BGP VMs with HRoT Verification in NFV Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Hardware Root-of-Trust (HRoT) systems and Network Function Virtualization (NFV) with Border Gateway Protocol (BGP) systems is not effectively addressed in current technologies, leading to security and control issues in communication networks.

Innovation Solution

A data communication system that utilizes BGP Virtual Machines (VMs) within NFV computer systems to integrate HRoT verification and NFV time-slice management through BGP signaling, ensuring secure and trusted communication by verifying HRoT and NFV data within BGP messages, and coordinating NFV time-slices to manage BGP state processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HRoT systems and NFV systems are integrated with BGP systems, then network security and control are enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines HRoT verification, NFV time-slice management, and BGP routing operations into a unified system where a single BGP message carries both routing information and verification data. This merging eliminates the need for separate verification channels and reduces overall system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The BGP message structure is enhanced to serve multiple functions simultaneously: it carries routing information, HRoT verification data, and NFV time-slice identifiers. This multi-functionality allows the same communication protocol to handle both security verification and network routing without requiring additional specialized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If HRoT verification is performed for each BGP message, then communication trust is ensured, but processing time increases

Engineering Contradiction:
Improvecommunication trustVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

HRoT verification is performed during the BGP connection establishment phase before actual routing exchanges begin. This preliminary verification ensures that subsequent communications are trusted without requiring repeated verification for each message, thereby reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once HRoT verification is established, the trust relationship continues across multiple BGP messages without interruption. The verification state is maintained and reused, allowing continuous routing information exchange without repeated verification overhead, thus minimizing time loss.

Inventive Principle:
Principle #20Continuity of useful action

3Manufacturing precision

If NFV time-slice management is integrated into BGP signaling, then resource allocation accuracy is improved, but message complexity increases

Engineering Contradiction:
Improveresource allocation accuracyVSAvoidmessage complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The BGP message structure is extended with specific fields for NFV time-slice identifiers and resource allocation parameters. These localized additions provide precise resource management information without fundamentally changing the entire message structure, maintaining compatibility while improving allocation accuracy.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces intermediary fields in BGP messages that carry NFV time-slice information. These intermediary elements act as mediators between the BGP routing function and NFV resource management, allowing accurate resource allocation without requiring complete restructuring of the BGP protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9917815B2Border gateway protocol (BGP) communications over trusted network function virtualization (NFV) hardware
Publication Date: 2018.03.13 T MOBILE INNOVATIONS LLC
  • US9917815B2 patent drawing
  • US9917815B2 patent drawing
  • US9917815B2 patent drawing

AI summary

A data communication system uses Border Gateway Protocol (BGP) and Network Function Virtualization (NFV). A first BGP Virtual Machine (VM) in a first NFV computer system transfers NFV request data in first BGP signaling for delivery to a second BGP VM in a second NFV computer system. The second BGP VM in the second NFV computer system processes the NFV request data and responsively transfers NFV time-slice data for the second BGP VM in second BGP signaling for delivery to the first BGP VM in the first NFV computer system. The first BGP VM in the first NFV computer system verifies the NFV time-slice data for the second BGP VM and performs a BGP state process only if the NFV time-slice data for the second BGP VM is verified. A Hardware Root of Trust (HRoT) verification for the second BGP VM may be also performed using the BGP signaling.