Devices, systems, and methods for operating software-defined networks
By designing control equipment with storage, control and comparison functions, the problem of network image comparison in software-defined networks is solved, the security and consistency of network images are achieved, and the reliability and security of networks are ensured.
Patent Information
- Application Number
- CN201980048967.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-05-22
- Filing Date
- 2019-05-08
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2039-05-08
AI Technical Summary
The prior art is difficult to simply and reliably compare network images of control devices of software-defined networks, resulting in network images being susceptible to local or public manipulation.
A control device is designed, including a storage unit, a control unit and a comparison unit. The storage unit is used to store network images, the control unit is used to control data flow forwarding based on the network image, and the comparison unit is used to compare the stored network image with the network image published in the blockchain to ensure the security and consistency of the network image.
Through the comparison function of the comparison unit, the stored network image can be protected from local manipulation, and the published network image can be protected from public manipulation through the consensus protocol of the blockchain, achieving simple and reliable comparison of network images.
Smart Images

Figure CN112424782B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a control device, a system, and a method for operating a software-defined network. Background Art
[0002] A software-defined network is known to be formed by a plurality of network elements such as SDN switches, which are controlled by a control device such as an SDN controller. The SDN switch identifies a data stream at the data level of the network and forwards the data stream according to a data stream rule implemented in the SDN switch. The SDN controller communicates with the SDN switch at the control level of the network to implement a data stream rule in the SDN switch based on a network image stored in the SDN controller. A plurality of virtual network areas or tenant network areas can be set in the software-defined network. A distributed network or a wide area network (WAN) based on SDN is considered, in which a plurality of physical sub-regions are controlled by respective SDN controllers. For this purpose, it is necessary to compare network images between SDN controllers to construct a plurality of tenant network areas spanning sub-regions.
[0003] An attacker who can access the network image can manipulate the data stream in the network. Therefore, the network image is conventionally locally protected in a private area. This contradicts the expectation of comparing the network image with other control devices of the WAN.
[0004] CN 107222478A discloses a method for establishing a security mechanism for a software-defined network control layer (SDN). In this method, an authenticated network flow is formed. The authenticated network flow acts on a switch, and the network flow and the state of the switch after acting respectively form a network flow transaction. The transaction with the network state is recorded in a blockchain. The data in the blockchain is immutable, and the network is inspected and traced by inspecting the network flow transaction and the network state transaction data for the SDN application, where the block is to be accessed. In this document, a chain consensus mechanism reaches a consensus on network state resources between controllers. The controller applies an attribute-based encryption tool (ABE) to set resource access control criteria for the SDN application identity and the category associated with the SDN application identity. Thereby, the network flow to the SDN can be authenticated, so that the network flow and the network state can be traced and monitored, and secure access control of network resources can be achieved. Summary of the Invention
[0005] In this context, the object of the present invention is to enable a simple and reliable comparison of network images of control devices of a software-defined network.
[0006] Therefore, a control device for operating a software-defined network having a certain number of network elements is proposed. The control device has: a storage unit configured to store a network image of the software-defined network; a control unit configured to control the forwarding of data streams through the certain number of network elements based on the stored network image; and a comparison unit configured to compare the stored network image with a network image published in a ledger of a blockchain.
[0007] The control device advantageously compares the network image stored in the control device with the published network image, so that the stored network image can be protected from local manipulation. The published network image is published in the blockchain, so that the published network image can be protected from public manipulation through the consensus protocol of the blockchain. Another advantage may be that the network image of the control device can be simply compared with the network images of other control devices via the network image published in the blockchain.
[0008] A software-defined network should in particular be understood as a virtualizable network in which a certain number of virtual network areas can be set up. The virtual network areas are also referred to as tenant network areas. Each tenant network area can be protected from the influence of other tenant network areas. Therefore, the software-defined network can also be referred to as a multi-tenant network.
[0009] "Software-defined" should in particular be understood as meaning that the functionality of the network formed by the network elements is not fixedly pre-given on the respective network elements. In particular, the functionality of each network element can be controlled by the control device in such a way that the control unit of the control device implements a respective number of data stream rules in the respective network elements based on the network image stored in the storage unit.
[0010] In this regard, each network element among the certain number of network elements can in particular be referred to as a software-defined network element. Each network element in particular has a plurality of connection ends and is configured to process a data stream input on one of the connection ends according to a data stream rule implemented by software in the network element. This processing can include, for example, forwarding to other connection ends among the connection ends. This forwarding can in particular also include parameterization. Parameterization should be understood as, for example, the implementation of service parameters such as bandwidth limits. The processing can also include discarding and / or executing virtual network functions.
[0011] Here and hereinafter, "a certain number" means a number of one or more.
[0012] The data stream is, for example, a data stream according to RFC 2722, RFC 3697, or RFC 3917. The data stream can be understood, for example, as a certain number of packets transmitted from a starting endpoint to a target endpoint using a defined protocol within a defined time period. The starting endpoint or the target endpoint of the data stream can be, for example, a defined port or service of a network terminal.
[0013] For example, each network element can identify an associated data stream rule in the data stream rules implemented in the network element based on the traffic attributes of the packets input at the data level of the network (such as defined protocol, starting endpoint, and / or target endpoint, etc.), and process the packets as part of the data stream according to the identified data stream rule, such as forwarding and parameterization. If no data stream rule associated with the input packet is identified, the network element can transmit the traffic attributes of the input packet to the control device via the control level of the software-defined network. The control device can be configured to calculate an associated data stream rule based on the network image stored in the storage unit in response to the traffic attributes transmitted from the network element, and establish a new data stream by implementing the calculated data stream rule in a certain number of network elements in the network, and the data stream will be transmitted along the certain number of network elements. In this way, the control unit of the control device can control the forwarding of the data stream through the certain number of network elements.
[0014] Each network image can particularly include information about the physical configuration of the software-defined network. An example of the information about the physical configuration is the physical topology, which includes network terminals, network elements, and the connection segments between them, and can define their respective attributes. In addition, the network image can include information about the virtual configuration of a certain number of virtual tenant network areas, such as the virtual topology of each tenant network area, and the definition of endpoints, services, and traffic parameters such as guaranteed bandwidth, bandwidth limit, etc.
[0015] Therefore, the functionality of processing and / or forwarding data streams through the network elements can be implemented in the software-defined network. This functionality is also referred to as the data level. The functionality for controlling the processing and / or forwarding of data streams and for setting tenant network areas, etc., can be implemented through the control device. Hereinafter, this functionality is also referred to as the "control level". Due to the clear separation between the data level and the control level, the software-defined network can be centrally controlled and quickly adapted to changing situations.
