Decoupled Control Plane for Dynamic Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication networks are vulnerable to advanced, dynamic attacks that exploit static security measures and network configurations, making them susceptible to espionage and unauthorized access.
Innovation Solution
A device that decouples the data plane and control plane of communication networks, using Software-Defined Networking (SDN) and Moving-Target-Defence (MTD) techniques to dynamically modify visible network characteristics during communication sessions, such as virtual addresses, routing behavior, and crypto-algorithms, thereby creating an unpredictable and secure environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static network configurations and signature-based security measures are used, then security implementation is simple and stable, but the network becomes vulnerable to dynamic attacks and espionage
Solution Approach 1:
The patent applies dynamics by making the network configuration dynamic instead of static. The control unit dynamically modifies network characteristics such as virtual addresses, routing behavior, and crypto-algorithms during communication sessions. This dynamic behavior prevents attackers from predicting or exploiting fixed patterns, thereby resolving the vulnerability to dynamic attacks while maintaining security simplicity through automated control.
Solution Approach 2:
The patent changes network parameters dynamically during operation. The control unit modifies parameters including virtual addresses of terminals, routing behavior, and cryptographic algorithms based on communication session state. These parameter changes make the network unpredictable to attackers while maintaining stable security control through the centralized control unit.
2Object-affected harmful factors
If dynamic modification of network characteristics is implemented, then network security against espionage increases, but system complexity increases
Solution Approach 1:
The patent segments the network system into two independent planes: data plane and control plane. The data plane handles communication traffic while the control plane manages configuration changes. This segmentation allows dynamic modification of network characteristics without complicating the data transmission path, as the control unit independently manages security-related parameter changes.
Solution Approach 2:
The control unit acts as an intermediary between the data plane and the external environment. It mediates all configuration changes and security modifications, centralizing the complexity in a single manageable component rather than distributing it throughout the network. This intermediary approach simplifies overall system management while enabling dynamic security adjustments.
3Difficulty of detecting and measuring
If decoupled control plane is used to dynamically modify network characteristics, then unpredictability for attackers increases, but control mechanism complexity increases
Solution Approach 1:
The patent extracts the control functionality from the data plane and places it in a separate control plane. The control unit is taken out as an independent entity that manages all configuration changes. This extraction allows the data plane to remain simple and focused on transmission, while the control plane handles the complexity of dynamic modifications, achieving unpredictability without overwhelming system complexity.
Data Source
AI summary
A device for controlling a communication network having a plurality of terminals for a data communication is provided. The device comprises a control unit configured to decouple a data plane and a control plane of the data communication and to modify at least one characteristic of the communication network which is visible from the outside of the communication network during a communication session using the decoupled control plane.


