Decoupled Control Plane for Dynamic Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks are vulnerable to advanced, dynamic attacks that exploit static security measures and network configurations, making them susceptible to espionage and unauthorized access.

Innovation Solution

A device that decouples the data plane and control plane of communication networks, using Software-Defined Networking (SDN) and Moving-Target-Defence (MTD) techniques to dynamically modify visible network characteristics during communication sessions, such as virtual addresses, routing behavior, and crypto-algorithms, thereby creating an unpredictable and secure environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static network configurations and signature-based security measures are used, then security implementation is simple and stable, but the network becomes vulnerable to dynamic attacks and espionage

Engineering Contradiction:
Improvenetwork securityVSAvoidsusceptibility to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the network configuration dynamic instead of static. The control unit dynamically modifies network characteristics such as virtual addresses, routing behavior, and crypto-algorithms during communication sessions. This dynamic behavior prevents attackers from predicting or exploiting fixed patterns, thereby resolving the vulnerability to dynamic attacks while maintaining security simplicity through automated control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes network parameters dynamically during operation. The control unit modifies parameters including virtual addresses of terminals, routing behavior, and cryptographic algorithms based on communication session state. These parameter changes make the network unpredictable to attackers while maintaining stable security control through the centralized control unit.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If dynamic modification of network characteristics is implemented, then network security against espionage increases, but system complexity increases

Engineering Contradiction:
Improveresistance to spyingVSAvoidcontrol system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the network system into two independent planes: data plane and control plane. The data plane handles communication traffic while the control plane manages configuration changes. This segmentation allows dynamic modification of network characteristics without complicating the data transmission path, as the control unit independently manages security-related parameter changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control unit acts as an intermediary between the data plane and the external environment. It mediates all configuration changes and security modifications, centralizing the complexity in a single manageable component rather than distributing it throughout the network. This intermediary approach simplifies overall system management while enabling dynamic security adjustments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If decoupled control plane is used to dynamically modify network characteristics, then unpredictability for attackers increases, but control mechanism complexity increases

Engineering Contradiction:
Improveunpredictability of network configurationVSAvoidcontrol plane architecture
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts the control functionality from the data plane and places it in a separate control plane. The control unit is taken out as an independent entity that manages all configuration changes. This extraction allows the data plane to remain simple and focused on transmission, while the control plane handles the complexity of dynamic modifications, achieving unpredictability without overwhelming system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10681057B2Device and method for controlling a communication network
Publication Date: 2020.06.09 RHEINMETALL DEFENCE ELECTRONICS GMBH
  • US10681057B2 patent drawing
  • US10681057B2 patent drawing
  • US10681057B2 patent drawing

AI summary

A device for controlling a communication network having a plurality of terminals for a data communication is provided. The device comprises a control unit configured to decouple a data plane and a control plane of the data communication and to modify at least one characteristic of the communication network which is visible from the outside of the communication network during a communication session using the decoupled control plane.