Virtualization server configuration method, virtualization server configuration system, virtualization server, and program
The integration of a MACsec manager within containers addresses the lack of network-level secure communication in conventional orchestrators, enabling efficient and secure MACsec communication between containers.
Patent Information
- Application Number
- PCT/JP2023/046899
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-03
AI Technical Summary
Conventional container orchestrators lack the functionality to configure network communication using MACsec, which is a secure protocol operating at the network level, for secure communication between containers.
A MACsec manager is provided within each container to manage MACsec functions, enabling the acquisition of MAC addresses and common keys for secure communication, and facilitating the setup and activation of MACsec devices for encrypted communication between containers.
Enables faster and secure communication between containers using MACsec, overcoming the limitations of conventional orchestrators by providing efficient key distribution and management for network-level encryption.
Smart Images

Figure JP2023046899_03072025_PF_FP_ABST
Abstract
Description
Virtualization server configuration method, virtualization server configuration system, virtualization server, and program
[0001] The disclosed technology relates to server virtualization and MACsec communication using container technology.
[0002] [Container] Server virtualization is a technology that runs multiple servers on a single physical server, allowing for flexible use of computer resources. Containers are one type of server virtualization technology. Compared to typical virtual servers (hypervisor type), they achieve fast startup and lightweight performance by sharing parts such as the OS kernel between containers and virtualizing only parts such as applications. Note that the term container can also refer to a virtually separated operating environment for applications.
[0003] [Container Orchestrator] Containers run various applications, but they cannot manage themselves or connect with other servers. As a result, managing containers on multiple hosts can be complicated. Kubernetes (Non-Patent Document 1) and Docker Swarm (Non-Patent Document 2) are systems that solve this problem. Using Kubernetes or Docker Swarm makes it possible to coordinate and manage networks, storage, and other aspects of containers when running them on multiple hosts. This type of mechanism is called "container orchestration," and Kubernetes and Docker Swarm are called "container orchestrators."
[0004] FIG. 1 shows a schematic diagram of a container and a container orchestrator. Physical server A (101) is assumed to have container A1 (102) and container A2 (103). Physical server B (101) is assumed to have container A1 (102) and container A2 (103). Container orchestrator 107 configures containers A1, A2, B1, and B2 to be able to communicate with each other using virtual bridge A (108) and virtual bridge B (109). Secure inter-container communication can be achieved by arranging a TLS (Transport Layer Security Protocol) communication function in each application A1, A2, B1, and B2.
[0005] [MACsec] While TLS is a secure protocol that operates at the application level (TCP / IP), MACsec is a secure protocol that operates at the network level (Layer 2). MACsec is a security standard for encrypting MAC frames (e.g., Ethernet frames) and functions as a defense against cyber attacks such as eavesdropping, tampering, and spoofing.
[0006] FIG. 2 shows a schematic diagram of TLS communication and MACsec communication. Assume that Server 1 (202) at Site 1 (201) and Server 2 (204) at Site 2 (203) communicate via a communication network 205. The communication network 205 includes L2 switch 1 (206) and L2 switch 2 (207). In TLS communication, for example, Server 1 encrypts a TCP / IP frame using Key 0, and Server 2 decrypts it using Key 0. In contrast, in MACsec communication, MAC frames are encrypted and communicated between communication nodes on the network from Server 1 to Server 2. That is, a MAC frame encrypted by Server 1 using Key 1 is decrypted by L2 switch 1 (using Key 1). L2 switch 1 re-encrypts the MAC frame using Key 2, and L2 switch 2 decrypts it using Key 2. L2 switch 2 re-encrypts the MAC frame using Key 3, and Server 2 decrypts it using Key 3. For this reason, MACsec communication requires the distribution of a common key to adjacent nodes or the exchange of a common key between adjacent nodes.
[0007] Kubernetes, "overview", [Retrieved December 11, 2023], Internet < https: / / kubernetes.io / docs / concepts / overview / > Docker docs, "Swarm mode overview", [Retrieved December 11, 2023], Internet<https: / / docs.docker.com / engine / swarm / > .
[0008] MACsec has the advantage of being able to be configured to run faster than TLS because it has less communication overhead. While it would be desirable to apply MACsec to inter-container communications, conventional container orchestrators do not have the functionality to configure a network using MACsec (setting the MAC address of the communication partner, key distribution / key exchange).
[0009] The disclosed technology provides a container-based virtualization server configuration method that solves the above-mentioned problems. In this method, a container is provided with a MACsec manager for providing MACsec functionality. The MACsec manager configures a MACsec device in the container that processes MACsec communication. The MACsec manager obtains the MAC address of the MACsec device of another container with which MACsec communication is to be performed. The MACsec manager obtains a shared key to be used for MACsec communication with the other container.
