-
公开(公告)号:US11095569B2
公开(公告)日:2021-08-17
申请号:US15587454
申请日:2017-05-05
Applicant: Huawei Technologies Co., Ltd.
Inventor: Tao Jin , Qingchun Lin , Chengyan Feng
IPC: H04L12/911 , H04L29/08 , G06F9/455
Abstract: The present embodiments provide a method for managing a hardware resource, a method for querying a location of a hardware resource, and a related apparatus. The method for managing a hardware resource includes receiving, by a virtualized infrastructure manager (VIM), a hardware resource allocation request message sent by a VNF management entity, where the hardware resource allocation request message is used to request the VIM to allocate a hardware resource to a virtual machine that runs a VNFC, and the hardware resource allocation request message includes location information of the hardware resource that the virtual machine requests to allocate. The method also includes allocating, by the VIM, the hardware resource at a corresponding location to the virtual machine according to the location information of the hardware resource.
-
公开(公告)号:US10757129B2
公开(公告)日:2020-08-25
申请号:US15795623
申请日:2017-10-27
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Inventor: Chengyan Feng , Jiangsheng Wang
Abstract: The present invention discloses a software security verification method, a device, and a system, and relates to the communications field, so as to resolve a problem in the prior art that security verification on a VNF packet increases a VNF instantiation delay and reduces VNF instantiation performance. In a specific solution, after a first device receives an instantiation request of a VNF, the first device performs security verification on a stored VNF packet of the VNF when or after starting to instantiate the VNF according to the instantiation request of the VNF, and the first device sends first result information to a second device when security verification on the VNF packet of the VNF succeeds. The first result information includes information that security verification on the VNF packet of the VNF succeeds. The present invention is applied to software security verification.
-
公开(公告)号:US10225246B2
公开(公告)日:2019-03-05
申请号:US15346357
申请日:2016-11-08
Applicant: Huawei Technologies Co., Ltd.
Inventor: Ying Xiong , Jiangsheng Wang , Chengyan Feng
Abstract: The embodiments of the present invention disclose a certificate acquiring method and device. A virtualized network function manager (VNFM) receives a certificate application proxy message sent by a virtualized network function (VNF) instance. The VNFM uses the authentication information to authenticate the VNF instance, and when the authentication succeeds, sends a certificate application message to a certificate authority (CA). Then the VNFM receives a certificate issued by the CA, and sends the certificate to the VNF instance. In this way, through a trusted link between the VNFM and the certificate authority, the instantiated VNF instance applies for a certificate issued by the certificate authority, thereby effectively ensuring security of a management channel between the VNF instance and the VNFM.
-
公开(公告)号:US20170338968A1
公开(公告)日:2017-11-23
申请号:US15673075
申请日:2017-08-09
Applicant: Huawei Technologies Co., Ltd.
Inventor: Chengyan Feng , Jiangsheng Wang
CPC classification number: H04L9/3268 , G06F21/33 , G06F2221/2143 , H04L9/0891 , H04L12/4641 , H04L29/06 , H04L63/0823 , H04W12/04
Abstract: A certificate management method, a device, and a system relate to the communications field and for certificate management are used to resolve a problem that communication security of a virtual network system is degraded because after a virtualized network function (VNF) instance is terminated in the virtual network system, a private key corresponding to a certificate of the VNF instance may be illegally obtained by an attacker to forge an identity of the VNF instance. A specific solution includes obtaining, by a first device, a certificate identifier of a first instance, and updating certificate status information of the first instance to a revocation state according to the certificate identifier of the first instance, or sending, by the first device, a first request message to a second device, where the first request message requests to revoke a certificate of the first instance.
-
5.
公开(公告)号:US20170244647A1
公开(公告)日:2017-08-24
申请号:US15587454
申请日:2017-05-05
Applicant: Huawei Technologies Co., Ltd.
Inventor: Tao Jin , Qingchun Lin , Chengyan Feng
IPC: H04L12/911 , G06F9/455
CPC classification number: H04L47/70 , G06F9/45504 , H04L29/08 , H04L67/10 , H04L67/18
Abstract: The present embodiments provide a method for managing a hardware resource, a method for querying a location of a hardware resource, and a related apparatus. The method for managing a hardware resource includes receiving, by a virtualized infrastructure manager (VIM), a hardware resource allocation request message sent by a VNF management entity, where the hardware resource allocation request message is used to request the VIM to allocate a hardware resource to a virtual machine that runs a VNFC, and the hardware resource allocation request message includes location information of the hardware resource that the virtual machine requests to allocate. The method also includes allocating, by the VIM, the hardware resource at a corresponding location to the virtual machine according to the location information of the hardware resource.
