SDN Application VPN Security Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Software Defined Networking (SDN) environments, there is a lack of mechanisms for SDN applications to define and implement traffic handling techniques and security policies across the network, leading to potential errors and vulnerabilities, with existing policies being either locally generated or centrally managed, limiting situational awareness and flexibility.

Innovation Solution

The implementation of program instructions that detect a VPN provider, receive server credentials, generate security policies based on network traffic patterns, and convert these policies into tables interpretable by network nodes, allowing SDN applications to authenticate with SDN controllers and transmit these policies for enforcement across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SDN applications generate and enforce security policies autonomously, then security and traffic handling improve, but system complexity and authentication requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism between SDN applications and the SDN controller. The controller verifies application credentials and establishes trusted relationships before allowing policy generation, thus improving security without requiring complex cryptographic protocols throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

SDN applications autonomously generate security policies based on observed traffic patterns and network conditions. The applications self-configure flow rules and security parameters without manual intervention, improving reliability through consistent automated enforcement while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If SDN applications autonomously generate security policies, then flexibility and situational awareness improve, but security risks from unauthorized applications increase

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication of SDN applications before they can generate or enforce security policies. The SDN controller verifies application credentials and establishes authorization levels in advance, ensuring that only authenticated applications can modify network behavior, thus preventing unauthorized policy changes while maintaining flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SDN controller continuously monitors policy enforcement and application behavior, providing feedback to verify that generated policies comply with security requirements. This feedback mechanism allows the system to maintain flexibility in policy generation while detecting and preventing security risks through ongoing verification.

Inventive Principle:
Principle #23Feedback

3Reliability

If centralized policy management is used, then security control is maintained, but situational awareness and response time decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments policy management functions between the SDN controller and authenticated SDN applications. The controller retains centralized authentication and oversight capabilities, while authorized applications can independently generate and enforce policies locally, reducing response time for traffic handling while maintaining centralized security control through the authentication framework.

Inventive Principle:
Principle #1Segmentation

4Manufacturing precision

If manual policy development is performed, then security precision is maintained, but productivity and adaptability decrease

Engineering Contradiction:
Improvesecurity precisionVSAvoidpolicy deployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

SDN applications automatically generate security policies based on observed traffic patterns, network conditions, and security requirements. The applications self-analyze traffic flows and self-configure appropriate security rules without manual intervention, maintaining precision through systematic analysis while dramatically improving productivity through automated policy deployment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11683346B2Methods and systems for establishment of VPN security policy by SDN application
Publication Date: 2023.06.20 CACI LGS INNOVATIONS LLC
  • US11683346B2 patent drawing
  • US11683346B2 patent drawing
  • US11683346B2 patent drawing

AI summary

The present application is directed to a non-transitory computer readable medium. The medium includes program instructions that, upon being executed by a processor, effectuate detecting a virtual private network (VPN) provider in a network. The program instructions also effectuate receiving, from the VPN provider, server credentials for a VPN. The program instructions further effectuate generating a security policy based upon a type or pattern of network traffic associated with the VPN. The program instructions even further effectuate converting the security policy to a table interpretable by a node in the network.