Configuring secure connectivity between devices in separate sites of a multi-site domain

By generating physical underlying and logical overlay models through an SDN controller and establishing a secure connection tunnel using a unique encryption key, the complexity and security issues of device interconnection in multi-site cloud computing networks are resolved, achieving efficient and secure network expansion.

CN115606152BActive Publication Date: 2026-04-10CISCO TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CISCO TECHNOLOGY INC
Filing Date
2021-05-24
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In multi-site cloud computing networks, existing technologies struggle to efficiently manage and configure physical links and logical overlays between network devices, resulting in complex configurations and insufficient security. This is especially true when expanding multi-site networks, where forgetting connectivity relationships and using pre-shared keys can lead to security risks.

Method used

The Software-Defined Networking (SDN) controller collects reachability data, generates entity-level and logical overlay models, and establishes secure connection tunnels using unique encryption keys to achieve secure interconnection between border gateway devices.

Benefits of technology

It enables efficient and secure device interconnection in multi-site networks, supports line-speed traffic encryption, and allows for the automated expansion of new sites and devices, reducing configuration complexity and security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115606152B_ABST
    Figure CN115606152B_ABST
Patent Text Reader

Abstract

The following techniques: utilize a software defined network (SDN) controller and / or data center network manager (DCNM) associated with a multi-site cloud computing network and network border gateway switches to provide reachability data indicative of physical links between border gateway switches disposed in different sites of the multi-site network to establish secure connection tunnels utilizing the physical links and unique encryption keys. The SDN controller and / or DCNM can be configured to generate a physical underlay model representing physical underlay or network transport capabilities and / or a logical overlay model representing a logical overlay or overlay control plane of the multi-site network. The SDN controller can also generate an encryption key model representing associations between encryption keys and associated network border gateway switches. The SDN controller can utilize these models to determine routing paths for sending network traffic at line speed between different sites of the multi-site network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related Applications

[0002] This application claims priority to U.S. Patent Application No. 16 / 930,947, filed July 16, 2020, and U.S. Provisional Patent Application No. 63 / 033,589, filed June 2, 2020, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0003] The present disclosure generally relates to generating a physical underlay and logical overlay model of a network using reachability data indicative of physical links between devices in separate sites of a multi-site domain network, and establishing secure interconnections between devices in separate sites of a multi-site domain. BACKGROUND

[0004] Cloud computing provides users with access to computing resources to meet their demand for computing resources. In some examples, service providers can manage cloud computing resources and provide them to users to meet their demand, without the need for users to invest and maintain their own computing infrastructure. Cloud computing typically involves the use of data center networks that house servers, routers, and other devices that provide computing resources, such as compute resources, network resources, storage resources, database resources, application resources, etc., to users. As data centers continue to scale and extend to multi-site cloud environments, the demand for secure interconnections of these sites that allow traffic to be encrypted at line rate while ensuring confidentiality, data integrity, and scalability increases. For example, each time a new site is added, many repetitive configurations must be provided in the new site and remote sites to accommodate the addition.

[0005] To support the integration of a new site into a multi-site domain, the necessary configurations depend on the local site topology and the location of the corresponding devices within the interconnectivity topology. As modern multi-site domains are capable of supporting a large number of sites and specialized network devices (e.g., border gateways for site interconnections), the amount of coordinated configurations that must be provided on the associated network devices becomes increasingly large. Furthermore, the pairwise assurance of interconnectivity relationships also grows exponentially.

[0006] To effectively support the expansion of multi-site domains utilizing network controllers, different entities and logical connectivity relationships must be understood. Extending this understanding to multiple sites requires an overall increase in multi-tenancy support from a topology perspective. While the configuration can be generated by automation tools, mapping and understanding the required connectivity relationships remains a significant burden for network administrators. Even with configuration automation, if one of the relationships is forgotten, the entire system is at risk of being compromised. In addition to the entity links that require Internet Protocol (IP) addresses and routing adjacencies in an arbitrary topology representing the network underlay, the logical overlay layer of the network requires the exchange of reachability information that is multi-tenant aware. While the network underlay and overlay can be well-known entities, the quantity of connectivity relationships required to configure such a network increases with the addition of each border gateway, core router, or site. Furthermore, to make a multi-site network scalable, pre-shared encryption keys can be utilized to ensure interconnectivity between border gateways in different sites. However, the use of pre-shared keys can result in the network being subject to various security limitations. BRIEF DESCRIPTION OF DRAWINGS

[0007] Specific embodiments will be described below with reference to the accompanying drawings. In the drawings, the left-most digit of a reference numeral identifies the first figure in which the reference numeral appears. The use of the same reference numerals in different drawings indicates similar or identical items. The systems depicted in the drawings are not to scale and the dimensions of the various components can be exaggerated for the sake of clarity.

[0008] Figure 1A A system architecture diagram illustrating the following example flow for a network controller for a multi-site cloud computing network that collects reachability data and generates entity underlay and logical overlay models of the multi-site network to determine routing paths between different sites of the multi-site network.

[0009] Figure 1B A system architecture diagram illustrating the following example flow for a network border gateway that is entity linked and disposed in different sites of a multi-site cloud computing network that sends an indication of the entity link to a network controller of the multi-site network and utilizes the entity link to establish a secure connection tunnel using a unique encryption key.

[0010] Figure 2A A diagram illustrating an entity underlay model of an example multi-site network including entity connections between various border gateways.

[0011] Figure 2B A diagram illustrating a logical overlay model of an example multi-site network including entity connections between various border gateways.

[0012] Figure 3A diagram is shown of a cryptographic key model including a cryptographic key map for establishing secure connection tunnels using entity links between border gateways disposed in various sites of a multi-site network.

[0013] Figure 4 A flowchart of an example method for a software defined network (SDN) controller of a multi-site cloud computing network is shown for collecting reachability data and generating entity underlay and logical overlay models of the multi-site network to determine routing paths between different sites of the multi-site network.

[0014] Figure 5 A flowchart of an example method for network border gateways coupled to entity links and disposed in different sites of a multi-site cloud computing network is shown for sending indications of the entity links to a software defined network (SDN) controller of the multi-site network and establishing secure connection tunnels using the entity links using unique cryptographic keys.

[0015] Figure 6 is a computer architecture diagram showing an illustrative computer hardware architecture for implementing a server device that can be used to implement various aspects of the various technologies presented herein. DETAILED DESCRIPTION

[0016] SUMMARY

[0017] Aspects of the application are set out in the independent claims, and preferred features are set out in the dependent claims. Features of one aspect can be applied to any aspect, either alone or in combination with features of other aspects.

[0018] The present disclosure describes methods of utilizing a software-defined network (SDN) controller and network border gateways of a multi-site network to provide reachability data indicative of physical links between border gateways in different sites of a multi-site network to establish secure connection tunnels utilizing the physical links and unique encryption keys. The methods can include collecting, by a software-defined network (SDN) controller, reachability data indicative of physical links between one or more first devices in a first site and one or more second devices in a second site. The methods can also include generating, by the SDN controller, a first model representing a physical underlay of a multi-site network comprising the first site and the second site based at least in part on the reachability data. The methods can also include allocating, by the SDN controller, IP subnets to the physical links based on a global management pool of the SDN controller and generating routing configurations between adjacent pairs. Alternatively, the methods can also include receiving, at the SDN controller, metadata indicative of Internet Protocol (IP) addresses and network protocols associated with the one or more first devices and the one or more second devices. The methods can also include generating, by the SDN controller, a second model representing a logical overlay layer of the multi-site network based at least in part on the first model and the metadata, the logical overlay layer indicative of reachability between the one or more first devices and the one or more second devices and EVPN peering therebetween.

[0019] Additionally or alternatively, a method includes sending, from a first device in a first site of a multi-site network, reachability data to a software-defined network (SDN) controller, the reachability data indicative of a physical link between the first device and a second device in a second site of the multi-site network. The method can also include sending, from the first device to the SDN controller, metadata indicative of Internet Protocol (IP) addresses and network protocols associated with the first device. The method can also include receiving, at the first device from the SDN controller, IP address allocations and routing configurations indicative of routing peering between the first device and the second device. The method can also include receiving, at the first device from the SDN controller, an encryption key configured for establishing a secure connection tunnel between the first device and the second device. The method can also include establishing, by the first device, the secure connection tunnel between the first device in the first site and the second device in the second site utilizing the encryption key.