[0010] According to the disclosed technology, MACsec becomes available for communication between containers.
[0011] 1 is a diagram for explaining containers and a container orchestrator. FIG. 1 is a diagram for explaining TLS communication and MACsec communication. A functional block diagram of a container-type virtualization system according to a first embodiment. A functional block diagram of a MACsec manager. A flowchart for explaining an overview of the operation of the virtualization server configuration system. A sequence diagram for explaining MAC address acquisition processing among the operations of the virtualization server configuration system. A sequence diagram for explaining key setting processing among the operations of the virtualization server configuration system. A sequence diagram for explaining MACsec device activation processing among the operations of the virtualization server configuration system. A sequence diagram for explaining key setting processing according to a second embodiment. A diagram showing an example of the functional configuration of a computer.
[0012] Hereinafter, embodiments of the disclosed technology will be described in detail. Note that components having the same functions are assigned the same numbers, and duplicated descriptions will be omitted.
[0013] [First Embodiment] Fig. 3 is a functional block diagram showing an example configuration of a container-type virtualization server configuration system 30 according to the first embodiment. The container-type virtualization server configuration system 30 has various functions for configuring an inter-container network using MACsec. The container-type virtualization server configuration system 30 includes a container orchestrator 301, a network controller 302, and container-type virtualization servers 310 and 320. The container-type virtualization server 310 includes a container C1 (311) and a container C3 (331). The container C1 includes a first Ethernet communication unit 312, a first MACsec device 313, a first MACsec manager 314, and a first application 315. The container C3 includes a first key server 332. Similarly, the container-type virtualization server 320 includes a container C2 (321) and a container C4 (341), and the container C2 includes a second Ethernet communication unit 322, a second MACsec device 323, a second MACsec manager 324, and a second application 325. The container C4 includes a second key server 332.
[0014] 4 shows a detailed configuration example of the MACsec manager. The first MACsec manager 314 includes a first network device management unit 411 and a first key manager 412. The first key manager 412 further includes a first key acquisition unit 413, a first authentication unit 414, and a first validity authentication unit 415. Similarly, the second MACsec manager 324 includes a second network device management unit 421 and a second key manager 422. The second key manager 422 further includes a second key acquisition unit 423, a second authentication unit 424, and a second validity authentication unit 425.
[0015] 5 is a flowchart illustrating the configuration procedure of the container-type virtualization server configuration system 30. The first MACsec device 313, first key manager 412, first key server 332, network orchestrator 301, network controller 302, second key server 342, second key manager 422, and second MACsec device 323 work together to perform MAC address acquisition processing (step S501), key configuration processing (step S502), MACsec device activation processing (step S503), encrypted communication (step S504), and key update processing (step S505).
[0016] Fig. 6 is a sequence diagram explaining the details of the MAC address acquisition process. Fig. 7 is a sequence diagram explaining the details of the key setting process. Fig. 8 is a sequence diagram explaining the details of the MACsec device activation process. Below, the setting procedure for enabling MACsec communication between container C1 and container C2 will be explained using Figs. 3, 4, 5, 6, 7, and 8. Note that "network" is sometimes abbreviated to "NW" in Figs. 6, 7, and 8.
[0017] [MAC Address Acquisition Process] This process causes the first MACsec device to acquire the MAC address of the second MACsec device, and causes the second MACsec device to acquire the MAC address of the first MACsec device. The network controller 302 requests network configuration information from the container orchestrator 301 (step S601). The container orchestrator 301 sends the network configuration information to the network controller 302 (step S602). The network controller 302 distributes the IP information of container C2 to the first key manager 412 (step S603) and distributes the IP information of container C1 to the second key manager 422 (step S604).
[0018] The first MACsec manager 314 constructs a first MACsec device (step S605). The first key manager 412 requests the MAC address of the first MACsec device from the first MACsec device 313 (step S606). The first key manager 412 acquires the MAC address of the first MACsec device from the first MACsec device 313 (step S607).
[0019] The second MACsec manager 422 constructs a second MACsec device (step S608). The second key manager 422 requests the MAC address of the second MACsec device from the second MACsec device 323 (step S609). The second key manager 422 acquires the MAC address of the second MACsec device from the second MACsec device 323 (step S610).
[0020] The second key manager 422 sends the MAC address of the second MACsec device to the first key manager 412 and requests the first key manager 412 to send the MAC address of the first MACsec device (step S611). The first key manager 412 sends the MAC address of the first MACsec device to the second key manager 422.
[0021] This concludes the description of the MAC address acquisition sequence.
