SDN Controller Security Zone Allocation for Data Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communications systems based on software-defined networking (SDN) face challenges in securely controlling and managing data exchange across different security zones, particularly in ensuring that data are forwarded only within designated security zones and preventing unauthorized data transmission across subnets.

Innovation Solution

The method involves allocating communications devices and data to specific security zones and specifying forwarding rules that are dynamically defined and distributed across network infrastructure components, ensuring that data are forwarded only within their allocated security zones, with a 'secure by default' approach where data are not forwarded unless explicitly permitted by a forwarding rule.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data are allowed to be forwarded across subnets without strict control, then network flexibility and data exchange capability are improved, but security compliance deteriorates as data may leave designated security zones

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsecurity compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network is segmented into multiple security zones with distinct security requirements. Each security zone is isolated from others, and data are allocated to specific security zones based on their security requirements. This segmentation ensures that data cannot leave their designated security zones unless explicitly permitted by forwarding rules, thereby maintaining security compliance while allowing flexible data exchange within zones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A logically centralized control instance (SDN controller) acts as an intermediary between communications devices and network infrastructure components. The controller centrally manages forwarding rules, allocates data to security zones, and distributes forwarding rules to network infrastructure components. This intermediary ensures secure data exchange by enforcing security policies while maintaining network flexibility through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict forwarding rules are enforced to prevent data from leaving security zones, then security compliance is improved, but network flexibility deteriorates

Engineering Contradiction:
Improvesecurity complianceVSAvoidnetwork flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The forwarding rules are dynamically managed by a centralized control instance that can adapt to changing network conditions and security requirements. The control instance receives allocation requests, determines appropriate security zones, and dynamically distributes forwarding rules to network infrastructure components. This dynamic approach maintains security compliance while allowing network flexibility through adaptive rule management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of forwarding rules based on security zone allocations and data characteristics. Forwarding rules are configured with specific parameters such as permitted destination security zones, data types, and communication patterns. By adjusting these parameters dynamically, the system enforces security compliance while maintaining necessary network flexibility for legitimate data exchange.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a centralized control instance manages all forwarding rules, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex security control logic is extracted from individual network infrastructure components and concentrated in a single logically centralized control instance. This extraction allows security policies to be managed centrally without burdening individual switches or routers with complex decision-making logic. The control instance handles security zone allocation, forwarding rule generation, and distribution, thereby improving security control while keeping individual network components relatively simple.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If forwarding rules are predefined and distributed to network components, then ease of operation is improved, but adaptability to changing security requirements deteriorates

Engineering Contradiction:
Improveforwarding rule managementVSAvoidadaptability to security changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The centralized control instance implements a feedback mechanism where it continuously monitors network conditions, security zone allocations, and data exchange patterns. Based on this feedback, the control instance dynamically adjusts forwarding rules and redistributes them to network infrastructure components. This feedback loop ensures ease of operation through automated rule management while maintaining high adaptability to changing security requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11496520B2Method for operating a communications system
Publication Date: 2022.11.08 ROBERT BOSCH GMBH
  • US11496520B2 patent drawing
  • US11496520B2 patent drawing

AI summary

A method for operating a communications system, in particular a communications system based on software-defined networking, which has at least one network infrastructure component, in particular an SDN switch, and at least one communications device, the network infrastructure component being developed for forwarding data to and/or from the at least one communications device. The method includes the following steps: allocating the communications device to at least one security zone; specifying at least one forwarding rule for forwarding data by the network infrastructure component to and/or from the communications device, the specification of the forwarding rule taking place under consideration of the security zone.