SDN Controller Automates Communication Flow Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and configuring traditional operational technology (OT) networks is complex due to distributed control and data forwarding logic in network devices, leading to challenges in optimizing network resources and ensuring secure, efficient communication flows.
Innovation Solution
Implementing a software-defined network (SDN) architecture with a centralized controller that automates the configuration of communication flows based on approved services and parameters, using attributes like TCP ports, IP addresses, and physical locations to create and manage data flows, while tracking metrics for issue identification and prioritization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If distributed control logic is used in traditional OT networks, then network devices can independently make forwarding decisions, but network management complexity increases and security control becomes difficult
Solution Approach 1:
The patent extracts the control plane functionality from individual network devices and consolidates it into a centralized SDN controller. This separation allows network devices to focus solely on data forwarding while the centralized controller handles complex control decisions, security policies, and flow management, thereby reducing overall network management complexity while maintaining operational independence at the device level
Solution Approach 2:
The patent segments the network control architecture into distinct control plane and data plane components. The control plane is further segmented into centralized controller functions that manage flow rules, security policies, and network-wide coordination, while the data plane operates independently at network devices. This segmentation resolves the contradiction by organizing complexity into manageable, separated functional domains
2Productivity
If manual configuration of communication flows is performed, then security control is possible, but configuration time and effort increase significantly
Solution Approach 1:
The patent implements preliminary action by pre-defining service templates, security policies, and flow rule patterns in the centralized controller. When new communication flows are needed, the controller automatically matches them against predefined templates and generates appropriate configuration rules, eliminating the need for manual, time-consuming configuration while maintaining security control through established policies
Solution Approach 2:
The patent enables self-service through automated flow discovery and configuration mechanisms. The centralized controller automatically discovers new communication flows, analyzes them against security policies, and configures appropriate flow rules without human intervention. This automation dramatically reduces configuration time while maintaining security through policy-based control
3Extent of automation
If centralized SDN controller is implemented, then automated flow management is achieved, but system architecture complexity increases
Solution Approach 1:
The patent applies universality by designing the centralized SDN controller to perform multiple functions: flow discovery, security policy enforcement, configuration management, and network-wide coordination. By consolidating these diverse functions into a single multi-functional platform, the system achieves high automation without proportionally increasing architectural complexity, as the controller serves as a universal management point for all network operations
Data Source
AI summary
The present disclosure pertains to systems and methods for automating the configuration of a software defined network (“SDN”). In one embodiment, a system may include a first communication host and a second communication host configured to transmit information to the first communication host. A network may provide communication between the first communication host and the second communication host using a plurality of network devices. An SDN controller in communication with the network may include an approved service subsystem to match the communication with an approved service. The SDN controller may also include an analysis subsystem configured to identify a communication flow corresponding to information transmitted by the second communication host to the first communication host. A traffic routing subsystem of the SDN controller may create the communication flow identified by the analysis subsystem between the second communication host and the first communication host.