[0022] [Key Setting Process] This process causes the first MACsec device and the second MACsec device to obtain a common key. The first key manager 412 requests a common key from the first key server 332 (step S701). The first key server 332 and the second key server 342 exchange keys to determine the common key (step S702). The first key server 332 sends the common key and the ID (key ID) of the common key to the first key manager 412 (step S703). The first key manager 412 and the second key manager 422 communicate via TLS, for example, to perform mutual authentication (step S704). The first key manager 412 sends the key ID and network information of the first MACsec device to the second key manager 422 and requests a key update (step S705).
[0023] The second key manager 422 verifies the validity of the received key ID and network information (step S706). The second key manager 422 sends the received key ID to the second key server 342 and requests a key (common key) corresponding to the key ID (step S707). The second key server 342 sends the key corresponding to the key ID to the second key manager 422 (step S708). The second key manager 422 sends a key ID receipt notification and network information of the second MACsec device to the first key manager 412 (step S709). The first key manager 412 verifies the validity of the received network information of the second MACsec device (step S710). The first key manager 412 sets the common key and the MAC address of the second MACsec device in the first MACsec device (step S711). The second key manager 422 sets the common key and the MAC address of the first MACsec device in the second MACsec device (step S712).
[0024] This concludes the description of the key establishment sequence.
[0025] [MACsec Device Activation Process] This process activates the MACsec devices by assigning the IP addresses of containers C1 and C2 to the MACsec devices. The first key manager 412 assigns the IP address of container C1 to the first MACsec device (step S801). The second key manager 422 assigns the IP address of container C2 to the second MACsec device (step S802). The first key manager 412 sends correspondence information (new combination information) between the IP address and MAC address of the first MACsec device to the network controller 302 (step S803). The second key manager 422 sends correspondence information (new combination information) between the IP address and MAC address of the second MACsec device to the network controller 302 (step S804). The network controller 302 changes the network configuration information of bases A and B based on the received information. If it is necessary to modify the network configuration information of the container orchestrator 301, the change setting of the network configuration information is sent to the container orchestrator, and consistency of the network configuration information is achieved (step S805).
[0026] This concludes the description of the MACsec device activation sequence.
[0027] [Implementation of Encrypted Communication] After the above settings are completed, the container C1 and the container C2 implement encrypted communication using MACsec (step S504).
[0028] [Key Update Processing] The common key used for MACsec communication is updated periodically (step S505). The key update processing may be performed in the same manner as the above-mentioned [Key Setting Processing].
[0029] The above is the description of the first embodiment.
[0030] Second Embodiment In the first embodiment, the common key is acquired from the key server, but the key may be shared and updated between MACsec managers.
[0031] The MAC address acquisition process is performed in the same manner as in the first embodiment, with the first MACsec device acquiring the MAC address of the second MACsec device and the second MACsec device acquiring the MAC address of the first MACsec device.
[0032] [Key Setting Process 2] Key setting process 2 according to the second embodiment will be described with reference to Fig. 9. The first key manager 412 and the second key manager 422 establish a common key through key exchange (step S901). Next, as in the first embodiment, the first key manager 412 sets the common key and the MAC address of the second MACsec device in the first MACsec device (step S711). The second key manager 422 sets the common key and the MAC address of the first MACsec device in the second MACsec device (step S712).
[0033] [MACsec device activation process] is performed in the same manner as in the first embodiment.
[0034] The periodic "key update process" is also performed by the above-mentioned "key configuration process 2." Note that the shared keys of the first MACsec device and the second MACsec device must be configured / updated synchronously. This can be achieved, for example, by mutually notifying and confirming the start and / or completion of the shared key configuration procedure between the first key manager and the second key manager.
[0035] The above is the description of the second embodiment.
[0036] [Supplementary Information] In the above embodiment, the common key is obtained from an external key server and the MACsec managers of the communication partners share and update the key. However, key acquisition and updating may be performed by switching between these methods. The external key server may be located outside the container, within the container, or within the same pod or node. The above embodiment assumes a network configuration in which L2 communication can be performed directly on the same network segment. When a host accommodating containers communicates between containers via a router (L3), the above function can be operated after configuring an L2 over L3 configuration such as VXLAN. When feedback to the container orchestrator is not required, the network controller can distribute distribution control information to the MACsec managers of each container in advance, thereby switching the communication partner with which secure communication is established. In the above embodiment, the network controller operates in cooperation with an existing container orchestrator. However, the container orchestrator may be configured to have the above network controller functionality in advance.
[0037] [Program, Recording Medium] The functions realized by the components described in this specification may be implemented in circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (Central Processing Units), conventional circuits, and / or combinations thereof, programmed to realize the described functions. A processor includes transistors and other circuits and is considered to be circuitry or processing circuitry. A processor may be a programmed processor that executes a program stored in a memory.
[0038] In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions.
[0039] If the hardware is a processor considered to be a type of circuitry, the circuitry, means, or unit is a combination of the hardware and software used to configure the hardware and / or processor.
