Horizontal Scaling of Software-Defined Wide Area Network (SD-WAN)

By establishing a peer-level session between the network controller and the orchestrator, the hardware complexity and routing leakage problems in cross-region network management are solved, and horizontal scaling and centralized control of the network are achieved.

CN116097630BActive Publication Date: 2025-08-01CISCO TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202280006032.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-07-29
Filing Date
2022-04-07
Publication Date
2025-08-01
Estimated Expiration
2042-04-07

AI Technical Summary

Technical Problem

The prior art has configuration complexity and security issues caused by increased hardware complexity and mix of IP addressing, especially the risk of routing leakage in network management across different geographical regions and domains.

Method used

By establishing a simultaneous session between the network controller and the orchestrator, using simultaneous data messages for address transmission, preventing the routing leakage of IPv4 or IPv6 addresses, and achieving cross-region network connection and management.

Benefits of technology

It realizes horizontal network scaling across different domains and geographical areas, centrally manages network control planes, and prevents routing leakage, improving network security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116097630B_ABST
    Figure CN116097630B_ABST
Patent Text Reader

Abstract

Systems, apparatuses, methods, and computer-readable media for managing a network are disclosed. According to at least one example, a method for connecting to a network controller across different regions is provided. The method includes identifying a first connection with a network orchestrator during establishment of a second connection with the network orchestrator from a network controller; establishing a peer session at a control plane that links the second connection and the first connection; inserting a peer data message identifying the peer session into a control message being sent; receiving, via the second connection, a message from the network orchestrator, the message including an address of the network controller associated with the second connection; and transmitting, via the first connection, a second address of the network controller to the network orchestrator.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims the benefit of priority of U.S. Non - Provisional Patent Application No. 17 / 389,008, filed on Jul. 29, 2021, entitled "HORIZONTAL SCALING FOR A SOFTWARE DEFINED WIDE AREA NETWORK (SD - WAN)", which claims the benefit of priority of U.S. Provisional Patent Application No. 63 / 172,491, filed on Apr. 8, 2021, entitled "BUDDY SESSION BASED NAT v6 DISCOVERY", the content of which is incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure generally relates to computer networks, and more particularly, to horizontal scaling of software - defined wide area networks (SD - WANs). Background Art

[0004] A software - defined wide area network (SD - WAN) represents the application of software - defined networking (SDN) principles to WAN connections, e.g., connections to cellular networks, the Internet, and multi - protocol label switching (MPLS) networks. The ability of an SD - WAN is to transparently provide a consistent service - level agreement (SLA) for critical application traffic over various underlying tunnels with different transmission qualities and to allow seamless tunnel selection based on tunnel performance characteristics that can match the application SLA. Brief Description of the Drawings

[0005] Figure 1 Shows an example of a high - level network architecture according to an embodiment;

[0006] Figure 2 Shows an example of a network topology according to an embodiment;

[0007] Figure 3 Shows an example of a diagram illustrating the operation of a protocol for managing an upper - layer network according to an embodiment;

[0008] Figure 4 Shows an example of a diagram illustrating the operation of a virtual private network for partitioning a network according to an embodiment;

[0009] Figure 5 Shows a network configuration for implementing a control plane over different domains according to an embodiment;

[0010] Figure 6 Shows an example sequence diagram for preventing IPv4 or IPv6 routing leaks according to an embodiment;

[0011] Figure 7 is a flowchart of a method for a network controller device according to an embodiment;

[0012] Figure 8 is a flowchart of a method for a network orchestrator device according to an embodiment;

[0013] Figure 9 is a flowchart of a method for a network edge device according to an embodiment;

[0014] Figures 10A to 10F shows various block diagrams showing network communications according to an embodiment; and

[0015] Figure 11 shows an example of a computing system 1100, which can be any computing device that can implement system components according to examples of the present disclosure. DETAILED DESCRIPTION

[0016] The detailed description set forth below is intended to describe various configurations of embodiments and is not intended to represent the only configurations in which the subject matter of the present disclosure can be practiced. The accompanying drawings are incorporated herein and constitute a part of the detailed description. To provide a more thorough understanding of the subject matter of the present disclosure, the detailed description includes specific details. However, it will be clear and apparent that the subject matter of the present disclosure is not limited to the specific details set forth herein and can be practiced without these details. In some instances, structures and components are shown in block diagram form to avoid obscuring the concepts of the subject matter of the present disclosure.

[0017] Overview

[0018] Aspects of the invention are set forth in the independent claims, and the preferred features are set forth in the dependent claims. The features of one aspect can be applied to each aspect individually or in combination with other aspects.

[0019] Methods for horizontally scaling network configurations are described in detail below. Entities can exist across different geographical regions, countries, and even continents. In some cases, commercial entities may wish to centralize aspects of the control plane of their networks. Accordingly, methods, systems, and techniques for horizontally scaling software-defined wide area networks (SD-WANs) are described below. In some examples, IP addresses of a network controller device from a central location are provided via a single network connection to network edge devices in different regions.

[0020] Systems, methods, and computer-readable media for scaling a network across different regions or domains are provided. According to at least one example, a method for scaling a network is provided. The method includes: identifying a first connection with a network orchestrator during establishment of a second connection from a network controller to the network orchestrator; establishing a sibling session at a control plane that links the second connection and the first connection; inserting a sibling data message identifying the sibling session into a control message being sent; receiving, via the second connection, a message from the network orchestrator that includes an address of a network controller associated with the second connection; and transmitting, via the first connection, a second address of the network controller to the network orchestrator. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is configured to transmit the first address and the second address during setup of a network edge device.

[0021] In another example, an apparatus for scaling a network across different regions or domains is provided. The apparatus includes a memory (e.g., configured to store data such as virtual content data, one or more images, etc.) and one or more processors (e.g., implemented in circuitry) coupled to the memory. The one or more processors are configured to and capable of: identifying a first connection with a network orchestrator during establishment of a second connection from a network controller to the network orchestrator; establishing a sibling session at a control plane that links the second connection and the first connection; inserting a sibling data message identifying the sibling session into a control message being sent; receiving, via the second connection, a message from the network orchestrator that includes an address of a network controller associated with the second connection; and transmitting, via the first connection, a second address of the network controller to the network orchestrator. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is configured to transmit the first address and the second address during setup of a network edge device.

[0022] In another example, a non-transitory computer-readable medium is provided, having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform the following operations: identify a first connection with a network orchestrator during establishment of a second connection with the network orchestrator from a network controller; establish a peer session at a control plane that links the second connection and the first connection; insert a peer data message identifying the peer session into a control message being sent; receive, via the second connection, a message from the network orchestrator that includes an address of the network controller associated with the second connection; and transmit, via the first connection, a second address of the network controller to the network orchestrator. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is configured to transmit the first address and the second address during setup of a network edge device.

[0023] In some examples, the peer session is identified based on identifying a universally unique identifier (UUID) of the network orchestrator.

[0024] In some examples, the network orchestrator receives the peer data message and associates the first connection and the second connection as a single logical connection.

[0025] In some examples, the identification of the first connection occurs during a process challenge phase of Datagram Transport Layer Security (DTLS) session initialization.

[0026] In some examples, the network orchestrator uses the first connection to notify the network edge device of the second address of the network controller.

[0027] In some examples, notifying the network edge device of the second address of the network controller via the first connection prevents leakage of routes associated with network address translation.

[0028] In some examples, the network controller is located in a first region and the network orchestrator is located in a second region different from the first region.

[0029] In some examples, a network address translator converts an IP address associated with the second region into an IP address associated with the first region.

