SDN Application Policy Validation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Software Defined Networking (SDN) environments, there is a lack of mechanisms for SDN applications to define and implement traffic handling techniques and security policies across the network, leading to potential errors and vulnerabilities, with existing policies being either locally generated or centrally managed, limiting situational awareness and flexibility.

Innovation Solution

SDN applications can generate control policies for network traffic events, convert them into tables for use by SDN controllers, and enforce security rules through network elements, enabling decentralized policy management and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SDN applications generate and enforce their own control policies, then traffic handling flexibility and situational awareness improve, but security risks increase due to potential unauthorized or malicious policies

Engineering Contradiction:
Improvetraffic handling flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a policy validation module as an intermediary between the SDN application's policy generation and the SDN controller's policy enforcement. This validator acts as a security gatekeeper that verifies policies against security criteria before they are deployed to network elements, allowing flexible application-generated policies while maintaining network security through centralized validation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the SDN controller monitors policy enforcement outcomes and provides information back to the SDN application. This allows the application to adjust its traffic handling policies based on actual network conditions and security events, improving both flexibility and security through continuous learning and adaptation

Inventive Principle:
Principle #23Feedback

2Productivity

If SDN applications directly enforce policies without conversion to controller format, then policy implementation speed improves, but system compatibility and control precision deteriorate

Engineering Contradiction:
Improvepolicy implementation speedVSAvoidpolicy control precision
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The patent implements a policy conversion module that transforms SDN application policies into SDN controller format in advance, before enforcement. This preliminary conversion ensures policies are in the correct format for precise controller execution while maintaining a streamlined process that doesn't significantly delay implementation, balancing speed and precision

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized policy management is maintained, then network security and control precision improve, but situational awareness and adaptability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidsituational awareness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the policy management function into two parts: policy generation by SDN applications that have situational awareness, and policy validation/enforcement by the SDN controller that ensures security. This segmentation allows both application-level adaptability and controller-level security to coexist, with each component performing its specialized function

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11374978B2Methods and systems for establishment of security policy between SDN application and SDN controller
Publication Date: 2022.06.28 CACI LGS INNOVATIONS LLC
  • US11374978B2 patent drawing
  • US11374978B2 patent drawing
  • US11374978B2 patent drawing

AI summary

The present application is directed a computer-implemented methods and systems implementing control policies created or modified by Software Defined Network applications. The control policies can be provided to SDN controllers for implementation.