BGP VMs with HRoT Verification in NFV Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of Hardware Root-of-Trust (HRoT) systems and Network Function Virtualization (NFV) with Border Gateway Protocol (BGP) systems is not effectively addressed in current technologies, leading to security and control issues in communication networks.
Innovation Solution
A data communication system that utilizes BGP Virtual Machines (VMs) within NFV computer systems to integrate HRoT verification and NFV time-slice management through BGP signaling, ensuring secure and trusted communication by verifying HRoT and NFV data within BGP messages, and coordinating NFV time-slices to manage BGP state processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HRoT systems and NFV systems are integrated with BGP systems, then network security and control are enhanced, but system complexity increases
Solution Approach 1:
The patent combines HRoT verification, NFV time-slice management, and BGP routing operations into a unified system where a single BGP message carries both routing information and verification data. This merging eliminates the need for separate verification channels and reduces overall system complexity while maintaining security.
Solution Approach 2:
The BGP message structure is enhanced to serve multiple functions simultaneously: it carries routing information, HRoT verification data, and NFV time-slice identifiers. This multi-functionality allows the same communication protocol to handle both security verification and network routing without requiring additional specialized protocols.
2Reliability
If HRoT verification is performed for each BGP message, then communication trust is ensured, but processing time increases
Solution Approach 1:
HRoT verification is performed during the BGP connection establishment phase before actual routing exchanges begin. This preliminary verification ensures that subsequent communications are trusted without requiring repeated verification for each message, thereby reducing processing time while maintaining security.
Solution Approach 2:
Once HRoT verification is established, the trust relationship continues across multiple BGP messages without interruption. The verification state is maintained and reused, allowing continuous routing information exchange without repeated verification overhead, thus minimizing time loss.
3Manufacturing precision
If NFV time-slice management is integrated into BGP signaling, then resource allocation accuracy is improved, but message complexity increases
Solution Approach 1:
The BGP message structure is extended with specific fields for NFV time-slice identifiers and resource allocation parameters. These localized additions provide precise resource management information without fundamentally changing the entire message structure, maintaining compatibility while improving allocation accuracy.
Solution Approach 2:
The patent introduces intermediary fields in BGP messages that carry NFV time-slice information. These intermediary elements act as mediators between the BGP routing function and NFV resource management, allowing accurate resource allocation without requiring complete restructuring of the BGP protocol.
Data Source
AI summary
A data communication system uses Border Gateway Protocol (BGP) and Network Function Virtualization (NFV). A first BGP Virtual Machine (VM) in a first NFV computer system transfers NFV request data in first BGP signaling for delivery to a second BGP VM in a second NFV computer system. The second BGP VM in the second NFV computer system processes the NFV request data and responsively transfers NFV time-slice data for the second BGP VM in second BGP signaling for delivery to the first BGP VM in the first NFV computer system. The first BGP VM in the first NFV computer system verifies the NFV time-slice data for the second BGP VM and performs a BGP state process only if the NFV time-slice data for the second BGP VM is verified. A Hardware Root of Trust (HRoT) verification for the second BGP VM may be also performed using the BGP signaling.