[0020] Further, the techniques described herein can be performed by a system and / or device having a non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more processors, perform the methods described above.

[0021] Example Embodiments

[0022] As described above, the expansion of multi-site cloud environments requires a large number of repetitive configuration settings in new sites as well as remote sites to establish secure interconnections for these sites and allow traffic to be encrypted at line speed without sacrificing scalability. While network administrators can utilize configuration automation tools to assist in mapping and understanding the connectivity relationships required, the risk of forgetting the connectivity relationships of these multi-site networks and encrypting interconnectivity links with pre-shared encryption keys can result in various inefficiencies and put the entire system at risk.

[0023] The present disclosure describes techniques in which a multi-site network controller (e.g., a data center network manager (DCNM) and / or a software-defined network (SDN) controller, by way of example) collects reachability data indicative of physical links between border gateway devices in different sites of a multi-site network to generate a physical underlay and a logical overlay model of the multi-site network and establish secure interconnections between the border gateway devices in different sites. Border gateway devices can utilize unique encryption keys to establish secure connection tunnels to support interconnections of the multi-site network and allow traffic to be encrypted at line speed. Further, the network controller can maintain a mapping of unique encryption keys to corresponding connection tunnels. According to the techniques and mechanisms described herein, each multi-site network can have one network controller, and each site of a multi-site network can have one or more border gateway devices that are communicatively coupled with one or more border gateway devices of another, separate site.

[0024] The various sites of the multi-site network can include one or more network switches. In some examples, the network switches can be configured as network spine switches, network leaf switches, and / or network border gateway switches. In some examples, the one or more network switches included in a network site can be physically connected to each other. Additionally or alternatively, a network border gateway switch disposed in a first site of the multi-site network can be physically connected to another network border gateway switch disposed in a second site of the multi-site network. Additionally or alternatively, a network border gateway switch disposed in a first site of the multi-site network can be physically connected to a core router that does not belong to any site. In some examples, the network border gateway switches can generate reachability data indicating such physical links using various network protocols (e.g., Link Layer Discovery Protocol (LLDP), Control Point Discovery (CPD) protocol, or Cisco Discovery Protocol (CDP), to name a few). In some examples, the network border gateway switches can be configured to send the reachability data to a network controller associated with the multi-site network.

[0025] The network controller associated with the multi-site network can be configured to collect reachability data and / or metadata from one or more devices of the various sites of the multi-site network. In some examples, the network controller can be configured to collect reachability data and / or metadata from devices configured as network border gateway switches. In some examples, the network controller can be configured to utilize the reachability data indicating the physical links between the network border gateway switches of the various sites of the multi-site network and their adjacent switches to generate a model representing the physical underlay of the multi-site network and to generate an underlay IP subnet and routing configuration. Additionally or alternatively, the network controller can be configured to utilize the model representing the physical underlay or network transport capabilities of the multi-site network to generate a model representing a logical overlay layer or overlay control plane of the multi-site network.

[0026] Additionally or alternatively, the network controller can be configured to generate an encryption key configured for establishing secure connection tunnels between the border gateway switches of the various sites of the multi-site network. In some examples, the network controller can be configured to generate a generic encryption key configured for establishing all secure encryption tunnels between the border gateway switches of the various sites of the multi-site network. Additionally or alternatively, the network controller can be configured to generate a pair-wise encryption key with metadata indicative of the IP addresses and network protocols of the network border gateway switches of the various sites of the multi-site network. In some examples, the pair-wise encryption key can be configured to be unique from one another and used to establish a secure encryption tunnel between a pair of network border gateway switches associated with the input metadata. In some examples, the network controller can be configured to generate an encryption key model comprising the pair-wise encryption keys. For example, the network controller can be configured to store a mapping or association between the encryption keys and the logical links between the associated network border gateway switches in an encryption key data store associated with the network controller. In some examples, the network controller can be configured to utilize the encryption key data store to generate an encryption key model representing the associations between the encryption keys and the links between the associated network border gateway switches. Additionally or alternatively, the network controller can be configured to generate and / or provide encryption algorithms associated with the encryption keys to the associated network border gateway switches.

[0027] In an example cloud computing network, a network controller, a first network site, and a second network site can be disposed in a multi-site network. Additionally or alternatively, a first border gateway switch and one or more first network switches comprising a first network leaf switch can be disposed in a first site of the multi-site network. Additionally or alternatively, a second border gateway switch and one or more second network switches comprising a second network leaf switch can be disposed in a second site of the multi-site network. Additionally or alternatively, the first border gateway switch of the first site can be physically linked to the second border gateway switch of the second site.

[0028] In some examples, the first network border gateway switch can send reachability data to the network controller indicating the physical links between the first border gateway switch and its adjacent switches, which can be core routers or a second border gateway switch. Additionally or alternatively, the second border gateway switch can send reachability data to the network controller indicating the physical links between the second border gateway switch and its adjacent switches, which can be the same or different core routers or the first border gateway switch. Additionally or alternatively, the network controller can be configured to collect the reachability data from the first border gateway switch and / or the second border gateway switch. In some examples, the network controller can utilize the reachability data to generate a physical underlay model of the multi-site network.

[0029] In some examples, the network controller can allocate an IP subnet from its pool to the external physical link and configure network protocols between the first border gateway switch and its adjacent switches connected by the external physical link. Additionally or alternatively, the network controller can allocate an IP subnet from its pool to the external physical link and configure network protocols between the second border gateway switch and its adjacent switches connected by the external physical link. In some examples, the network controller can utilize the physical underlay model and / or the metadata to generate a logical overlay model of the multi-site network that includes EVPN BGP peering interconnection configurations between the border gateway switches in different sites or between the border gateway switches and the router servers. The EVPN peering interconnection configurations can enable overlay network / vrf information exchange between the various sites.

[0030] In some examples, the network controller can generate a pair of encryption keys associated with the logical link between the first border gateway switch and the second border gateway switch utilizing the metadata associated with the first border gateway switch and / or the metadata associated with the second border gateway switch. In some examples, the network controller can store the association between the encryption keys and the logical link between the first border gateway switch and the second border gateway switch in an encryption key data store associated with the network controller. Additionally or alternatively, the network controller can utilize the encryption key data store to generate an encryption key model representing the association between the encryption keys and the logical link between the first border gateway switch and the second border gateway switch.

[0031] In some examples, the network controller can send the pair of encryption keys to the first border gateway switch and / or the second border gateway switch. Additionally or alternatively, the network controller can send an encryption algorithm associated with the encryption keys to the first border gateway switch and / or the second border gateway switch. In some examples, the first border gateway switch and / or the second border gateway switch can utilize the encryption keys and / or the encryption algorithm to establish a secure connection tunnel with a logical link between the first border gateway switch and the second border gateway switch.

[0032] In some examples, a first network leaf switch in a first site can send a request to a network controller for sending data associated with a first compute resource associated with the first network leaf switch to a second compute resource associated with a second network leaf switch in a second site. Additionally or alternatively, one or more first network switches of the first site can include a first network spine switch. In some examples, the first network leaf switch can send the request to the first network spine switch, and the first network spine switch can forward the request to the network controller. In some examples, the network controller can determine a routing path from the first network leaf switch in the first site to the second network leaf switch in the second site utilizing an entity underlay model, a logical overlay model, and / or an encryption key model. In some examples, the routing path can include a secure connection tunnel utilizing an entity link between a first border gateway switch and a second border gateway switch. In some examples, the network controller can provide the routing path to the first network leaf switch. Additionally or alternatively, the network controller can provide an indication of the routing path to the first network spine switch, and the first network spine switch can forward the indication of the routing path to the first network leaf switch. In some examples, the first network leaf switch in the first site can utilize the routing path including the secure connection tunnel utilizing the entity link between the first border gateway switch and the second border gateway switch to send the data to the second border leaf gateway switch in the second site.

