SDN Controller Automates Network Rule Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems lack an efficient and automated method for generating and configuring rules across different network devices to restrict access to specific sites and content, requiring manual intervention and lacking scalability and dynamic provisioning.

Innovation Solution

A software-defined networking (SDN) controller automates the identification, generation, and configuration of rules across various network devices, such as routers and firewalls, to enforce data access controls for different sets of users without manual user intervention, dynamically scaling and provisioning based on demand.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual configuration of access control rules is used on network devices, then ease of operation is reduced requiring user intervention, but device complexity and scalability are limited

Engineering Contradiction:
Improveautomation of rule generation and configurationVSAvoidcomplexity of network management system
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

An SDN controller is introduced as an intermediary between the network administrator and the network devices. The controller receives access control requests, automatically generates appropriate rules, and configures them on the relevant network devices. This mediator handles the complexity of rule generation and device configuration, automating the process while managing system complexity centrally rather than at each device level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual rule configuration is performed for each network device, then productivity is reduced due to time-consuming manual intervention, but manufacturing precision of rule configuration may be maintained

Engineering Contradiction:
Improvespeed of rule deployment across network devicesVSAvoidtime for manual user intervention
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The SDN controller performs preliminary actions by automatically generating the appropriate access control rules before configuring them on network devices. When an administrator submits an access control request, the controller pre-processes the information, determines the necessary rules, and prepares the configuration commands in advance, eliminating the need for manual rule creation and significantly reducing deployment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service automation where the SDN controller autonomously generates and configures rules without requiring manual user intervention. The controller automatically interprets access control requests, formulates appropriate rules, and pushes them to the relevant network devices, allowing the system to service itself rather than relying on continuous manual operation.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If dynamic provisioning and scaling is implemented, then adaptability of the network system is improved, but device complexity increases

Engineering Contradiction:
Improvedynamic provisioning and scaling capabilityVSAvoidcomplexity of SDN controller
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The SDN controller implements dynamic provisioning and scaling by automatically adjusting network configurations in response to changing demands. When new access control requirements arise or network conditions change, the controller dynamically generates and deploys appropriate rules without requiring manual reconfiguration. This dynamic capability allows the system to adapt to varying network conditions and requirements while maintaining centralized control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11985127B2Systems and methods for automated network-based rule generation and configuration of different network devices
Publication Date: 2024.05.14 VERIZON PATENT & LICENSING INC
  • US11985127B2 patent drawing
  • US11985127B2 patent drawing
  • US11985127B2 patent drawing

AI summary

Provided is a controller for configuring network devices at different network locations with rules that prevent different sets of clients from accessing specific network resources. The controller may receive a request with an identifier of a first resource from a particular network point of access. The controller may identify one or more network devices (e.g., wireless access point, router, switch, firewall, gateway, etc.) that are in the network path between the particular network point of access and the first resource. The controller may select a particular network device in the network path, may establish a connection to the particular network device, and may configure the particular network device with a rule that prevents access to the first resource from the particular network point of access, while permitting access to other resources from the particular network point of access.