .
24) Update_NewVNFCAllocati on, Update_Store_NFStatus, VNFM
25 T h i s me s sa ge d ef i ne s the u pd at ion of st o r in g t he NF stat us i n sec u re
storage (SS) 120 and new VNFC a l l o c a t i o n by VNFM 118.
25) Notify_NewVNFCAllocation, Notify_Store_NFSta tus,
VNFC<-VNFM
T h i s messa ge defi ne s the n ot if ic at io n of sto r in g t he NF s ta tu s i n se c u re
30 storage (SS) 120 and new VNFC a l l o c a t i o n by VNFM 118 to VNFC 1233.
26) Notify_Store_NFStatus, VNF<-VNFC
T h i s messa ge defi ne s the n ot if ic at io n of sto r in g t he NF s ta tu s i n se c u re
storage (SS) 120 and by VNFC 1233 to VNF.
[0084]
53
As described above usecases, the proposed method is a scheme
t ha t ena b le s the au t he nt ic at io n of a H I S E E and a l so ac h ie vi n g t he
privacy f o r t he t r u s t e d th i rd p a rt y se r ve rs or ve n do r b y no t reveali ng
t he ir ide n t i t y . HISEE ca n pro ve a nd va l i da te th e t ru s te d t hi rd p a r ty
5 t ha t it i s a t r us t ed syst em wit ho ut re ve al in g i ts id en ti t y. In t he
proposed scheme, private key(P S )of HISEE can be accessed using the
prop ose d sc he me u s in g un iq ue ide nt i f ie r of th e NFV s e cu re c re d ent ia l s .
T he pro po se d me th od n ot o nl y se cu r e s the t r u s t e d th i rd pa r ty k eys f ro m
m a l ic io us u ser i n the case o f a host c omp ro mi s e , bu t a ls o r e s t r ic ts
10 ac ce s s to secu re ke y c re de nt ia l s by a dmi n domai ns . The use of t he
prop ose d me th od wi ll s ol ve s ma ny of the potent ia l a t ta c ks s uc h a s
i n sid e r a tt ac k s , bru te fo r ce a tt ack, i mp lemen t at io n f a i lu re a t t a c k ,
al go r i t hm ic a t t a c k li k e sec r e t key t am pe r i n g , d up l ic a t i ng t he s ecu r it y
c re de nt ia l s .
15 [0085]
T he pro po se d sch eme imp rovi s e s sec u r i t y s t ren gth an d off e r s
ad dit ion a l t rust p r ope r t i e s f o r the tru s te d th i rd pa r ty sy s te m . With t h is
prop ose d me th od, t r ust e d t hi rd par ty c re den t ia ls i n NFV s ys t e m wil l
ha ve sec ured p r iva te me mo r y th at the y ca n u se to s to re d a ta a nd
20 prop r ie ta ry sen s i t i ve c red e n t ia l s . The prop osed f ra m e wo r k a ls o off e rs
se c u r i t y f o r crit ic al com po ne nt s i n N FV s yst em by im plemen ti ng
a u t h e n t i c a t i o n mechanism, which acts as an additional security zone for
secure c r e d e n t i a l s.
[0086]
25 While the preferred exemplary embodiment of the present
i n ven t io n ha s bee n de s c r i be d, it i s to be u nde r s to od th at the pre se nt
i n ven t io n is no t lim i te d to t he e xe mpl a r y em bod ime n t abo ve an d that
f u r th e r m od i f ic a t io n s , re pla cemen ts , an d adj u s tme n t s may be a dd e d
wi t ho ut de pa rt in g f r om t he ba s ic tec hn ic a l co nce pt of t he p re s e nt
30 invention. For example, the NFV system 100 and 100a to 100g in the
us eca se s a bo ve ma y be i mpl em e n te d as a d e d i c a t e d se r v e r .
[0087]
F i n a l l y, the f o l lo wi ng s umm a ri z e s the p ref e r r e d ex em pla r y
embodiments of the present invention.
54

(See the network function v i r t u a l i z a t i o n system in a first aspect
above)

5 T he n e t wo rk f unc ti on vi r tu a l i z a t i on s ys te m acco r di ng t o t he fi rs t
exemplary embodiment wherein
t he p r i va t e key g en e ra to r t ha t re - ge ne ra t e s a fi r st pri va te key
i nfo rma ti on u s in g a se co nd p r iva te key i nf ormat io n sto re d i n t he
ha rd ware - ba se d iso la ted se c u re e xe c u t i on en v i ro n me nt whe n t he
10 pre de te r mi ned co nd i t i on i s sa ti sfi e d .