[0030] In some examples, the network controller is connected to a second network orchestrator in a different region.

[0031] In some examples, the first connection is an IPv4 connection and the second connection is an IPv6 connection, or the first connection is an IPv6 connection and the second connection is an IPv4 connection.

[0032] Systems, apparatuses, methods, and computer-readable media for managing a network are disclosed. According to at least one example, a method for connecting to a network controller across different regions is provided. The method includes: receiving a message that includes a peer data message indicating that a first connection is related to a second connection, the message being received when the first connection and the second connection are established with the network controller; transmitting the message to the network controller via the second connection, the message including a second address of the network controller associated with the second connection; receiving, via the first connection, an address of the network controller associated with the second connection from the network controller; linking the first connection and the second connection as a single logical connection; and in response to receiving a request to connect a network edge device, transmitting the message to the network edge device via the first connection, the message identifying the second address and a first address of the network controller associated with the first connection.

[0033] In another example, an apparatus for connecting to a network controller across different regions is provided. The apparatus includes a memory (e.g., configured to store data such as virtual content data, one or more images, etc.) and one or more processors (e.g., implemented in a circuit) coupled to the memory. The one or more processors are configured to and capable of: receiving a message that includes a peer data message indicating that a first connection is related to a second connection, the message being received when the first connection and the second connection are established with the network controller; transmitting the message to the network controller via the second connection, the message including a second address of the network controller associated with the second connection; receiving, via the first connection, an address of the network controller associated with the second connection from the network controller; linking the first connection and the second connection as a single logical connection; and in response to receiving a request to connect a network edge device, transmitting the message to the network edge device via the first connection, the message identifying the second address and a first address of the network controller associated with the first connection.

[0034] In another example, a non-transitory computer-readable medium is provided, having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform the following operations: receiving a message that includes a peer data message indicating that a first connection is related to a second connection, the message being received when the first connection and the second connection are established with the network controller; transmitting the message to the network controller via the second connection, the message including a second address of the network controller associated with the second connection; receiving, via the first connection, an address of the network controller associated with the second connection from the network controller; linking the first connection and the second connection as a single logical connection; and in response to receiving a request to connect a network edge device, transmitting the message to the network edge device via the first connection, the message identifying the second address and a first address of the network controller associated with the first connection.

[0035] In some examples, one or more of the above methods, apparatuses, and computer-readable media further include analyzing each connection of each network controller associated with a first type of address managed by a network orchestrator, and analyzing each connection of each network controller associated with a second type of address that is not linked to a connection associated with the first type of address.

[0036] Systems, apparatuses, methods, and computer-readable media for managing a network are disclosed. According to at least one example, a method for controlling network edge devices in different regions is provided. The method includes: a transceiver; a processor configured to execute instructions and cause the processor to perform the following operations: identifying a first connection with a network orchestrator during establishing a second connection with the network orchestrator from a network controller; establishing a peer session at a control plane that links the second connection and the first connection; inserting a peer data message identifying the peer session into a control message; receiving, via the second connection, a message from the network orchestrator, the message including an address of the network controller associated with the second connection; transmitting, via the first connection, a second address of the network controller to the network orchestrator. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is further configured to transmit the first address and the second address during provisioning the network edge device.

[0037] In another example, an apparatus for controlling network edge devices in different regions is provided, the apparatus including a memory (e.g., configured to store data such as virtual content data, one or more images, etc.) and one or more processors (e.g., implemented in circuitry) coupled to the memory. The one or more processors are configured to and capable of: a transceiver; a processor configured to execute instructions and cause the processor to perform the following operations: identifying a first connection with a network orchestrator during establishing a second connection with the network orchestrator from a network controller; establishing a peer session at a control plane that links the second connection and the first connection; inserting a peer data message identifying the peer session into a control message; receiving, via the second connection, a message from the network orchestrator, the message including an address of the network controller associated with the second connection; transmitting, via the first connection, a second address of the network controller to the network orchestrator. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is further configured to transmit the first address and the second address during provisioning the network edge device.

[0038] In another example, a non-transitory computer-readable medium is provided, having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform the following operations: a transceiver; a processor configured to execute the instructions and cause the processor to perform the following operations: identify a first connection with a network orchestrator during establishment of a second connection with the network orchestrator from a network controller; establish a peer session at a control plane that links the second connection and the first connection, insert a peer data message identifying the peer session into a control message, receive a message from the network orchestrator via the second connection, the message including an address of the network controller associated with the second connection, and transmit a second address of the network controller to the network orchestrator via the first connection. The network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection. The network orchestrator is further configured to transmit the first address and the second address during setup of a network edge device.

[0039] In some examples, the peer session is identified based on identifying a UUID of the network orchestrator.

[0040] In some examples, the network orchestrator receives the peer data message and associates the first connection and the second connection as a single logical connection.

[0041] In some examples, the identification of the first connection occurs during a process challenge phase of DTLS session initialization.

[0042] In some examples, the network orchestrator uses the first connection to notify the network edge device of the second address of the network controller.

[0043] In some examples, notifying the network edge device of the second address of the network controller via the first connection prevents leakage of routes associated with network address translation.

[0044] In some examples, the network controller is located in a first region and the network orchestrator is located in a second region different from the first region.

[0045] In some examples, a network address converter converts an IP address associated with the second region into an IP address associated with the first region.

[0046] Exemplary Embodiments

[0047] As described above, a business entity may wish to horizontally scale a network across different geographical regions while centrally managing the network. In some cases, the network may be associated with different domains (e.g., different network providers), and each domain will have different Internet Protocol (IP) addresses. Existing management solutions for different domains exist and require additional devices to be present in each domain to implement control plane functionality. This forces business entities to increase the hardware and complexity of their network management. Additionally, the entity has a combination of equipment that supports both IPv4 and IPv6, and the hybrid of IP addressing adds additional configuration complexity as well as security issues (e.g., routing leaks). Network providers may require customers not to leak any routes to prevent various malicious network attacks (e.g., man-in-the-middle, etc.).

[0048] A method for horizontally scaling a network across different domains is disclosed in detail below. Referring to Figure 6 the network controller device is configured to provide IPv4 addresses and IPv6 addresses (e.g., IPv4 connections or IPv6 connections) to the network manager device at each domain or region, thereby allowing the network manager device, or being configured to provide IPv4 or IPv6 to network edge devices managed by a single network connection. Thus, the network edge devices are able to select and connect to the network controller device using appropriate interfaces from different domains or regions. A business entity can thus horizontally scale network locations across different domains and different geographical regions while providing a centralized control plane for managing network devices.

[0049] Figure 1 An example of a network architecture 100 for implementing aspects of the present technology is shown. An example implementation of the network architecture 100 is an SD-WAN architecture. However, those of ordinary skill in the art will understand that for the network architecture 100 and any other systems discussed in this disclosure, additional or fewer components may exist in similar or alternative configurations. For the sake of brevity and clarity, this disclosure provides illustrations and examples. Other embodiments may include different numbers and / or types of elements, but those of ordinary skill in the art will recognize that such variations do not depart from the scope of this disclosure.

[0050] In this example, the network architecture 100 may include an orchestration plane 102, a management plane 120, a control plane 130, and a data plane 140. The orchestration plane 102 may assist in the automatic enrollment of edge network devices 142 (e.g., switches, routers, etc.) in the upper-layer network. The orchestration plane 102 may include one or more physical or virtual network orchestrator devices 104. The (one or more) network orchestrator devices 104 may perform the initial authentication of the edge network devices 142 and the orchestration connections between the devices of the control plane 130 and the data plane 140. In some embodiments, the (one or more) network orchestrator devices 104 may also enable communication of devices located behind a network address translation (NAT). In some embodiments, the physical or virtual SD-WAN vBond devices may operate as the (one or more) network orchestrator devices 104.

