Hierarchical SDN Controller Architecture for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing SDN network architectures, when a controller is attacked, networking information can be leaked, compromising network security.

Innovation Solution

Each level of controller manages its domain's status information, with upper-level controllers overseeing lower-level controllers and boundary nodes, ensuring that networking information cannot be leaked even if a controller is attacked, by implementing a hierarchical management structure using OpenFlow or non-OpenFlow protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If each controller acquires networking information for path calculation, then path routing capability is improved, but network security deteriorates due to information leakage when controllers are attacked

Engineering Contradiction:
Improvepath routing capabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the networking information into two types: topology information (managed locally by each controller for path calculation) and status information (managed separately and not fully visible to individual controllers). This segmentation allows controllers to have necessary routing capabilities while preventing them from accessing complete network information that could be exploited for attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces boundary nodes as intermediaries between controllers and the rest of the network. These boundary nodes collect and manage status information, acting as a buffer that prevents controllers from directly accessing sensitive networking information while still enabling necessary path calculation functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If controllers manage complete networking information, then network control capability is improved, but information leakage risk increases when controllers are compromised

Engineering Contradiction:
Improvenetwork control capabilityVSAvoidinformation leakage risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent divides network information management responsibilities by segmenting information types: controllers manage topology information for control functions, while boundary nodes manage status information. This segmentation maintains network control capability while reducing the attack surface for information leakage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by giving different controllers access to different types of information based on their specific functions. Controllers have access to topology information needed for path calculation, but not to complete status information, creating localized information access rights that balance control capability with security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3637700B1SDN network system, controller, and controlling method
Publication Date: 2024.05.29 HUAWEI TECH CO LTD
  • EP3637700B1 patent drawingFigure 1~2
  • EP3637700B1 patent drawingFigure 3
  • EP3637700B1 patent drawingFigure 4

AI summary

The present invention provides an SDN network system, controller, and controlling method. The SDN network system includes: at least one Nth level controller and at least two (N+1)th level controllers directly belonging to the Nth level controller, where N is an integer greater than or equal to 1, where the (N+1)th level controller is configured to receive a first message sent by a node belonging to the (N+1)th level controller, and when it is determined that the first message is a cross-domain message according to status information of each node that is managed by the (N+1)th level controller and that belongs to the (N+1)th level controller, forward the first message to the Nth level controller to which the (N+1)th level controller belongs; and the Nth level controller is configured to receive the first message forwarded by the (N+1)th level controller belonging to the Nth level controller, and perform decision processing according to status information of the (N+1)th level controller that is managed by the Nth level controller and that belongs to the Nth level controller and status information of boundary nodes of the (N+1)th level controller belonging to the Nth level controller. A controller manages network information in a hierarchical manner, so that when any controller is attacked, networking information cannot be leaked, thereby improving security of the network information.