EMAIL SUPPORT

dclessons@dclessons.com

LOCATION

AF

Authentication between vSmart Controller & vEdge Router

Authentication between vSmart Controller & vEdge Router

Authentication between vSmart Controller & vEdge Router

It the last step, in automatic authentication process, between vSmart controller and vEdge Router.

To perform this authentication process, one of the two devices initiates an encrypted DTLS connection or session to each other and this encrypted session is done by RSA public and Private Key generated by each device.

Now let’s see how vSmart controller authenticates a vEdge Router.

  1. vSmart send the 256 bit challenge to vEdge router and this challenge is a random value.
  2. The vEdge router sends following response for the challenge that include following:
  • vEdge Serial number
  • vEdge Chassis number
  • vEdge Board ID certificate
  • 256 bit random value signed by vEdge router Private key
  1. vSmart after receiving this information , compares the serial and chassis number from its vEdge authorized device list file , if there is no match vSmart will tear down the connection
  2. if the match is found vSmart check if the signing of 256 bit random value is proper or not by using vEdge router public key which it extracts from Router Board ID certificate , if the signing value is not matched vSmart will down the DTLS connection
  3. if the value is proper , vSmart uses root CA chain from vEdge router board ID certificate to validate that board id certificate is itself valid or not , the certificate is not valid the vSmart will tear down the connection
  4. The vSmart Controller also compares the response with original challenge, if the response matches the challenge that vBond has issued, authentication between two device happens successfully, else vSmart will tear down the connection.

Now after this authentication, vSmart controller knows that vEdge router is valid and its authentication of the router is completed.


Comment

    You are will be the first.

LEAVE A COMMENT

Please login here to comment.