[0051] The management plane 120 may be responsible for the central configuration and monitoring of the network. The management plane 120 may include one or more physical or virtual network management devices 122. In some embodiments, the (one or more) network management devices 122 may provide centralized management of the network via a graphical user interface to enable a user to monitor, configure, and maintain the edge network devices 142 and the links (e.g., Internet transport network 160, MPLS network 162, 4G / LTE network 164) in the lower-layer network and the upper-layer network. The (one or more) network management devices 122 may support multi-tenancy and enable centralized management of logically isolated networks associated with different entities (e.g., enterprises, departments within an enterprise, groups within a department, etc.). Alternatively or additionally, the (one or more) network management devices 122 may be a dedicated network management system for a single entity. In some embodiments, the physical or virtual SD-WAN vManage devices may operate as the (one or more) network management devices 122.

[0052] The control plane 130 can build and maintain a network topology and determine where traffic flows. The control plane 130 can include one or more physical or virtual network controller devices 132. The (one or more) network controller devices 132 can establish secure connections to each network device 142 and distribute routing and policy information via control plane protocols (e.g., Overlay Management Protocol (OMP) (discussed further below in detail), Open Shortest Path First (OSPF), Intermediate System to Intermediate System (IS-IS), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), Internet Group Management Protocol (IGMP), Internet Control Message Protocol (ICMP), Address Resolution Protocol (ARP), Bidirectional Forwarding Detection (BFD), Link Aggregation Control Protocol (LACP), etc.). In some embodiments, the (one or more) network controller devices 132 can operate as route reflectors. The (one or more) network controller devices 132 can also orchestrate secure connections in the data plane 140 between two or more edge network devices 142. For example, in some embodiments, the (one or more) network controller devices 132 can distribute encryption key information between the (one or more) edge network devices 142. This can allow the network to support secure network protocols or applications (e.g., Internet Protocol Security (IPSec), Transport Layer Security (TLS), Secure Shell (SSH), etc.) without Internet Key Exchange (IKE) and enable network scalability. In some embodiments, the physical or virtual The SD-WAN vSmart controller can operate as the (one or more) network controller devices 132.

[0053] The data plane 140 can be responsible for forwarding packets based on decisions from the control plane 130. The data plane 140 can include edge network devices 142, which can be physical or virtual network devices. The edge network devices 142 can operate at the edge in various network environments of an organization, such as in one or more data centers or co-location centers 150, campus networks 152, branch office networks 154, local office networks 156, etc. or in the cloud (e.g., Infrastructure as a Service (IaaS), Platform as a Service (PaaS), SaaS, and other cloud service provider networks). The edge network devices 142 can provide secure data plane connections between sites through: one or more WAN transports (e.g., via one or more Internet transport networks 160 (e.g., Digital Subscriber Line (DSL), cable, etc.), MPLS network 162 (or other private packet-switching networks (e.g., Metro Ethernet, Frame Relay, Asynchronous Transfer Mode (ATM), etc.), mobile network 164 (e.g., 3G, 4G / LTE, 5G, etc.), or other WAN technologies (e.g., Synchronous Optical Network (SONET), Synchronous Digital Hierarchy (SDH), Dense Wavelength Division Multiplexing (DWDM), or other fiber technologies; leased lines (e.g., T1 / E1, T3 / E3, etc.); Public Switched Telephone Network (PSTN), Integrated Services Digital Network (ISDN), or other private circuit-switched networks; Very Small Aperture Terminal (VSAT) or other satellite networks, etc.). The edge network devices 142 can be responsible for traffic forwarding, security, encryption, Quality of Service (QoS), and routing (e.g., BGP, OSPF, etc.) as well as other tasks. In some embodiments, the physical or virtual The SD-WAN vEdge router can operate as the edge network device 142.

[0054] Figure 2An example of a network topology 200 for illustrating aspects of a network architecture 100 is shown. The network topology 200 may include a management network 202, a pair of network sites 204A and 204B (collectively 204) (e.g., (one or more) data centers 150, (one or more) campus networks 152, (one or more) branch office networks 154, (one or more) local office networks 156, (one or more) cloud service provider networks, etc.), and a pair of Internet transport networks 160A and 160B (collectively 160). The management network 202 may include one or more network orchestrator devices 104, one or more network management devices 122, and one or more network controller devices 132. Although the management network 202 is shown as a single network in this example, those of ordinary skill in the art will understand that each element of the management network 202 may be distributed across any number of networks and / or co-located with the sites 204. In this example, each element of the management network 202 may be reached via the transport network 160A or 160B.

[0055] Each site may include one or more endpoints 206 connected to one or more site network devices 208. The endpoints 206 may include general computing devices (e.g., servers, workstations, desktop computers, etc.), mobile computing devices (e.g., laptops, tablets, mobile phones, etc.), wearable devices (e.g., watches, glasses or other head-mounted displays (HMDs), ear devices, etc.), etc. The endpoints 206 may also include Internet of Things (IoT) devices or equipment, such as agricultural equipment (e.g., livestock tracking and management systems, watering devices, unmanned aerial vehicles (UAVs), etc.); connected cars and other vehicles; smart home sensors and devices (e.g., alarm systems, security cameras, lighting, appliances, media players, HVAC equipment, utility meters, windows, automatic doors, doorbells, locks, etc.); office equipment (e.g., desk phones, copiers, fax machines, etc.); medical devices (e.g., pacemakers, biosensors, medical equipment, etc.); industrial equipment (e.g., robots, factory machinery, construction equipment, industrial sensors, etc.); retail equipment (e.g., vending machines, point-of-sale (POS) devices, radio frequency identification (RFID) tags, etc.); smart city devices (e.g., streetlights, parking meters, waste management sensors, etc.); transportation and logistics equipment (e.g., rotary vehicles, rental car trackers, navigation devices, inventory monitors, etc.), etc.

[0056] The site network device 208 can include physical or virtual switches, routers, and other network devices. Although in this example site 204A is shown as including a pair of site network devices and site 204B is shown as including a single site network device, the site network device 208 can include any number of network devices in any network topology, including multi-layer (e.g., core, distribution, and access layers), spine-leaf, mesh, tree, bus, hub and spoke, etc. For example, in some embodiments, one or more data center networks can implement Application Centric Infrastructure (ACI) architecture and / or one or more campus networks can implement Software Defined Access (SD Access or SDA) architecture. The site network device 208 can connect the endpoints 206 to one or more edge network devices 142, and the edge network devices 142 can be used to directly connect to the transport network 160.

[0057] In some embodiments, "colors" can be used to identify separate WAN transport networks, and different WAN transport networks can be assigned different colors (e.g., mpls, private1, biz-internet, metro-ethernet, lte, etc.). In this example, the network topology 200 can use the color called "biz-internet" for the Internet transport network 160A and the color called "public-internet" for the Internet transport network 160B.

[0058] In some embodiments, each edge network device 208 can form a Datagram Transport Layer Security (DTLS) or TLS control connection to the (one or more) network controller devices 132 and connect to any network controller device 132 through each transport network 160. In some embodiments, the edge network device 142 can also securely connect to edge network devices in other sites via an IPSec tunnel. In some embodiments, the BFD protocol can be used within each of these tunnels to detect loss, latency, jitter, and path failures.

