Openflow Bridge Replaces MAC Bridge for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The controllability of IP tables and layer-2 MAC forwarding tables in cloud platforms is poor compared to Openflow tables, leading to non-uniform security configurations across different bridges on the same cloud server.
Innovation Solution
Establishing an Openflow bridge on the cloud server that replaces the MAC bridge, utilizing a preconfigured Openflow security table with matching conditions and forwarding actions to manage packet forwarding, and combining Openflow entries to enhance packet forwarding efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP table and layer-2 MAC forwarding table are used for cloud platform security, then security filtering can be achieved, but controllability and uniformity of security configuration deteriorate
Solution Approach 1:
The patent changes the fundamental parameter of the forwarding table structure from traditional IP table and MAC forwarding table to Openflow table. This transformation enables centralized control through SDN controller, allowing uniform security configuration across different bridges while maintaining security filtering capabilities. The Openflow table provides a standardized format that improves controllability and consistency.
Solution Approach 2:
The patent implements a unified Openflow table that serves multiple functions: security filtering, packet forwarding, and centralized control. This universal table structure replaces the need for separate IP tables and MAC forwarding tables, enabling consistent security policies to be applied across different network bridges while maintaining all necessary filtering and forwarding capabilities.
2Adaptability or versatility
If multiple network bridges with separate forwarding tables are used, then network functionality is maintained, but packet forwarding efficiency deteriorates due to repeated searches
Solution Approach 1:
The patent merges multiple separate forwarding tables (IP table, MAC forwarding table, and other bridge tables) into a single unified Openflow table. This consolidation eliminates the need for repeated searches across multiple tables, significantly improving packet forwarding efficiency. The unified table maintains all necessary network bridge functionalities while enabling centralized management and faster lookup operations.
3Adaptability or versatility
If dynamic learning is used for forwarding tables, then adaptability to network changes is improved, but configuration uniformity across bridges deteriorates
Solution Approach 1:
The patent introduces an SDN controller as an intermediary between the network bridges and the forwarding tables. The controller centrally manages the unified Openflow table, distributing consistent security policies and forwarding rules to all bridges. This intermediary enables dynamic adaptation to network changes while maintaining configuration uniformity across all bridges through centralized control.
Data Source
AI summary
Examples of the present disclosure provide a method and device for achieving the cloud platform security. In the present disclosure, an Openflow bridge is established on a cloud server of a cloud platform to replace a MAC bridge, the Openflow bridge may achieve the cloud platform security through an Openflow security table.