[0016] Preferably, each network element can be an SDN network element, an SDN router, and / or an SDN switch, and the control device can be an SDN controller.
[0017] A blockchain can be understood as a distributed, public, tradable, tamper-proof, consensus-based database. "Distributed" should be particularly understood as the blockchain being composed of multiple discontinuous blockchain nodes. "Public" should be particularly understood as the blockchain nodes being under the control of different participants (such as different tenants of the network or different operators in different networks or different physical network regions). "Tradable" should be particularly understood as data being stored in the blockchain as a sequence of transactions. The sequence of all transactions stored in the blockchain can be called the "general ledger" of the blockchain. "Tamper-proof" should be particularly understood as it being impossible or only possible with the consensus among the majority of blockchain nodes to make post-facto changes to the general ledger of the blockchain. "Consensus-based" should be understood as reaching a consensus among the majority of blockchain nodes being required to incorporate other transactions into the general ledger.
[0018] In particular, a blockchain can be designed as follows: The general ledger of the blockchain includes a chain formed by consecutive blocks. Each respective block includes at least one of the transactions stored in the general ledger, and these transactions are also called "confirmed transactions". Each respective block contains the hash value of all the confirmed transactions in that block. The hash value of all the confirmed transactions can be, for example, the hash value of a Merkle tree formed by the hash values of the respective transactions of the block. Each respective block also includes a reference value, which is, for example, the hash value of the previous block in the chain. In this way, the general ledger can be constructed as a hash value-based blockchain. Manipulation of the transactions in the general ledger may cause the hash value of the block including the manipulated transaction to be invalid, and thereby may also cause all the hash values of all subsequent blocks to be invalid.
[0019] In particular, each respective blockchain node stores one or more local copies of the general ledger. The blockchain node can process the longest local copy of the general ledger as the valid copy of the general ledger, and thus as the general ledger.
[0020] In particular, the blockchain can also be designed in the following manner: Blockchain nodes exchange the following unconfirmed transactions with each other, and the unconfirmed transactions should be added to the general ledger. The exchange can be carried out in a peer-to-peer manner, where each blockchain node is connected to at least one other blockchain node, but not necessarily to all blockchain nodes. Each blockchain node can form the following unconfirmed blocks from the exchange transactions that reach it, and the unconfirmed blocks can have the same structure as the confirmed blocks. Blockchain nodes exchange unconfirmed blocks with each other in the same way as unconfirmed transactions. Only when the unconfirmed block and its respective unconfirmed transactions correspond to the consensus protocol of the blockchain, will each blockchain node absorb the unconfirmed blockchain node of the exchange that reaches it into one local copy or one of the multiple local copies of the general ledger.
[0021] The consensus protocol of the blockchain can at least stipulate that the reference value of the unconfirmed block is the hash value of the last block of the local copy of the general ledger. In this way, it can be ensured that the unconfirmed block is absorbed into the general ledger only when the originator of the unconfirmed block is a blockchain node that knows the entire unmanipulated general ledger. The consensus protocol can also stipulate that the transaction sequence of the unconfirmed block represents a valid state transition of the state described by the general ledger. Other criteria that the consensus protocol can stipulate, such as proof of stake, will be described in more detail below.
[0022] In particular, consensus among blockchain nodes can be generated in the following way, that is, most blockchain nodes accept unconfirmed blocks as confirmed blocks into the general ledger.
[0023] Malicious blockchain nodes working according to a modified consensus protocol and / or with a modified general ledger may lose the ability to participate in reaching a consensus or changing the state of the general ledger, because the blocks they transmit may be discarded by the remaining blockchain nodes.
[0024] Therefore, any change in the state of the general ledger or any change in the data stored in the general ledger is advantageously controlled by most blockchain nodes. In this way, a high level of protection against manipulation of the general ledger can be advantageously guaranteed through automatic consensus.
[0025] The network image published in the general ledger of the blockchain can be stored as the payload of one or more transactions in the general ledger of the blockchain. In this regard, the published network image can also be understood as a sequence of change transactions published in the general ledger or a sequence of the following changes, which are executed successively to reflect the current state of the published network image.
[0026] Comparing the network image stored in the storage unit of the control device with the network image published in the general ledger of the blockchain should be understood in particular as incorporating changes to one of the network images into the other network image, so that the stored network image is kept in sync with the published network image.
[0027] The comparison unit of the control device can access the general ledger of the blockchain, for example, in such a way that the comparison unit includes one of the blockchain nodes, and / or the comparison unit is communicatively connected to at least one of the blockchain nodes in the blockchain.
[0028] The blockchain can be a private blockchain of the operator of the control device, a blockchain of a group consisting of multiple operators of multiple control devices, or a public blockchain. In particular, the exchange of transactions and blocks can be carried out by the blockchain nodes at the data level of the software-defined network. Therefore, the general ledger of the blockchain can be stored at the data level of the software-defined network. Thus, it is advantageously possible to simplify the comparison of the published network image, for example, by using other control devices. At the same time, the published network image can be advantageously protected from manipulation by the consensus protocol of the blockchain.
[0029] According to another embodiment, the comparison unit is configured to transmit the changes to the stored network image as a change request for the published network image to the blockchain; if the change request for the published network image is published as a change to the published network image in the general ledger of the blockchain, then accept the changes to the stored network image; and if the change request for the published network image is not published as a change to the published network image in the general ledger of the blockchain, then discard the changes to the stored network image.
[0030] Thus, it is advantageously possible to protect the network image stored in the control device from local manipulation. In particular, the network image stored in the control device can only be successfully changed when consensus is reached among the blockchain nodes of the blockchain. Thus, it can be said that the changes to the network image of the control device are subject to peer review by multiple participants (such as tenants of the software-defined network or operators of other control devices).
[0031] The "change" of each network image can be understood as a transaction that converts the network image before the change into the network image after the change, and / or as data that is configured to change the network image when applied to the network image.
[0032] A "change request" can be interpreted as an unconfirmed change, and in this regard, as an unconfirmed transaction (unconfirmed change transaction).
[0033] "Transmitting the changes of the stored network image as a change request for the published network image to the blockchain" can be carried out in particular by the blockchain nodes formed by or communicatively coupled to the comparison unit of the control device of the blockchain forming an unconfirmed block with the change request as an unconfirmed transaction, and transmitting the unconfirmed block to at least one other blockchain node of the blockchain.
[0034] "Publishing the change request as a change to the published network image in the general ledger of the blockchain" is to be understood in particular as reaching a consensus among multiple blockchain nodes and each blockchain node accepting the change transaction as a confirmed transaction into the general ledger.