[0059] On edge network device 142, colors can be used to help identify or distinguish separate WAN transport tunnels (e.g., the same color cannot be used twice on a single edge network device). The colors themselves also have significance. For example, colors such as metro-ethernet, mpls, and private1, private2, private3, private4, private5, and private6 can be considered private colors, which can be used for private networks or where there is NAT addressing without transport IP endpoints (e.g., because there may be no NAT between two endpoints of the same color). When edge network devices 142 use private colors, they can attempt to use local, private, underlying IP addresses to build IPSec tunnels to other edge network devices. Public colors can include 3g, biz, internet, blue, bronze, custom1, custom2, custom3, default, gold, green, lte, public internet, red, and silver. Public colors can be used by edge network device 142 to build tunnels to post-NAT IP addresses (if NAT is involved). If edge network device 142 uses a private color and needs NAT to communicate with other private colors, the carrier setting in the configuration can specify whether edge network device 142 uses a private IP address or a public IP address. Using this setting, two private colors can establish a session when one or both use NAT.

[0060] Figure 3 An example of illustration 300 showing the operation of OMP is shown. OMP can be used in some embodiments to manage the overlay of a network (e.g., network architecture 100). In this example, OMP messages 302A and 302B (collectively 302) can be transmitted back and forth between network controller device 132 and edge network devices 142A and 142B respectively, where control plane information (e.g., routing prefixes, next-hop routes, encryption keys, policy information, etc.) can be exchanged via corresponding secure DTLS or TLS connections 304A and 304B. Network controller device 132 can operate similarly to a route reflector. For example, network controller device 132 can receive routes from edge network device 142, process any policies and apply any policies to the routes, and advertise the routes to other edge network devices 142 in the upper layer. If there are no defined policies, edge network device 142 can operate in a manner similar to a full-mesh topology, in which each edge network device 142 can be directly connected to another edge network device 142 at another site and receive full routing information from each site.

[0061] OMP can announce three types of routes:

[0062] · OMP routes, which can correspond to prefixes learned from the local site or service side of the edge network device 142. The prefixes can be originated as static or connected routes, or originated from within protocols such as OSPF or BGP and redistributed into OMP so that the prefixes can be transported across upper layers. OMP routes can announce attributes such as transport location (TLOC) information (which can be similar to the BGP next-hop IP address) and other attributes such as origin, originator, preference, site identifier, label, and virtual private network (VPN). If the TLOC pointed to by the OMP route is active, the OMP route can be installed in the forwarding table.

[0063] · TLOC routes, which can correspond to logical tunnel endpoints connected to the edge network device 142 in the transport network 160. In some embodiments, TLOC routes can be uniquely identified and represented by a triple (including an IP address, a link color, and an encapsulation (e.g., Generic Routing Encapsulation (GRE), IPSec, etc.)). In addition to the system IP address, color, and encapsulation, TLOC routes can also transport attributes such as TLOC private and public IP addresses, carrier, preference, site identifier, label, and weight. In some embodiments, when an active BFD session is associated with the TLOC, the TLOC can be active on a particular edge network device 142.

[0064] · Service routes, which can represent services (e.g., firewall, distributed denial of service (DDoS) mitigator, load balancer, intrusion prevention system (IPS), intrusion detection system (IDS), WAN optimizer, etc.) that can be connected to the local site of the edge network device 142 and accessible to other sites for service insertion. Additionally, these routes can include VPNs; the VPN label can be sent in an update type to notify the network controller device 132 what VPN is served at the remote site.

[0065] In Figure 3In the example, OMP is shown to operate over a DTLS / TLS tunnel 304 established between an edge network device 142 and a network controller device 132. Additionally, illustration 300 shows an IPSec tunnel 306A established between TLOC 308A and TLOC 308C over a WAN transport network 160A, and an IPSec tunnel 306B established between TLOC 308B and TLOC 308D over a WAN transport network 160B. Once the IPSec tunnel 306A and the IPSec tunnel 306B are established, BFD can be enabled on each of them.

[0066] Figure 4 An example of an illustration 400 showing the operation of VPNs is shown, which can be used in some embodiments to provide segmentation for a network (e.g., network architecture 100). The VPNs can be isolated from each other and can have their own forwarding tables. Interfaces or sub-interfaces can be explicitly configured under a single VPN and cannot be part of more than one VPN. Labels can be used in OMP routing attributes and packet encapsulation, which can identify the VPN to which a packet belongs. The VPN number can be a four-byte integer with a value from 0 to 65530. In some embodiments, one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 can each include a transport VPN 402 (e.g., VPN 0) and a management VPN 404 (e.g., VPN 512). The transport VPN 402 can include one or more physical or virtual network interfaces (e.g., network interface 410A and network interface 410B) that are respectively connected to WAN transport networks (e.g., an MPLS network 162 and an Internet transport network 160). A secure DTLS / TLS connection to one or more network controller devices 132 or located between one or more network controller devices 132 and one or more network orchestrator devices 104 can be initiated from the transport VPN 402. Additionally, static or default routes or dynamic routing protocols can be configured inside the transport VPN 402 to obtain appropriate next-hop information so that a control plane 130 can be established and an IPSec tunnel 306 (not shown) can be connected to a remote site.

[0067] The management VPN 404 can transport out-of-band management traffic to and from one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 via a network interface 410C. In some embodiments, the management VPN 404 can be transported over an upper-layer network.

[0068] In addition to the transport VPN 402 and the management VPN 404, the (one or more) network orchestrator devices 104, the (one or more) network management devices 122, the (one or more) network controller devices 132, or the (one or more) edge network devices 142 may further include one or more service - side VPNs 406. The service - side VPN 406 may include one or more physical or virtual network interfaces (e.g., network interfaces 410D and 410E) that are connected to one or more local site networks 412 and convey user data traffic. The (one or more) service - side VPNs 406 may be enabled for features such as OSPF or BGP, Virtual Router Redundancy Protocol (VRRP), QoS, traffic shaping, policing, etc. In some embodiments, by re - distributing the OMP routes received from the (one or more) network controller devices 132 at the site 412 into the service - side VPN routing protocol, user traffic may be tunneled via an IPSec tunnel to other sites. Further, by advertising the service VPN routes into the OMP routing protocol, the routes from the local site 412 may be advertised to other sites, and the OMP routing protocol may be sent to the (one or more) network controller devices 132 and re - distributed to other edge network devices 142 in the network. Although the network interfaces 410A through 410E (collectively 410) are shown as physical interfaces in this example, those of ordinary skill in the art will recognize that the interfaces 410 in the transport VPN and the service VPN may also be sub - interfaces.

[0069] Figure 5 A network configuration that implements a control plane across different domains is shown. In some instances, a network provider may desire to horizontally scale a network configuration across different geographical regions while centrally managing the network. In this example, the network 500 includes a data center 505, and the data center 505 includes management - plane and control - plane functions. The data center 505 includes at least one network management device 522 that manages at least one network controller device 532.

[0070] The network 500 is geographically divided into a first region 510 and a second region 515, and either region may include a data center 505. For example, the first region 510 and the second region 515 are different geographical regions and may also be different network operators with different domains. For example, a first network operator may operate and manage the first region 510, while a different second network operator may operate and manage the second region 515. In any case, the data center 505 may be associated with either of the different regions and is shown separately for clarity.