[0040] The various processes described above can be implemented by loading a program that executes each step of the above method into the recording unit 2020 of the computer 2000 shown in Figure 10, and operating the control unit 2010, input unit 2030, output unit 2040, display unit 2050, etc.
[0041] The program describing the processing contents can be recorded on a computer-readable recording medium, which may be, for example, a magnetic recording device, an optical disk, a magneto-optical recording medium, a semiconductor memory, or any other suitable recording medium.
[0042] The program may be distributed by, for example, selling, transferring, lending, etc. portable recording media such as DVDs and CD-ROMs on which the program is recorded. Furthermore, the program may be stored in a storage device of a server computer, and then transferred from the server computer to other computers via a network, thereby distributing the program.
[0043] A computer that executes such a program may first temporarily store the program recorded on a portable recording medium or transferred from a server computer in its own storage device. Then, when executing a process, the computer reads the program stored in its storage device and executes the process in accordance with the read program. Alternatively, the computer may read the program directly from a portable recording medium and execute the process in accordance with the program. Furthermore, the computer may execute the process in accordance with the program each time a program is transferred from a server computer to the computer. Alternatively, the server computer may not transfer the program to the computer, but may instead execute the process through a so-called ASP (Application Service Provider) service, which realizes the processing function by issuing an execution instruction and obtaining the results. Furthermore, the server computer may execute the process at the terminal using a so-called SaaS (Software as a Service) service, which allows users to use part of the server computer along with the program. In this embodiment, the program includes information used for processing by an electronic computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that dictate computer processing).
[0044] Furthermore, in this embodiment, the device is configured by executing a predetermined program on a computer, but at least a part of the processing contents may be realized by hardware.
[0045] 30 Container-type virtualization system with MACsec 301 Container orchestrator 302 Network controller 310 Container-type virtualization server 311 Container C1 312 First Ethernet communication unit 313 First MACsec device 314 First MACsec manager 315 First application 320 Container-type virtualization server 321 Container C2 322 Second Ethernet communication unit 323 Second MACsec device 324 Second MACsec manager 325 Second application 331 Container C3 332 First key server 341 Container C4 342 Second key server 411 First network device management unit 412 First key manager 413 First key acquisition unit 414 First authentication unit 415 First validity authentication unit 421 Second network device management unit 422 Second key manager 423 Second key acquisition unit 424 Second authentication unit 425 Second authenticity authentication unit 2000 Computer 2010 Control unit 2020 Recording unit 2030 Input unit 2040 Output unit 2050 Display unit
Claims
1. A method for configuring a virtualized server using container technology, wherein the container is provided with a MACsec manager for imparting a MACsec function, the MACsec manager constructs a MACsec device for processing MACsec communication in the container, the MACsec manager obtains the MAC address of the MACsec device of another container that is the counterpart of the MACsec communication, and the MACsec manager obtains a common key to be used for MACsec communication with the other container. A virtualized server configuration method.
2. The virtualized server configuration method according to claim 1, wherein the MACsec manager replaces the IP address of the container with the MACsec device. A virtualized server configuration method.
3. The virtualized server configuration method according to claim 2, wherein the MACsec manager obtains part or all of the container network configuration information held by the container orchestrator, and the MACsec manager requests the MAC address from the other container based on the network configuration information. A virtualized server configuration method.
4. The virtualized server configuration method according to claim 3, wherein the MACsec manager transmits correspondence information in which the MAC address of the MACsec device and the IP address are paired to the network controller to update the container network configuration information. A virtualized server configuration method.
5. The virtualized server configuration method according to claim 1, wherein a first key server and a second key server perform key exchange to determine the common key, the MACsec manager obtains the common key from the first key server, and the MACsec manager of the other container obtains the common key from the second key server. A virtualized server configuration method.
6. A program for causing a computer to execute the procedure of the virtualized server configuration method according to any one of claims 1 to 5.
7. A virtualized server configuration system comprising a container orchestrator, a network controller, and a container equipped with a MACsec manager, wherein the network controller acquires container network configuration information from the container orchestrator, and the MACsec manager constructs a MACsec device for processing MACsec communication in the container, acquires network information of another container that is a counterpart for MACsec communication from the network controller, acquires the MAC address of the MACsec device of the other container based on the network information, and acquires a common key used for MACsec communication with the other container.
8. A virtualized server using container technology, wherein the container is equipped with a MACsec manager for imparting a MACsec function, and the MACsec manager constructs a MACsec device for processing MACsec communication in the container, acquires the MAC address of the MACsec device of another container that is a counterpart for MACsec communication, and acquires a common key used for MACsec communication with the other container.
Citation Information
Patent Citations
Secret calculation device, secret calculation method and program
JP2018087917A