[0035] "Accepting the changes of the stored network image" is to be understood in particular as applying the changes to the stored network image, and the control unit of the control device controlling the forwarding of data streams in the software-defined network through the certain number of network elements based on the changed stored network image from that moment on.
[0036] The control device (control unit, storage unit, and / or comparison unit) can query the blockchain (the blockchain nodes included or communicatively connected to the comparison unit) at regular intervals to determine whether the respective change requests for the published network image transmitted to the blockchain have been published, or the control device can be notified by the blockchain node when the change request is published.
[0037] "Discarding the changes of the stored network image" is to be understood in particular as not applying the changes to the network image stored in the storage unit, and / or withdrawing the changes if the changes have already been applied to the network image stored in the storage unit, and the control unit of the control device continuing to control the forwarding of data streams in the software-defined network through the certain number of network elements based on the unchanged network image stored in the storage unit.
[0038] According to another embodiment, the comparison unit is configured to accept the changes of the published network image as the changes of the stored network image if the change request for the published network image is published as the changes of the published network image in the general ledger of the blockchain.
[0039] Thus, advantageously, the network image stored in the storage unit can be compared with other control devices. If, for example, the network image of the other control device is changed and an associated change request for the published network image is published in the general ledger of the blockchain, the network image stored in the storage unit is correspondingly changed. It can also be advantageous, for example, to provide the control device at a remote location and the control device can be remotely configured by the operator of the software-defined network by publishing a change request in the general ledger of the blockchain.
[0040] Thus, a simple possibility of comparing or changing the network image stored in the storage unit can be created. Although data transmission at the data level of the software-defined network and / or data transmission in a public network can be used for the comparison, the consensus protocol of the blockchain can ensure that only legitimate change requests are published in the general ledger of the blockchain. Thus, the network image stored in the storage unit of the control device can be protected from manipulation by malicious third parties by the consensus protocol of the blockchain.
[0041] According to another embodiment, the comparison unit includes a blockchain node of the blockchain. The blockchain node is configured to agree to the consensus for publishing the change request of the published network image transmitted to the blockchain in the general ledger of the blockchain if the change request of the published network image corresponds to the consensus protocol of the blockchain.
[0042] Thus, the need for dedicated secure communication between the control device and a blockchain node external to the control device can be advantageously eliminated. The comparison unit of the control device can directly participate in the blockchain. In addition, the control device can advantageously participate in the consensus reaching of the blockchain nodes of the blockchain regarding the publication of change requests for the published network image.
[0043] According to another embodiment, the control unit is configured to receive quality of service information from at least one of the certain number of network elements, wherein the consensus protocol of the blockchain is based on the quality of service information.
[0044] The quality of service information should in particular be understood as information describing the operating quality of an entity connected to the respective network element or a network service provided by the entity. The entity can be, for example, a network terminal, other network elements, and / or other control devices. The quality of service information can be, for example, information about the availability (uptime / downtime), traffic volume, packet loss frequency, average bandwidth, response speed, etc. of the entity or the network service and / or a quality of service parameter derived from such information.
[0045] In other words, the control device can obtain information about the network operation implemented by the network element from the network element. Based on this information, the control device can evaluate the network operation quality of the software-defined network, the quality of each tenant network area, and / or the operation quality of the endpoints of each tenant network area and / or the adjacent software-defined network.
[0046] "The consensus protocol of the blockchain is based on service quality information" can particularly mean that changes to the published network image can only be made when service quality-based conditions are met. In particular, consensus on changes to the published network image can only be reached when service quality-based conditions are met.
[0047] For example, only when the service quality information received by the control unit indicates that the change request originates from other blockchain nodes, can the blockchain node of the comparison unit of the control device agree to the consensus. The other blockchain nodes are part of entities (network terminals, other network elements, other control devices) that provide sufficient service quality and / or are arranged in tenant network areas of the software-based network that provide sufficient service quality, and / or are arranged in other software-defined networks that provide sufficient service quality compared to the software-defined network controlled by the control device.
[0048] "Sufficient service quality" should particularly be understood as that the service quality parameter derived from the service quality information is greater than a predetermined threshold. The service quality parameter can describe the current service quality and / or the average value of the service quality detected over a predetermined period.
[0049] Since reaching a consensus can depend on the provided service quality, proof of stake can be advantageously implemented. "Proof of stake" can consist in that changes to the published network image can only be successfully requested by blockchain nodes located in the responsible area of the participant. The participant is, for example, an operator of another software-defined network or a tenant of the software-defined network, and the participant has obtained credibility in such a way that network elements, control devices, tenant network areas, or other software-defined networks provide or have provided sufficient-quality service for the software-defined network under the responsibility of the participant.
[0050] According to another embodiment, at least the control unit is arranged in a private area, and at least the blockchain node is arranged in a public area.
[0051] Preferably, the storage unit is also arranged in the private area.
[0052] The private area is in particular a physical network area or a virtual network area, which is protected, for example, against network access by endpoints in the tenant network area of the software-defined network and / or by endpoints in other software-defined networks and / or by the blockchain nodes of the blockchain and / or by non-participating third parties.
[0053] The public area is in particular a physical network area or a virtual network area, which can be accessed at least by other blockchain nodes of the blockchain.
[0054] Therefore, functionality for comparing the stored network image with the published network image for network access by external entities (such as other blockchain nodes) is disclosed. At the same time, the functionality of the control device for controlling the software-defined network and / or the stored network image is advantageously protected against manipulation by external network access.
[0055] According to another aspect, a system for operating a software-defined network having a certain number of network elements is proposed. The system has: a certain number of control devices as described above, a plurality of blockchain nodes, the plurality of blockchain nodes together forming a blockchain and being arranged to exchange change requests for the published network image transmitted to the blockchain with each other; and the change requests are published as changes to the published network image in the ledger of the blockchain only when consensus is reached among the plurality of blockchain nodes according to the consensus protocol of the blockchain.
[0056] Each control device can be arranged to control a respective discontinuous selection from the certain number of network elements.
[0057] The embodiments and features described for the proposed control device correspondingly apply to the proposed system.
[0058] According to another embodiment, the control unit of a certain number of control devices is arranged to control the forwarding of data streams through the certain number of network elements in such a way that the control unit communicates with the certain number of network elements at the control level of the software-defined network. The plurality of blockchain nodes together forming the blockchain are arranged to communicate with each other at the data level of the software-defined network and / or via a public network.
[0059] The control level of the software-defined network can be reserved for the communication between the certain number of control devices and the certain number of network elements. Therefore, the communication for controlling network operation can be advantageously protected against external influences and manipulation.
[0060] In contrast, the data level of the software-defined network can be jointly used for the data streams of the software-defined network and the communication between the blockchain nodes.
