IP Library Granted Patent US 12,413,597
Granted Patent B2
US 12,413,597 · App. 18/044,630 · Granted Sep 9, 2025

Domain name system security extension (DNSSEC) for container signature management

Inventors: Daniel Migault (Montreal, CA); Stere Preda (Longueuil, CA); Thomas Ingemarsson (Saltsjö-Boo, SE)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04L63/123H04L9/3247H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,597
App. No.
18/044,630
Granted
Sep 9, 2025
Kind
B2
Abstract

A method, system and apparatus are disclosed. According to one or more embodiments, a verifier is provided. The verifier includes processing circuitry configured to obtain a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image, determine an identifier for the VNF image based at least on the hash algorithm and the FQDN, perform domain name system security extensions, DNSSEC, resolution of the determined identifier for the VNF image at least in part by requesting at least one attribute of the VNF image using the determined identifier for the VNF image and validating a response associated with the request, and perform validation of the VNF image in response to successful DNSSEC resolution.

Claims (68)

1. A verifier, comprising:

processing circuitry configured to:

obtain a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image;

determine an identifier for the VNF image based at least on the hash algorithm and the FQDN;

perform domain name system security extensions, DNSSEC, resolution of the determined identifier for the VNF image at least in part by requesting at least one attribute of the VNF image using the determined identifier for the VNF image and validating a response associated with the request; and

perform validation of the VNF image in response to successful DNSSEC resolution.

2. The verifier of claim 1 , wherein the DNSSEC resolution is successful based at least on the at least one requested attribute of the VNF image being received and the response associated with the request being validated; and

the DNSSEC resolution is unsuccessful based at least on a proof of non-existence of the at least one requested attribute of the VNF image being received in response to the request.

3. The verifier of claim 1 , wherein the processing circuitry is further configured to receive a manifest including the VNF image; and

the performing of validation of the VNF image includes:

determining at least one attribute of the VNF image based at least on the manifest; and

comparing the determined at least one attribute of the VNF image to the requested at least one attribute of the VNF image.

4. The verifier of claim 1 , wherein the at least one attribute includes a content type and a hash of the VNF image.

5. The verifier of claim 1 , wherein the processing circuitry is further configured to instantiate the VNF image based at least on successful validation of the VNF image.

6. The verifier of claim 1 , wherein the response includes a DNSSEC signature; and

the processing circuitry configured to validate the DNSSEC signature at least in part by checking a chain of trust up to a root zone.

7. The verifier of claim 1 , wherein the obtaining includes receiving a manifest and extracting at least one of the hash algorithm and the FQDN.

8. The verifier of claim 1 , wherein the obtaining is based on a pre-configuration of the hash algorithm and the FQDN for performing the DNSSEC resolution and the validation of the VNF image.

9. A signer, comprising:

processing circuitry configured to:

obtain a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image;

determine an identifier for the VNF image based at least on the hash algorithm and the FQDN;

determine at least one attribute of the VNF image;

store the identifier for the VNF image and the at least one attribute of the VNF image;

receive a request for at least one attribute of the VNF image for validation, the request being based on the identifier for the VNF image; and

respond to the request for the at least one attribute of the VNF image, the response being part of a domain name system security extensions, DNSSEC, resolution of the identifier of the VNF image.

10. The signer of claim 9 , wherein the response includes one of:

the at least one requested attribute of the VNF image; and

an indication of a proof of non-existence of the at least one requested attribute of the VNF image.

11. The signer of claim 9 , wherein the storing includes inserting the identifier for the VNF and the at least one attribute of the VNF image in a zone; and

the processing circuitry being further configured to sign the zone with a zone signing key to generate at least one DNSSEC signature, a delegation of the zone being provided by DNSSEC until a root zone, the root zone being a trusted zone from which a chain of trust is built.

12. The signer of claim 11 , wherein the response includes the DNSSEC signature.

13. The signer of claim 9 , wherein the at least one attribute of the VNF image includes a content type and a hash of the VNF image.

14. The signer of claim 9 , wherein the obtaining includes receiving a manifest and extracting at least one of the hash algorithm and the FQDN.

15. The signer of claim 9 , wherein the obtaining is based on a pre-configuration of the hash algorithm and the FQDN for performing the DNSSEC resolution and the validation of the VNF image.

16. A method implemented by a verifier, the method comprising:

obtaining a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image;

determining an identifier for the VNF image based at least on the hash algorithm and the FQDN;

performing domain name system security extensions, DNSSEC, resolution of the determined identifier for the VNF image at least in part by requesting at least one attribute of the VNF image using the determined identifier for the VNF image and validating a response associated with the request; and

performing validation of the VNF image in response to successful DNSSEC resolution.

17. The method of claim 16 , wherein the DNSSEC resolution is successful based at least on the at least one requested attribute of the VNF image being received and the response associated with the request being validated; and

the DNSSEC resolution is unsuccessful based at least on a proof of non-existence of the at least one requested attribute of the VNF image being received in response to the request.

18. The method of claim 16 , further comprising receiving a manifest including the VNF image; and

the performing of validation of the VNF image includes:

determining at least one attribute of the VNF image based at least on the manifest; and

comparing the determined at least one attribute of the VNF image to the requested at least one attribute of the VNF image.

19. The method of claim 16 , wherein the at least one attribute includes a content type and a hash of the VNF image.

20. The method of claim 16 , further comprising instantiating the VNF image based at least on successful validation of the VNF image.

21. The method of claim 16 , wherein the response includes a DNSSEC signature; and

the method further comprising validating the DNSSEC signature at least in part by checking a chain of trust up to a root zone.