T he net wo r k fu nc ti on virt u a l i za t io n s ys te m acco r di ng t o t he f i r s t
or second exemplary embodiment wherein
t he pri va te key ge ne rat or th at gen e r a te s a fi r s t p ri va te ke y us in g
15 t he sec on d pri va te ke y, tru s te d th i rd pa r t y ' s p r i va te ke y a nd t he un i que
at t r ib ute s.

T he net wo r k f un ct io n virt ua li za t io n syst e m acc ord in g to on e o f
t he f i r s t t o t hi r d e xe m p l a ry e m bod imen t s whe re in t he private ke y
20 ge ne rat or i s s el e c te d and use d b y the use r ba sed on th e se c u r i t y
requirement.

T he net wo r k f un ct io n virt ua li za t io n syst e m acc ord in g to on e o f
t he f i r s t to fo urt h e xe m p l a r y e mb od imen ts wh e re in th e seco nd pri v a te
25 ke y inf orma t i on i s d i s t r i bu te d t o servi ce pro vid e r s th rou gh a sec u re
ch an ne l.

T he net wo r k f un ct io n virt ua li za t io n syst e m acc ord in g to on e o f
t he fi r st t o fift h e xe m pla ry e m bo dimen t s w he r e i n t he ne t wo r k f unc t io n
30 vi r tu a li za t i on syst em v e r i f ie s at l ea st one of the P KI ce r t i f i ca te , VNF
P ac kage a n d t he Truste d t hi rd pa r ty pri va te ke y fo r a u t he nt i c a t io n .

T he net wo r k f un ct io n virt ua li za t io n syst e m acc ord in g to on e o f
the first to sixth exemplary embodiments wherein the network function
55
vi r tu a li za t i on syst e m v e r ifi es the s ca li ng tri gge re d req ue s t f rom t he
co m po ne nt of ne tw ork f u n c t i on vi rt ua li za t i on syst em .

The network function v i r t u a l i z a t i o n sy s t em according to one of
5 t he first to seven th e x em pla ry e m bo di me nt s wh e r e in the ne t w ork
f u n c t i on vi rt u a l i za ti on syst e m v e ri f ie s t he V NFC fa i lu r e req ue s t or
VN FC fai lu re ser v ic e s t a t e .

( S ee th e ve rif yin g me t ho d in a seco nd aspe c t a bo ve )
10
T he ne tw ork f unct io n virt u a l i za ti on s ys te m c an be e xp r e s s e d a s
follows.
The network function v i r t u a l i z a t i o n comprising: a NFVO/MANO
t ha t re ce i ves a r e que s t t o ce rt if ic at e of at le ast one of da ta e xc han gin g
15 pa rt ie s ; a HISEE a r c hi t ec tu re tha t genera te s a fi r s t p r i va te ke y
i nfo rma ti on u s in g a se co nd p r iva te key i nf ormat io n sto re d i n t he
hardware -based isolated secure execution environment, in response to a
request from NFVO/MANO. The HISEE architecture extracts and
s t o re s a pu b l i c ke y i nf orm a t io n of the f i rst p r iva te key i nf ormat ion .
20 T he n e tw ork fu n c t i on vi r tu a l iz a ti on syst e m f urt he r c omp r i s in g a sec u re
s t ora ge tha t is ac c e s s ib le f r om the re que s t rece i v i n g u ni t . And t he
se c u re sto r age ve r if i e s t he c e r t i f i c a t e u s i n g t he pu b l i c ke y i nf orma t io n
co r r e sp on di ng t o the c ert if ic a te . T he c omm uni ca t i on bet wee n the
se c u re sto r age an d se c u re d e nvi ro nm ent e ngin e in th e HISE E i s relaye d
25 by a normal environment engine .
[0088]
T he d i sc lo s u re of Pa t en t Lite ra tu re s a nd No n Pat e nt L i te ra t u re s
gi ven a bo ve i s here b y i nco r po r a te d b y re f e ren ce i nt o th is d is cl osu re .
The exemplary embodiment s may be changed and adjusted in the scope
30 of t he e nt i re di s cl o s u r e (i nc lu din g cla i ms ) of t he pre s en t i nven t io n an d
ba sed o n t he basic te c hno lo g ic a l co nc e p t . I n t he sc ope of t he cla i ms of
t he p r es e nt i nve nt io n , va r io us d is c lo sed e l em ent s ma y be c omb i ne d and
se le ct e d in a vari et y of wa ys . T ha t i s, it i s to b e u nd e r s to od tha t
m o di fic a ti ons an d c ha n ges tha t may be ma de by t ho se sk i l l e d in the a r t
56
wi t hi n the disc lo s u re o f t he p re se nt i nven t io n a re i nc l u ded .
[ Re fe re n ce Sign s List ]
[0089]
1 0, 1 0 0 , 1 00a -1 0 0 g ne t work f un c ti on virt ua l i za ti on sy s t em
5 11 Re que st r ecei vi ng unit
12 Verif yin g uni t
13 Pu bl ic ke y i nf o r mat io n sto r a g e u nit
14 Pu bl ic key e xtr ac t o r
15 P ri va te ke y gen e ra t or
10 110 MANO (Management and Orchestration)
111 NFVO
112 VIM
113 NFVI
118 VNFM
15 119 EM/VNFN
12 0 Secu r e sto ra ge
121 TTP Private Key
122 OSS/BSS
1231, 1232, 1233 VNFC
20 124 NF
130 Normal environment engine (NEE)
140 HISEE
141 Secured environment engine (SEE)
142 PKC container
25 143 Private Key (PS )
144 Private Key (PH)
200 Cloud
210 Cloud sever

