Secure Token Stateless SDN Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional zero touch provisioning (ZTP) methods for network devices fail in environments where core services like DHCP are not available, requiring manual configuration that is costly, time-consuming, and error-prone, and poses security risks due to persistent configuration.

Innovation Solution

Implementing secure tokens that store cryptographically secure certificates with initial configuration information, allowing network devices to securely communicate with controllers without relying on core services, using a process that includes creating an initial configuration, generating a secure certificate, and inserting it into a secure token reader for configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If traditional zero touch provisioning methods are used, then automated configuration is achieved, but the method fails in environments where core services like DHCP are not available

Engineering Contradiction:
Improveautomated configurationVSAvoidconfiguration success rate
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces secure tokens as an intermediary carrier that contains cryptographically signed configuration data. Instead of relying on core services like DHCP for automated configuration, the secure token serves as a self-contained mediator that delivers configuration information directly to network devices, enabling automated configuration to work in environments without core services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by pre-loading configuration data into secure tokens before deployment. The configuration information is prepared, cryptographically signed, and stored in secure tokens in advance, so that when network devices are deployed in environments without core services, they can immediately obtain pre-prepared configuration data without needing DHCP or other core services.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration is used to deploy network devices in environments without core services, then configuration can be achieved, but it is costly, time-consuming, and error-prone

Engineering Contradiction:
Improveconfiguration success rateVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling network devices to automatically extract and apply configuration data from secure tokens without human intervention. The devices autonomously read the configuration from the secure token, verify its cryptographic integrity, and configure themselves, eliminating the need for manual configuration while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure token acts as an intermediary that bridges the gap between configuration management and network device deployment. It carries pre-prepared configuration data that enables automated, reliable configuration without requiring manual intervention, thus improving both reliability and productivity simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If persistent configuration is used in network devices, then device functionality is maintained, but security risks increase due to potential compromise

Engineering Contradiction:
Improveconfiguration persistenceVSAvoidsecurity vulnerability
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent applies periodic action by implementing configuration rotation where secure tokens are periodically updated and exchanged. Instead of using persistent configuration indefinitely, the system periodically replaces configuration data through new secure tokens, limiting the exposure window if a configuration is compromised and reducing long-term security risks.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements discarding and recovering by securely discarding old configuration data after it has been used and replaced by new secure tokens. The system recovers functionality by continuously deploying new secure tokens with updated configuration, ensuring that compromised configurations are discarded and replaced, thereby reducing security vulnerabilities while maintaining configuration persistence.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11831775B1Using secure tokens for stateless software defined networking
Publication Date: 2023.11.28 RIVERBED TECH LLC
  • US11831775B1 patent drawing
  • US11831775B1 patent drawing
  • US11831775B1 patent drawing

AI summary

Systems and techniques are described to facilitate using secure tokens for stateless software defined networking. An initial configuration may be created for deploying a network device at a deployment site. A cryptographically secure certificate may be created that includes the initial configuration for deploying the network device at the deployment site. The cryptographically secure certificate may be stored in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the device at the deployment site. The network device may then be configured at the deployment site by using the secure token.