SDN Controller Automates Network Rule Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems lack an efficient and automated method for generating and configuring rules across different network devices to restrict access to specific sites and content, requiring manual intervention and lacking scalability and dynamic provisioning.
Innovation Solution
A software-defined networking (SDN) controller automates the identification, generation, and configuration of rules across various network devices, such as routers and firewalls, to enforce data access controls for different sets of users without manual user intervention, dynamically scaling and provisioning based on demand.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual configuration of access control rules is used on network devices, then ease of operation is reduced requiring user intervention, but device complexity and scalability are limited
Solution Approach 1:
An SDN controller is introduced as an intermediary between the network administrator and the network devices. The controller receives access control requests, automatically generates appropriate rules, and configures them on the relevant network devices. This mediator handles the complexity of rule generation and device configuration, automating the process while managing system complexity centrally rather than at each device level.
2Productivity
If manual rule configuration is performed for each network device, then productivity is reduced due to time-consuming manual intervention, but manufacturing precision of rule configuration may be maintained
Solution Approach 1:
The SDN controller performs preliminary actions by automatically generating the appropriate access control rules before configuring them on network devices. When an administrator submits an access control request, the controller pre-processes the information, determines the necessary rules, and prepares the configuration commands in advance, eliminating the need for manual rule creation and significantly reducing deployment time.
Solution Approach 2:
The system enables self-service automation where the SDN controller autonomously generates and configures rules without requiring manual user intervention. The controller automatically interprets access control requests, formulates appropriate rules, and pushes them to the relevant network devices, allowing the system to service itself rather than relying on continuous manual operation.
3Adaptability or versatility
If dynamic provisioning and scaling is implemented, then adaptability of the network system is improved, but device complexity increases
Solution Approach 1:
The SDN controller implements dynamic provisioning and scaling by automatically adjusting network configurations in response to changing demands. When new access control requirements arise or network conditions change, the controller dynamically generates and deploys appropriate rules without requiring manual reconfiguration. This dynamic capability allows the system to adapt to varying network conditions and requirements while maintaining centralized control.
Data Source
AI summary
Provided is a controller for configuring network devices at different network locations with rules that prevent different sets of clients from accessing specific network resources. The controller may receive a request with an identifier of a first resource from a particular network point of access. The controller may identify one or more network devices (e.g., wireless access point, router, switch, firewall, gateway, etc.) that are in the network path between the particular network point of access and the first resource. The controller may select a particular network device in the network path, may establish a connection to the particular network device, and may configure the particular network device with a rule that prevents access to the first resource from the particular network point of access, while permitting access to other resources from the particular network point of access.


