Configuration of a software defined network
First Claim
1. A system operable to configure a software defined network (SDN), the system comprising:
- a first communication host;
a second communication host;
a network in communication with the first communication host and the second communication host, the network comprising a plurality of network devices, the plurality of network devices configured to;
selectively operate in each of an open mode and an SDN operating mode; and
identify a discovered path between the first communication host and the second communication host to forward data through the network in the open mode,wherein the plurality of network devices are configured to implement an allow-by-default communication security policy using at least one automated communication protocol in the open mode;
an SDN controller in communication with the network, the SDN controller comprising;
a mode selection subsystem configured to cause the plurality of network devices to transition between the open mode and the SDN operating mode;
an analysis subsystem configured to identify a communication flow corresponding to the discovered path between the first communication host and the second communication host; and
a traffic routing subsystem configured to create a communication flow corresponding to the discovered path, the communication flow operable to allow communication between the first communication host and the second communication host in the SDN operating mode;
wherein the plurality of network devices are configured to implement a deny-by-default communication security policy in the SDN operating mode.
3 Assignments
0 Petitions
Accused Products
Abstract
The present disclosure pertains to systems and method for configuration of communication flows in a software defined network (“SDN”). In one embodiment, a system is operable to configure a communication flow between a first host and a second host. A mode selection subsystem is configured to cause a plurality of network devices in a network connecting the first communication host and the second communication host to transition between an open mode and an SDN operating mode. In the open mode, the network devices may discover a communication path between the first host and the second host. An analysis subsystem may receive information from the plurality of network devices information about the discovered path, and a topology discovery subsystem may be configured to create a communication flow corresponding to the discovered path. The communication flow may allow communication between the first host and the second host in the SDN operating mode.
-
Citations
17 Claims
-
1. A system operable to configure a software defined network (SDN), the system comprising:
-
a first communication host; a second communication host; a network in communication with the first communication host and the second communication host, the network comprising a plurality of network devices, the plurality of network devices configured to; selectively operate in each of an open mode and an SDN operating mode; and identify a discovered path between the first communication host and the second communication host to forward data through the network in the open mode, wherein the plurality of network devices are configured to implement an allow-by-default communication security policy using at least one automated communication protocol in the open mode; an SDN controller in communication with the network, the SDN controller comprising; a mode selection subsystem configured to cause the plurality of network devices to transition between the open mode and the SDN operating mode; an analysis subsystem configured to identify a communication flow corresponding to the discovered path between the first communication host and the second communication host; and a traffic routing subsystem configured to create a communication flow corresponding to the discovered path, the communication flow operable to allow communication between the first communication host and the second communication host in the SDN operating mode; wherein the plurality of network devices are configured to implement a deny-by-default communication security policy in the SDN operating mode. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method of configuring a software defined network (SDN), comprising:
-
operating the SDN in an open mode at a first time; identifying a plurality of communication paths between a plurality of communicating hosts using a plurality of network devices, the plurality of communicating hosts including a first communication host and a second communication host, and the plurality of communication paths comprising a discovered path between the first communication host and the second communication host, wherein the plurality of network devices are configured to implement an allow-by-default communication security policy using at least one automated communication protocol in the open mode; creating a plurality of communication flows using an SDN controller based on at least a subset of the plurality of communication paths, the plurality of communication flows comprising a communication flow corresponding to the discovered path between the first communication host and the second communication host; transitioning the SDN to an SDN operating mode at a second time, wherein the plurality of network devices are configured to implement a deny-by-default communication security policy in the SDN operating mode; and routing traffic in the SDN between the first communication host and the second communication host based on the plurality of communication flows. - View Dependent Claims (9, 10, 11, 12)
-
-
13. A system operable to configure a communication flow between a first communication host and a second communication host in a software defined network (SDN), the system comprising:
-
a mode selection subsystem configured to cause a plurality of network devices in a network connecting the first communication host and the second communication host to transition between an open mode and an SDN operating mode, wherein the plurality of network devices are configured to discover a path between the first communication host and the second communication host in the open mode, wherein the plurality of network devices are configured to implement an allow-by-default communication security policy using at least one automated communication protocol in the open mode; an analysis subsystem configured to receive information from the plurality of network devices about the discovered path between the first communication host and the second communication host; and a topology subsystem configured to create a communication flow corresponding to the discovered path between the first communication host and the second communication host, the communication flow operable to allow communication between the first communication host and the second communication host in the SDN operating mode, wherein the plurality of network devices are configured to implement a deny-by-default communication security policy in the SDN operating mode. - View Dependent Claims (14, 15, 16, 17)
-
Specification