SDN Controller Secure Proof Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networks face inefficiencies in providing secure proofs of network properties, such as location and path guarantees, which are cumbersome and resource-intensive, often requiring manual interventions and multiple exchanges.

Innovation Solution

The method leverages SDN functionality to provide secure proofs of network properties by using existing functionalities, including OpenFlow and PKI, to establish trustworthy paths and secure certificates, minimizing overhead on SDN controllers, and enabling secure and accountable communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention and multiple mail exchanges are used to provide secure proofs of network properties, then security and trustworthiness are improved, but complexity and resource consumption increase

Engineering Contradiction:
Improvesecure proof of network propertyVSAvoidmanual intervention complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service provisioning of secure network proofs through SDN controllers that automatically generate, validate, and enforce network property guarantees without requiring manual administrative intervention. The controllers autonomously manage the provisioning process by receiving requests from endpoints, verifying network properties, and issuing cryptographic proofs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (administrative mail exchanges and manual configurations) with automated electronic systems based on SDN control planes, cryptographic protocols, and automated verification mechanisms. This substitution eliminates the need for human operators to manually exchange emails or configure network policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional manual methods are used for providing network property proofs, then security guarantees are achieved, but time consumption and inefficiency increase

Engineering Contradiction:
Improvenetwork property guaranteeVSAvoidtime for manual exchanges
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The SDN controllers pre-establish network property guarantees and cryptographic proofs before actual data transmission occurs. The system proactively provisions secure paths, validates network properties in advance, and issues proofs of location and path guarantees before endpoints initiate communications, eliminating the need for time-consuming manual exchanges during actual operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Endpoints automatically receive and utilize cryptographic proofs from SDN controllers without requiring manual administrative intervention. The automated system handles the entire process from request to proof delivery, significantly reducing the time required compared to traditional manual methods involving multiple email exchanges and administrative procedures.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If SDN functionality is used to provide secure proofs of network properties, then automation and efficiency are improved, but controller overhead increases

Engineering Contradiction:
Improveautomated secure proof provisioningVSAvoidcontroller overhead
Core Design Contradiction:
Extent of automationVSUse of energy by moving object

Solution Approach 1:

The system segments the automation of secure proof provisioning into distinct functional modules: endpoint request handling, network property verification, cryptographic proof generation, and proof delivery. Each SDN controller manages its own domain independently, and controllers can be distributed across multiple nodes, allowing the automation overhead to be distributed and managed in smaller, more efficient units rather than concentrated in a single controller.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3000207B1Method for operating a network and a network
Publication Date: 2020.02.12 NEC CORP
  • EP3000207B1 patent drawingFigure 1~3

AI summary

For allowing a very simple and resource saving provision of a secure proof of at least one network property a method for operating a network is claimed, wherein a SDN, Software-defined Networking, functionality between at least some of a plurality of elements of the network is realized by at least one controller and wherein a secure proof of at least one network property is provided. The method is characterized in that the secure proof of the at least one network property is provided by the SDN functionality. Further, an according network is claimed, preferably for carrying out the above mentioned method.