System and method of establishing trusted operability between networks in a network functions virtualization environment

US9749294B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9749294-B1
Application numberUS-201514847992-A
CountryUS
Kind codeB1
Filing dateSep 8, 2015
Priority dateSep 8, 2015
Publication dateAug 29, 2017
Grant dateAug 29, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for establishing a trusted end-to-end communication link between different NFV networks is disclosed. The system comprises a server operating in a trusted security zone and configured to generate and send a trust ticket, a communication request, and disable communication with the first NFV network. The system further comprises a virtual machine executing virtualized network functions and a session border controller. The session border controller is configured to receive the trust ticket, request, and trusted data from the first server; transmit the trust ticket and request to a second session border controller, wherein the trust ticket and request are transmitted to a second server associated with a second NFV network, and receive a response and second trust ticket from the second NFV network, compare the first and second trust ticket for compatibility, and transmit the trusted data if the trust tickets are compatible.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for establishing a trusted end-to-end communication link between different Network Function Virtualization (NFV) networks, comprising: a first server associated with a first NFV network, wherein the first server comprises a processor coupled to memory and is configured to: generate and send a first trust ticket establishing the security protocol for communicating with the first NFV network, a request to engage in communication with a second server associated with a second NFV network, and trusted data from the first NFV network, wherein the first NFV network is executing in a trusted security zone that provides hardware assisted security, and wherein the second server comprises a processor coupled to memory; and disable communication with the first NFV network after the first trust ticket, request and trusted data are sent; a virtual machine stored on the first NFV network, wherein the virtual machine executes virtualized network functions and is executing in a trusted security zone; and a session border controller executing in a trusted security zone, wherein the session border controller comprises a trust node and an application stored on the trust node, configured to: receive the first trust ticket, request, and trusted data from the first server; transmit the first trust ticket and request to a second session border controller, wherein the second session border controller transmits the request and first trust ticket to the second server associated with the second NFV network; receive a response to the request and a second trust ticket from the second server, wherein the second trust ticket establishes the security protocol for communicating with the second NFV network, wherein the response and second trust ticket are transmitted from the second session border controller to the first session border controller, and wherein the second NFV network is executing in in a trusted security zone, that provides hardware assisted security; compare the first and second trust tickets for compatibility; and transmit the trusted data to the second server if the trust tickets are compatible. 2. The system of claim 1 , wherein the first NFV network and the second NFV network comprise one of the following group: a compute network, a data network, a server, or other computer system in communication with a network operating in an NFV environment. 3. The system of claim 1 , wherein the first session border controller, executing in a trusted security zone, transmits data to the second NFV network by way of an outbound session router. 4. The system of claim 3 , wherein the second session border controller, executing in a trusted security zone, transmits data to the first NFV network by way of an inbound session router. 5. The system of claim 4 , wherein the outbound session router and inbound session router transmit data on independent pathways. 6. The system of claim 1 , wherein the first and second session border controller are located on the same device. 7. The system of claim 1 , wherein the second server is configured to disable communication between the second session border controller and the second server after the transmission of the trusted data is complete. 8. A system for establishing a trusted end-to-end communication link between different Network Function Virtualization (NFV) networks, comprising: a first server associated with a first NFV network, wherein the first server comprises a processor coupled to memory and is configured to: generate and send a first trust ticket establishing the security protocol for communicating with the first NFV network, a request to engage in communication with a second server associated with a second NFV network, and trusted data from the first NFV network, wherein the first NFV network is executing in a trusted security zone that provides hardware assisted security, and wherein the second server comprises a processor coupled to memory; and disable communication with the first NFV network after the first trust ticket, request and trusted data are sent; a virtual machine stored on the first NFV network, wherein the virtual machine executes virtualized network functions and is executing in a trusted security zone; and a session border controller executing in a trusted security zone, wherein the session border controller comprises a trust node and an application stored on the trust node, configured to: receive the first trust ticket, request, and trusted data from the first server; transmit the first trust ticket and request to a second session border controller, wherein the second session border controller transmits the request and first trust ticket to the second server associated with the second NFV network; receive a response to the request and a second trust ticket from the second server, wherein the second trust ticket establishes the security protocol for communicating with the second NFV network, wherein the response and second trust ticket are transmitted from the second session border controller to the first session border controller, and wherein the second NFV network is executing in a trusted security zone that provides hardware assisted security; compare the first and second trust tickets for compatibility; and transmit, in response to a determination that the first and second trust tickets are incompatible, a message to the first server refusing to transmit the trusted data. 9. The system of claim 8 , wherein the first NFV network and the second NFV network comprise one of the following group: a compute network, a data network, a server, or other computer system in communication with a network operating in an NFV environment. 10. The system of claim 8 , wherein the first session border controller, executing in a trusted security zone, transmits data to the second NFV network by way of an outbound session router. 11. The system of claim 10 , wherein the second session border controller, executing in a trusted security zone, transmits data to the first NFV network by way of an inbound session router. 12. The system of claim 11 , wherein the outbound session router and inbound session router transmit data on independent pathways. 13. The system of claim 8 , wherein the first and second session border controller are located on the same device. 14. The system of claim 8 , wherein the first session border controller is configured to disable communication with the second session border controller and the second server after refusing transmission of the trusted data. 15. The system of claim 8 , wherein the first NFV network provides core network services to a radio access network (RAN) that provides communication service to user equipment (UE), where the RAN supports at least one of an orthogonal frequency division multiple access, a code division multiple access (CDMA), a global system for mobile communication, and a worldwide interoperability for microwave access wireless communication protocol. 16. A method of establishing a trusted end-to-end communication link between different Network Function Virtualization (NFV) networks, comprising: receiving, by a first session border controller, from a first server associated with a first NFV network, a first ticket of trust establishing the security protocol for communicating with the first NFV network, a request to engage in communication with a second server, the second server associated with a second NFV network, and trusted data from the first NFV network, wherein the first NFV network is executing in a trusted security zone that provides hardware assisted security; disabl

Assignees

Inventors

Classifications

  • Hypervisor-specific management and integration aspects · CPC title

  • Electricity · mapped topic

  • Virtual private networks · CPC title

  • Electricity · mapped topic

  • for accessing one among a plurality of replicated servers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9749294B1 cover?
A system for establishing a trusted end-to-end communication link between different NFV networks is disclosed. The system comprises a server operating in a trusted security zone and configured to generate and send a trust ticket, a communication request, and disable communication with the first NFV network. The system further comprises a virtual machine executing virtualized network functions a…
Who is the assignee on this patent?
Sprint Communications Co Lp
What technology area does this patent fall under?
Primary CPC classification H04L63/0272. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 29 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).