Selective Encryption in Software Defined Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electric power transmission and distribution systems, existing communication networks face challenges in managing data flows and ensuring security, particularly in software-defined networks (SDNs), where traditional network management complexity and security concerns intersect with performance requirements, leading to latency issues and vulnerability to cyberattacks.

Innovation Solution

The implementation of selective encryption at the data link or network layer within the SDN's data plane, using hardware-based encryption techniques to minimize latency and allow operators to control which data flows are encrypted, ensuring transparency to other devices and enabling fail-over without disrupting packet transport.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network management is used in SDNs, then network control is centralized and manageable, but security vulnerabilities increase and latency increases

Engineering Contradiction:
Improvenetwork securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring encryption rules and security policies in the SDN controller before data flows are established. The controller proactively identifies critical data flows that require encryption and pre-establishes security parameters, so that when data packets are transmitted, encryption is already in place without adding real-time processing latency. This resolves the contradiction by preparing security measures in advance rather than applying them during data transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption module in the data plane that acts as a mediator between the SDN controller and data flows. This module receives encryption instructions from the controller and handles the actual encryption/decryption operations locally, eliminating the need for centralized processing of every data packet through the controller. This intermediary approach maintains centralized management while reducing latency by distributing encryption functions to edge devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full encryption is applied to all data flows, then security is maximized, but network performance deteriorates and latency increases

Engineering Contradiction:
Improvedata securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing selective encryption where only specific data flows requiring security protection are encrypted, while other data flows remain unencrypted. The SDN controller analyzes data flow characteristics and applies encryption rules locally to critical flows (such as control signals or sensitive data) without affecting the performance of non-critical flows. This resolves the contradiction by making encryption quality local rather than universal, maintaining network performance while providing security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying encryption to only the necessary portion of data flows rather than all traffic. The system identifies and encrypts only the minimum required data flows that need security protection, leaving the majority of data flows unencrypted to maintain optimal network performance. This partial application of encryption resolves the contradiction between security and performance by avoiding excessive encryption that would degrade network productivity.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If selective encryption is implemented, then security is enhanced for critical flows, but device complexity increases

Engineering Contradiction:
Improveselective securityVSAvoidencryption management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the SDN controller to perform multiple functions: flow identification, security policy management, encryption rule configuration, and monitoring all in one centralized platform. The controller serves as a multi-functional device that handles both network management and security encryption tasks, eliminating the need for separate dedicated security management systems. This resolves the contradiction by consolidating functions rather than adding complexity through multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the SDN controller continuously monitors data flow characteristics, encryption effectiveness, and network performance. Based on this feedback, the controller dynamically adjusts encryption rules and identifies new flows that may require security protection. This automated feedback loop reduces the complexity of manual encryption management by enabling the system to self-adjust and optimize security configurations without requiring complex manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10721218B2Communication device for implementing selective encryption in a software defined network
Publication Date: 2020.07.21 SCHWEITZER ENGINEERING LABORATORIES INC
  • US10721218B2 patent drawing
  • US10721218B2 patent drawing
  • US10721218B2 patent drawing

AI summary

The present disclosure pertains to systems and methods for selectively encrypting data flows within a software defined network (SDN). In one embodiment, a communication device may be configured to receive a plurality of unencrypted data packets. The communication device may receive from an SDN controller a criterion used to identify at least one of the unencrypted data flows to be encrypted. Based on the criterion, an encryption subsystem may generate an encrypted data flow the unencrypted data packets based on an encryption key. In some embodiments, the encryption system may parse the packets and encrypt the data payloads without encrypting the routing information associated with the packet. In other embodiments, the encryption subsystem may be configured to encapsulate and encrypt the entire unencrypted data packet. In some embodiments, the encryption subsystem may further be configured to authenticate a sending device and/or to verify the integrity of a message.