Sharded SDN Control Plane for Scalable Secure Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As software defined networks (SDNs) scale, managing them with a single controller becomes burdensome and slow, necessitating a more efficient method to handle increased network complexity.

Innovation Solution

Implementing a sharded control plane architecture where SDN controllers are divided by dimensions such as function or virtual network, allowing each controller to manage partial network information and scale functionalities independently, with authentication and authorization protocols to enable cross-network communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single controller manages the SDN, then centralized control is maintained, but management becomes slow and burdensome as network size increases

Engineering Contradiction:
Improvenetwork management speedVSAvoidcontroller complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides the single SDN controller into multiple sharded controllers, each responsible for specific dimensions (virtual networks, functions, or host devices). This segmentation distributes the management workload, improving network management speed while reducing individual controller complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If controllers are sharded by dimensions, then scaling and updates become easier, but cross-network communication requires additional authentication protocols

Engineering Contradiction:
Improvescaling capabilityVSAvoidauthorization protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authorization protocol that works across all sharded controllers regardless of their specific dimension assignments. This multi-functional protocol handles authentication and authorization for cross-network communication uniformly, enabling easy scaling while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authorization protocol acts as an intermediary layer between sharded controllers, mediating cross-network communication requests. This mediator verifies permissions and coordinates between different controller shards, enabling versatile scaling while containing complexity within the authorization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a single controller manages all network devices, then centralized authorization is simple, but management becomes burdensome with increased network size

Engineering Contradiction:
Improvenetwork management easeVSAvoidmanagement time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments the centralized controller into multiple sharded controllers that can independently manage their assigned dimensions. This segmentation makes network management easier by distributing responsibilities, reducing the time required to manage large networks while maintaining centralized authorization through inter-controller communication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12489667B2Sharded SDN control plane with authorization
Publication Date: 2025.12.02 GOOGLE LLC
  • US12489667B2 patent drawing
  • US12489667B2 patent drawing
  • US12489667B2 patent drawing

AI summary

Aspects of the disclosure are directed to a software defined network (SDN) having a sharded control plane. The SDN may include a host device and a sharded control plane. The sharded control plane may include a first controller and a second controller sharded by one or more dimensions. The first controller and the second controller may be configured to process requests received from the first host device based on their respective sharded one or more dimensions. The one or more dimensions may be networks or functions.