[0033] As described herein, computing resources generally can include any type of computing resource, e.g., entity resources associated with entity servers and / or entity links in a network. Additionally or alternatively, entity resources can be apportioned or allocated to virtual resources, e.g., containers, virtual machines, virtual memories, etc., implemented through virtualization technology, where the virtual resources can utilize an allocated portion of entity resources of entity servers in the network. Moreover, although these techniques are described as being implemented in a data center and / or a multi-site cloud computing network, these techniques are generally applicable to any network of devices managed by any entity providing computing resources. In some cases, these techniques can be performed by a scheduler or coordinator, while in other examples, various components can be used in a system to perform the techniques described herein. The devices and components that perform the techniques described herein are a matter of implementation, and the techniques are not limited to any particular architecture or implementation.

[0034] The techniques described herein provide various improvements and efficiencies in collecting reachability data indicative of entity links between border gateway switches in separate sites of a multi-site network or entity links between border gateway switches and core routers to generate an entity underlay model and a logical overlay model of the multi-site network. For example, the techniques described herein can allow for generation of a logical overlay model of the multi-site network indicative of reachability between devices in separate sites of the multi-site network. Moreover, the border gateway switches can establish secure connection tunnels between separate sites of the multi-site network using pairwise encryption keys and / or encryption algorithms provided by a network controller. By establishing secure connection tunnels using logical links between the border gateway switches, the network controller can configure a path for encrypted transmission or data flow at wire speed between computing resources in separate sites of the multi-site network, which was not possible before. Moreover, the techniques described herein allow for automated scalability of the multi-site network, e.g., adding new sites, new border gateway switches, and / or new core switches to the multi-site network in an automated manner, which was not possible before.

[0035] Certain implementations and embodiments of the present disclosure will now be described more fully with reference to the accompanying drawings, in which various aspects can be seen. The various aspects, however, can be implemented in many different forms and should not be construed as limited to the implementations set forth herein. The present disclosure includes all variations of the embodiments described herein. Like reference numbers refer to like elements throughout.

[0036] Figure 1AA system-architecture diagram 100 showing an example flow for collecting reachability data to generate a logical overlay model and establish secure connection tunnels over a multi-site cloud computing network 102. The cloud computing network can include one or more data centers across one or more network sites 104(a), 104(b) that include various networking components, e.g., network controllers 106, spine network switches 108(a), 108(b), leaf network switches 110(a), 110(b), network border gateway switches 112(a), 112(b), and / or entity servers 114. In some examples, the network sites 104 can be located in various geographic regions, and the cloud computing network 102 can be a distributed network through which users (typically customers) can interact via user devices to manage or otherwise interact with services provided by the cloud computing network 102.

[0037] The cloud computing network 102 can provide on-demand availability of computing system resources of the entity servers 114, e.g., data storage, computing power (e.g., CPU, GPU, etc.), networking, databases, etc., without the user having to directly and actively manage. In some examples, the cloud computing network 102 can be managed and maintained by a service provider, such that the user does not have to invest in and maintain computing infrastructure for their computing resource needs. Typically, a user can gain access to or be allocated usage of a portion of the computing resources of the entity servers 114 in the cloud computing network 102. The cloud computing network 102 can scale based on the needs of individual users, e.g., by spinning up resources or spinning down resources. Some portions of the cloud computing network 102 can be allocated using hardware virtualization, such that these portions of the cloud computing network 102 can be configured and managed by the user (e.g., security configurations, load balancing configurations, etc.). However, the cloud computing network 102 need not be managed by a service provider, but can be managed by any entity, including the user themselves running an application or service. In some examples, the entity servers 114 can host one or more virtual machines. Each virtual machine can be configured to perform one of various operations and act as one or more virtual components of the cloud computing network 102, e.g., resource 116, to name a few.

[0038] In some examples, a virtual machine can be configured to perform one of various operations and act as a network border gateway 112. In some examples, a network border gateway switch 112(a) disposed in a first network site 104(a) of a multi-site cloud computing network 102 can be physically connected to a network border gateway switch 112(b) disposed in a second network site 104(b) of the multi-site cloud computing network. In some examples, the network border gateway switches 112 can generate reachability data indicating such physical links using various network protocols (e.g., Link Layer Discovery Protocol (LLDP), Control Point Discovery (CPD) protocol, or Cisco Discovery Protocol (CDP), to name a few). Additionally or alternatively, the network border gateway switches 112 can generate metadata indicating Internet Protocol (IP) addresses and / or network protocols associated with the network border gateway switches.

[0039] In some examples, a network controller 106 associated with the multi-site cloud computing network 102 can be configured to collect reachability data and / or metadata from the network border gateway switches 112 of the multi-site network. In some examples, the network controller can be configured to utilize the reachability data indicating the physical links 124 between the network border gateway switches 112(a), 112(b) of the various sites 104(a), 104(b) of the multi-site cloud computing network 102 to generate a physical underlay model 118 representing a physical underlay or network transport capacity of the multi-site cloud computing network 102. Additionally or alternatively, the network controller 106 can be configured to utilize the physical underlay model 118 of the multi-site network and / or the metadata indicating the IP addresses and network protocols of the network border gateway switches 112(a), 112(b) of the various sites 104(a), 104(b) of the multi-site cloud computing network 102 to generate a logical overlay model 120 representing a logical overlay or overlay control plane of the multi-site cloud computing network 102.

[0040] Additionally or alternatively, the network controller 106 can be configured to generate an encryption key for establishing a secure connection tunnel 122 between the network border gateway switch 112(a) of the network site 104(a) and the network border gateway switch 112(b) of the network site 104(b) of the multi-site cloud computing network 102. In some examples, the network controller 106 can be configured to generate a generic encryption key that is configured for establishing all secure encryption tunnels 122 between the border gateway switches 112 of the various sites 104 of the multi-site cloud computing network 102. Additionally or alternatively, the network controller 106 can be configured to generate a pair-wise encryption key with metadata that indicates the IP address and network protocol of the network border gateway switches 112. In some examples, the pair-wise encryption key can be configured to be unique to each other and for establishing a secure encryption tunnel 122 between a pair of network border gateway switches 112(a), 112(b) associated with the input metadata. In some examples, the network controller 106 can be configured to generate an encryption key model 124 that includes the pair-wise encryption keys. For example, the network controller 106 can be configured to store a mapping or association between the encryption key and the physical link between the associated network border gateway switches 112(a), 122(b) in an encryption key data store associated with the network controller 106. In some examples, the network controller 106 can be configured to generate the encryption key model 124 with the encryption key data store. Additionally or alternatively, the network controller 106 can be configured to generate and / or provide an encryption algorithm associated with the encryption key to the associated network border gateway switches 112.

[0041] Generally, the number of network sites 104, network border gateway switches 112, and / or resources 116 can be scaled based on the number of users 126 interacting with the cloud computing network 102. The users 126 can include one or more of individual users, groups of users, organizations, businesses, or other entities interacting with the cloud computing network 102 through respective user devices. The user devices can be any type of computing device capable of connecting to the cloud computing network 102 via a suitable data communication network 128, such as, but not limited to, a laptop or desktop computer, a tablet computing device, a server computer, a television, or a mobile phone. Administrative users employed by an operator of the cloud computing network 102 (e.g., administrators managing the operation of the cloud computing network 102) can also connect, manage, and utilize the resources provided by the service provider network 102 in a similar manner.

[0042] The users 126 can provide input data 130 over the network 128 to interact with services supported by the resources 116 running on the servers 114. For example, the users 126 can submit requests to process data, retrieve data, store data, etc., such that virtual machines hosting the resources 116 are added or removed to process the requests based on demand. Additionally or alternatively, the users 126 can be administrative users 126 that can provide input data 130 via the network 128 to interact with the multi-site cloud computing network 102 and add and / or remove networked devices. For example, the administrative users 126 can submit requests to add sites 104 and / or network switches, such as, for example, the network border gateway switches 112.

