Blockchain SDN Cloud Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud management systems face challenges in securing cloud architecture due to reliance on third-party networking services, which can compromise security and are susceptible to single points of failure.

Innovation Solution

A blockchain-powered SDN-enabled networking infrastructure that integrates blockchain-based security and autonomy management with a multi-controller SDN networking layer, utilizing Ethereum blockchain and OpenFlow 1.3, to enhance the integrity of control and management messages and provide autonomous bandwidth provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a centralized Security Manager is used to detect falsely injected packets, then security detection capability is improved, but the system becomes susceptible to single point of failure

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem availability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the centralized security management into multiple distributed SDN controllers, each capable of independent security detection and packet verification. This eliminates the single point of failure while maintaining detection capabilities through distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces blockchain as an intermediary layer between SDN controllers and the security management system. The blockchain ledger serves as a trusted mediator that verifies controller identities and maintains security policies, enabling decentralized security management without a single point of failure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If third-party networking services are used to support cloud infrastructure, then networking capability is improved, but security trustworthiness deteriorates

Engineering Contradiction:
Improvenetworking capabilityVSAvoidsecurity trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where SDN controllers continuously verify each other's operations and security states through blockchain-based consensus. This creates a self-regulating system that maintains security trustworthiness while utilizing third-party networking services.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The blockchain platform acts as a trusted intermediary that enables secure interactions between cloud service providers and third-party networking services. It provides verifiable security policies and controller authentication without requiring direct trust in third-party providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If SDN controllers are centralized for simplified management, then ease of operation is improved, but the system becomes vulnerable to manipulation attacks

Engineering Contradiction:
Improvemanagement simplicityVSAvoidmanipulation attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the centralized SDN controller into multiple distributed controllers that peer through blockchain. Each controller maintains independent security verification capabilities, preventing manipulation attacks while distributing management responsibilities across multiple nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the operational parameters of SDN controllers by implementing blockchain-based identity verification and cryptographic authentication. This transforms the controllers from potentially vulnerable centralized entities to secured distributed nodes with tamper-resistant identity management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12273458B2Blockchain-powered cloud management system
Publication Date: 2025.04.08 THE UNIVERSITY OF AKRON
  • US12273458B2 patent drawing
  • US12273458B2 patent drawing
  • US12273458B2 patent drawing

AI summary

In various embodiments, the present invention relates to a blockchain-powered SDN-enabled networking infrastructure in which the integration between blockchain-based security and autonomy management layer and multi-controller SDN networking layer is defined to enhance the integrity of the control and management messages. In one or more embodiments, this networking infrastructure is utilized achieve three main functionalities: (1) integrity verification of control and management commands for cloud platforms, (2) identification of the malicious hosts abusing the cloud platform, and (3) enhancing the availability of the cloud platform via autonomous bandwidth provisioning.