[0061] In other words, the blockchain can be constructed in the data level of the software-defined network and / or in a public network. This advantageously enables a comparison of network images between the certain number of control devices, where the blockchain is responsible for manipulation-proof security.
[0062] The public network should in particular be understood as a network different from the software-defined network. "Public" can mean, for example, that the public network for data transmission is accessible to more than one participant (such as an operator or a tenant).
[0063] According to another embodiment, the plurality of blockchain nodes are configured to reach a consensus on publishing the change in the general ledger of the blockchain based on a proof of legitimate right of the blockchain node requesting the change.
[0064] Thus, unauthorized participants can be advantageously prevented from changing the published network image.
[0065] The proof of legitimate right can include, for example, identity proof and / or proof of work and / or proof of stake.
[0066] "The blockchain node requesting the change" should in particular be understood as the blockchain node in which a change request for the published network image is created. The requesting blockchain node can be identified, for example, based on a digital signature included in the change request.
[0067] "Legitimate right" can relate to the blockchain node itself and / or to an entity such as a network terminal, one of the network elements, and / or one of the control devices including the requesting blockchain node, and / or to the operator of such an entity.
[0068] According to another embodiment, authorization information is published in the general ledger of the blockchain, the authorization information specifying the blockchain nodes in the blockchain that are authorized to request changes to the published network image. The proof of legitimate right includes proof that the blockchain node requesting the change is authorized to request changes to the published network image according to the authorization information published in the general ledger of the blockchain.
[0069] Thus, the manipulation-proof protection for the published network image and the stored network image can be advantageously further enhanced by the fact that only those blockchain nodes that have been explicitly authorized in advance can change the published network image.
[0070] The authorization information can be published in the general ledger of the blockchain as the payload of a transaction in the same way as the published network image.
[0071] For example, the authorization information may include the public digital key of the blockchain node authorized to issue the request and / or a certificate from a Certificate Authority (CA). The proof of the legitimate right may include the digital signature of the blockchain node that issues the request, and the digital signature can be verified based on the public digital key and / or the certificate.
[0072] According to another embodiment, a plurality of virtual tenant network regions are set in the software-defined network, and the plurality of virtual tenant network regions are defined by the published network image. A respective blockchain node among a certain number of the plurality of blockchain nodes is respectively assigned to one of the virtual tenant network regions.
[0073] The blockchain node "assigned to one of the virtual tenant network regions" should be particularly understood as that the blockchain node constitutes an endpoint in the virtual tenant network region, and / or it can be proved that the blockchain node is operated by the tenant assigned to the virtual tenant network region.
[0074] Therefore, the virtual customer network region tenant having a legitimate interest in the stable operation of the software-defined network can advantageously participate in the consensus protocol of the blockchain. It can be said that these tenants decide the published network image in a common consensus and thus decide the configuration of the software-defined network. Here, "decide" should be particularly understood as an automatic decision made by the blockchain node based on the consensus protocol.
[0075] According to another embodiment, respective control devices are set to control a physical sub-region of the software-defined network. Each physical sub-region is formed by a discontinuous selection from the certain number of network elements. A respective blockchain node among a certain number of the plurality of blockchain nodes is respectively assigned to one of the physical sub-regions.
[0076] In particular, the respective control devices may be respectively operated by different operators.
[0077] In this regard, the software-defined network can also be understood as a complex composed of a plurality of software-defined networks, and each physical sub-region can also be understood as each software-defined network.
[0078] The blockchain node "assigned to one of the physical sub-regions" should be particularly understood as that the blockchain node constitutes an endpoint in the physical sub-region, and / or the blockchain node is operated by the operator of the control device that controls the physical sub-region.
[0079] Preferably, the respective blockchain nodes assigned to the physical sub - regions can be configured as part of the control devices that control the respective physical sub - regions.
[0080] Thus, the operators of the control devices described below can advantageously participate in the consensus protocol of the blockchain, and these control devices compare their network images via the blockchain. It can be said that the operators decide the published network images in a common consensus and thereby decide the configuration of the software - defined network. Here, "decide" especially refers to the automatic decision made by the blockchain nodes based on the consensus protocol.
[0081] According to another embodiment, the proof of legitimate interest includes: proof of the assignment of the requesting blockchain node to one of the virtual tenant network regions and / or one of the physical sub - regions, and proof of the quality of service of the virtual tenant network region and / or physical sub - region to which the requesting blockchain node is assigned.
[0082] Therefore, only blockchain nodes that have obtained a reputation in the following way can successfully request a change to the published network image, that is, the virtual client network regions and / or physical sub - regions assigned to the blockchain nodes provide services of sufficient quality.
[0083] The assignment of the requesting blockchain node to one of the virtual tenant network regions and / or one of the physical sub - regions can be proven, for example, by means of a digital signature.
[0084] It is also conceivable to determine the association of the requesting blockchain node with the tenant network region and / or physical network region based on the data stream used by the requesting blockchain node to transmit the change request.
[0085] The proof of the quality of service can be carried out especially as follows: each blockchain node participating in the consensus queries its respective control device for confirmation of whether the virtual tenant network region and / or physical sub - region to which the requesting blockchain node is assigned provides a quality of service higher than a predetermined threshold.
[0086] According to another embodiment, the control unit of each control device among the plurality of control devices is configured to receive quality-of-service information related to the quality of service of a certain number of other physical sub-regions from at least a discontinuous selection of network elements of the physical sub-region controlled by this control device. The storage unit of each control device among the plurality of control devices is configured to store, for each of the certain number of other physical sub-regions, the time course of the quality-of-service information received from the control unit. The proof of the quality of service of the physical sub-region to which the requesting blockchain node is assigned is based on the time course of the quality-of-service information related to the physical sub-region, and the time course is stored in the storage unit of each control device among the plurality of control devices.
[0087] At least one network element of the physical sub-region controlled by each control device can in particular be the following network element, which constitutes a transition point to the network elements of the adjacent physical sub-region. Therefore, the at least one network element can have quality-of-service information regarding the quality of service and / or the operating quality of the adjacent physical sub-region.
[0088] Therefore, historical quality-of-service information regarding adjacent physical sub-regions can exist at the respective control devices of the physical sub-regions.
[0089] Therefore, the following blockchain can be advantageously constructed. In the case of this blockchain, for example, each blockchain node is assigned to or included in each control device, and changes to the published virtual network image jointly used by the plurality of control devices can be made only when a consensus is reached among the blockchain nodes of the plurality of control devices. The consensus can advantageously be in particular based on the fact that the control device requesting the change (the control device assigned to the blockchain node requesting the change) has always provided services of sufficient quality over a predetermined historical period. Thereby, proof of stake can be provided.
