Flow Controller Path Establishment in Split Architecture Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Split architecture networks face disruptions and security threats, requiring secure and non-disruptive communication paths between multiple devices to ensure network security, availability, and integrity, especially under attacks like Denial of Service (DoS) and information leakage.

Innovation Solution

A method involving a flow controller that sends three messages to establish a communication path: a first message to prepare switches, a second message to establish connections through identified routing paths, and a third message to finalize connections between source and destination ports, ensuring accurate and secure path establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional network architecture with control plane functionality on every node is used, then network autonomy and robustness are improved, but device complexity and security vulnerability increase

Engineering Contradiction:
Improvenetwork robustnessVSAvoidcontrol plane distribution
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network control architecture into two distinct planes: a centralized control plane residing on a controller and a distributed data plane residing on network devices. This segmentation allows the control logic to be centralized for simplified management while the data forwarding remains distributed for robustness, resolving the contradiction between centralized control simplicity and distributed control robustness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a controller as an intermediary component that mediates between network devices and external management systems. The controller acts as a centralized brain that programs and manages flow switches, providing a simplified interface for network management while maintaining distributed data plane operations, thus reducing overall system complexity while preserving robustness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a split architecture network with centralized controller is used, then device complexity is reduced, but network security and availability under attacks worsen

Engineering Contradiction:
Improveflow switch simplicityVSAvoidnetwork availability under attack
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary actions by pre-programming flow switches with flow tables and rules before attacks occur. The controller proactively configures the data plane with predetermined forwarding rules, security policies, and anomaly response actions. This preliminary configuration enables the network to respond automatically and rapidly to attacks without requiring real-time control plane intervention, thereby maintaining availability under attack conditions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by pre-configuring the data plane with security rules and anomaly detection capabilities that automatically counteract potential attacks. The flow tables include predefined actions for detecting and responding to malicious traffic patterns, enabling the network to mount defensive actions before attacks fully manifest, thus protecting against security threats while maintaining simplified device architecture.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If traditional path establishment methods are used, then communication paths can be established, but incorrect or blocked paths may occur leading to data leakage

Engineering Contradiction:
Improvepath establishment speedVSAvoidpath accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the controller continuously monitors the state of flow switches and communicates with them to verify path establishment. The controller receives status information from devices and adjusts flow tables accordingly, ensuring that communication paths are correctly established and blocked if anomalies are detected. This feedback loop guarantees path accuracy while maintaining efficient establishment through automated control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10069763B2Method to establish a non-disruptive communications path between multiple devices
Publication Date: 2018.09.04 NETSCOUT SYSTEMS INC
  • US10069763B2 patent drawing
  • US10069763B2 patent drawing
  • US10069763B2 patent drawing

AI summary

A method for establishing a communications path is provided. A routing path between a source port on a source switch and a destination port on a destination switch through intermediate switches is identified. A first message is sent to the source switch, the destination switch and the intermediate switches instructing the recipient switches to prepare for establishing a connection. In response to receiving a first set of acknowledgment messages from the recipient switches, a second message is sent to the destination switch and the intermediate switches instructing these switches to establish a connection to the destination port along the identified routing path. In response to receiving a second set of acknowledgment messages from the destination switch and each of the intermediate switches, a third message is sent to the source switch instructing it to establish a connection between the source port and the established connection to the destination port.