[0071] In this example, the edge network device 542 is managed by the entity or virtual network orchestrator device 504 in each corresponding region. Although the management and controller functions can be incorporated into each different geographical region, this would require additional devices (e.g., the network controller device 532) to be incorporated into the region. For this reason, network operators may prefer to keep the management plane and control plane functions in a single location and then scale horizontally the additional network capacity in different regions without incurring the additional costs associated with additional network devices.

[0072] Each connection operating as a DTLS tunnel is established after successful device authentication and conveys an encrypted payload between the network controller device 532 and the edge network device 542. The payload consists of the routing information required by the network controller device 532 to determine the network topology, then calculate the best route to a network destination and distribute the routing information to the edge network device 542. The DTLS connection between the network controller device 532 and the edge network device 542 is a static connection. The network controller device 532 does not have a direct peer relationship with any device that the edge network device 542 is connected to on the service side.

[0073] This type of solution would require NAT to translate between the addresses of one domain (e.g., the first region 510) and another domain (e.g., the second region 515). In this example, it is assumed that the data center 505 is set within the first region 510 and thus NAT is not required for the first domain. However, NAT 520 is required to communicate between the first region 510 (including the data center 505) and the second region 515. NAT 520 translates the addresses within the second region into addresses associated with the first region to allow the edge network device 542 to communicate with the network controller device 532. Although Figure 5 the illustrated NAT 520 is not specifically located in any region, NAT 520 can be configured in the first region 510, the second region 515, or between different regions.

[0074] Figure 5 The various network devices illustrated are capable of IPv4 and / or IPv6 communication. Devices that include both an IPv4 interface and an IPv6 interface are referred to as dual-stack configurations. However, the network controller device 532 may be able to service only a single interface (e.g., IPv4 or IPv6) of each client device. Therefore, using NAT 520 may leak IPv4 routes or IPv6 routes. In some cases, network operators may require that routes not be leaked to prevent malicious man-in-the-middle attacks and other security precautions. For example, there may be security and / or regional regulatory considerations that prevent routes from being leaked. For this reason, Figure 5The solution in requires additional configuration to prevent IPv4 or IPv6 route leakage.

[0075] Figure 6 illustrates an example sequence diagram 600 of using Figure 5 the network configuration shown to prevent IPv4 or IPv6 route leakage. As described below, different IP addresses of the network controller device 532 will be relayed on a single connection (e.g., IPv4 or IPv6) to prevent route leakage. The address information will be relayed from the network controller device 532 to the network orchestrator device 504, and the network orchestrator device 504 will provide this information to the edge network device 542.

[0076] After the network controller device 532 has configured a first connection (e.g., an IPv4 connection) with the network orchestrator device 504, the network controller device 532 may request to establish an additional DTLS connection for a second address (e.g., an IPv6 address). During the DTLS challenge phase, at block 610, the network controller device 532 may identify the existence of a connection (e.g., an IPv4 connection) and identify that the IPv4 connection is a peer session. Thus, at block 612, the network controller device 532 determines to insert a peer session field (e.g., a type length value (TLV)) into the control message being transmitted to the network orchestrator device 504.

[0077] The network orchestrator device 504 receives the control message, analyzes the control message, and identifies the peer session field. At block 614, the network orchestrator device 504 transmits the IPv6 address of the network controller device 532 perceived by the network orchestrator device 504 to the network controller device 532. Thus, the transmitted IPv6 address is the address perceived by the network orchestrator device 504 because the network controller device 532 is behind a NAT.

[0078] The network controller device 532 identifies the corresponding IPv4 session and, at block 616, returns the IPv6 address of the network controller device 532 to the network orchestrator device 504 using the IPv4 connection. At block 618, the network orchestrator device 504 and the network controller device 532 associate the IPv4 address and the IPv6 address of the network controller device 532. In some examples, the IPv6 address of the network controller device 532 may be associated with a boolean value in the network orchestrator device, which indicates that the IPv6 address is related to another IPv4 address, but does not necessarily explicitly identify which IPv4 address. As described below, this boolean value will allow the network orchestrator device to understand that the IPv6 address is associated with another address and can be skipped. In other examples, the IPv6 address and the IPv4 address may be explicitly linked via a pointer or some other data structure.

[0079] At block 620, the edge network device 542 can be activated and can request the network orchestrator device 504 to identify a network controller device. This can occur when the edge network device 542 is activated (e.g., started, restarted, etc.), and the request to identify the network controller device is to identify the network controller device to handle control communication via an overlay management protocol (OMP).

[0080] At block 622, the network orchestrator device 504 searches for a network controller device to identify to the edge network device 542. During the search, even if the network controller device is a dual-stack device and includes both an IPv4 address and an IPv6 address, the network orchestrator device 504 only considers each network controller device once. That is, the network orchestrator device 504 prevents duplicate counting of network controller devices.

[0081] The network orchestrator device 504 sends a response identifying at least one network controller device. When the network controller device includes an IPv4 address and an IPv6 address, at block 622, the response identifies both the IPv4 address and the IPv6 address. In this example, communication with the network controller device 532 is restricted in the IPv6 domain. Therefore, at block 622, the network orchestrator 504 uses an IPv4 connection to transmit a message identifying both the IPv4 address and the IPv6 address.

[0082] Accordingly, the edge network device 542 receives both the IPv4 address and the IPv6 address of the network controller device 532 and is able to configure an appropriate network connection with the network controller device 532. That is, the edge network device 542 receives identification information of the IPv4 address and the IPv6 address and can select an appropriate connection with the network controller device. Therefore, since it is assumed that the data center 505 is located in the first region 510, devices located in the second region 515 will be able to connect to network devices in the first region 510 for control plane and management plane functions. This configuration allows for horizontal scaling of additional domains and geographical regions and prevents routing leaks while allowing the network edge device 542 to configure an optimal connection to the network controller device 532.

[0083] Although the examples described above in Figure 5 and Figure 6 are described as constraining messages to the IPv4 domain, these descriptions equally apply to IPv6 and constrain communication in the IPv4 domain. For example, the IPv4 address of the network controller device 532 can be transmitted to the network orchestrator device via an IPv6 connection to prevent IPv4 routing leaks.

[0084] Figure 7Illustrates an example method 700 for a network controller device. Although the example method 700 depicts a specific order of operations, this order can be changed without departing from the scope of the present disclosure. For example, some of the depicted operations can be performed in parallel or in a different order that substantially does not affect the functionality of method 700. In other examples, different components of an example device or system implementing method 700 can perform functions substantially simultaneously or in a specific order.

[0085] According to some examples, method 700 includes: at block 710, when a second connection to a network orchestrator is requested, identifying a first connection to the network orchestrator. In some examples, the identification of the first connection occurs during the challenge phase of the DTLS session initialization between a network orchestrator and a network controller located in different regions. As an example, Figure 11 the illustrated processor 1100 can identify a first connection to a network orchestrator during the establishment of a second connection to the network orchestrator from the network controller.

[0086] To illustrate this example, it will be assumed for discussion that the first connection is an IPv4 connection and that the second connection is an IPv6 connection. However, the first connection can be an IPv6 connection and the second connection can be an IPv4 connection.

[0087] Since the network orchestrator and the network controller are located in different regions, the network orchestrator and the network controller can be associated with different domains, and a network address converter can be implemented to translate IP addresses. In some examples, as described below with reference to Figure 10F what is described, the network controller can be connected to multiple network orchestrators.

[0088] According to some examples, method 700 includes at block 720 establishing a sibling session at the control plane that links an IPv6 connection and an IPv4 connection. By linking the sessions, this can prevent the network controller and the network orchestrator from double-counting network connections, thereby preventing the device from discovering the best network connection. To this end, the processor 1100 can use the universally unique identifier (UUID) of the network orchestrator to discover and establish a sibling session at the control plane that links an IPv6 connection and an IPv4 connection.

