IP Library Granted Patent US 10,374,870
Granted Patent B2
US 10,374,870 · App. 15/109,646 · Granted Aug 6, 2019

Efficient access control for trigger events in SDN

Inventors: Felix Klaedtke (Heidelberg, DE); Ghassan Karame (Heidelberg, DE); Roberto Bifulco (Heidelberg, DE)
Assignee: NEC CORPORATION
H04L41/06H04L47/2483H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,374,870
App. No.
15/109,646
Granted
Aug 6, 2019
Kind
B2
Abstract

A method of providing access control for a software defined network (SDN) controller includes triggering, by the SDN controller upon receiving a trigger event from a data plane of the software defined network, one or more applications that are installed to run at a control plane of the software defined network atop the SDN controller to react to the trigger event, applying, by the SDN controller before triggering applications due to a trigger event, a conflict resolution scheme. The conflict resolution scheme includes determining all flow spaces that are affected by the trigger event and selecting from these flow spaces a single selected flow space that complies with a predetermined policy, determining, a single master application according to predefined criteria, and triggering, in addition to the master application, only those applications whose reactions to the trigger event do not conflict with the master application.

Claims (30)

1. A method of providing access control for a software defined network (SDN) controller to control access to network resources, the method comprising:

triggering, by the SDN controller upon receiving a trigger event from a data plane of the software defined network, one or more applications that are installed to run at a control plane of the software defined network atop the SDN controller to react to the trigger event, and

applying, by the SDN controller before triggering applications due to a trigger event, a conflict resolution scheme configured to resolve conflicts among the applications, the conflict resolution scheme comprising:

determining all flow spaces that are affected by the trigger event and selecting from these flow spaces a single selected flow space having assigned a priority that complies with a predetermined policy,

determining, from the applications related to the selected flow space, a single master application according to predefined criteria, and

triggering, in addition to the master application, only those applications whose reactions to the trigger event do not conflict with the master application,

wherein the flow spaces are objects on the control plane.

2. The method according to claim 1 , wherein the flow spaces are hierarchically organized in a tree-based data structure.

3. The method according to claim 1 , wherein a flow space is defined as a tuple comprising a parameter that specifies a set of packet headers, a parameter that specifies a set of actions, and a parameter that specifies a set of attributes.

4. The method according to claim 1 , wherein according to a predetermined policy, priority is given to flow spaces that are more local with respect to the flow space hierarchy.

5. The method according to claim 1 , wherein according to a predetermined policy, priority is given to flow spaces that are more global with respect to the flow space hierarchy.

6. The method according to claim 1 , wherein an application with the highest priority is determined, from the applications related to the selected flow space, as the master application.

7. The method according to claim 1 , wherein, in addition to the master application, only those applications are triggered that are related to the selected flow space and whose reactions to the trigger event do not conflict with the master application.

8. The method according to claim 1 , wherein users are empowered to install and run their own applications at the control plane atop the controller.

9. The method according to claim 1 , wherein the installation of an application the specification of reactions of the application.

10. The method according to claim 1 , wherein applications that are in conflict with each other in terms of their reaction are pre-computed.

11. The method according to claim 1 , wherein the trigger event includes at least one packet-in event sent by a switch of the software defined network to the SDN controller when the switch receives a packet that does not match any of the entries in a flow table of the switch.

12. A software defined network (SDN) controller, the controller being configured to execute a method according to claim 1 .

13. A software defined network (SDN) with access control to control access to network resources, the SDN comprising:

a network device comprising a controller that is configured, upon receiving a trigger event from a data plane of the software defined network, to trigger one or more applications that are installed to run at a control plane of the software defined network atop the controller to react to the trigger event,

wherein the controller is further configured, before triggering applications due to the trigger event, to apply a conflict resolution scheme configured to resolve conflicts among the applications, the conflict resolution scheme comprising:

determining all flow spaces that are affected by the trigger event and selecting from these flow spaces a single selected flow space having assigned a priority that complies with a predetermined policy,

determining, from the applications related to the selected flow space, a single master application according to predefined criteria, and

triggering, in addition to the master application, only those applications whose reactions to the trigger event do not conflict with the master application, and

wherein the flow spaces are objects on the control plane.

14. The network according to claim 13 , wherein the controller comprises a north-bound Advanced Programming Interface (API) that is configured to be employed by users for installing and running their own applications at the control plane atop said controller.

15. The network according to claim 13 , wherein the controller comprises a reference monitor that is configured to execute the conflict resolution scheme.

16. The network according to claim 15 , wherein the reference monitor is configured to pre-compute applications that are in conflict with each other in terms of their reaction.

17. The Network according to claim 16 , wherein the reference monitor is configured to pre-compute the applications each time a new application is installed.

18. The method of claim 10 , wherein applications that are in conflict with each other in terms of their reaction are pre-computed each time a new application is installed.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2019
From: NEC LABORATORIES EUROPE GMBH
To: NEC CORPORATION
Reel/Frame 049480/0817 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2017
From: NEC EUROPE LTD.
To: NEC LABORATORIES EUROPE GMBH
Reel/Frame 044979/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 4, 2016
From: KLAEDTKE, FELIX; KARAME, GHASSAN; BIFULCO, ROBERTO
To: NEC EUROPE LTD.
Reel/Frame 039068/0830 →
Continuity (1)
Related Publication 20160337164A1 · Nov 17, 2016
Cited By (1)
US 12,238,010