IP Library › Granted Patent US 11,822,946
Granted Patent B2
US 11,822,946 · App. 16/457,278 · Granted Nov 21, 2023

Systems and methods for secure network management of virtual network functions

Inventors: Igor Faynberg (East Brunswick, NJ); Donald E. A. Clarke (Louisville, CO); Steven J. Goeringer (Westminster, CO)
Assignee: Cable Television Laboratories, Inc.
G06F9/45558H04L43/0817H04L63/04G06F2009/45595H04L45/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,822,946
App. No.
16/457,278
Granted
Nov 21, 2023
Kind
B2
Abstract

A virtual network system for a computer network is provided. The system includes a first host executing a virtual network function manager. The system also includes a second host executing a management virtual machine. The management virtual machine is in communication with the virtual network function manager and with one or more virtual network function component instantiations. The management virtual machine is programmed to route messages between the one or more virtual network function component instantiations and the virtual network function manager.

Claims (32)

1. A virtual network system for a computer network, comprising:

a first host executing a virtual network function manager; and

a second host comprising a first network interface and a second network interface, the second host executing a management virtual machine, wherein the management virtual machine is in communication with the virtual network function manager and with one or more virtual network function component instantiations, and wherein the management virtual machine is programmed to route messages between the one or more virtual network function component instantiations and the virtual network function manager, wherein the second host is separate from the first host, wherein the management virtual machine executed by the first host includes a monitoring agent and a management agent, wherein the monitoring agent transmits messages to the virtual network function manager by providing one way communication from the management virtual machine to the virtual network function manager and the management agent receives messages from the virtual network function manager by providing one-way communication from the virtual network function manager to the management virtual machine.

2. The system of claim 1 , wherein the first host and the second host are connected via a Command and Control Network via the first network interface.

3. The system of claim 2 , wherein the second host is connected to a host network via the second network interface, wherein the host network is connected to the one or more virtual network function component instantiations, and wherein the first host and the virtual network function manager are isolated from the host network.

4. The system of claim 1 , wherein the second host executes a hypervisor in communication with the management virtual machine and the one or more virtual network function component instantiations.

5. The system of claim 1 , wherein the monitoring agent transmits notifications to the virtual network function manager, wherein the notifications include information about the one or more virtual network function component instantiations.

6. The system of claim 1 , wherein the managing agent receives requests from the virtual network function manager, wherein the managing agent executes the requests on the one or more virtual network function component instantiations.

7. A method for providing virtual network functions implemented by at least one processor in communication with at least one memory device and further in communication with a first network interface and a second network interface, the method comprising:

executing a management virtual machine for communicating with a remote host computing device over a first computing network via the first network interface;

executing a plurality of virtual network function component instantiations;

executing a first agent for transmitting messages to the remote host computing device by providing one-way communication from the management virtual machine to the remote host computing device;

executing a second agent for receiving messages from the remote host computing device by providing one-way communication from the remote host computing device to the management virtual machine;

receiving status information about a first virtual network function component instantiation of the plurality of virtual network function component instantiations;

transmitting the status information to the remote host computing device via the first computing network;

receiving a request from the remote host computing device via the first computing network; and

executing the request one the first virtual network function component instantiation.

8. The method of claim 7 further comprising communicating with a second virtual network function component instantiation via a second computing network via the second network interface, where the first computing network and the second computing network are separate.

9. The method of claim 7 further comprising executing a hypervisor for controlling the plurality of virtual network function component instantiations.

10. The method of claim 7 further comprising terminating the first virtual network function component instantiation based on the received request.

11. A host computing device comprising at least one processor in communication with at least one memory device and further comprising a first network interface and a second network interface, the at least one processor programmed to:

execute a management virtual machine for communicating with a remote host computing device over a first computing network via the first network interface;

execute a plurality of virtual network function component instantiations;

execute a first agent for transmitting messages to the remote host computing device by providing one-way communication from the management virtual machine to the remote host computing device;

execute a second agent for receiving messages from the remote host computing device by providing one-way communication from the remote host computing device to the management virtual machine;

receive status information about a first virtual network function component instantiation of the plurality of virtual network function component instantiations;

transmit the status information to the remote host computing device via the first computing network;

receive a request from the remote host computing device via the first computing network; and

execute the request one the first virtual network function component instantiation.

12. The host computing device of claim 11 , wherein the at least one processor is further programmed to communicate with a second virtual network function component instantiation via a second computing network via the second network interface, where the first computing network and the second computing network are separate.

13. The host computing device of claim 11 , wherein the at least one processor is further programmed to execute a hypervisor for controlling the plurality of virtual network function component instantiations.

14. The host computing device of claim 11 , wherein the at least one processor is further programmed to terminate the first virtual network function component instantiation based on the received request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2019
From: FAYNBERG, IGOR; CLARKE, DONALD E. A.; GOERINGER, STEVEN J.
To: CABLE TELEVISION LABORATORIES, INC
Reel/Frame 049743/0513 →
Continuity (2)
Provisional Application 62691259 · Jun 28, 2018
Related Publication 20200004572A1 · Jan 2, 2020