[0043] The network controller 106 can communicate with respective network switches, such as, for example, the spine network switches 108, the leaf network switches 110, and / or the network border gateway switches 112, to receive a request from a leaf network switch 110 associated with an entity server 114 hosting a computing resource 116 located in the multi-site cloud computing network 102 to send data to a leaf network switch 110 associated with another entity server 114 hosting a computing resource 116 located in a separate site 104 of the multi-site cloud computing network 102. In some examples, the network controller 106 can be configured to determine a routing path for sending data between leaf network switches 110 in separate sites 104 of the multi-site cloud computing network 102. For example, the network controller 106 can be configured to utilize the entity underlay model 118 and / or the logical overlay model 120 to determine a routing path for sending data between leaf network switches 110 in separate sites 104 of the multi-site cloud computing network 102 utilizing the secure connection tunnels 122.

[0044] At "1", the network controller 106 associated with the multi-site cloud computing network 102 can collect reachability data from a first network border gateway switch 112(a) disposed in a first site 104(a) and a second network border gateway switch 112(b) disposed in a second site 104(b). In some examples, the reachability data can indicate entity links that can be used to establish a secure connection tunnel 122 between the first network border gateway switch 112(a) and the second network border gateway switch 112(b).

[0045] At "2", the network controller 106 can generate an entity underlay model 118 of the multi-site cloud computing network 102. In some examples, the entity underlay model 118 can represent an entity underlay, or network transport capability, of the multi-site cloud computing network 102. Additionally or alternatively, the network controller 106 can generate the entity underlay model 118 using the reachability data.

[0046] At "3," the network controller 106 can receive metadata from one or more network border gateway switches 112(a) of the first site 104(a) and one or more network border gateway switches 112(b) of the second site 104(b). In some examples, the metadata can indicate an Internet Protocol (IP) address and / or a network protocol associated with the respective network border gateway switches 112(a), 112(b).

[0047] At "4," the network controller 106 can generate a logical overlay model 120 of the multi-site cloud computing network 102. In some examples, the logical overlay model 120 can represent a logical overlay, or overlay control plane, of the multi-site cloud computing network 102. Additionally or alternatively, the network controller 106 can generate the logical overlay model 120 based at least in part on the physical overlay model 118. Additionally or alternatively, the network controller 106 can generate the logical overlay model 120 based at least in part on the metadata received from the one or more network border switches 112.

[0048] At "5," the network controller 106 can receive a request to send data from a computing resource 116 executing on a physical server 114 associated with a leaf network switch 110(a)(n) in the first network site 104(a) to a computing resource 116 executing on a physical server 114 associated with at least one leaf network switch 110(b) in the second network site 104(b). Additionally or alternatively, the network controller 106 can receive the request to send data from a spine network switch 108(a)(l)-(n) associated with the leaf network switch 110(a)(n).

[0049] At "6," the network controller 106 can determine a routing path for sending the data from the computing resource 116 in the first network site 104(a) to the computing resource 116 in the second network site 104(b). In some examples, the network controller 106 can determine a routing path that includes a secure encrypted tunnel 122 that utilizes a physical link between the first network border gateway switch 112(a) and the second network border gateway switch 112(b). In some examples, the network controller 106 can determine the routing path based at least in part on the logical overlay model 120.

[0050] At "7," the network controller can provide the routing path to the leaf network switch 110(a)(n) associated with the computing resource 116.

[0051] In some examples, the example flow can continue from step "7" of Figure 1A toFigure 1B Step "8". Additionally or alternatively, the example process can be derived from... Figure 1B Begin with step “8”, and start from Figure 1B Step "12" continues to Figure 1A Step “1”. Additionally or alternatively, Figure 1A The example process can be compared with Figure 1B The example process is executed simultaneously.

[0052] Figure 1B A system-architecture diagram 200 illustrates the following example flow for network border gateway switches 112(a), 112(b) located at different sites 104(a), 104(b) of a multi-site cloud computing network 102: Network border gateway switches 112(a), 112(b) send an indication of a physical link to the network controller 106 of the multi-site network 102 and use the physical link to establish a secure connection tunnel 122 using a unique encryption key.

[0053] Network controller 106 can be configured to generate encryption keys configured to establish secure connection tunnels 122 between network border gateway switches 112(a) of network site 104(a) and 112(b) of network site 104(b) in a multi-site cloud computing network 102. In some examples, network controller 106 can be configured to generate generic encryption keys configured to establish all secure encrypted tunnels 122 between the border gateway switches 112 of the various sites 104 in the multi-site cloud computing network 102. Additionally or alternatively, network controller 106 can be configured to generate paired encryption keys using metadata indicating the IP addresses and network protocols of the network border gateway switches 112. In some examples, the paired encryption keys can be configured to be unique to each other and used to establish secure encrypted tunnels 122 between a pair of network border gateway switches 112(a), 112(b) associated with the input metadata. In some examples, network controller 106 can be configured to generate an encryption key model 124 that includes paired encryption keys. For example, network controller 106 may be configured to store the mapping or association of encryption keys with physical links between associated network border gateway switches 112(a), 122(b) in an encryption key data repository associated with network controller 106. In some examples, network controller 106 may be configured to use the encryption key data repository to generate encryption key model 124. Additionally or alternatively, network controller 106 may be configured to generate and / or provide encryption algorithms associated with the encryption keys to the associated network border gateway switch 112.

[0054] The network controller 106 can communicate with respective network switches (e.g., for example, the spine network switches 108, the leaf network switches 110, and / or the network border gateway switches 112) to receive a request from a leaf network switch 110 associated with an entity server 114 of a hosted computing resource 116 located in the multi-site cloud computing network 102 to send data to a leaf network switch 110 associated with another entity server 114 of a hosted computing resource 116 located in a separate site 104 of the multi-site cloud computing network 102. In some examples, the network controller 106 can be configured to determine a routing path for sending data between leaf network switches 110 in separate sites 104 of the multi-site cloud computing network 102. For example, the network controller 106 can be configured to utilize the entity underlay model 118 and / or the logical overlay model 120 to determine a routing path for sending data between leaf network switches 110 in separate sites 104 of the multi-site cloud computing network 102 utilizing secure connection tunnels 122.

[0055] At "8", a first network border gateway switch 112(a) disposed in a first site 104(a) of the multi-site cloud computing network 102 can send reachability data indicative of an entity link to a second network border gateway switch 112(b) disposed in a second site 104(b) of the multi-site cloud computing network 102. Additionally or alternatively, the second network border gateway switch 112(b) can send reachability data indicative of the entity link to the first network border switch 112(a). In some examples, the first network border gateway switch 112(a) and / or the second network border gateway switch 112(b) can utilize various network protocols (e.g., for example, a Link Layer Discovery Protocol (LLDP), a Control Point Discovery (CPD) protocol, or a Cisco Discovery Protocol (CDP)) to discover the entity link and / or generate the reachability data indicative of such entity link.

[0056] At "9", the first network border gateway switch 112(a) can send metadata to the network controller 106. Additionally or alternatively, the second network border gateway switch 112(b) can send metadata to the network controller 106. In some examples, the metadata can be indicative of an Internet Protocol (IP) address and / or a network protocol associated with the respective network border gateway switch 112.

[0057] At "10," the first network border gateway switch 112(a) can receive routing data from the network controller 106. Additionally or alternatively, the second network border gateway switch 112(b) can receive routing data from the network controller 106. Additionally or alternatively, one or more spine network switches 108 and / or one or more leaf network switches 110 disposed in the first network site 104(a) and / or the second network site 104(b) can receive routing data. In some examples, the routing data can indicate a data transmission route from a computing resource 116 in the first network site 104(a) to a computing resource 116 in the second network site 104(b).

[0058] At "11," the first network border gateway switch 112(a) can receive an encryption key from the network controller 106. Additionally or alternatively, the second network border gateway switch 112(b) can receive an encryption key from the network controller 106. In some examples, the encryption key can be configured as a paired encryption key configured such that only the first network border gateway switch 112(a) and / or the second network border gateway switch 112(b) can utilize this encryption key. Additionally or alternatively, the first network border gateway switch 112(a) and / or the second network border gateway switch 112(b) can receive an encryption algorithm associated with the encryption key such that the encryption algorithm can be used in conjunction with the encryption key to encrypt and decrypt network traffic.