22. The method of claim 16 , wherein the obtaining includes receiving a manifest and extracting at least one of the hash algorithm and the FQDN.

23. The method of claim 16 , wherein the obtaining is based on a pre-configuration of the hash algorithm and the FQDN for performing the DNSSEC resolution and the validation of the VNF image.

24. A method implemented by a signer, the method comprising:

obtaining a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image;

determining an identifier for the VNF image based at least on the hash algorithm and the FQDN;

determining at least one attribute of the VNF image;

storing the identifier for the VNF image and the at least one attribute of the VNF image;

receiving a request for at least one attribute of the VNF image for validation, the request being based on the identifier for the VNF image; and

responding to the request for the at least one attribute of the VNF image, the response being part of a domain name system security extensions, DNSSEC, resolution of the identifier of the VNF image.

25. The method of claim 24 , wherein the response includes one of:

the at least one requested attribute of the VNF image; and

an indication of a proof of non-existence of the at least one requested attribute of the VNF image.

26. The method of claim 24 , wherein the storing includes inserting the identifier for the VNF and the at least one attribute of the VNF image in a zone; and

the method further comprising signing the zone with a zone signing key to generate at least one DNSSEC signature, a delegation of the zone being provided by DNSSEC until a root zone, the root zone being a trusted zone from which a chain of trust is built.

27. The method of claim 26 , wherein the response includes the DNSSEC signature.

28. The method of claim 24 , wherein the at least one attribute of the VNF image includes a content type and a hash of the VNF image.

29. The method of claim 24 , wherein the obtaining includes receiving a manifest and extracting at least one of the hash algorithm and the FQDN.

30. The method of claim 24 , wherein the obtaining is based on a pre-configuration of the hash algorithm and the FQDN for performing the DNSSEC resolution and the validation of the VNF image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2023
From: MIGAULT, DANIEL; PREDA, STERE; INGEMARSSON, THOMAS
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 062932/0191 →
Continuity (2)
Provisional Application 63077926 · Sep 14, 2020
Related Publication 20230370474A1 · Nov 16, 2023
References Cited (28)
US 8407471B1 · Sobel · 2013 [cited by examiner]
US 8495717B1 · Beacham · 2013 [cited by examiner]
US 9338182B2 · Devarapalli · 2016 [cited by examiner]
US 11271948B2 · Hermoni · 2022 [cited by examiner]
US 20030163737A1 · Roskind · 2003 [cited by examiner]
US 20120155646A1 · Seshadri · 2012 [cited by examiner]
US 20160021055A1 · Krzywonos · 2016 [cited by examiner]
US 20160337329A1 · Sood · 2016 [cited by examiner]
US 20180337931A1 · Hermoni · 2018 [cited by examiner]
US 20190238505A1 · Richards · 2019 [cited by examiner]
US 20200210589A1 · Sood · 2020 [cited by examiner]
International Search Report and Written Opinion dated Nov. 19, 2021 issued in PCT Application No. PCT/IB2021/058384, filed Sep. 14, 2021, consisting of 13 pages. [cited by applicant]
ETSI GS NFV-SEC 021 V2.6.1 (Jun. 2019); Network Functions Virtualisation (NFV) Release 2; Security; VNF Package Security Specification, consisting of 11 pages. [cited by applicant]
OpenStack Documentation; Support VNF Package (TOSCA CSAR) in Tacker; Aug. 27, 2019, consisting of 14 pages. [cited by applicant]
OpenStack Documentation; Feature Support Matrix; Dec. 20, 2018, consisting of 20 pages. [cited by applicant]
OASIS; TOSCA Simple Profile in YAML Version 12; OASIS Standard; Jan. 17, 2019, consisting of 315 pages. [cited by applicant]
ETSI GS NFV-SOL 004 V2.5.1 (Sep. 2018); Network Functions Virtualisation (NFV) Release 2; Protocols and Data Models; VNF Package specification, consisting of 21 pages. [cited by applicant]
Aaron Weitekamp; Container Image Signing; Red Hat Blog; Jul. 22, 2016, consisting of 13 pages. [cited by applicant]
Antonio Murdaca; Secure Your Kubernetes Production Cluster; Jan. 18, 2018, consisting of 10 pages. [cited by applicant]
Docker Documentation; Content Trust in Docker; May 12, 2020, consisting of 13 pages. [cited by applicant]
Microsoft Docs; Azure Container Registry; Sep. 6, 2019, consisting of 11 pages. [cited by applicant]
Debian Wiki; All About Secure Apt; Aug. 13, 2019, consisting of 20 pages. [cited by applicant]
Joe Damata; HOWTO: GPG sign and Verify Deb Packages and APT Repositories; Oct. 28, 2014, consisting of 17 pages. [cited by applicant]
Packagecloud:Blog; Attacks Against GPG Signed APT Repositories; Feb. 21, 2018, consisting of 23 pages. [cited by applicant]
International Preliminary Report on Patentability dated Mar. 23, 2023 issued in PCT Application No. PCT/IB2021/058384, filed Sep. 14, 2021, consisting of 9 pages. [cited by applicant]
Vbatts, Open Container Initiative Runtime Specification; Specification Version 1.0.2; Mar. 27, 2020, consisting of 58 pages. [cited by applicant]
OpenStack, Image Signature Verification; Aug. 21, 2019, consisting of 5 pages. [cited by applicant]
OpenStack, Instructions for Mitaka Image Signature Verification Feature; Apr. 2016, consisting of 17 pages. [cited by applicant]