SDN Middlebox for Residential Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security solutions are complex and costly, making them unsuitable for residential networks, which lack the expertise and budget to implement effective security measures, leading to weak security and liability risks from unauthorized access.

Innovation Solution

A service provider network system using software defined networking and network function virtualization establishes a secure communication channel via a cloud-based proxy device or middlebox, outsourcing network management and securing traffic exchanges for residential networks, thereby minimizing attack risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security solutions (hardware firewalls, proxy servers, intrusion detection systems) are implemented, then network security is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security service as an intermediary between the residential network and external threats. This cloud service performs security functions (firewall, intrusion detection, threat intelligence) remotely, eliminating the need for complex local security infrastructure while maintaining protection. The security provider acts as a mediator that handles security management centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security devices (hardware firewalls, on-premise proxy servers) with software-based security services delivered through cloud infrastructure. This substitution transitions from mechanical/physical security systems to virtualized security functions, reducing local device complexity while maintaining security capabilities through network-delivered security policies and threat intelligence.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional network security solutions are implemented, then network security is improved, but implementation cost increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidbudget requirement
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The cloud-based security service provides multiple security functions (firewall, intrusion detection, antivirus, threat intelligence) through a single unified service platform. This multi-functional approach allows residential networks to access enterprise-grade security capabilities without purchasing multiple separate security devices, thereby reducing overall cost while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables residential networks to access security capabilities traditionally available only to large enterprises by copying and delivering these security functions through cloud infrastructure. Security policies, threat intelligence databases, and detection algorithms are replicated and delivered to multiple customers, allowing small networks to benefit from enterprise-level security at a fraction of the cost.

Inventive Principle:
Principle #26Copying

3Reliability

If residential networks implement security measures independently, then security control is improved, but ease of operation deteriorates due to lack of expertise

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud-based security service operates autonomously, automatically detecting threats, updating security policies, and blocking attacks without requiring user intervention. The system performs self-diagnosis, self-protection, and self-updating functions, eliminating the need for residents to have security expertise while maintaining effective security control through automated response mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security system continuously monitors network traffic, analyzes threat patterns, and automatically adjusts security policies based on real-time feedback from cloud-based threat intelligence. This closed-loop feedback mechanism enables the system to adapt to emerging threats automatically, maintaining security control without requiring user expertise in security analysis or policy configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10348687B2Method and apparatus for using software defined networking and network function virtualization to secure residential networks
Publication Date: 2019.07.09 WORCESTER POLYTECHNIC INSTITUTE
  • US10348687B2 patent drawing
  • US10348687B2 patent drawing
  • US10348687B2 patent drawing

AI summary

A service provider device includes a controller having a memory and a processor. The controller is configured to receive a device access request from the client device via a residential network, the server provider device being located external to the residential network and detect a communication type identifier associated with the device access request. The controller is configured to establish a secure communication channel between the client device and a middlebox associated with the detected communication type identifier and provide communication between the client device and the server device via the secure communication channel between the client device.