Invention Grant
- Patent Title: Continuous integrity validation-based control plane communication in a container-orchestration system
-
Application No.: US17016046Application Date: 2020-09-09
-
Publication No.: US11770251B2Publication Date: 2023-09-26
- Inventor: Nagendra Kumar Nainar , Carlos M. Pignataro , Akram Ismail Sheriff
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32 ; G06F9/50 ; H04L9/06

Abstract:
Techniques and mechanisms for providing continuous integrity validation-based control plane communication in a container-orchestration system, e.g., the Kubernetes platform. A worker node generates a nonce and forwards the nonce to a master node while requesting an attestation token. Using the nonce, the master node generates the attestation token and replies back to the worker node with the attestation token. The worker node validates the attestation token with a CA server to ensure that the master node is not compromised. The worker node sends its authentication credentials to the master node. The master node generates a nonce and forwards the nonce to the worker node while requesting an attestation token. Using the nonce, the worker node generates the attestation token and replies back to the master node with the attestation token. The master node validates the attestation token with the CA server to ensure that the worker node is not compromised.
Public/Granted literature
- US20220078015A1 CONTINUOUS INTEGRITY VALIDATION-BASED CONTROL PLANE COMMUNICATION IN A CONTAINER-ORCHESTRATION SYSTEM Public/Granted day:2022-03-10
Information query