Blockchain SDN Cloud Security Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud management systems face challenges in securing cloud architecture due to reliance on third-party networking services, which can compromise security and are susceptible to single points of failure.
Innovation Solution
A blockchain-powered SDN-enabled networking infrastructure that integrates blockchain-based security and autonomy management with a multi-controller SDN networking layer, utilizing Ethereum blockchain and OpenFlow 1.3, to enhance the integrity of control and management messages and provide autonomous bandwidth provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a centralized Security Manager is used to detect falsely injected packets, then security detection capability is improved, but the system becomes susceptible to single point of failure
Solution Approach 1:
The patent segments the centralized security management into multiple distributed SDN controllers, each capable of independent security detection and packet verification. This eliminates the single point of failure while maintaining detection capabilities through distributed architecture.
Solution Approach 2:
The patent introduces blockchain as an intermediary layer between SDN controllers and the security management system. The blockchain ledger serves as a trusted mediator that verifies controller identities and maintains security policies, enabling decentralized security management without a single point of failure.
2Adaptability or versatility
If third-party networking services are used to support cloud infrastructure, then networking capability is improved, but security trustworthiness deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where SDN controllers continuously verify each other's operations and security states through blockchain-based consensus. This creates a self-regulating system that maintains security trustworthiness while utilizing third-party networking services.
Solution Approach 2:
The blockchain platform acts as a trusted intermediary that enables secure interactions between cloud service providers and third-party networking services. It provides verifiable security policies and controller authentication without requiring direct trust in third-party providers.
3Ease of operation
If SDN controllers are centralized for simplified management, then ease of operation is improved, but the system becomes vulnerable to manipulation attacks
Solution Approach 1:
The patent divides the centralized SDN controller into multiple distributed controllers that peer through blockchain. Each controller maintains independent security verification capabilities, preventing manipulation attacks while distributing management responsibilities across multiple nodes.
Solution Approach 2:
The patent changes the operational parameters of SDN controllers by implementing blockchain-based identity verification and cryptographic authentication. This transforms the controllers from potentially vulnerable centralized entities to secured distributed nodes with tamper-resistant identity management.
Data Source
AI summary
In various embodiments, the present invention relates to a blockchain-powered SDN-enabled networking infrastructure in which the integration between blockchain-based security and autonomy management layer and multi-controller SDN networking layer is defined to enhance the integrity of the control and management messages. In one or more embodiments, this networking infrastructure is utilized achieve three main functionalities: (1) integrity verification of control and management commands for cloud platforms, (2) identification of the malicious hosts abusing the cloud platform, and (3) enhancing the availability of the cloud platform via autonomous bandwidth provisioning.