[0090] For a control device newly added to the system, it can be advantageously particularly first refused to change the published network image. If the physical sub-region controlled by the control device has always operated with sufficient quality of service over a predetermined period of time, the control device can gain credibility, and after a period of time, the possibility of changing the published network image can be achieved.
[0091] Therefore, an automatic consensus regarding that a control device operating with sufficient credibility is granted the permission to change the published network image can be advantageously facilitated.
[0092] The respective units of the respective control devices, such as control units, storage units, and / or comparison units, can be implemented by hardware technology and / or software technology. In the case of implementation by hardware technology, the respective units can be constructed as a device or a part of a device, such as being constructed as a computer or a microprocessor or a control computer of a vehicle. In the case of implementation by software technology, the respective units can be constructed as a computer program product, a function, a routine, a part of program code, or an executable object.
[0093] According to another aspect, a method for operating a software-defined network having a certain number of network elements is proposed. The method includes: storing a network image of the software-defined network in a storage unit of a control device; controlling, by a control unit of the control device, the forwarding of a data stream through the certain number of network elements based on the stored network image; and comparing the network image stored in the storage unit of the control device with the network image published in a ledger of a blockchain.
[0094] The embodiments and features described for the proposed control device and / or the specified system correspondingly apply to the proposed method.
[0095] Furthermore, a computer program product is proposed, which causes the method explained above to be executed on a program-controlled device.
[0096] For example, a computer program product such as a computer program device can be provided or delivered as a storage medium such as a memory card, a USB stick, a CD-ROM, a DVD, or in the form of a file downloadable from a server in a network. For example, this can be done in a wireless communication network by transmitting the corresponding file with the computer program product or the computer program device.
[0097] Other possible implementations of the present invention also include combinations of features or embodiments not explicitly mentioned above or below in the description of the embodiments. Here, those skilled in the art will also add various aspects as improvements or supplements to the respective basic forms of the present invention.
[0098] Other advantageous designs and aspects of the present invention are the subject matter of the dependent claims and the embodiments of the present invention described below. The present invention will be explained in more detail below based on preferred embodiments with reference to the accompanying drawings. Brief Description of the Drawings
[0099] Figure 1 Shows a control device, a software-defined network, and a blockchain according to a first embodiment;
[0100] Figure 2 Shows a method for operating a software-defined network according to a first embodiment;
[0101] Figure 3 shows the expansion of the control device and the physical view of the software-defined network; Figure 1
[0102] Figure 4 shows the expansion of the control device and the virtual view of the software-defined network; and Figure 3
[0103] Figure 5 shows a system for operating a software-defined network having a plurality of physical sub-regions according to a second embodiment.
[0104] In the drawings, unless otherwise noted, the same or functionally identical elements are provided with the same reference numerals. DETAILED DESCRIPTION
[0105] Figure 1 shows a control device 1, a software-defined network 2, and a blockchain 11 according to a first embodiment.
[0106] The control device 1 includes a storage unit 5, a control unit 7, and a comparison unit 9. A network image 6 of the software-defined network 2 is stored in the storage unit 5.
[0107] The software-defined network 2 includes two network elements 4 that are arranged to forward a data stream 8 within the software-defined network 2.
[0108] In Figure 1 a blockchain 11 is also shown, which is shown as a cloud. It can be understood that the blockchain 11 can be created by a large number of blockchain nodes (not shown).
[0109] Figure 1 a general ledger 12 of the blockchain 11 is also shown. The published network image 13 is stored in the general ledger 12. The published network image is shown as a sequence of a plurality of changes or change transactions 13.
[0110] Figure 2 shows a method for operating the software-defined network 2. Referring together to Figure 1 and Figure 2 .
[0111] In step S1, the network image 6 of the software-defined network 2 is stored in the storage unit 5.
[0112] In step S2, the control unit 7 controls the forwarding of the data stream 8 through the network element 4 based on the network image 6.
[0113] In particular, the network element 4 reports the service parameters of unrecognized data packets (not shown) to the control unit 7. The control unit 7 determines the data flow rules for each of the two network elements 4 based on the network image 6 stored in the storage unit 5, and implements the data flow rules on the two network elements 4. Thereby, a data flow 8 will be created. If other packets with the same service parameters arrive at the network element 4, the other packets can be recognized as belonging to the data flow 8 based on the implemented data flow rules and forwarded to other network elements 4 and / or endpoints (represented by circles) according to the data flow rules, and the other packet parameters can be parameterized if necessary, without further communication with the control unit 7 for this purpose.
[0114] In step S3, the network image 6 stored in the storage unit 5 is compared with the network image 13 published in the general ledger 12 of the blockchain 11.
[0115] In particular, in order to perform the comparison, the changes of the published network image 13 published in the general ledger 12 can be incorporated into the stored network image 6, and / or the changes of the stored network image 6 can be published as the changes of the published network image 13 in the general ledger 12.
[0116] In particular, the comparison unit 7 can be set to not incorporate the following changes into the stored network image 6 (preventing the acceptance of the following changes and / or withdrawing the following changes), which should be made to the network image 6, but the blockchain 11 rejects the publication of the changes based on the consensus protocol of the blockchain 11.
[0117] Figure 3 Shows Figure 1 the expansion of the control device 1 and the physical view of the software-defined network 2.
[0118] The software-defined network 2 consists of two network elements 4 at the physical layer. Each respective network element 4 has its own certain number of connection ends 15. A plurality of terminals 16 are respectively connected to one of the connection ends 15 of one of the network elements 4. At least one endpoint 3 is respectively constructed on each respective terminal 16.
[0119] Some of the connection ends of the network element 4 are not connected to the terminal 16. Thus, the connection end 115 of the network element 104 is connected to the connection end 215 of the network element 204. The connection end 315 of the network element 204 represents a transition point to an external network and / or to other software-defined networks (not shown).
[0120] In a conventional physical network created in a manner similar to that shown in Figure 3 if the network element 4 is a conventional switch, each endpoint 3 can communicate with each endpoint 3, and the respective data flows may affect each other.
[0121] However, the control unit 7 of the control device 1 implements a virtual tenant network area ( Figure 4 17 in) in the software-defined network 2 based on the network image 6, in such a way that the control unit implements respective data flow rule sets in respective network elements 4 (which is indicated by arrows in Figure 3 ). The network elements 4 are arranged to forward and parameterize data flows ( Figure 1 8 in) in the software-defined network 2 based on the data flow rule sets respectively implemented in the network elements 4.
[0122] Figure 4 shows Figure 1 the extension of the control device 1 and a virtual view of the software-defined network 2.