[0059] At "12," the first border gateway switch 112(a) can utilize the encryption key to establish a secure connection tunnel 122 from the first network site 104(a) to the second network border gateway switch 112(b) in the second network site 104(b). Additionally or alternatively, the second border gateway switch 112(b) can utilize the encryption key to establish a secure connection tunnel 122 from the second network site 104(b) to the first network border gateway switch 112(a) in the first network site 104(a).

[0060] Figure 2A A diagram illustrating an entity underlay model 118 including physical connections 202 between respective border gateway switches 112(a), 112(b) of an example multi-site cloud computing network 102 is shown.

[0061] In some examples, the fabric underlay model 118 can include one or more network sites of the multi-site cloud computing network 102, e.g., site A and site B. In some examples, the fabric underlay model 118 can include one or more network switches associated with one or more sites. For example, the fabric underlay model 118 can include one or more spine network switches 108, one or more leaf network switches 110, and / or one or more border gateway switches 112. In some examples, the fabric underlay model 118 can include a fabric connection 202 connecting a first network border gateway switch 112(a) in site A and a second border gateway switch 112(b) in site B.

[0062] In some examples, the fabric underlay model 118 can be generated based on reachability data received from the first network border gateway switch 112(a) and / or the second network border gateway switch 112(b) and / or collected by the network controller 106. In some examples, the reachability data can indicate fabric links between network border gateway switches in separate sites of the multi-site cloud computing network 102. In some examples, the network border gateway switches 112 can use various network protocols, e.g., Link Layer Discovery Protocol (LLDP), Control Point Discovery (CPD) protocol, or Cisco Discovery Protocol (CDP), to generate reachability data indicating such fabric links.

[0063] Figure 2B An illustration of an example logical overlay model 120 of the example multi-site cloud computing network 102 is shown, including secure connection tunnels 122 between respective border gateway switches 112(a), 112(b), and one or more reachability indications 212 indicating reachability between one or more network devices in a first site and one or more network devices in a second site.

[0064] In some examples, the logical overlay model 120 can include one or more network sites of the cloud computing network 102, such as, for example, site A and site B. In some examples, the logical overlay model 120 can include one or more network switches associated with one or more sites. For example, the logical overlay model 120 can include one or more spine network switches 108, one or more leaf network switches 110, and / or one or more border gateway switches 112. In some examples, the logical overlay model 120 can include a secure transport tunnel 122 utilizing a physical connection 202 connecting a first network border gateway switch 112(a) in site A to a second border gateway switch 112(b) in site B. In some examples, the logical overlay model 120 can include one or more reachability indications 212. In some examples, the reachability indications 212 can indicate that a network switch disposed in site A can communicate with a network switch disposed in site B utilizing the secure transport tunnel 122.

[0065] In some examples, the logical overlay model 120 can be generated based on the physical underlay model 118. Additionally or alternatively, the logical overlay model 120 can be generated based at least in part on reachability data received from the first network border gateway switch 112(a) and / or the second network border gateway switch 112(b) and / or collected by the network controller 106.

[0066] Figure 3 A diagram illustrating the encryption key model 124 including an encryption key map 302 for establishing one or more secure connection tunnels 304(a)-(b) utilizing physical connections between respective border gateway switches 306(a)-(b) disposed in respective sites of the multi-site cloud computing network 102 is shown.

[0067] In some examples, the encryption key model 124 can include one or more sites of the multi-site cloud computing network 102, such as, for example, site A, site B, site C, and / or site D. Additionally or alternatively, the multi-site cloud computing network 102 can include any number of sites. In some examples, the one or more sites can include one or more network switches associated with the one or more sites. For example, the encryption key model 124 can include one or more spine network switches 108, one or more leaf network switches 110, and / or one or more border gateway switches 306 (or 112). In some examples, the encryption key model 124 can include one or more secure tunnels 304(a)-(d), such as, for example, tunnel 1 304(a), tunnel 2 304(b), tunnel 3 304(c), and / or tunnel 4 304(d). In some examples, the encryption key model 124 can include an encryption key map 302 including one or more records representing an association between an encryption key and an associated secure tunnel 304 between a border gateway switch 306.

[0068] For example, site A includes a border gateway A 306(a) that can be configured to transmit data to a border gateway B 306(b) disposed in site B with a secure tunnel 1 304(a). The encryption key map 302 includes a first record representing an association between the secure tunnel 1 304(a), the border gateway A 306(a) and the border gateway B 306(b) and a key ID K-l indicating that the border gateway A 306(a) and / or the border gateway B 306(b) must utilize the secure tunnel 1 304(a) with an encryption key having the key ID K-l. Additionally or alternatively, the border gateway switches 306 can utilize one or more secure tunnels 304 by utilizing a corresponding encryption key. Additionally or alternatively, the network controller 106 can be configured to generate and / or provide an encryption algorithm associated with an encryption key to an associated network border gateway switch 306.

[0069] In some examples, the encryption key map 302 can be generated by the network controller 106 based on the physical underlay model 118, the logical overlay model 120, and / or metadata received from one or more border gateway switches 306. In some examples, the metadata can indicate an Internet Protocol (IP) address and / or a network protocol associated with a network border gateway switch 306.

[0070] Additionally or alternatively, the encryption key model 124 may be generated by the network controller 106 based on the encryption key map 302, the entity underlying model 118, the logical overlay model 120, and / or metadata received from one or more border gateway switches 306.

[0071] Figure 4 and Figure 5 Flowcharts for example methods 400 and 500 are shown, and at least in part by, as Figures 1A-2B This document describes various aspects of the functions performed by the multi-site cloud computing network 102 as described herein. Figure 4 and Figure 5 The logical operations can be implemented as (1) a series of computer-implemented actions or program modules running on a computing system and / or (2) interconnected machine logic circuits or circuit modules within a computing system.

[0072] The implementation of the various components described herein depends on the choice of computing system performance and other requirements. Therefore, the logical operations described herein are referred to differently as operations, structural devices, actions, or modules. These operations, structural devices, actions, and modules can be implemented using software, firmware, special-purpose digital logic, and any combination thereof. It should also be understood that it is possible to perform operations that are more complex than... Figure 4 and Figure 5 The operations shown and described herein may be more or fewer. These operations may also be performed in parallel or in a different order than those described herein. Some or all of these operations may also be performed by components other than those specifically identified components. Although the techniques described in this disclosure are implemented with reference to specific components, in other examples, these techniques may be implemented by fewer components, more components, different components, or components of any configuration.

[0073] Figure 4 A flowchart of example method 400 is shown. In some examples, method 400 may be executed by a system comprising one or more processors and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform method 400.

[0074] At 402, a software defined network (SDN) controller 106 associated with a multi-site cloud computing network 102 can collect reachability data. In some examples, the reachability data can indicate an entity link between one or more first devices in a first site of the multi-site cloud computing network 102 and one or more second devices in a second site. In some examples, the one or more first devices and / or the one or more second devices can be configured as a spine network switch 108, a leaf network switch 110, and / or a border gateway switch 112.

[0075] At 404, the SDN controller 106 can generate a first model representing an entity underlay of the multi-site cloud computing network 102 including the first site and the second site. In some examples, the SDN controller 106 can generate the first model based at least in part on the reachability data. In some examples, the first model can be configured as Figures 1A-2B the entity underlay model 118 in any of the figures.

[0076] At 406, the SDN controller 106 can receive metadata indicating Internet Protocol (IP) addresses and network protocols associated with the one or more first devices and the one or more second devices.

[0077] At 408, the SDN controller 106 can generate a second model representing a logical overlay layer of the multi-site cloud computing network 102. In some examples, the SDN controller 106 can generate the second model based at least in part on the first model and / or the metadata. Additionally or alternatively, the second model representing the logical overlay layer can indicate reachability between the one or more first devices and the one or more second devices. In some examples, the second model can be configured as Figures 1A-2B the logical overlay layer model 120 in any of the figures.

[0078] At 410, the SDN controller 106 can receive a request from a first device of the one or more first devices to send data to a second device of the one or more second devices. In some examples, the first device and / or the second device can be configured as a leaf network switch 110. Additionally or alternatively, the first device and / or the second device can be configured as a computing resource to receive input from one or more users 126.