-
公开(公告)号:US10367647B2
公开(公告)日:2019-07-30
申请号:US15345829
申请日:2016-11-08
Applicant: Huawei Technologies Co., Ltd.
Inventor: Chengyan Feng , Jiangsheng Wang
Abstract: A certificate acquiring method and device, where the method includes receiving a certificate application representation message sent by a newly installed virtualized network function component (VNFC) instance, sending a certificate request message to a certification authority, and acquiring a certificate issued by the certification authority. In this way, the newly installed VNFC instance does not need to use a current manner for a virtualized network function (VNF) to acquire a certificate, which effectively avoids a problem of a cumbersome and more complex process caused when the newly installed VNFC instance acquires a certificate.
-
公开(公告)号:US10581619B2
公开(公告)日:2020-03-03
申请号:US15673075
申请日:2017-08-09
Applicant: Huawei Technologies Co., Ltd.
Inventor: Chengyan Feng , Jiangsheng Wang
Abstract: A certificate management method, a device, and a system relate to the communications field and for certificate management are used to resolve a problem that communication security of a virtual network system is degraded because after a virtualized network function (VNF) instance is terminated in the virtual network system, a private key corresponding to a certificate of the VNF instance may be illegally obtained by an attacker to forge an identity of the VNF instance. A specific solution includes obtaining, by a first device, a certificate identifier of a first instance, and updating certificate status information of the first instance to a revocation state according to the certificate identifier of the first instance, or sending, by the first device, a first request message to a second device, where the first request message requests to revoke a certificate of the first instance.
-
公开(公告)号:US20170054565A1
公开(公告)日:2017-02-23
申请号:US15345829
申请日:2016-11-08
Applicant: Huawei Technologies Co., Ltd.
Inventor: Chengyan Feng , Jiangsheng Wang
CPC classification number: H04L9/3263 , H04L9/14 , H04L9/30 , H04L9/32 , H04L63/06 , H04L63/0823
Abstract: A certificate acquiring method and device, where the method includes receiving a certificate application representation message sent by a newly installed virtualized network function component (VNFC) instance, sending a certificate request message to a certification authority, and acquiring a certificate issued by the certification authority. In this way, the newly installed VNFC instance does not need to use a current manner for a virtualized network function (VNF) to acquire a certificate, which effectively avoids a problem of a cumbersome and more complex process caused when the newly installed VNFC instance acquires a certificate.
Abstract translation: 一种证书获取方法和装置,其中所述方法包括接收由新安装的虚拟网络功能组件(VNFC)实例发送的证书应用程序表示消息,向证书颁发机构发送证书请求消息,以及获取证书颁发机构颁发的证书 。 这样,新安装的VNFC实例就不需要使用虚拟化网络功能(VNF)来获取证书,这有效地避免了当新安装的VNFC实例获取时引起的繁琐复杂过程的问题 证书。
-
公开(公告)号:US11646973B2
公开(公告)日:2023-05-09
申请号:US17386662
申请日:2021-07-28
Applicant: Huawei Technologies Co., Ltd.
Inventor: Tao Jin , Qingchun Lin , Chengyan Feng
CPC classification number: H04L47/70 , G06F9/45504 , H04L65/40 , H04L67/10 , H04L67/52
Abstract: The present embodiments provide a method for managing a hardware resource, a method for querying a location of a hardware resource, and a related apparatus. The method for managing a hardware resource includes receiving, by a virtualized infrastructure manager (VIM), a hardware resource allocation request message sent by a VNF management entity, where the hardware resource allocation request message is used to request the VIM to allocate a hardware resource to a virtual machine that runs a VNFC, and the hardware resource allocation request message includes location information of the hardware resource that the virtual machine requests to allocate. The method also includes allocating, by the VIM, the hardware resource at a corresponding location to the virtual machine according to the location information of the hardware resource.
-
公开(公告)号:US20210359953A1
公开(公告)日:2021-11-18
申请号:US17386662
申请日:2021-07-28
Applicant: Huawei Technologies Co., Ltd.
Inventor: Tao Jin , Qingchun Lin , Chengyan Feng
IPC: H04L12/911 , H04L29/08 , G06F9/455
Abstract: The present embodiments provide a method for managing a hardware resource, a method for querying a location of a hardware resource, and a related apparatus. The method for managing a hardware resource includes receiving, by a virtualized infrastructure manager (VIM), a hardware resource allocation request message sent by a VNF management entity, where the hardware resource allocation request message is used to request the VIM to allocate a hardware resource to a virtual machine that runs a VNFC, and the hardware resource allocation request message includes location information of the hardware resource that the virtual machine requests to allocate. The method also includes allocating, by the VIM, the hardware resource at a corresponding location to the virtual machine according to the location information of the hardware resource.
-
-
-
-
-
-
-
-
-