[0089] According to some examples, method 700 includes at block 730 inserting a sibling data field that identifies the sibling session into a control message. For example, the processor 1100 can insert a sibling data message that identifies the sibling session into a control message. The network orchestrator receives the sibling data message and associates the IPv4 connection and the IPv6 connection as a single logical connection.

[0090] In response to a control message, method 700 may receive a message from a network orchestrator at block 740 via an IPv6 connection that includes the address of a network controller associated with the IPv6 connection. The received address is the address of the network controller as perceived by the network orchestrator (i.e., the translated IP address). Notably, the network controller is unaware of its perceived public IP address and must therefore receive this address from an external source. Accordingly, the processor 1100 may receive a message from the network orchestrator via an IPv6 connection that includes the address of a network controller associated with the IPv6 connection.

[0091] According to some examples, method 700 includes transmitting the address of the network controller to the network orchestrator at block 750 via a different connection. For example, the processor 1100 may transmit the IPv6 address of the network controller to the network orchestrator via an IPv4 connection. The network orchestrator receives the IPv6 address of the network controller and associates the IPv4 connection and the IPv6 connection as a single logical connection. The network orchestrator is configured to transmit the IPv4 address and the IPv6 address using a single interface during the setup of an edge network device, and the edge network device may select an ideal interface for network connection. However, in some examples, the network orchestrator uses the IPv4 connection to notify the edge network device of the IPv6 address of the network controller.

[0092] Accordingly, method 700 allows the network orchestrator to provide both the IPv4 address and the IPv6 address to the edge network device using a single connection. In this example, notifying the edge network device of the IPv6 address of the network controller via the IPv4 connection prevents the leakage of routes associated with network address translation, as communication with the edge network device restricts communication with the network controller to a single interface.

[0093] Figure 8 An example method 800 for a network orchestrator is shown. Although the example method 800 depicts a particular order of operations, this order may be changed without departing from the scope of the present disclosure. For example, some of the depicted operations may be performed in parallel or in a different order that substantially does not affect the functionality of method 800. In other examples, different components of an example device or system implementing method 800 may perform functions substantially simultaneously or in a specific order.

[0094] According to some examples, method 800 includes receiving a message at block 810 that includes a peer data field indicating that a first connection is related to a second connection. The peer data field is a TLV inserted by the network controller and indicates the existence of an existing connection to the network controller. For example, Figure 11The illustrated processor 1100 may receive a message when creating an IPv6 session, the message including a peer data message indicating that an IPv4 connection is related to the IPv6 connection.

[0095] According to some examples, method 800 includes transmitting, at block 820, a message to a network controller via a second connection. The message may include a second address of the network controller associated with the second connection. For example, assuming there is an IPv4 session, the processor 1100 may transmit a message to the network controller via an IPv6 connection, the message including the IPv6 address of the network controller perceived by the network orchestrator. As described above, due to NAT, the network controller does not know its IPv6 address in different regions, and thus the network orchestrator provides the IPv6 NAT address of the network controller to the network controller.

[0096] According to some examples, method 800 includes receiving, at block 830, from the network controller an address of the network controller associated with the second connection via a first connection. For example, in order for the network orchestrator to link an IPv4 session and an IPv6 session, the processor 1100 may receive the IPv6 NAT address of the network controller from the network controller via an IPv4 connection.

[0097] According to some examples, method 800 links, at block 840, the first connection and the second connection as a single logical connection. For example, the processor 1100 may link an IPv4 connection and an IPv6 connection as a single logical connection.

[0098] According to some examples, the network orchestrator may receive a request to connect a network edge device. Thus, the processor 1100 of the network orchestrator may search for network controllers to identify to the edge network device. Thus, the network orchestrator may analyze each edge network device based on the IPv4 address. However, when the IPv6 address and the IPv4 address are not linked, the network orchestrator may analyze each network edge device based on the IPv6 address. That is, the network orchestrator analyzes each network controller one by one.

[0099] Method 800 may further include: at block 850, in response to receiving a request to connect a network edge device, transmitting a message to the network edge device via an IPv4 connection. The message may identify a second address and a first address of the network controller associated with the first connection. For example, the processor 1100 may transmit a message to the network edge device via an IPv4 connection in response to receiving a request to connect a network edge device, the message identifying the IPv4 address and the IPv6 address of the network controller.

[0100] Figure 9An example method 900 for a network edge device connected to a network controller is shown. Although the example method 900 depicts a particular order of operations, the order can be changed without departing from the scope of the present disclosure. For example, some of the depicted operations can be performed in parallel or in a different order that does not materially affect the functionality of the method 900. In other examples, different components of the example device or system implementing the method 900 can perform functions substantially simultaneously or in a specific order.

[0101] According to some examples, method 900 includes transmitting a request for an address of a network controller to manage a network edge device via a first connection to a network orchestrator at block 910. For example, processor 1100 may transmit the request for an address of a network controller to manage a network edge device via an IPv4 connection to the network orchestrator.

[0102] According to some examples, method 900 includes receiving a message identifying a first address of a network controller and a second network address of the network controller at block 920. For example, processor 1100 may receive a message identifying an IPv4 address of the network controller and an IPv6 network address of the network controller.

[0103] According to some examples, method 900 includes determining to connect to the network controller via the first address or the second address at block 930. For example, processor 1100 may determine to connect to the network controller via an IPv4 address or an IPv6 address.

[0104] Figure 10A 、 Figure 10B 、 Figure 10C 、 Figure 10D 、 Figure 10E and Figure 10F is a block diagram illustrating the communication of networks in different areas or domains. Specifically, Figure 10A Network controller 1002 and network orchestrator 1004 are shown communicating via an IPv4 connection and an IPv6 connection. Although not shown, network controller 1002 and network orchestrator 1004 are located in different geographic regions and are associated with different domains. NAT 1006 is used to translate the IPv6 connection to prevent route leaks. Network controller 1002 and network orchestrator 1004 exchange UUIDs via the IPv4 connection at step 1010 and exchange UUIDs via the IPv6 connection at step 1012.

[0105] Figure 10B A peer session 1014 is shown formed, which enables the IPv4 connection and the IPv6 connection to be viewed as a single logical connection.

[0106] Figure 10CShows that at step 1016, the network orchestrator transmits the IPv6 address of the network controller 1002 sensed by the network orchestrator 1004 at interface If0, and this IPv6 address is transmitted to the network controller 1002.

[0107] Figure 10D Shows that at step 1020, the IPv6 address of the network controller 1002 sensed by the network orchestrator 1004 is transmitted to the network orchestrator 1004 via an IPv4 connection. Once received by the network orchestrator 1004, the network orchestrator 1004 associates the IPv4 address and the IPv6 address, and treats the IPv4 connection and the IPv6 connection as a single logical connection.

[0108] Figure 10E Shows that the edge device 1022 requests a network controller from the network orchestrator 1004. At step 1024, the network orchestrator sends the IPv4 address and the IPv6 address of the network controller 1002 to the edge device via an IPv4 connection. The edge device 1022 can communicate with the network controller 1002 using the IPv4 connection or using an IPv6 connection with NAT 1006.

[0109] Figure 10F Shows that the second network orchestrator 1054, the second NAT 1056, and the second edge device 1058 can be implemented in different regions or different domains to horizontally scale the network while centralizing the network management function. That is, the network controller 1002 can be implemented to control both the edge device 1020 and the edge device 1058, even if they are in different domains.

