发明名称 Border gateway protocol (BGP) communications over trusted network function virtualization (NFV) hardware
摘要 A first Network Function Virtualization (NFV) computer system generates Hardware Root-of-Trust (HRoT) challenge data and transfers the HRoT challenge data in first Border Gateway Protocol (BGP) signaling to a second NFV computer system. The second NFV computer system identifies a physically-embedded HRoT code and generates an HRoT result based on the challenge data and code. The second NFV computer system transfers second BGP signaling having the HRoT result to the first NFV computer system. The first NFV computer system compares the HRoT result from the second BGP signaling to target HRoT data. The first NFV computer system executes a BGP process based on the second BGP signaling if the HRoT result corresponds to the target HRoT data. In some examples, the NFV computer systems also exchange the BGP signaling to verify NFV time slices for BGP Virtual Machines (VMs).
申请公布号 US9386001(B1) 申请公布日期 2016.07.05
申请号 US201514635631 申请日期 2015.03.02
申请人 Sprint Communications Company L.P. 发明人 Marquardt Ronald R.;Paczkowski Lyle Walter;Rajagopal Arun
分类号 H04L12/66;H04L29/06;H04L12/771 主分类号 H04L12/66
代理机构 代理人
主权项 1. A method of operating a data communication system using Border Gateway Protocol (BGP), Network Function Virtualization (NFV), and Hardware Root-of-Trust (HRoT) comprising: in a first NFV computer system, generating HRoT challenge data, executing a first BGP virtual machine, and transferring the HRoT challenge data in first BGP signaling for delivery to a second BGP virtual machine in a second NFV computer system; in the second NFV computer system, executing the second BGP virtual machine, processing the first BGP signaling, and responsively identifying an HRoT code physically-embedded in the second NFV computer system, generating HRoT result data based on the HRoT challenge data and the HRoT code, and transferring second BGP signaling having the HRoT result data for delivery to the first BGP virtual machine in the first NFV computer system; in the first NFV computer system, generating target HRoT result data based on the HRoT challenge and the HRoT code, receiving the second BGP signaling, and responsively comparing the HRoT result data from the second BGP signaling to the target HRoT data generated by the first NFV computer system; and in the first NFV computer system, executing a BGP state process based on the second BGP signaling if the HRoT result data from the second BGP signaling corresponds to the target HRoT data generated by the first NFV computer system.
地址 Overland Park KS US