Openflow Bridge Replaces MAC Bridge for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The controllability of IP tables and layer-2 MAC forwarding tables in cloud platforms is poor compared to Openflow tables, leading to non-uniform security configurations across different bridges on the same cloud server.

Innovation Solution

Establishing an Openflow bridge on the cloud server that replaces the MAC bridge, utilizing a preconfigured Openflow security table with matching conditions and forwarding actions to manage packet forwarding, and combining Openflow entries to enhance packet forwarding efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP table and layer-2 MAC forwarding table are used for cloud platform security, then security filtering can be achieved, but controllability and uniformity of security configuration deteriorate

Engineering Contradiction:
Improvecloud platform securityVSAvoidcontrollability of security configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the fundamental parameter of the forwarding table structure from traditional IP table and MAC forwarding table to Openflow table. This transformation enables centralized control through SDN controller, allowing uniform security configuration across different bridges while maintaining security filtering capabilities. The Openflow table provides a standardized format that improves controllability and consistency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements a unified Openflow table that serves multiple functions: security filtering, packet forwarding, and centralized control. This universal table structure replaces the need for separate IP tables and MAC forwarding tables, enabling consistent security policies to be applied across different network bridges while maintaining all necessary filtering and forwarding capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple network bridges with separate forwarding tables are used, then network functionality is maintained, but packet forwarding efficiency deteriorates due to repeated searches

Engineering Contradiction:
Improvenetwork bridge functionalityVSAvoidpacket forwarding efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges multiple separate forwarding tables (IP table, MAC forwarding table, and other bridge tables) into a single unified Openflow table. This consolidation eliminates the need for repeated searches across multiple tables, significantly improving packet forwarding efficiency. The unified table maintains all necessary network bridge functionalities while enabling centralized management and faster lookup operations.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If dynamic learning is used for forwarding tables, then adaptability to network changes is improved, but configuration uniformity across bridges deteriorates

Engineering Contradiction:
Improvedynamic network adaptationVSAvoiduniformity of flow table configuration
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent introduces an SDN controller as an intermediary between the network bridges and the forwarding tables. The controller centrally manages the unified Openflow table, distributing consistent security policies and forwarding rules to all bridges. This intermediary enables dynamic adaptation to network changes while maintaining configuration uniformity across all bridges through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10887280B2Cloud platform security achievement
Publication Date: 2021.01.05 NEW H3C TECH CO LTD
  • US10887280B2 patent drawing
  • US10887280B2 patent drawing
  • US10887280B2 patent drawing

AI summary

Examples of the present disclosure provide a method and device for achieving the cloud platform security. In the present disclosure, an Openflow bridge is established on a cloud server of a cloud platform to replace a MAC bridge, the Openflow bridge may achieve the cloud platform security through an Openflow security table.