SDN Controller Profile Switching for Secure Telnet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-defined network (SDN) technologies require cumbersome and error-prone processes to temporarily enable Telnet communications for authorized operators, disrupting network security and usability.

Innovation Solution

A networking device with a profile selection input that allows switching between predefined network operation profiles, enabling or disabling Telnet communications without disrupting other network traffic, using a secondary communication channel such as a contact input, allowing for seamless transitions between secure and accessible modes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Telnet communications are enabled for authorized operators, then usability is improved, but network security is compromised

Engineering Contradiction:
ImproveusabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The networking device dynamically switches between a secure network operation profile and an accessible network operation profile based on received commands. The secure profile disables Telnet communications to maintain security, while the accessible profile enables Telnet for authorized operators. This dynamic switching allows the system to adapt its security posture based on operational requirements rather than being static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of the networking device by switching between different network operation profiles. Each profile contains specific configuration parameters that control Telnet accessibility and other network settings. By changing which profile is active, the system can enable or disable Telnet communications as needed without permanently altering the device configuration.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If Telnet communications are disabled for security, then network security is improved, but usability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidusability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system transitions from a static security configuration to a dynamic one where the networking device can switch between secure and accessible modes. The secure network operation profile maintains strong security by disabling Telnet, while the accessible profile temporarily enables it for authorized operators. This dynamic capability ensures both security and usability are maintained at appropriate times.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses parameter changes through profile switching to resolve the contradiction. The secure network operation profile has parameters that disable Telnet for security, while the accessible profile has parameters that enable Telnet. By changing which profile is active based on received commands, the system can temporarily adjust parameters to improve usability without permanently compromising security.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If manual configuration changes are made to enable Telnet, then usability is improved, but error-proneness increases

Engineering Contradiction:
ImproveusabilityVSAvoiderror-proneness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system provides self-service by automatically switching between network operation profiles in response to received commands. Instead of requiring manual configuration changes by operators, the networking device autonomously transitions between secure and accessible profiles based on simple command inputs. This eliminates the need for operators to manually configure complex network settings, thereby reducing human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The network operation profiles act as intermediaries that encapsulate complex configuration settings. Rather than requiring operators to manually adjust multiple individual parameters, the system uses pre-defined profiles as intermediaries that contain complete configuration sets. Switching between these profile intermediaries enables Telnet access without requiring operators to understand or manually configure the underlying complex network parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple network operation profiles are maintained, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the network configuration into distinct, manageable network operation profiles. Each profile represents a self-contained configuration set for specific operational scenarios (e.g., secure mode, accessible mode). This segmentation allows the device to maintain multiple configurations without creating a monolithic complex system, as each profile can be independently managed and switched between.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10581684B2Network management via a secondary communication channel in a software defined network
Publication Date: 2020.03.03 SCHWEITZER ENGINEERING LABORATORIES INC
  • US10581684B2 patent drawing
  • US10581684B2 patent drawing
  • US10581684B2 patent drawing

AI summary

A software-defined network controller (SDN controller) defines a first network flow to be selectively implemented by a networking device according to a first network operation profile. The SDN controller defines a second network flow to be selectively implemented by the networking device according to a second network operation profile. The first and second network operation profiles are stored within a memory of the networking device to be selectively implemented based on the status of a profile selection input on the networking device. The profile selection input is a contact input in some embodiments. When the contact input is de-asserted, the networking device implements the first network flow according to the first network operation profile. When the contact input is asserted, the networking device implements the second network flow according to the second network operation profile.