SDN Controller End-to-End MAC Security Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional MAC security communication methods are inefficient as they require frequent encryption and decryption of data packets across multiple switches, leading to resource wastage, especially when applied to larger networks, and struggle to enable secure communication between hosts on different networks.

Innovation Solution

An end-to-end security communication method using Software Defined-Networking (SDN) where a communication controller generates and shares a security key between hosts, setting forwarding rules to enable direct packet transmission between switches connected to these hosts, thereby reducing unnecessary encryption and decryption processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional MAC security communication method is used across multiple switches, then security communication can be established between hosts on the same network, but encryption and decryption must be performed at each switch leading to huge resource waste in larger networks

Engineering Contradiction:
Improvesecurity communicationVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a controller as an intermediary that manages security key distribution across the network. The controller generates and distributes security keys to switches and hosts, enabling end-to-end security communication without requiring each switch to perform encryption/decryption operations. This mediator approach resolves the contradiction by maintaining security reliability while eliminating the resource waste associated with repeated encryption/decryption at each network node.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the encryption/decryption operations from the switches and consolidates them only at the end hosts. By removing the unnecessary intermediate encryption/decryption steps from the network switches, the system maintains security communication between hosts on different networks while eliminating the huge resource waste that would occur if each switch performed these operations.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional MAC security communication method is used, then security can be provided on the same LAN, but MAC security communication cannot be applied to communication between hosts on different networks

Engineering Contradiction:
Improvesecurity communicationVSAvoidnetwork coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the security communication system universal by enabling it to operate across multiple networks and different host pairs. The controller generates and manages security keys for any host pair in the network, allowing MAC security communication to function not only on the same LAN but also between hosts on different networks. This multi-functional approach resolves the contradiction by maintaining security reliability while expanding network coverage adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The controller acts as a central intermediary that enables security communication between hosts on different networks. It manages the distribution of security keys across network boundaries, allowing hosts that would otherwise be unable to establish secure communication to do so through the controller's key management infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security key is generated separately for each switch pair, then security communication can be maintained at each hop, but the number of encryption and decryption operations increases significantly with network size

Engineering Contradiction:
Improvesecurity communicationVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the encryption/decryption operations from intermediate switches and performs them only at the end hosts. This extraction eliminates the multiplicative increase in encryption/decryption operations that would occur with larger networks, while maintaining security communication through end-to-end encryption managed by the controller.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of encrypting/decrypting at each intermediate hop (the conventional approach), the patent inverts the approach by performing encryption only at the source host and decryption only at the destination host. This inversion dramatically reduces the number of cryptographic operations while maintaining security, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11075907B2End-to-end security communication method based on mac protocol using software defined-networking, and communication controller and computer program for the same
Publication Date: 2021.07.27 KOREA UNIV RES & BUSINESS FOUND
  • US11075907B2 patent drawing
  • US11075907B2 patent drawing
  • US11075907B2 patent drawing

AI summary

An end-to-end security communication method includes, when receiving a security key generation request packet from a first host, generating, by a communication controller, a security key for end-to-end security communication between the first host and a second host, transmitting the generated security key to each of the first host and the second host, and setting a forwarding rule for transmission of a packet destined for a Media Access Control (MAC) address of the first host or a MAC address of the second host to a first switch and a second switch connected respectively to the first host and the second host. According to the end-to-end security communication method, the communication controller performs the process of generating a security key that will be shared between hosts using Software Defined-Networking (SDN), so that MAC security communication technology can be applied to communication between hosts belonging to different networks.