SDN Orchestration Validation Using Mutable Network Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Software Defined Networks (SDN), the lack of insight into the content of northbound and southbound application programming interfaces (APIs) poses a risk to network integrity due to potential manipulation by malicious actors, leading to security breaches and network failures.

Innovation Solution

Implement a mutable network element (MNE) that simulates network elements to verify the correct implementation of business policies and security configurations before allowing network elements to become operational, using off-line operational tests and policy-based verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS encryption is used to protect API content, then security is improved, but the ability to monitor and validate API content is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidAPI content monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by implementing validation of SDN orchestration requests before they are encrypted and transmitted through the API. The system validates the intent and configuration parameters of network element instantiation requests at the orchestrator level, before TLS encryption obscures the content. This allows security validation to occur while maintaining encryption protection during transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism that sits between the orchestrator and the encrypted API communication channel. This intermediary layer validates requests without requiring decryption of the API content, thus maintaining both security (encryption) and validation capability simultaneously. The intermediary checks configuration parameters against security policies before allowing encrypted transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual input or automatic configuration is used to command SDN controller, then network configuration flexibility is improved, but the risk of malicious manipulation is increased

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidmalicious manipulation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by creating a validation loop that checks SDN orchestration requests against security policies and business rules before configuration is applied. The system provides feedback on whether a request complies with security requirements, allowing legitimate flexible configurations to proceed while blocking malicious ones. This feedback mechanism maintains configuration flexibility while preventing harmful manipulations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by proactively validating and potentially blocking malicious configuration requests before they can manipulate the SDN controller. The system preemptively checks requests for signs of malicious manipulation, such as attempts to create security breaches or violate business policies, and prevents these actions before they affect the network. This allows legitimate flexible configurations while countering harmful ones in advance.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If SDN controller manipulates southbound APIs to misinterpret commands, then network security is compromised, but configuration speed may be improved

Engineering Contradiction:
Improveconfiguration speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by validating SDN orchestration requests at the orchestrator level before they reach the SDN controller, preventing malicious manipulation from occurring in the first place. This validation happens upstream, so even if the SDN controller is compromised, the malicious requests are blocked before reaching it, maintaining both security and configuration speed by avoiding rework from security failures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by creating a validation mechanism that monitors and verifies SDN orchestration requests against security policies. This feedback loop detects potential malicious manipulations before they execute, allowing legitimate fast configurations to proceed while blocking security threats. The feedback ensures that configuration speed does not come at the expense of network security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12375346B2System and method for SDN orchestration validation
Publication Date: 2025.07.29 AT&T INTELLECTUAL PROPERTY I L P
  • US12375346B2 patent drawing
  • US12375346B2 patent drawing
  • US12375346B2 patent drawing

AI summary

A system includes an orchestrator for a software-defined network and configured to receive a request for operation of the software-defined network, a software-defined network controller in communication with the orchestrator through a northbound application programming interface, at least one network element in communication with the software defined network controller though a southbound application programming interface, and a mutable network element configured to receive the request and instantiate a virtual function within the mutable network element to test the at least one network element in accordance with the request.