Secure Token Stateless SDN Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional zero touch provisioning (ZTP) methods for network devices fail in environments where core services like DHCP are not available, requiring manual configuration that is costly, time-consuming, and error-prone, and poses security risks due to persistent configuration.
Innovation Solution
Implementing secure tokens that store cryptographically secure certificates with initial configuration information, allowing network devices to securely communicate with controllers without relying on core services, using a process that includes creating an initial configuration, generating a secure certificate, and inserting it into a secure token reader for configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If traditional zero touch provisioning methods are used, then automated configuration is achieved, but the method fails in environments where core services like DHCP are not available
Solution Approach 1:
The patent introduces secure tokens as an intermediary carrier that contains cryptographically signed configuration data. Instead of relying on core services like DHCP for automated configuration, the secure token serves as a self-contained mediator that delivers configuration information directly to network devices, enabling automated configuration to work in environments without core services.
Solution Approach 2:
The patent applies preliminary action by pre-loading configuration data into secure tokens before deployment. The configuration information is prepared, cryptographically signed, and stored in secure tokens in advance, so that when network devices are deployed in environments without core services, they can immediately obtain pre-prepared configuration data without needing DHCP or other core services.
2Reliability
If manual configuration is used to deploy network devices in environments without core services, then configuration can be achieved, but it is costly, time-consuming, and error-prone
Solution Approach 1:
The patent implements self-service by enabling network devices to automatically extract and apply configuration data from secure tokens without human intervention. The devices autonomously read the configuration from the secure token, verify its cryptographic integrity, and configure themselves, eliminating the need for manual configuration while maintaining high reliability.
Solution Approach 2:
The secure token acts as an intermediary that bridges the gap between configuration management and network device deployment. It carries pre-prepared configuration data that enables automated, reliable configuration without requiring manual intervention, thus improving both reliability and productivity simultaneously.
3Stability of the object's composition
If persistent configuration is used in network devices, then device functionality is maintained, but security risks increase due to potential compromise
Solution Approach 1:
The patent applies periodic action by implementing configuration rotation where secure tokens are periodically updated and exchanged. Instead of using persistent configuration indefinitely, the system periodically replaces configuration data through new secure tokens, limiting the exposure window if a configuration is compromised and reducing long-term security risks.
Solution Approach 2:
The patent implements discarding and recovering by securely discarding old configuration data after it has been used and replaced by new secure tokens. The system recovers functionality by continuously deploying new secure tokens with updated configuration, ensuring that compromised configurations are discarded and replaced, thereby reducing security vulnerabilities while maintaining configuration persistence.
Data Source
AI summary
Systems and techniques are described to facilitate using secure tokens for stateless software defined networking. An initial configuration may be created for deploying a network device at a deployment site. A cryptographically secure certificate may be created that includes the initial configuration for deploying the network device at the deployment site. The cryptographically secure certificate may be stored in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the device at the deployment site. The network device may then be configured at the deployment site by using the secure token.


