IP Library Granted Patent US 10,868,835
Granted Patent B2
US 10,868,835 · App. 16/343,006 · Granted Dec 15, 2020

Method for managing data traffic within a network

Inventors: Ghassan Karame (Heidelberg, DE); Felix Klaedtke (Heidelberg, DE); Takayuki Sasaki (Tokyo, JP)
Assignee: NEC CORPORATION
H04L63/20H04L41/0816H04L41/0893H04L63/0263H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,868,835
App. No.
16/343,006
Granted
Dec 15, 2020
Kind
B2
Abstract

A method manages data traffic within a network having controllers that each control a part of the network having a forwarding element (FE), the controllers being connected to a reference monitor (RM) for enforcing a security policy. The method includes: receiving a rule request by a controller and transmitting it its RM; the RM checking the rule request for policy compliance and authorizing a poly compliant part of the rule request. When the rule request has an outside modification: the controller contacts controllers impacted by the outside modification for obtaining an authorization, and upon receipt of authorization, sending the controller sends the modifications and authorizations to the impacted controllers to implement the modification in their FE.

Claims (40)

1. A method for managing data traffic within a network, the network comprising a plurality of controllers, each of the controllers being configured to control a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one reference monitor (RM) for enforcing a security policy for the network part managed by the corresponding one of the controllers, the method comprising:

a) receiving a rule request by a controller of the controllers and transmitting the rule request to the corresponding RM,

b) checking, by the RM, the rule request for policy compliance,

c) authorizing, by the RM, a part of the rule request that is policy compliant, and

wherein when the rule request comprises an outside modification, the outside modification impacting at least one other network part not managed by the controller:

d) the controller contacts at least the one or more controllers being impacted by the outside modification for obtaining an authorization for the outside modification, and

e) upon reception of the one or more authorizations for the outside modification, sending all modifications of the rule request and corresponding authorizations by the controller to all other controllers being impacted by the rule request for implementing the modification in the corresponding at least one FE of each of the controllers impacted.

2. The method according to claim 1 , wherein the at least one RM of each of the controllers is running isolated from the controllers.

3. The method according to claim 1 , wherein step d comprises performing of a commit-agree procedure.

4. The method according to claim 1 , the method comprising, based upon the rule request comprising only outside modifications, the controller drops the rule request.

5. The method according to claim 1 , wherein the controller uses a general binary contact tree for contacting the one or more controllers being impacted by the outside modification.

6. The method according to claim 5 , wherein the general binary contact tree is computed based on network domain parameters.

7. The method according to claim 5 , wherein the controller uses a fastest-node-first heuristic for contacting the one or more controllers being impacted by the outside modification.

8. The method according to claim 5 , wherein the general binary contact tree is checked for correctness by the RM.

9. The method according to claim 1 , wherein the authorization by the RM is provided using a BLS signature.

10. The method according to claim 1 , wherein the authorization is only valid for a predefined period of time.

11. The method according to claim 1 , wherein in a case where the modification fails, a rollback is performed.

12. The method according to claim 1 , wherein in a case where a number of controllers within the network is less than 10, then communication between the controllers is based on broadcasting and/or based on point-to-point.

13. The method of claim 1 ,

wherein the FE operates in a data plane of the network,

wherein the RM and the controller operate in a control plane of the network,

wherein a rule request comprises at least one of a request for installing, modifying, or deleting a data flow rule in the FE.

14. A network for performing data traffic, the network comprising:

a plurality of controllers, each of the controllers controlling a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one reference monitor (RM) for enforcing a security policy for the network part managed by the corresponding one of the controllers,

wherein a controller of the plurality of controllers is adapted to receive a rule request and to transmit the rule request to the corresponding RM,

wherein when the rule request comprises an outside modification, the outside modification impacting at least one other network part not managed by the controller,

wherein the controller is adapted to contact at least the one or more controllers being impacted by the outside modification for obtaining an authorization for the outside modification, and upon reception of the one or more authorizations for the outside modification, to send all modifications of the rule request and corresponding authorizations to all other controllers being impacted by the rule request for implementing the modification in the corresponding FE of the controllers impacted, and

wherein the RM is adapted to check the rule request for policy compliance and to authorize a part of the rule request which is policy compliant.

15. A non-transitory computer-readable medium storing a program causing a computer to execute a method for managing data traffic within a network, the network comprising a plurality of controllers, each of the controllers being configured to control a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one reference monitor (RM) for enforcing a security policy for the network part managed by the corresponding one of the controllers, wherein the method comprises:

a) receiving a rule request by a controller of the controllers and transmitting the rule request to the corresponding RM,

b) checking, by the RM, the rule request for policy compliance,

c) authorizing, by the RM, a part of the rule request that is policy compliant, and

wherein when the rule request comprises an outside modification, the outside modification impacting at least one other network part not managed by the controller:

d) the controller contacts at least the one or more controllers being impacted by the outside modification for obtaining an authorization for the outside modification, and

e) upon reception of the one or more authorizations for the outside modification, sending all modifications of the rule request and corresponding authorizations by the controller to all other controllers being impacted by the rule request for implementing the modification in the corresponding at least one FE of each of the controllers impacted.

16. A controller for controlling a part of a network, the network part comprising at least one forwarding element (FE) for forwarding data within the network,

wherein the controller is connectable to at least one reference monitor (RM) for enforcing a security policy for the network part managed by the controller,

wherein the controller is adapted to receive a rule request and to transmit the rule request to the RM,

wherein when the rule request comprises an outside modification, the outside modification impacting at least one other network part not managed by the controller, the controller is adapted to contact at least one or more other controllers of the network being impacted by the outside modification for obtaining an authorization for the outside modification, and upon reception of the one or more authorizations for the outside modification, to send all modifications of the rule request and corresponding authorizations to all other controllers being impacted by the rule request for implementing the modification in one or more forwarding elements of the controllers impacted.

17. The method of claim 13 , wherein the network is a software defined network, and the FE is a software defined network switch.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2026
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 074916/0414 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2026
From: NEC ASIA PACIFIC PTE LTD.
To: CBS INTERACTIVE INC.
Reel/Frame 074916/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2020
From: NEC LABORATORIES EUROPE GMBH
To: NEC CORPORATION
Reel/Frame 054319/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: KARAME, GHASSAN; KLAEDTKE, FELIX; SASAKI, TAKAYUKI
To: NEC LABORATORIES EUROPE GMBH
Reel/Frame 048976/0297 →
Continuity (1)
Related Publication 20200059495A1 · Feb 20, 2020