Unlock instant, AI-driven research and patent intelligence for your innovation.

Network domain isolation device and method based on SDN (software defined network)

A technology for isolating devices and network domains, applied in the field of SDN-based network domain isolating devices, can solve problems such as complex configuration, inflexibility, and error-prone

Active Publication Date: 2016-11-23
刘昱
View PDF6 Cites 10 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, the current network domain isolation method has the disadvantages of complex configuration and inflexibility. That is, if the above two technologies realize the general network isolation function, they must be used in conjunction with each other on the access device and aggregation device (usually a layer-3 switch). For configuration, the configuration is complex and error-prone, or in special scenarios, such as the situation where isolation is required between networks in the same VLAN, isolation between the same network segments, etc., it is difficult to achieve with the above method

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Network domain isolation device and method based on SDN (software defined network)
  • Network domain isolation device and method based on SDN (software defined network)
  • Network domain isolation device and method based on SDN (software defined network)

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0030] figure 1 It is an application environment diagram of an embodiment of the SDN-based network domain isolation device 10 of the present invention. exist figure 1 Among them, an SDN controller 1 is connected to several SDN switches 2, and the SDN switches 2 are connected to several hosts or subnets. In this embodiment, several hosts or subnets can be divided into multiple domains according to human needs, so as to realize network domain isol...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention relates to a network domain isolation device based on an SDN (software defined network), and is applied to an SDN controller. The network domain isolation device comprises an isolation domain management unit, a message receiving unit and a data processing unit, wherein the isolation domain management unit builds a network domain list according to user requirements; the message receiving unit receives data messages received and transmitted by an SDN switch, and records a target MAC (media access control) address in the data messages and a port, for receiving the data messages, of the SDN switch; the data processing unit finds whether a port matched with the target MAC address exists in an MAC address and port relationship list; if the port matched with the target MAC address exists in the MAC address and port relationship list, whether the port matched with the target MAC address and the port, for receiving the data messages, of the SDN switch exist in the same network domain in the network domain list or not is judged; if the port matched with the target MAC address and the port, for receiving the data messages, of the SDN switch exist in the same network domain in the network domain list, a forwarding flow table is generated and issued according to the port matched with the target MAC address. The invention also provides a network domain isolation method based on the SDN. The network message broadcasting range can be controlled, and meanwhile, the flexibility and the security of the network are improved.

Description

technical field [0001] The present invention relates to the field of network communication, in particular, an SDN-based network domain isolation device and method. Background technique [0002] Network domain isolation refers to the division of two or more computers or networks into independent areas, and can isolate harmful, different security levels, different types, and different purpose network domains to ensure that data information is trusted Perform secure interaction and resource sharing in the network, and control the broadcast range of broadcast messages. The current network domain isolation methods mainly include: access control technology, which is generally an access control instruction applied to the interface of a router or a layer-3 switch. These instructions are used to tell the router which data packets can be received and which data packets need to be rejected. As for whether the data packet is received or rejected, it can be determined by specific indica...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): H04L29/06H04L29/12
CPCH04L63/02H04L61/5069
Inventor 刘昱
Owner 刘昱