Virtual Partition Isolation for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transfer technologies lack secure and reliable methods for guaranteed bandwidth and latency in virtual networks, especially for sensitive information, and are vulnerable to attacks and resource overflows.

Innovation Solution

A system and method utilizing virtual partitions with switch/router devices configured to provide secure, deterministic connections using OpenFlow SDN protocol, ensuring secure prioritization, routing, and bandwidth control, with separate buffers and VLANs to isolate and protect virtual partition traffic from other traffic, preventing resource overflows and maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If shared network infrastructure is used to provide multiple wireless service providers access, then network resource utilization is improved, but security and reliability of data transfer deteriorates

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity and reliability of data transfer
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared network infrastructure into isolated virtual networks using VLANs and virtual partitions. Each service provider gets a dedicated virtual network segment that is logically separated from others, ensuring that while physical resources are shared, security and reliability are maintained through virtual isolation boundaries that prevent cross-contamination of traffic and attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary control mechanisms including OpenFlow SDN controllers and policy enforcement points that mediate between the shared physical infrastructure and multiple service providers. These intermediaries enforce security policies, control traffic flow, and manage resource allocation, thereby maintaining security and reliability while enabling shared resource utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If bandwidth and latency guarantees are provided for secure connections, then service reliability is improved, but network complexity and resource management difficulty worsens

Engineering Contradiction:
Improveservice reliability with guaranteed bandwidth and latencyVSAvoidnetwork complexity and resource management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal resource management mechanisms through OpenFlow SDN controllers that can serve multiple service providers simultaneously with a single centralized control system. The same control infrastructure provides bandwidth guarantees, latency control, and security policies across all virtual networks, reducing overall complexity compared to managing separate systems for each provider while maintaining service reliability guarantees.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes network parameters dynamically through SDN control, allowing bandwidth allocations, latency constraints, and routing policies to be adjusted programmatically without manual reconfiguration. This enables reliable service guarantees to be implemented through software-controlled parameter changes rather than complex hardware configurations, simplifying resource management while maintaining service quality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If virtual partitions with separate buffers and VLANs are implemented, then security and isolation are improved, but device complexity and configuration difficulty worsens

Engineering Contradiction:
Improvesecurity and isolation of virtual partition trafficVSAvoiddevice complexity and configuration difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the OpenFlow SDN controllers automatically configure VLANs, virtual partitions, and buffer allocations based on service provider requirements. The system performs self-provisioning and auto-configuration, reducing manual configuration complexity while maintaining strong security isolation. The controllers automatically generate the necessary network policies and enforce them across the infrastructure without requiring manual intervention for each virtual network setup.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2951973B1Data transfer
Publication Date: 2020.05.27 BAE SYSTEMS PLC
  • EP2951973B1 patent drawingFigure 1

AI summary

A data transfer system includes a set of switch and/or router devices (104B, 104E, 104F), each said device in the set being a layer 1, 2 and/or 3 device of OSI seven-layer model and being configured, in use, to transfer data, directly or indirectly, between a plurality of computing devices (102A, 102B). Each said switch or router device in the set is configured to provide a virtual partition (VP), wherein only data designated as virtual partition data is transferrable to another said device in the set via the virtual partition.