SDN Controller Automates Communication Flow Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and configuring traditional operational technology (OT) networks is complex due to distributed control and data forwarding logic in network devices, leading to challenges in optimizing network resources and ensuring secure, efficient communication flows.

Innovation Solution

Implementing a software-defined network (SDN) architecture with a centralized controller that automates the configuration of communication flows based on approved services and parameters, using attributes like TCP ports, IP addresses, and physical locations to create and manage data flows, while tracking metrics for issue identification and prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If distributed control logic is used in traditional OT networks, then network devices can independently make forwarding decisions, but network management complexity increases and security control becomes difficult

Engineering Contradiction:
Improvenetwork managementVSAvoiddistributed control structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the control plane functionality from individual network devices and consolidates it into a centralized SDN controller. This separation allows network devices to focus solely on data forwarding while the centralized controller handles complex control decisions, security policies, and flow management, thereby reducing overall network management complexity while maintaining operational independence at the device level

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network control architecture into distinct control plane and data plane components. The control plane is further segmented into centralized controller functions that manage flow rules, security policies, and network-wide coordination, while the data plane operates independently at network devices. This segmentation resolves the contradiction by organizing complexity into manageable, separated functional domains

Inventive Principle:
Principle #1Segmentation

2Productivity

If manual configuration of communication flows is performed, then security control is possible, but configuration time and effort increase significantly

Engineering Contradiction:
Improveconfiguration speedVSAvoidconfiguration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining service templates, security policies, and flow rule patterns in the centralized controller. When new communication flows are needed, the controller automatically matches them against predefined templates and generates appropriate configuration rules, eliminating the need for manual, time-consuming configuration while maintaining security control through established policies

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service through automated flow discovery and configuration mechanisms. The centralized controller automatically discovers new communication flows, analyzes them against security policies, and configures appropriate flow rules without human intervention. This automation dramatically reduces configuration time while maintaining security through policy-based control

Inventive Principle:
Principle #25Self-service

3Extent of automation

If centralized SDN controller is implemented, then automated flow management is achieved, but system architecture complexity increases

Engineering Contradiction:
Improveautomated configurationVSAvoidcentralized controller architecture
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the centralized SDN controller to perform multiple functions: flow discovery, security policy enforcement, configuration management, and network-wide coordination. By consolidating these diverse functions into a single multi-functional platform, the system achieves high automation without proportionally increasing architectural complexity, as the controller serves as a universal management point for all network operations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11418432B1Automated communication flow discovery and configuration in a software defined network
Publication Date: 2022.08.16 SCHWEITZER ENGINEERING LABORATORIES INC
  • US11418432B1 patent drawing
  • US11418432B1 patent drawing
  • US11418432B1 patent drawing

AI summary

The present disclosure pertains to systems and methods for automating the configuration of a software defined network (“SDN”). In one embodiment, a system may include a first communication host and a second communication host configured to transmit information to the first communication host. A network may provide communication between the first communication host and the second communication host using a plurality of network devices. An SDN controller in communication with the network may include an approved service subsystem to match the communication with an approved service. The SDN controller may also include an analysis subsystem configured to identify a communication flow corresponding to information transmitted by the second communication host to the first communication host. A traffic routing subsystem of the SDN controller may create the communication flow identified by the analysis subsystem between the second communication host and the first communication host.