[0079] At 412, the SDN controller 106 can determine a routing path for sending data from the first device to the second device. In some examples, the SDN controller 106 can determine the routing path based at least in part on the second model. Additionally or alternatively, the SDN controller 106 can determine the routing path based at least in part on the first model and / or the metadata. In some examples, the routing path can include a third device in the second site and / or an entity link between the first device and the third device.

[0080] At 414, the SDN controller 106 can provide an indication of the routing path to the first device. Additionally or alternatively, the SDN controller 106 can provide an indication of the routing path to one or more first devices, one or more second devices, and / or the second device described above.

[0081] Additionally or alternatively, the method 400 can include storing, in an encryption key data store associated with the SDN controller 106, an association between the encryption key and the entity link between the first device and the third device. The method 400 can further include generating, by the SDN controller 106, a third model representing associations between encryption keys and entity links of the multi-site network 102 based at least in part on the encryption key data store. Additionally or alternatively, the third model can be configured as the encryption key model 124 in any of the figures. Figure 1A 、 Figure 1B and / or Figure 3 .

[0082] Figure 5 A flowchart illustrating an example method 500 is shown. In some examples, the method 500 can be performed by a system comprising one or more processors and one or more non-transitory computer-readable media having stored computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method 500.

[0083] At 502, a first device 112(a) in a first site 104(a) of a multi-site cloud computing network 102 can send reachability data indicative of an entity link to a second network border gateway switch 112(b) disposed in a second site 104(b) of the multi-site cloud computing network 102 to a software defined network (SDN) controller 106 associated with the multi-site cloud computing network 102. Additionally or alternatively, the second device 112(b) can send the reachability data indicative of the entity link to the first device 112(a). In some examples, the first device 112(a) and / or the second device 112(b) can discover the entity link and / or generate the reachability data indicative of such entity link using various network protocols, such as, for example, a link layer discovery protocol (LLDP), a control point discovery (CPD) protocol, or a Cisco Discovery Protocol (CDP).

[0084] At 504, the first device 112(a) can send metadata to the SDN controller 106. Additionally or alternatively, the second device 112(b) can send the metadata to the SDN controller 106. In some examples, the metadata can be indicative of an internet protocol (IP) address and / or a network protocol associated with the first device 112(b) and / or the second device 112(b).

[0085] At 506, the first device 112(a) can receive routing data from the SDN controller 106. Additionally or alternatively, the second device 112(b) can receive the routing data from the SDN controller 106. In some examples, the routing data can be indicative of a data transmission route between the first device 112(a) and the second device 112(b).

[0086] At 508, the first device 112(a) can receive an encryption key from the SDN controller 106. Additionally or alternatively, the second device 112(b) can receive the encryption key from the SDN controller 106. In some examples, the encryption key can be configured to establish a secure connection tunnel 122 between the first device 112(a) and the second device 112(b).

[0087] At 510, the first device 112(a) can establish the secure connection tunnel 122 between the first device 112(a) in the first site 104(a) and the second device 112(b) in the second site 104(b) using the encryption key. Additionally or alternatively, the second device 112(b) can establish the secure connection tunnel 122 between the second device 112(b) in the second site 104(b) and the first device 112(a) in the first site 104(a) using the encryption key.

[0088] Figure 6is a computing system diagram illustrating a configuration of a data center 600 that can be used to implement various aspects of the technology disclosed herein. Figure 6 The example data center 600 illustrated in FIG. 6 includes a number of server computers 602A-602E (which can be referred to herein as "server computers 602") that are used to provide computing resources. In some examples, the server computers 602 can include or correspond to the servers 114 described herein.

[0089] The server computers 602 can be standard tower, rack-mounted, or blade server computers that are appropriately configured to provide the computing resources described herein. As described above, the computing resources provided by the cloud computing network 102 can be data processing resources, e.g., VM instances or hardware computing systems, database clusters, computing clusters, storage clusters, data storage resources, database resources, network resources, etc. Some of the servers 602 can also be configured to execute a resource manager that is capable of instantiating and / or managing the computing resources. For example, in the case of VM instances, the resource manager can be a hypervisor or another type of program that is configured to be capable of executing multiple VM instances on a single server computer 602. The server computers 602 in the data center 600 can also be configured to provide network services and other types of services.

[0090] In Figure 6 In the example data center 600 illustrated, the server computers 602A-602E are also interconnected with an appropriate LAN 608. It should be understood that the configurations and network topologies described herein have been greatly simplified, and that more computing systems, software components, networks, and networking devices can be utilized to interconnect the various computing systems disclosed herein and provide the functionality described above. Appropriate load balancing devices or other types of network infrastructure components can also be utilized to balance the load among the data centers 600, among the various server computers 602A-602E in each data center 600, and possibly among the computing resources in each server computer 602. It should be understood that reference to a single data center 600 is intended to refer to a single data center 600 or to a plurality of data centers 600 that are interconnected and operate in a similar manner. Figure 6 The configuration of the data center 600 described is merely illustrative, and other implementations can be utilized.

[0091] In some examples, the server computers 602 can each execute one or more resources 116 that support a service or application that is disposed in the set or cluster of servers 602, e.g., a multicast data source 118 and / or a multicast data sink 120, by way of example. The resources 116 on each server computer 602 can support a single application or service, or multiple applications or services (for one or more users).

[0092] In some cases, the cloud computing network 102 can provide computing resources, such as application containers, VM instances, and storage, on a permanent or on-demand basis. Among other types of functionality, the computing resources provided by the cloud computing network 102 can be used to implement the various services described above. The computing resources provided by the cloud computing network 102 can include various types of computing resources, such as data processing resources (e.g., application containers and VM instances), data storage resources, networking resources, data communication resources, network services, and the like.

[0093] The various types of computing resources provided by the cloud computing network 102 can be general purpose, or can also be used for a variety of specific configurations. For example, data processing resources can be used as entity computers or VM instances in a variety of different configurations. The VM instances can be configured to execute applications, including web servers, application servers, media servers, database servers, some or all of the network services described above, and / or other types of programs. Data storage resources can include file storage devices, block storage devices, and the like. The cloud computing network 102 can also be configured to provide other types of computing resources not specifically mentioned herein.

[0094] In one embodiment, the computing resources provided by the cloud computing network 102 can be implemented by one or more data centers 600 (which can be referred to herein as “data centers 600”). A data center 600 is a facility used to house and operate computer systems and associated components. Data centers 600 typically include redundant and backup power supplies, communication, cooling, and security systems. Data centers 600 can also be located in different geographic locations. An illustrative embodiment of a data center 600 that can be used to implement the technology disclosed herein is described below in connection with Figure 6 An illustrative embodiment of a data center 600 that can be used to implement the technology disclosed herein is described below in connection with

[0095] Figure 6 An example computer architecture for a computing device (or network switch) 114 capable of executing the program components for implementing the functionality described above is shown. Figure 5 The computer architecture shown illustrates a conventional server computer, workstation, desktop computer, laptop computer, tablet computer, network appliance, e-reader, smart phone, or other computing device, and can be used to execute any of the software components presented herein. In some examples, the computing device 114 can correspond to the entity servers 114 described herein.

[0096] The computing device 114 includes a motherboard 114, or "mainboard," which is a printed circuit board to which a multitude of components or devices can be connected, by way of a system bus or other electrical communication paths. In one illustrative configuration, one or more central processing units ("CPUs") 604 operate with a chipset 606. The CPUs 604 can be standard programmable processors that execute arithmetic and logical operations required for the operation of the computing device 114.

[0097] The CPUs 604 perform operations by manipulating and altering the states of switches that represent discrete entities, from one discrete state to the next. The switches typically include electronic circuits that hold one of two binary states, for example, a flip-flop, and electronic circuits that provide output states based on logical combinations of the states of other switches, for example, logic gates. These basic switching elements can be combined to create more complex logic circuits, including registers, adders, arithmetic logic units, floating point units, and the like.

[0098] The chipset 606 provides an interface between the CPUs 604 and the rest of the components and devices on the motherboard 114. The chipset 606 can provide an interface to the RAM 608, which is used as the main memory in the computing device 114. The chipset 606 can further provide an interface to a computer-readable storage medium, such as a read-only memory ("ROM") 610 or a non-volatile RAM ("NVRAM"), for storing basic routines that help to start the computing device 114 and transfer information between the various components and devices. The ROM 610 or NVRAM can also store other software components required for the operation of the computing device 114 according to the configurations described herein.