[0110] Figure 11 Shows an example of a computing system 1100, which can be, for example, any computing device that constitutes the network orchestrator device 504, the network controller device 532, the edge network device 542, or any component of any computing device where the components of the system communicate with each other using the connection 1105. The connection 1105 can be a physical connection via a bus or a direct connection to the processor 1110, such as in a chipset architecture. The connection 1105 can also be a virtual connection, a network connection, or a logical connection.

[0111] In some embodiments, the computing system 1100 is a distributed system, where the functions described in this disclosure can be distributed within one data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more of the described system components represent many such components, and each component performs some or all of the functions described for the component. In some embodiments, the components can be physical or virtual devices.

[0112] Example system 1100 includes at least one processing unit (CPU or processor) 1110 and connections 1105 that couple various system components, including system memory 1115 (e.g., read-only memory (ROM) 1120 and random access memory (RAM) 1125), to the processor 1110. Computing system 1100 may include a cache of high-speed memory 1112 that is directly connected to, contiguous with, or integrated as part of the processor 1110.

[0113] Processor 1110 may include any general-purpose processor and hardware services or software services (e.g., services 1132, 1134, and 1136 stored in storage device 1130) that are configured to control the processor 1110 and special-purpose processors (where software instructions are incorporated into the actual processor design). Processor 1110 may in essence be a fully self-contained computing system that includes multiple cores or processors, buses, memory controllers, caches, etc. A multi-core processor may be symmetric or asymmetric.

[0114] To enable user interaction, computing system 1100 includes input device 1145, which may represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. Computing system 1100 may also include output device 1135, which may be one or more of a variety of output mechanisms known to those of ordinary skill in the art. In some instances, a multimodal system may enable a user to provide multiple types of input / output to communicate with computing system 1100. Computing system 1100 may include communication interface 1140 (e.g., a transceiver), which generally may regulate and manage user input and system output. There are no limitations on operating on any particular hardware arrangement, and thus the basic features herein may be readily replaced by improved hardware or firmware arrangements when they are developed.

[0115] Storage device 1130 may be a non-volatile storage device and may be a hard disk or other type of computer-readable medium that can store data accessible by a computer, such as a magnetic tape cartridge, a flash memory card, a solid-state storage device, a digital versatile disc, a cassette tape, random access memory (RAM), read-only memory (ROM), and / or some combination of these devices.

[0116] The storage device 1130 may include software services, servers, services, etc., which, when the code defining such software is executed by the processor 1110, cause the system to perform functions. In some embodiments, the hardware services that perform specific functions may include software components stored in a computer-readable medium connected to the necessary hardware components (e.g., the processor 1110, the connection 1105, the output device 1135, etc.) to perform the function.

[0117] For clarity of explanation, in some cases, the present technology may be represented as including various functional blocks, which include functional blocks having the following: devices, device components, steps or routines in methods embodied in software, or combinations of hardware and software.

[0118] Any steps, operations, functions, or processes described herein may be performed or implemented by a combination of hardware and software services or by the services alone or in combination with other devices. In some embodiments, the service may be software residing in the memory of a client device and / or one or more servers of a content management system and may perform one or more functions when the processor executes the software associated with the service. In some embodiments, the service is a program or a collection of programs that perform specific functions. In some embodiments, the service may be considered a server. The memory may be a non-transitory computer-readable medium.

[0119] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bitstreams, etc. However, when mentioned, non-transitory computer-readable storage media explicitly exclude media such as energy, carrier signals, electromagnetic waves, and signals themselves.

[0120] The methods according to the above examples may be implemented using computer-executable instructions stored in or retrievable from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or configure a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform a certain function or a set of functions. Some of the computer resources used may be accessed via a network. The computer-executable instructions may be, for example, binary, intermediate format instructions, such as assembly language, firmware, or source code. Examples of computer-readable media that may be used to store instructions, the information used during and / or created by the methods according to the examples include magnetic or optical disks, solid-state memory devices, flash memory, USB devices providing non-volatile memory, networked storage devices, etc.

[0121] Devices according to these disclosed implementation methods may include hardware, firmware, and / or software, and may be in any of a variety of form factors. Typical examples of such form factors include servers, laptop computers, smart phones, small form factor personal computers, personal digital assistants, etc. The functionality described herein may also be embodied in a peripheral device or add-on card. As a further example, such functionality may also be implemented on a circuit board between different chips or different processes executed in a single device.

[0122] Instructions, a medium for conveying such instructions, computing resources for executing such instructions, and other structures for supporting such computing resources are modules for providing the functionality described in these disclosures.

[0123] Although various examples and other information are used to explain various aspects within the scope of the appended claims, no limitation on the claims should be implied based on specific features or arrangements in such examples, because those of ordinary skill in the art will be able to use these examples to obtain a wide variety of implementations. Additionally, although some subject matter may have been described in language specific to examples of structural features and / or method steps, it should be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or actions. For example, such functionality may be distributed differently among components other than those identified herein or performed by components other than those identified herein. Of course, the described features and steps are disclosed as examples of components of a system and methods within the scope of the appended claims.

[0124] Illustrative examples of the present disclosure include:

[0125] Aspect 1. A method, comprising: identifying a first connection with the network orchestrator during establishment of a second connection with the network orchestrator from a network controller; establishing, at a control plane, a peer session that links the second connection and the first connection; inserting a peer data message identifying the peer session into a control message being sent; receiving, via the second connection, a message from the network orchestrator, the message including an address of the network controller associated with the second connection; and transmitting, via the first connection, a second address of the network controller to the network orchestrator, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and wherein the network orchestrator is configured to transmit the first address and the second address during setup of a network edge device.

[0126] Aspect 2. The method according to Aspect 1, wherein the peer session is identified based on identifying a UUID of the network orchestrator.

[0127] Aspect 3. The method according to any one of Aspects 1 to 2, wherein the network orchestrator receives the peer data message and associates the first connection and the second connection as a single logical connection.

[0128] Aspect 4. The method according to any one of Aspects 1 to 3, wherein the identification of the first connection occurs during the process challenge phase of DTLS session initialization.

[0129] Aspect 5. The method according to any one of Aspects 1 to 4, wherein the network orchestrator uses the first connection to notify the network edge device of the second address of the network controller.

[0130] Aspect 6. The method according to any one of Aspects 1 to 5, wherein notifying the network edge device of the second address of the network controller via the first connection prevents the leakage of routes associated with network address translation.

[0131] Aspect 7. The method according to any one of Aspects 1 to 6, wherein the network controller is located in a first region and the network orchestrator is located in a second region different from the first region.

[0132] Aspect 8. The method according to any one of Aspects 1 to 7, wherein the network address converter converts the IP address associated with the second region into the IP address associated with the first region.

[0133] Aspect 9. The method according to any one of Aspects 1 to 8, wherein the network controller is connected to a second network orchestrator in a different region.

[0134] Aspect 10. The method according to any one of Aspects 1 to 9, wherein the first connection is an IPv4 connection and the second connection is an IPv6 connection, or wherein the first connection is an IPv6 connection and the second connection is an IPv4 connection.

[0135] Aspect 11. A method includes: receiving a message, the message including a sibling data message indicating that a first connection is related to a second connection, wherein the message is received when establishing the first connection and the second connection with a network controller; transmitting the message to the network controller via the second connection, the message including a second address of the network controller associated with the second connection; receiving, via the first connection, an address of the network controller associated with the second connection from the network controller; linking the first connection and the second connection as a single logical connection; and in response to receiving a request to connect a network edge device, transmitting a message to the network edge device via the first connection, the message identifying the second address and a first address of the network controller associated with the first connection.