[0123] As Figure 4 shown in, a first virtual tenant network area 17, 117 is formed by endpoints 103, 203 and 403. A second virtual tenant network area 17, 217 is formed by endpoints 303, 503 and 603. The data flow rules implemented in the network elements 4 ( Figure 3 ) cause the virtual tenant network areas 17, 117, 217 to behave like completely separate physical network areas with respect to their respective endpoints 3. In other words, the network elements 4 can prevent the data flow of one virtual tenant network area 117 ( Figure 1 8 in) from affecting the data flow of the second virtual tenant network area 217 through appropriate parameterization such as bandwidth limitation, setting up a firewall, etc.
[0124] It can thus be understood that the network image 6 stored in the storage unit 5 of the control device 1 is particularly sensitive information that needs to be protected against manipulation, wherein the forwarding and parameterization of data flows ( Figure 1 8 in) through the network elements 4 are controlled based on the network image 6 in the software-defined network 2.
[0125] The control device 1 advantageously implements protection against manipulation of the stored network image 6 by comparing the stored network image 6 with the network image 13 ( Figure 1 ) published in the general ledger 12 of the blockchain 11 ( Figure 1 ) as described above.
[0126] Figure 3 and Figure 4 the extension of the control device 1 shown in Figure 1The control device 1 shown in also differs as follows: The control unit 7 obtains quality-of-service information from the respective network elements 4. For example, the control unit 7 obtains quality-of-service information regarding the quality of service of other software-defined networks (not shown) from the network element 204, and the connection end 315 constitutes a transition point to the other software-defined network. The control unit 7 stores the obtained quality-of-service information as stored quality-of-service information 21 in the storage unit 5.
[0127] The comparison unit 9 includes the blockchain node 18 of the blockchain 11. The blockchain node 18, together with other blockchain nodes (not shown), constitutes the blockchain 11. In particular, the blockchain node 18 participates in consensus reaching according to the consensus protocol of the blockchain 11. If other blockchain nodes (not shown) request other control devices (not shown) to change the published network image ( Figure 1 in ), the blockchain node 18 only agrees to publish the consensus of the change if it is derived from the quality-of-service information 21 that the other control device runs the other software-defined network with a quality of service higher than a predetermined threshold.
[0128] Therefore, it is advantageous that only the control device 1 that runs its respective software-defined network 2 with sufficient quality of service can successfully request a change to the published network image ( Figure 1 in ).
[0129] Figure 5 Fig. shows a system 10 for running a software-defined network 2 having a plurality of physical sub-regions 102, 202 according to a second embodiment.
[0130] The system 10 includes a first control device 101 and a second control device 102, and a plurality of blockchain nodes 18, 118, 218, 318 of the blockchain 11.
[0131] The software-defined network 2 includes a first physical sub-region 102 and a second physical sub-region 202. A mixed virtual / physical view is shown for the respective physical sub-regions 102, 202.
[0132] At the physical level, the first physical sub-region 102 is constituted by two SDN switches (network elements) 104, 204 and a plurality of network terminals (not shown). The physical sub-region 202 is constituted by two SDN switches 304, 404 and a plurality of network terminals (not shown). The respective SDN switches 104, 204; 304, 404 of the respective physical sub-regions 102, 202 are connected to each other. In addition, the SDN switch 204 is connected to the SDN switch 304. Therefore, the SDN switches 204, 304 each constitute a transition point between the physical sub-regions 102, 202.
[0133] At the virtual level, a large number of endpoints 3 are constructed in the physical sub-regions 102, 202. The endpoints 3 can be services, ports, etc. of network terminals (not shown). In addition, a large number of virtual network regions or tenant network regions 17 are constructed in the physical sub-regions 102, 202. Some tenant network regions 317, 417 extend across the two physical sub-regions 102, 202; other tenant network regions extend only across a single sub-region 102, 202.
[0134] The respective control devices 1 of the system 10 are the respective SDN controllers 101, 201.
[0135] The first SDN controller 101 includes a storage unit 105, a control unit 107, and a comparison unit 109. A network image 106 of the software-defined network 2 formed by the physical sub-regions 102, 202 is stored in the storage unit 105.
[0136] Based on the network image 106, the control unit 107 implements respective data flow rules in the respective SDN switches 104, 204, and thereby controls the forwarding of data flows ( Figure 1 in 8) through the SDN switches 104, 204. These data flow rules are set such that when implemented on the network elements 104, 204, they cause the construction of the virtual tenant network regions 17 (some parts of the virtual tenant network regions 17 within the first physical sub-region 102).
[0137] In addition, the control unit 107 continuously receives quality-of-service information from the SDN switches 104, 204. Specifically, the control unit 107 of the first SDN controller 101 receives quality-of-service information from the SDN switch 204, which forms a transition point to the second physical sub-region 202, and the quality-of-service information describes the quality of service of the second physical sub-region 202 and can thus be regarded as a measure of the reputation of the second SDN controller 201. The control unit 107 stores the time course 121 of the received quality-of-service information in the storage unit 105.
[0138] The comparison unit 109 compares the network image 106 stored in the storage unit 105 with the network image 13 published in the general ledger 12 of the blockchain 11. For this purpose, the comparison unit 109 communicates with the blockchain node 118 assigned to the comparison unit 109.
[0139] Authorization information 19 is also published in the general ledger 12 of the blockchain 11, and the authorization information is, for example, the public keys of the blockchain nodes 118, 218, and 318.
[0140] The second SDN controller 201 includes: a storage unit 205 in which a time variation process 221 of quality of service information and a network image 206 are stored; and a control unit 207 and a comparison unit 209. Each of the units 205, 207, 209 of the second SDN controller 201 is designed in the same manner as the corresponding units 105, 107, 109 of the first SDN controller 101.
[0141] In addition to the advantage of anti-tampering protection for the stored image 106 already described based on the first embodiment, the comparison by the comparison units 101, 201 can provide a further advantage, that is, the SDN controllers 101 and 201 can reach a consensus on the common network images 106, 206, 13 by means of blockchain-based comparison. In this way, the SDN controllers 101, 102 can jointly control the network elements 4 of their respective physical sub-regions 102, 202, so that tenant network regions 317, 417 spanning more than one physical sub-region 102, 202 are constructed.