[0099] The computer 114 can operate in a networked environment using logical connections to remote computing devices and computer systems through a network, such as the network 624. The chipset 606 can include functionality for providing network connectivity through a NIC 612, such as a gigabit Ethernet adapter. The NIC 612 is capable of connecting the computing device 114 to other computing devices through the network 624 (or 128). It should be appreciated that multiple NICs 612 can be present in the computing device 114, connecting the computer to other types of networks and remote computer systems.

[0100] The computing device 114 can connect to a storage device 618 that provides non-volatile storage for the computer. The storage device 618 can store an operating system 620, programs 622, and data, which have been described in greater detail herein. The storage device 618 can connect to the computing device 114 through a storage controller 614 connected to the chipset 606. The storage device 618 can be made up of one or more physical storage units. The storage controller 614 can interact with the physical storage units through a serial attached SCSI ("SAS") interface, a serial advanced technology attachment ("SATA") interface, a fiber channel interface, or other type of interface for physically connecting and transferring data between the computer and the physical storage units.

[0101] The computing device 114 can store data on the storage device 618 by transforming the physical state of the physical storage units to reflect the information being stored. The specific transformation of physical state can depend on various factors, in different embodiments of this description. Examples of such factors can include, but are not limited to, the technology used to implement the physical storage units, whether the storage device 618 is characterized as primary or secondary storage, or the like.

[0102] For example, the computing device 114 can store information to the storage device 618 by issuing instructions through the storage controller 614 to alter the magnetic characteristics of a particular location within a disk drive unit, to alter the reflective or refractive characteristics of a particular location within an optical storage unit, or to

[0103] In addition to the mass storage device 618 described above, the computing device 114 can have access to other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. It should be appreciated by those skilled in the art that a computer-readable storage medium is any available medium that provides for the non-transitory storage of data and that is accessible by the computing device 114. In some examples, operations performed by the cloud computing network 102 and or any components included therein can be supported by one or more devices similar to the computing device 114. In other words, some or all of the operations performed by the cloud computing network 102 and or any components included therein can be performed by one or more computer devices 114 operating in a cloud-based arrangement.

[0104] By way of example, and not limitation, computer-readable storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Computer-readable storage media include, but are not limited to, RAM, ROM, Erasable Programmable ROM ("EPROM"), Electrically Erasable Programmable ROM ("EEPROM"), flash memory or other solid state memory technology, compact disc ROM ("CD-ROM"), digital versatile disc ("DVD"), high definition DVD ("HD-DVD"), BLU-RAY, or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information in a non-transitory fashion.

[0105] As briefly mentioned above, the storage device 618 can store an operating system 620 used to control the operation of the computing device 114. According to one embodiment, the operating system comprises a LINUX operating system. According to another embodiment, the operating system comprises a WINDOWS® SERVER operating system from MICROSOFT CORPORATION of Redmond, Washington. According to a further embodiment, the operating system can comprise a UNIX operating system or one of its variants. It should be appreciated that other operating systems can also be utilized. The storage device 618 can store other systems or applications and data utilized by the computing device 114.

[0106] In one embodiment, the storage device 618 or other computer readable storage medium is encoded with computer-executable instructions, which, when loaded into the computing device 114, transform the computer from a general-purpose computing system into a special-purpose computing system configured to implement any of the embodiments described herein. As noted above, these computer-executable instructions, when executed by the CPU 604, cause the computing device 114 to transform its internal state from a first state to a second state. According to one embodiment, the computing device 114 can access a computer-readable storage medium that stores computer-executable instructions that, when executed by the computing device 114, perform the various processes described above with respect to FIGS. 1 through 6. Figure 6 The computing device 114 can also include computer-readable storage media having stored thereon computer-executable instructions that, when executed by the computing device 114, perform any of the other computer-implemented operations described herein.

[0107] The computing device 114 can also include one or more input / output controllers 616 for receiving and processing input from a number of input devices, such as a keyboard, mouse, touchpad, touchscreen, electronic stylus, or other type of input device. Similarly, the input / output controller 616 can provide output to a display, such as a computer monitor, flat-panel display, digital projector, printer, or other type of output device. It is understood that the computing device 114 can not include Figure 6 ​All of the components shown can include Figure 6 other components not explicitly shown or can utilize entirely different architectures. The embodiments described and pictured herein illustrate only some of the ways consistent with the present principles and are not meant to be limiting. ​

[0108] The border gateway switch 112 can send and receive various data and provide it to the components. For example, the border gateway switch 112 can send an indication of a physical link to another border gateway switch 112 in a separate site in the network to the network controller 106. The network border gateway switch 112 can receive a routing path and / or encryption key for establishing a secure connection tunnel with the other border gateway switch 112 and can use the routing path to route data between separate sites of the multi-site cloud computing network.

[0109] In light of the foregoing, the following techniques are described: utilizing a software defined network (SDN) controller and / or data center network manager (DCNM) associated with a multi-site cloud computing network and network border gateway switches to provide reachability data indicating physical links disposed between border gateways in different sites of the multi-site network, to establish secure connection tunnels utilizing the physical links and unique encryption keys. The SDN controller and / or DCNM can be configured to generate a physical underlay model representing physical underlay or network transport capabilities, and / or a logical overlay model representing a logical overlay or overlay control plane of the multi-site network. The SDN controller can also generate an encryption key model representing associations between encryption keys and associated network border gateway switches and physical links therebetween. The SDN controller can utilize these models to determine routing paths for sending network traffic at line speed between different sites of the multi-site network.

[0110] While the application has been described with respect to specific examples including presently preferred modes of carrying out the application, those skilled in the art will recognize that the application is not limited to the specific details described and that other modifications and variations are possible in light of the above teachings. It is therefore intended to cover within the scope of the application all such and similar modifications as can come within the spirit and scope of this application.

[0111] While the present application describes embodiments with specific structural features and / or method acts, it is to be understood that the claims are not necessarily limited to the specific features or acts described. Rather, the specific features and acts are disclosed as exemplary forms of implementing the claims.​

Claims

1. A system for configuring secure connectivity between devices, comprising: One or more processors; as well as One or more non-transitory computer-readable media including instructions, which, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: The Software-Defined Networking (SDN) controller collects reachability data, which indicates physical links between one or more first devices in a first site and one or more second devices in a second site. The SDN controller generates a first model based at least in part on the reachability data, the first model representing the underlying entity of a multi-site network including the first site and the second site; The SDN controller receives metadata indicating the Internet Protocol (IP) address and network protocol associated with the one or more first devices and the one or more second devices. The SDN controller generates a second model representing a logical overlay of the multi-site network, based at least in part on the first model and the metadata, the logical overlay indicating the reachability between the one or more first devices and the one or more second devices; At the SDN controller, a request is received from a first device among the one or more first devices to send data to a second device among the one or more second devices; The SDN controller determines, at least in part, a routing path for sending data from the first device to the second device, based on the second model; and The SDN controller provides the routing path indication to the first device.

2. The system of claim 1, wherein, The physical link between the one or more first devices in the first site and the one or more second devices in the second site is determined using at least one of the Link Layer Discovery Protocol (LLDP), Control Point Discovery Protocol (CPD), or Cisco Discovery Protocol (CDP).

3. The system of claim 1 or 2, wherein, The routing path includes the third device in the second site, and the physical link between the first device and the third device. The operation further includes: The SDN controller generates an encryption key, which is configured to establish a secure connection tunnel between the first device and the third device. The encryption key is sent from the SDN controller to the first device and the third device; and The SDN controller enables the first device and the second device to use the encryption key to establish a secure connection tunnel between the first device in the first site and the third device in the second site.

4. The system according to claim 3, wherein the operation further includes: The association between the encryption key and the physical link between the first device and the third device is stored in an encryption key data repository associated with the SDN controller, the encryption key data repository including the association between the encryption key and the physical link of the multi-site network; as well as The SDN controller generates a third model, at least in part, based on the encryption key data repository, representing the association between encryption keys and physical links in the multi-site network.

