Sharded SDN Control Plane for Scalable Secure Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As software defined networks (SDNs) scale, managing them with a single controller becomes burdensome and slow, necessitating a more efficient method to handle increased network complexity.
Innovation Solution
Implementing a sharded control plane architecture where SDN controllers are divided by dimensions such as function or virtual network, allowing each controller to manage partial network information and scale functionalities independently, with authentication and authorization protocols to enable cross-network communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a single controller manages the SDN, then centralized control is maintained, but management becomes slow and burdensome as network size increases
Solution Approach 1:
The patent divides the single SDN controller into multiple sharded controllers, each responsible for specific dimensions (virtual networks, functions, or host devices). This segmentation distributes the management workload, improving network management speed while reducing individual controller complexity.
2Adaptability or versatility
If controllers are sharded by dimensions, then scaling and updates become easier, but cross-network communication requires additional authentication protocols
Solution Approach 1:
The patent creates a universal authorization protocol that works across all sharded controllers regardless of their specific dimension assignments. This multi-functional protocol handles authentication and authorization for cross-network communication uniformly, enabling easy scaling while managing complexity through standardization.
Solution Approach 2:
The authorization protocol acts as an intermediary layer between sharded controllers, mediating cross-network communication requests. This mediator verifies permissions and coordinates between different controller shards, enabling versatile scaling while containing complexity within the authorization layer.
3Ease of operation
If a single controller manages all network devices, then centralized authorization is simple, but management becomes burdensome with increased network size
Solution Approach 1:
The patent segments the centralized controller into multiple sharded controllers that can independently manage their assigned dimensions. This segmentation makes network management easier by distributing responsibilities, reducing the time required to manage large networks while maintaining centralized authorization through inter-controller communication.
Data Source
AI summary
Aspects of the disclosure are directed to a software defined network (SDN) having a sharded control plane. The SDN may include a host device and a sharded control plane. The sharded control plane may include a first controller and a second controller sharded by one or more dimensions. The first controller and the second controller may be configured to process requests received from the first host device based on their respective sharded one or more dimensions. The one or more dimensions may be networks or functions.


