SDN Multi-Site Controller for Secure Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key distribution and management mechanisms, such as the IEEE's Media Access Control Security (MACsec) standard, are not well suited for providing secure key distribution and management for multi-site data centers that use Layer 3 networks for communication between sites.

Innovation Solution

A Software-Defined Networking (SDN)-based upstream approach that uses an SDN Multi-Site Controller (MSC) to manage the distribution of keys between sites, allowing for secure key distribution and management across Layer 3 networks, and supporting re-keying with error handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control plane-based key distribution mechanisms (such as IEEE MACsec) are used, then key management is standardized and reliable for Layer 2 networks, but they are not suitable for Layer 3 network environments in multi-site data centers

Engineering Contradiction:
Improveadaptability to Layer 3 network environmentVSAvoidcomplexity of key distribution mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an SDN controller as an intermediary component that mediates key distribution between sites in a multi-site data center. The SDN controller receives key material from a key management server and distributes it to network devices, bridging the gap between standardized key management and Layer 3 network requirements. This intermediary approach allows the system to maintain standardized key management practices while adapting to the specific needs of Layer 3 networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If downstream key distribution approaches are used, then key management can be implemented in multi-site data centers, but they require more computational and storage resources

Engineering Contradiction:
Improveresource efficiencyVSAvoidimplementation simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent inverts the traditional downstream key distribution approach by implementing upstream key distribution. Instead of each site generating and distributing keys downstream to other sites, the SDN controller centrally manages and distributes keys upstream to all sites. This inversion reduces the computational and storage resources required at each individual site while maintaining comprehensive key management capabilities across the multi-site data center.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If existing key management mechanisms are used, then basic security is provided, but they lack better packet-level traceability and troubleshooting capabilities

Engineering Contradiction:
Improvedata securityVSAvoidpacket-level traceability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms that enable the SDN controller to monitor and track key distribution and usage across the multi-site data center. The controller receives status information from network devices and uses this feedback to maintain accurate records of key usage at the packet level. This feedback loop provides both enhanced security through centralized control and improved traceability for troubleshooting, as the SDN controller can detect and respond to security events in real-time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250193165A1Upstream approach for secure cryptography key distribution and management for multi-site data centers
Publication Date: 2025.06.12 CISCO TECHNOLOGY INC
  • US20250193165A1 patent drawing
  • US20250193165A1 patent drawing
  • US20250193165A1 patent drawing

AI summary

A Software-Defined Networking (SDN)-based “upstream” approach is a controller-based solution that provides secure key distribution and management for multi-site data centers. The approach uses an SDN Multi-Site Controller (MSC) that acts as an intermediary between SDN controllers at sites in a multi-site data center and manages the distribution of keys to sites. The approach is not dependent upon any particular routing protocol, such as the Border Gateway Protocol (BGP), and is well suited for multicast stream encryption by allowing the same key to be used for all replicated packets sent to downstream sites from an upstream source site. The approach distributes keys in a secure manner, ensures that data transferred between sites is done in a secure manner, and supports re-keying with error handling.