[0142] In the current case, the blockchain 11 is composed of three blockchain nodes 118, 218, 318. The first blockchain node 118 is assigned to the comparison unit 109 of the first SDN controller 101. The first blockchain node 118 constitutes an endpoint 703 in the part of the tenant network region 317 located in the first physical sub-region 102. Therefore, it can be said that the first blockchain node 118 is assigned to the first physical sub-region 102. The second blockchain node 218 is assigned to the comparison unit 209 of the second SDN controller 201. The second blockchain node 218 constitutes an endpoint 803 in the part of the tenant network region 317 located in the second physical sub-region 202. Therefore, the second blockchain node 218 is assigned to the second physical sub-region 202. The third blockchain node 318 is not assigned to the SDN controllers 101, 201. The third blockchain node 318 also constitutes an endpoint 903 in the tenant network region 317. Therefore, it can be said that the third blockchain node 318 is assigned to the virtual tenant network region 317.
[0143] The blockchain nodes 118, 218, 318 communicate with each other in the public area between the endpoints 703, 803, 903 formed by these blockchain nodes within the tenant network region 317 at the data level of the software-defined network 2 by means of a data stream ( Figure 1 in 8). The comparison unit 109 of the first SDN controller 101 located in the private area communicates with the first blockchain node 118 at the control level of the software-defined network 2. Similarly, the comparison unit 209 communicates with the second blockchain node 218 at the said control level.
[0144] Thus, the tenant network area 317 can be a tenant network area reserved for running the blockchain 11 at the data level of the software-defined network 2. In other words, the operator of the blockchain 11 is a tenant of the tenant network area 317.
[0145] It can be understood that the blockchain 11 can include other blockchain nodes (not shown). By adding other blockchain nodes, the redundancy of the blockchain 11 and the protection against manipulation of the blockchain 11 can be further improved.
[0146] If the published network image 13 is to be changed (and thus also the stored network images 106 and 206), one of the blockchain nodes 18 transmits a change request as an unconfirmed transaction to the blockchain 11.
[0147] Preferably, according to the consensus protocol of the blockchain 11, only when the transmitted change request is provided with a digital signature, the validity of which can be verified based on one of the public keys included in the authorization information 19, will the respective blockchain nodes 118, 218, 318 agree to publish the change request as a change to the published network image 13 in the general ledger 12 of the blockchain 11 (and then accept the block including the change request as an unconfirmed transaction as a confirmed block with a confirmed transaction into the local copy of this block of the general ledger 12).
[0148] In this way, it is possible to advantageously prevent the publication of change requests transmitted from other blockchain nodes (not shown) to the blockchain 11. The other blockchain nodes can be blockchain nodes run by an attacker who has obtained illegal access to the tenant network area 317.
[0149] Preferably, other conditions for reaching a consensus can be associated with the quality of service. For example, if the change transaction transmitted to the blockchain 11 is signed by the blockchain node 218, for example, the blockchain node 118 checks whether it can be inferred from the stored time course 121 of the quality of service information obtained from the control unit 107 that the second physical sub-region 202 to which the blockchain node 218 is assigned has been operating with an average quality of service higher than a predetermined threshold for a predetermined period of time. If the average quality of service of the operation of the second physical sub-region 202 is higher than the predetermined threshold during the predetermined period of time, the first blockchain node 118 agrees to the consensus. Otherwise, the first blockchain node 118 does not agree to the consensus.
[0150] Thus, it can be said that the blockchain 11 implements a consensus protocol based on proof of stake. For example, the proof of interest or legal right of the blockchain node 218 that requests the change includes the signature of the blockchain node 218 that identifies the change request, and quality of service information regarding the quality of service of the second physical sub-region 202 to which the second blockchain node 218 is assigned, and the quality of service information is included in the time-varying process 121.
[0151] Thus, the system 10 (SDN controllers 101, 201, and blockchain node 18) advantageously enables the construction of a software-defined wide area network 2 having a plurality of SDN controllers 101, 102, and these SDN controllers 101, 102 compare the network images 106, 206 stored in these SDN controllers in a secure manner by means of the blockchain 11 formed by the blockchain nodes 18.
[0152] Here, an infinite trust relationship between the operators of the SDN controllers 101, 201 is advantageously unnecessary. Instead, each SDN controller 101, 201 can obtain a reputation by continuously operating with a sufficient quality of service for a relatively long time, and thus obtain the permission to request a change to the published network image 13 for the comparison.
[0153] Although the present invention has been described based on embodiments, the present invention can be modified in many ways.
[0154] The software-defined network 2 is described in the second embodiment, which includes two physical sub-regions 102, 202 having respective control devices 101, 201. It should be noted that the view of referring to the physical sub-regions 102, 202 as software-defined networks 102, 202 and referring to the software-defined network 2 as a network complex is functionally equivalent.
[0155] Instead of the SDN controllers 101, 201 described in the second embodiment, the system 10 of the second embodiment can also operate using the control device 1 according to the first embodiment or its extension.
[0156] The consensus protocol may include other conditions for enhancing anti-manipulation protection.
[0157] For example, the consensus protocol may stipulate in advance that the change request will generate a changed published network image when applied to the published network image, and the changed published network image itself is logical, for example, does not contain loops, open ends, contradictory definitions, etc.
[0158] According to the second embodiment, the respective blockchain nodes 18 each form an endpoint in the tenant area 317, and the blockchain nodes 18 communicate with each other by means of the data stream in the tenant area 317. This exemplary design can also be referred to as in-band blockchain or blockchain with in-band communication.
[0159] An out-of-band blockchain or a hybrid form is also conceivable, in which some blockchain nodes 18 communicate with each other in-band, while some blockchain nodes 18 communicate with each other out-of-band.
[0160] Out-of-band communication is here to be understood in particular as communication via a public network and / or communication via a network different from the software-defined network 2.
[0161] Even in the case of an out-of-band blockchain, the respective blockchain nodes 18 can be assigned to the virtual tenant network area 17 and / or the physical sub-areas 102, 202 of the software-defined network 2. This assignment can be achieved by having the tenant and / or operator of the physical sub-area or control device manage the blockchain nodes 18. This assignment can be recorded by the respective assigned blockchain nodes 18 having a corresponding digital key, which can be used to sign transactions, change requests, etc.
[0162] The proposed control devices 1, 101, 201 and the proposed system 10 can advantageously be applied in the context of Industry 4.0, in which it is advantageously possible to create a software-defined wide area network 2 with a large number of network operators and tenants in industrial facilities that can be distributed over multiple locations.
