SDN Controller Selective Encryption for Virtualized Workloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized data centers, existing technologies face challenges in efficiently managing encryption policies across computing devices, leading to inefficient use of resources and potential security vulnerabilities, as not all devices are configured to provide the necessary level of encryption for specific application workloads.
Innovation Solution
A policy framework is implemented using a software-defined networking (SDN) controller and orchestration engine to configure networks and manage tunnels based on security policies, ensuring that virtualized application workloads requiring encrypted communications are deployed on devices capable of providing enhanced encryption, while others are not forced to handle encrypted traffic unnecessarily.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to all communications between all computing devices, then security is improved, but resource consumption and system complexity increase unnecessarily
Solution Approach 1:
The patent implements selective encryption by identifying specific computing devices that require enhanced security (those executing sensitive application workloads) and applying encryption only to communications involving these devices. The SDN controller marks certain devices as requiring encryption and configures tunnels accordingly, rather than forcing encryption on all devices and all communications.
Solution Approach 2:
The network is segmented into different communication channels: encrypted tunnels for sensitive communications and non-encrypted paths for regular traffic. The SDN controller creates separate tunnel configurations based on security requirements, allowing the system to optimize resource usage by encrypting only the necessary portion of network traffic.
2Reliability
If encryption is enforced on all computing devices, then security policy compliance is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The SDN controller acts as an intermediary that centralizes the complexity of encryption management. Instead of requiring each computing device to be individually configured for encryption, the SDN controller automatically identifies devices needing encryption, creates appropriate tunnel configurations, and manages the encryption overhead centrally. This shields individual devices from complexity while ensuring policy compliance.
Solution Approach 2:
The system implements automated security policy enforcement where the SDN controller automatically detects which computing devices require encryption based on the application workloads they execute, and automatically configures the appropriate tunnel settings. This self-service approach eliminates manual configuration requirements and reduces operational complexity.
3Reliability
If all computing devices are configured for enhanced encryption, then security capability is improved, but productivity and resource efficiency decrease
Solution Approach 1:
Enhanced encryption capabilities are deployed only at specific locations (computing devices executing sensitive workloads) rather than uniformly across all devices. The SDN controller identifies which devices need encryption capabilities and configures tunnels to route traffic through these devices, allowing the system to maintain high security where needed while preserving resource efficiency elsewhere.
Data Source
AI summary
Techniques are disclosed for implementing scalable policies across a plurality of categories that support application workloads. In one example, the policy is a security policy that indicates which types of virtualized application workloads are required to communicate with encryption and groups computing devices into zones that communicate via respective tunnels configured to carry encrypted communication. An orchestration engine selects a computing device based on the zones fined in the security policy to ensure that the virtualized application workloads requiring encrypted communication communicate via tunnels configured to carry encrypted communication.