5. The system according to claim 3, wherein: The IP address includes a first IP address associated with the first device and a second IP address associated with the third device; and The Internet protocol includes a first Internet protocol associated with the first device and a second Internet protocol associated with the third device; The operation further includes generating the encryption key based at least in part on the first IP address, the second IP address, the first Internet Protocol, and the second Internet Protocol.

6. The system according to claim 3, wherein, The encryption key is configured to be at least one of the following: A common encryption key, configured to establish secure connection tunnels in the multi-site network; or A unique encryption key, configured to establish a secure connection tunnel between the first device in the first site and the third device in the second site.

7. The system according to claim 1 or 2, wherein: The reachability data also indicates other entity links between the one or more first devices in the first site and the one or more third devices in the third site; The metadata also indicates other IP addresses and other network protocols associated with the one or more third devices; The operation also includes: The first model, representing the underlying entity of a multi-site network including the first site, the second site, and the third site, is generated by the SDN controller at least in part based on the reachability data; and The SDN controller generates a second model representing a logical overlay of the multi-site network, based at least in part on the first model and the metadata, the logical overlay indicating the reachability between the one or more first devices and the one or more second devices and the one or more third devices.

8. The system according to claim 1 or 2, wherein the operation further comprises: The SDN controller enables the first device to establish a routing path for sending data from the first device to the second device.

9. A system for configuring secure connectivity between devices, comprising: One or more processors; as well as One or more non-transitory computer-readable media including instructions, which, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: A first device in a first site of a multi-site network sends reachability data to a software-defined networking (SDN) controller, the reachability data indicating a physical link between the first device and a second device in a second site of the multi-site network; The first device sends metadata indicating the Internet Protocol IP address and network protocol associated with the first device to the SDN controller; At the first device, routing data indicating the data transmission route between the first device and the second device is received from the SDN controller; At the first device, an encryption key is received from the SDN controller, the encryption key being configured to establish a secure connection tunnel between the first device and the second device; and The first device uses the encryption key to establish a secure connection tunnel between the first device in the first site and the second device in the second site.

10. The system according to claim 9, wherein the operation further comprises: The first device uses at least one of the Link Layer Discovery Protocol (LLDP), Control Point Discovery Protocol (CPD), or Cisco Discovery Protocol (CDP) to determine the physical link between the first device and the second device. as well as The physical link between the first device and the second device is determined at least in part based on the first device, and reachability data indicating the physical link is generated.

11. The system according to claim 9 or 10, wherein, The encryption key is configured to be at least one of the following: A common encryption key, configured to establish secure connection tunnels in the multi-site network; or A unique encryption key, configured to establish a secure connection tunnel between the first device at the first site and the third device at the second site.

12. The system according to claim 9 or 10, wherein, The first device is a border device type and is configured to establish a secure connection tunnel with one or more other devices of the border device type located at other sites in the multi-site network.

13. The system according to claim 9 or 10, wherein, The encryption key is based at least in part on metadata associated with the first device and additional metadata associated with the second device.

14. A computer-implemented method, comprising: The Software-Defined Networking (SDN) controller collects reachability data, which indicates physical links between one or more first devices in a first site and one or more second devices in a second site. The SDN controller generates a first model representing the entity layer of a multi-site network including the first site and the second site, based at least in part on the reachability data; The SDN controller receives metadata indicating the Internet Protocol (IP) address and network protocol associated with the one or more first devices and the one or more second devices. The SDN controller generates a second model representing a logical overlay of the multi-site network, based at least in part on the first model and the metadata, the logical overlay indicating the reachability between the one or more first devices and the one or more second devices; At the SDN controller, a request is received from a first device among the one or more first devices to send data to a second device among the one or more second devices; The SDN controller determines, at least in part, a routing path for sending data from the first device to the second device based on the second model; as well as The SDN controller provides the routing path indication to the first device.

15. The computer-implemented method according to claim 14, wherein, The physical link between the one or more first devices in the first site and the one or more second devices in the second site is determined using at least one of the Link Layer Discovery Protocol (LLDP), Control Point Discovery Protocol (CPD), or Cisco Discovery Protocol (CDP).

16. The computer-implemented method according to claim 14, wherein, The routing path includes a third device in the second site, and a physical link between the first device and the third device. The computer-implemented method further includes: The SDN controller generates an encryption key, which is configured to establish a secure connection tunnel between the first device and the third device. The encryption key is sent from the SDN controller to the first device and the third device; and The SDN controller enables the first device and the second device to use the encryption key to establish a secure connection tunnel between the first device in the first site and the third device in the second site.

17. The computer-implemented method according to claim 16, further comprising: The association between the encryption key and the physical link between the first device and the third device is stored in an encryption key data repository associated with the SDN controller, the encryption key data repository including the association between the encryption key and the physical link of the multi-site network; as well as The SDN controller generates a third model, at least in part, based on the encryption key data repository, representing the association between encryption keys and physical links in the multi-site network.

18. The computer-implemented method according to claim 16 or 17, wherein: The IP address includes a first IP address associated with the first device and a second IP address associated with the third device; and The Internet protocol includes a first Internet protocol associated with the first device and a second Internet protocol associated with the third device; The computer-implemented method further includes generating the encryption key based at least in part on the first IP address, the second IP address, the first Internet Protocol, and the second Internet Protocol.

19. The computer-implemented method according to claim 16 or 17, wherein, The encryption key is configured to be at least one of the following: A universal encryption key, configured to establish secure connection tunnels in the multi-site network; or A unique encryption key, configured to establish a secure connection tunnel between the first device in the first site and the third device in the second site.

20. The computer-implemented method according to any one of claims 14 to 17, further comprising: The SDN controller enables the first device to establish a routing path for sending data from the first device to the second device.

21. A software-defined networking (SDN) controller, comprising: Components for collecting reachability data, which indicates physical links between one or more first devices in a first site and one or more second devices in a second site; A component for generating, at least in part, a first model representing the underlying entity of a multi-site network including the first site and the second site, based on the reachability data; A component for receiving metadata, the metadata indicating Internet Protocol (IP) addresses and network protocols associated with the one or more first devices and the one or more second devices; Components for generating a second model representing a logical overlay of the multi-site network based at least in part on the first model and the metadata, the logical overlay indicating reachability between the one or more first devices and the one or more second devices; A component for receiving a request from a first device in the one or more first devices to send data to a second device in the one or more second devices; A component for determining, at least in part, a routing path for sending data from the first device to the second device based on the second model; as well as A component for providing an indication of the routing path to the first device.

22. A first device for configuring secure connectivity between devices, comprising: A component for sending reachability data from a first device in a first site of a multi-site network to a software-defined networking (SDN) controller, the reachability data indicating a physical link between the first device and a second device in a second site of the multi-site network; A component for sending metadata indicating the Internet Protocol IP address and network protocol associated with the first device from the first device to the SDN controller; A component for receiving, at the first device, routing data from the SDN controller indicating a data transmission route between the first device and the second device; A component for receiving an encryption key from the SDN controller at the first device, the encryption key being configured to establish a secure connection tunnel between the first device and the second device; as well as A component for establishing a secure connection tunnel between the first device in the first site and the second device in the second site using the encryption key.

23. A method for configuring secure connectivity between devices, comprising the following steps: A first device in a first site of a multi-site network sends reachability data to a software-defined networking (SDN) controller, the reachability data indicating a physical link between the first device and a second device in a second site of the multi-site network; The first device sends metadata indicating the Internet Protocol IP address and network protocol associated with the first device to the SDN controller; At the first device, routing data indicating the data transmission route between the first device and the second device is received from the SDN controller; At the first device, an encryption key is received from the SDN controller, the encryption key being configured to establish a secure connection tunnel between the first device and the second device; as well as The first device uses the encryption key to establish a secure connection tunnel between the first device in the first site and the second device in the second site.

24. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 14 to 20 or claim 23.

25. A computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 14 to 20 or claim 23.

Citation Information

Patent Citations

  • SDN Based Interdomain and Intradomain Traffic Engineering

    US20160218917A1

  • Single point of management for multi-cloud environment including route propagation, security, and application deployment

    US20200059370A1