WE CLAIM:
[Claim 1]
A network function virtualization system, comprising:
a request receiving unit that receives a request to certificate of at
least one of data exchanging parties;
a private key generator that generates a first private key
information using a second private key information stored in the
hardware-based isolated secure execution environment, in response to a
request;
a public key extractor that extracts a public key information of
the first private key information;
a public key information storage unit that stores the public key
information; and
a verifying unit that is accessible from the request receiving unit
and the verifying unit verifies the certificate using the public key
information corresponding to the certificate.
[Claim 2]
The network function virtualization system as defined by claim 1,
wherein
the private key generator that re-generates a first private key
information using a second private key information stored in the
hardware-based isolated secure execution environment when the
predetermined condition is satisfied.
[Claim 3]
The network function v i r t u a l i z a t i o n system as defined by claim 1 or 2,
wherein
the private key generator that generates a first private key using
the second private key, trusted third party's private key and the unique
a t t r i b u t e s .
[Claim 4]
The network function v i r t u a l i z a t i o n system as defined by any one of
claims 1 to 3, wherein the private key generator is selected and used by
the user based on the security requirement.
[Claim 5]
The network function v i r t u a l i z a t i o n system as defined by any one of
claims 1 to 4, wherein the second private key information is distributed
to service providers through a secure channel.
[Claim 6]
The network function v i r t u a l i z a t i o n system as defined by any one of
claims 1 to 5, wherein the network function v i r t u a l i z a t i o n system
verifies at least one of the PKI c e r t i f i c a t e , VNF Package and the Trusted
third party private key for authentication.
[Claim 7]
The network function v i r t u a l i z a t i o n system as defined by any one of
claims 1 to 6, wherein the network function v i r t u a l i z a t i o n system
verifies the scaling triggered request from the component of network
function v i r t u a l i z a t i o n system.
[Claim 8]
The network function v i r t u a l i z a t i o n system as defined by any one of
claims 1 to 7, wherein the network function virtualization system
verifies the VNFC failure request or VNFC failure service state.
[Claim 9]
A verifying method in a network function virtualization system,
comprising the steps of:
receiving a request to certificate of at least one of data
exchanging parties;
generating a first private key information using a second private
key information stored in the hardware-based isolated secure execution
environment, in response to a request;
extracting extracts a public key information of the first private
key information; and
verifying the certificate or request using the public key
information corresponds to the certificate by an authentication unit that
is accessible from an application programming interface.

Documents

Application Documents

# Name Date
1 Power of Attorney [08-09-2016(online)].pdf 2016-09-08
2 Form 5 [08-09-2016(online)].pdf 2016-09-08
3 Form 3 [08-09-2016(online)].pdf 2016-09-08
4 Drawing [08-09-2016(online)].pdf 2016-09-08
5 Description(Complete) [08-09-2016(online)].pdf 2016-09-08
6 201611030702-Power of Attorney-210916.pdf 2016-09-24
7 201611030702-Correspondence-210916.pdf 2016-09-24
8 abstract.jpg 2016-10-05
9 REQUEST FOR CERTIFIED COPY [17-10-2016(online)].pdf 2016-10-17
10 Request For Certified Copy-Online.pdf 2016-10-18
11 Other Patent Document [01-12-2016(online)].pdf 2016-12-01
12 201611030702-OTHERS-091216.pdf 2016-12-14
13 201611030702-Correspondence-091216.pdf 2016-12-14