Software-Defined Network Path Switching with Adaptive Security Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SDN environments experience network disruptions and delays due to the need to interrupt network traffic for security upgrades or path modifications, which is particularly pronounced in large and complex networks.

Innovation Solution

A method to pre-establish multiple paths and security profiles in an SDN, allowing seamless switching to a redundant path or security profile in response to trigger events such as security alerts or performance changes, minimizing traffic disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are upgraded or paths are modified in existing SDN environments, then network security is improved, but network traffic is interrupted causing delays and disruptions

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork traffic delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-establishes multiple candidate paths and security profiles before any security incidents occur. When a trigger event is detected, the system can immediately switch to a pre-configured alternative path without interrupting traffic flow, as the alternative paths are already initialized and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes operational parameters by switching between different pre-configured security profiles and path configurations based on detected trigger events. This allows the network to adapt its security level and routing parameters in response to security incidents while maintaining continuous operation.

Inventive Principle:
Principle #35Parameter changes

2Loss of time

If multiple paths are pre-established for rapid switching, then network disruption is reduced, but system complexity increases

Engineering Contradiction:
Improvepath switching timeVSAvoidSDN controller complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the path management functionality by separating the control plane (SDN controller) from the data plane (network devices). The controller handles the complexity of managing multiple candidate paths and security profiles, while network devices simply execute forwarding based on received instructions. This segmentation allows rapid switching without overwhelming individual components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SDN controller is designed to manage multiple candidate paths and security profiles universally, allowing it to handle various types of trigger events and switch between different pre-configured configurations. This multi-functionality enables the system to reduce switching time while keeping the added complexity centralized in the controller rather than distributed across all network devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4409836B1Methods and systems of operating software-defined networks
Publication Date: 2025.07.02 BRITISH TELECOM PLC
  • EP4409836B1 patent drawingFigure 1
  • EP4409836B1 patent drawingFigure 2
  • EP4409836B1 patent drawingFigure 3

AI summary

A computer-implemented method of operating a software-defined network, the method comprising: obtaining specifications of a plurality of data plane elements which together form a path through a data plane suitable for carrying traffic associated with a category of applications and/or services; determining, based on the specifications, which one or more of a plurality of security profiles the path is capable of complying with; selecting one of the one or more security profiles to be an initial security profile; routing traffic associated with the category of applications and/or services via the path in compliance with the initial security profile; subsequently obtaining an alert that network performance conditions have worsened; and responsive thereto: selecting a different one of the plurality of security profiles, that is less resource-intensive than the initial security profile, to be a replacement security profile; and routing traffic associated with the category of applications and/or services in compliance with the replacement security profile.