Claims
1. A control device (1) for operating a software-defined network (2) having a certain number of network elements (4), wherein the control device (1) has: A storage unit (5) which is arranged to store a network image (6) of the software-defined network (2), A control unit (7) which is arranged to control the forwarding of a data stream (8) through the certain number of network elements (4) based on the stored network image (6), and A comparison unit (9) which is arranged to compare the stored network image (6) with a network image (13) published in a ledger (12) of a blockchain (11), characterized in that a) The comparison is carried out in such a way that the stored network image (6) and the published network image (13) are kept in sync, b) The comparison unit (9) includes a blockchain node (18) of the blockchain (11), wherein the blockchain node (18) is arranged to consent to the consensus of a change request for the published network image (13) transmitted to the blockchain (11) for publication in the ledger (12) of the blockchain (11) if the change request of the published network image (13) corresponds to the consensus protocol of the blockchain (11), c) The control unit (7) is arranged to receive quality-of-service information (21) from at least one of the certain number of network elements (4), wherein the consensus protocol of the blockchain (11) is based on the quality-of-service information (21).
2. The control device according to claim 1, It is characterized in that The comparison unit (9) is arranged to - Transmit a change of the stored network image (6) as a change request for the published network image (13) to the blockchain (11), - Accept the change of the stored network image (6) if the change request of the published network image (13) is published as a change of the published network image in the ledger (12) of the blockchain (11), and - Discard the change of the stored network image (6) if the change request of the published network image (6) is not published as a change of the published network image (13) in the ledger (12) of the blockchain (11).
3. The control device according to claim 1 or 2, It is characterized in that The comparison unit (9) is arranged to accept the change of the published network image (13) as a change of the stored network image (6) if the change request of the published network image (13) is published as a change of the published network image (13) in the ledger (12) of the blockchain (11).
4. The control device according to any one of claims 1 to 2, It is characterized in that At least the control unit (7) is arranged in a private area, and at least the blockchain node (18) is arranged in a public area.
5. A system (10) for operating a software-defined network (2) having a certain number of network elements (4), wherein the system (10) has: A certain number of control devices (1, 101, 201) according to any one of claims 1 to 4, and a plurality of blockchain nodes (18), the plurality of blockchain nodes together constituting a blockchain (11) and being configured to: - Exchange change requests for the published network image (13) transmitted to the blockchain (11) with each other; and - Publish the change request as a change to the published network image (13) in the general ledger (12) of the blockchain (11) only when consensus is reached among the plurality of blockchain nodes (18) according to the consensus protocol of the blockchain (11).
6. The system according to claim 5, It is characterized in that The control units (7, 107, 207) of a certain number of control devices (1, 101, 201) are configured to control the forwarding of the data stream (8) by the certain number of network elements (4) in such a way that the control units communicate with the certain number of network elements (4) at the control level of the software-defined network (2); and The plurality of blockchain nodes (18) that together constitute the blockchain (11) are configured to communicate with each other at the data level of the software-defined network (2) and / or via a public network.
7. The system according to claim 5 or 6, It is characterized in that The plurality of blockchain nodes (18) are configured to reach a consensus on publishing the change in the general ledger (12) of the blockchain (11) based on a proof of the legitimate rights and interests of the blockchain node (18) requesting the change.
8. The system according to claim 7, It is characterized in that, Publish authorization information (19) in the general ledger (12) of the blockchain (11), the authorization information indicating the blockchain nodes among the blockchain nodes (18) that are authorized to request changes to the published network image (13), and The proof of the legitimate rights and interests includes a proof that the blockchain node (18) requesting the change is authorized to request the change to the published network image (13) according to the authorization information (19) published in the general ledger (12) of the blockchain (11).
9. The system according to claim 7, It is characterized in that Set a plurality of virtual tenant network areas (17) in the software-defined network (2), the plurality of virtual tenant network areas being defined by the published network image (13), wherein each blockchain node (18, 318) among a certain number of the plurality of blockchain nodes is respectively assigned to one of the virtual tenant network areas (17, 317).
10. The system according to claim 9, Characterized in that, Each control device (1, 101, 201) is configured to control a physical sub-region (102, 202) of the software-defined network (2), wherein each physical sub-region (102, 202) is formed by making a discontinuous selection from the certain number of network elements (4). Among them, respective blockchain nodes (18, 118, 218) of a certain number of blockchain nodes among the multiple blockchain nodes are respectively assigned to one of the physical sub-regions (102, 202).
11. The system according to claim 10, It is characterized in that The proof of legitimate interest includes: Proof of the assignment of the requesting blockchain node (18, 118, 218, 318) to one of the virtual tenant network regions (17, 317) and / or one of the physical sub-regions (102, 202), and Proof of the quality of service of the virtual tenant network region (17, 317) and / or physical sub-region (102, 202) to which the requesting blockchain node (18, 118, 218, 318) is assigned.
12. The system according to claim 11, It is characterized in that The control unit (7, 107, 207) of each control device among the multiple control devices (1, 101, 201) is configured to receive quality-of-service information related to the quality of service of a certain number of other physical sub-regions (102, 202) from at least a discontinuous selection of network elements (4) of the physical sub-region (102, 202) controlled by the control device (1, 101, 201), The storage unit (5, 105, 205) of each control device among the multiple control devices (1, 101, 201) is configured to store, for each of the certain number of other physical sub-regions (101, 202), the time variation process (21, 121, 221) of the quality-of-service information received from the control unit (7, 107, 207); and The proof of the quality of service of the physical sub-region (102, 202) to which the requesting blockchain node (18, 118, 218) is assigned is based on the time variation process (21, 121, 221) of the quality-of-service information related to the physical sub-region (102, 202), and the time variation process is stored in the storage unit (5, 105, 205) of each control device among the multiple control devices (1, 101, 201).
13. A method for operating a software-defined network (2) having a certain number of network elements (4), wherein the method includes: Storing a network image (6) of the software-defined network (2) in a storage unit (5) of a control device (1), Controlling, by a control unit (7) of the control device (1), the forwarding of a data stream (8) through the certain number of network elements (4) based on the stored network image (6), and Comparing, by a comparison unit (9) of the control device (1), the network image (6) stored in the storage unit (5) of the control device (1) with the network image (13) published in a general ledger (12) of a blockchain (11), such that a) The comparison is performed in such a way that the stored network image (6) and the published network image (13) are kept synchronized. b) The comparison unit (9) includes a blockchain node (18) of the blockchain (11), such that the blockchain node (18) is operated to consent to the consensus for the change request of the published network image (13) transmitted to the blockchain (11) for publication in the general ledger (12) of the blockchain (11) if the change request of the published network image (13) corresponds to the consensus protocol of the blockchain (11). c) The control unit (7) receives quality of service information (21) from at least one of the certain number of network elements (4), wherein the consensus protocol of the blockchain (11) is based on the quality of service information (21).
14. A computer program product that causes the method according to claim 13 to be executed on a program-controlled device.
Citation Information
Patent Citations
Method for constructing software defined network control layer security mechanism based on block chain
CN107222478A
Software defined networking system
WO2017220115A1