SDN Controller Selective Encryption for Virtualized Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized data centers, existing technologies face challenges in efficiently managing encryption policies across computing devices, leading to inefficient use of resources and potential security vulnerabilities, as not all devices are configured to provide the necessary level of encryption for specific application workloads.

Innovation Solution

A policy framework is implemented using a software-defined networking (SDN) controller and orchestration engine to configure networks and manage tunnels based on security policies, ensuring that virtualized application workloads requiring encrypted communications are deployed on devices capable of providing enhanced encryption, while others are not forced to handle encrypted traffic unnecessarily.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to all communications between all computing devices, then security is improved, but resource consumption and system complexity increase unnecessarily

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements selective encryption by identifying specific computing devices that require enhanced security (those executing sensitive application workloads) and applying encryption only to communications involving these devices. The SDN controller marks certain devices as requiring encryption and configures tunnels accordingly, rather than forcing encryption on all devices and all communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network is segmented into different communication channels: encrypted tunnels for sensitive communications and non-encrypted paths for regular traffic. The SDN controller creates separate tunnel configurations based on security requirements, allowing the system to optimize resource usage by encrypting only the necessary portion of network traffic.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is enforced on all computing devices, then security policy compliance is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SDN controller acts as an intermediary that centralizes the complexity of encryption management. Instead of requiring each computing device to be individually configured for encryption, the SDN controller automatically identifies devices needing encryption, creates appropriate tunnel configurations, and manages the encryption overhead centrally. This shields individual devices from complexity while ensuring policy compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated security policy enforcement where the SDN controller automatically detects which computing devices require encryption based on the application workloads they execute, and automatically configures the appropriate tunnel settings. This self-service approach eliminates manual configuration requirements and reduces operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If all computing devices are configured for enhanced encryption, then security capability is improved, but productivity and resource efficiency decrease

Engineering Contradiction:
Improveencryption capabilityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Enhanced encryption capabilities are deployed only at specific locations (computing devices executing sensitive workloads) rather than uniformly across all devices. The SDN controller identifies which devices need encryption capabilities and configures tunnels to route traffic through these devices, allowing the system to maintain high security where needed while preserving resource efficiency elsewhere.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10728288B2Policy-driven workload launching based on software defined networking encryption policies
Publication Date: 2020.07.28 JUNIPER NETWORKS INC
  • US10728288B2 patent drawing
  • US10728288B2 patent drawing
  • US10728288B2 patent drawing

AI summary

Techniques are disclosed for implementing scalable policies across a plurality of categories that support application workloads. In one example, the policy is a security policy that indicates which types of virtualized application workloads are required to communicate with encryption and groups computing devices into zones that communicate via respective tunnels configured to carry encrypted communication. An orchestration engine selects a computing device based on the zones fined in the security policy to ensure that the virtualized application workloads requiring encrypted communication communicate via tunnels configured to carry encrypted communication.