[0136] Aspect 12. The method according to aspect 11 further includes: analyzing each connection of each network controller managed by a network orchestrator associated with a first type of address, and analyzing each connection of each network controller associated with a second type of address and not linked to a connection associated with the first type of address.

[0137] Aspect 13. A network controller includes: a transceiver; a processor configured to execute instructions and cause the processor to: identify a first connection with a network orchestrator during establishing a second connection with the network orchestrator; establish a sibling session at a control plane that links the second connection and the first connection; insert a sibling data message identifying the sibling session into a control message; receive a message from the network orchestrator via the second connection, the message including an address of the network controller associated with the second connection; transmit the second address of the network controller to the network orchestrator via the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and the network orchestrator is configured to transmit the first address and the second address during setting up a network edge device.

[0138] Aspect 14. The network controller according to aspect 13 identifies a sibling session based on identifying a UUID of the network orchestrator.

[0139] Aspect 15. The network controller according to any one of aspects 13 to 14, wherein the network orchestrator receives the sibling data message and associates the first connection and the second connection as a single logical connection.

[0140] Aspect 16. The network controller according to any one of aspects 13 to 15, wherein the identification of the first connection occurs during a process challenge phase of DTLS session initialization.

[0141] Aspect 17. The network controller according to any one of aspects 13 to 16, wherein the network orchestrator notifies the second address of the network controller to the network edge device using a first connection.

[0142] Aspect 18. The network controller according to any one of aspects 13 to 17, notifying the second address of the network controller to the network edge device through the first connection prevents leakage of routes associated with network address translation.

[0143] Aspect 19. The network controller according to any one of aspects 13 to 18, wherein the network controller is located in a first region, and the network orchestrator is located in a second region different from the first region.

[0144] Aspect 20. The network controller according to any one of aspects 13 to 19, wherein a network address converter converts an IP address associated with the second region into an IP address associated with the first region.

[0145] Aspect 21. A network device includes a transceiver (e.g., a network interface, a wireless transceiver, etc.) and a processor coupled to the transceiver. The processor is configured to execute instructions and cause the processor to: identify a first connection with a network orchestrator during establishment of a second connection with the network controller; establish a peer session at a control plane that links the second connection and the first connection; insert a peer data message identifying the peer session into a control message being sent; receive a message from the network orchestrator through the second connection, the message including the address of the network controller associated with the second connection; and transmit the second address of the network controller to the network orchestrator through the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and wherein the network orchestrator is configured to transmit a first address and the second address during setup of a network edge device.

[0146] Aspect 22. The network device according to aspect 21, wherein the peer session is identified based on identifying a UUID of the network orchestrator.

[0147] Aspect 23. The network device according to any one of aspects 21 to 22, wherein the network orchestrator receives the peer data message and associates the first connection and the second connection as a single logical connection.

[0148] Aspect 24. The network device according to any one of aspects 21 to 23, wherein the identification of the first connection occurs during a process challenge phase of DTLS session initialization.

[0149] Aspect 25. The network device according to any one of aspects 21 to 24, wherein the network orchestrator notifies the second address of the network controller to the network edge device using a first connection.

[0150] Aspect 26. The network device according to any one of aspects 21 to 25, wherein notifying the second address of the network controller to the network edge device through the first connection prevents leakage of routes associated with network address translation.

[0151] Aspect 27. The network device according to any one of aspects 21 to 26, wherein the network controller is located in a first region, and the network orchestrator is located in a second region different from the first region.

[0152] Aspect 28. The network device according to any one of aspects 21 to 27, wherein the network address converter converts an IP address associated with the second region into an IP address associated with the first region.

[0153] Aspect 29. The network device according to any one of aspects 21 to 28, wherein the network controller is connected to a second network orchestrator in a different region.

[0154] Aspect 30. The network device according to any one of aspects 21 to 29, wherein the first connection is an IPv4 connection and the second connection is an IPv6 connection, or wherein the first connection is an IPv6 connection and the second connection is an IPv4 connection.

[0155] Aspect 31. A network device includes a transceiver (e.g., a network interface, a wireless transceiver, etc.) and a processor coupled to the transceiver. The processor is configured to execute instructions and cause the processor to: receive a message that includes a peer data message indicating a relationship between a first connection and a second connection, wherein the message is received when establishing the first connection and the second connection with a network controller; transmit, through the second connection, a message to the network controller, the message including a second address of the network controller associated with the second connection; receive, through the first connection, an address of the network controller associated with the second connection from the network controller; link the first connection and the second connection as a single logical connection; and in response to receiving a request to connect to a network edge device, transmit, through the first connection, a message to the network edge device, the message identifying the second address and a first address of the network controller associated with the first connection.

[0156] Aspect 32. The network device according to aspect 31, wherein the processor is configured to execute instructions and cause the processor to: analyze each connection of each network controller managed by a network orchestrator associated with a first type of address, and analyze each connection of each network controller associated with a second type of address and not linked to a connection associated with the first type of address.

[0157] Aspect 33. A network device includes a transceiver (e.g., a network interface, a wireless transceiver, etc.) and a processor coupled to the transceiver. The processor is configured to execute instructions and cause the processor to: transceiver; processor, configured to execute instructions and cause the processor to: identify a first connection to the network orchestrator during establishment of a second connection to the network orchestrator from a network controller; establish a peer session at a control plane that links the second connection and the first connection; insert a peer data message identifying the peer session into a control message; receive a message from the network orchestrator via the second connection, the message including an address of the network controller associated with the second connection; transmit a second address of the network controller to the network orchestrator via the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and the network orchestrator is configured to transmit the first address and the second address during setup of a network edge device.

[0158] Aspect 34. The network device according to aspect 33, wherein the peer session is identified based on identifying a UUID of the network orchestrator.

[0159] Aspect 35. The network device according to any one of aspects 33 to 34, wherein the peer session is identified based on identifying a UUID of the network orchestrator.

[0160] Aspect 36. The network device according to any one of aspects 33 to 35, wherein the identification of the first connection occurs during a process challenge phase of DTLS session initialization.

[0161] Aspect 37. The network device according to any one of aspects 33 to 36, wherein the network orchestrator uses the first connection to notify the network edge device of the second address of the network controller.

[0162] Aspect 38. The network device according to any one of aspects 33 to 37, wherein the processor is configured to execute instructions and cause the processor to: notifying the network edge device of the second address of the network controller via the first connection prevents leakage of a route associated with network address translation.

[0163] Aspect 39. The network device according to any one of aspects 33 to 38, wherein the network controller is located in a first region, and the network orchestrator is located in a second region different from the first region.

[0164] Aspect 40. The network device according to any one of aspects 33 to 39, wherein a network address converter converts an IP address associated with the second region into an IP address associated with the first region.

Claims

1. A method for network communication, comprising: identifying a first connection with the network orchestrator during establishing a second connection with the network orchestrator from a network controller; establishing, at a control plane, a peer session that links the second connection and the first connection; inserting a peer data message identifying the peer session into a control message being sent; receiving, via the second connection, a message from the network orchestrator, the message including a second address of the network controller associated with the second connection; and transmitting the second address of the network controller to the network orchestrator via the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, wherein the network orchestrator is configured to transmit the second address and a first address of the network controller associated with the first connection during setting up a network edge device.

2. The method according to claim 1, wherein Identifying the peer session based on identifying a Universally Unique Identifier (UUID) of the network orchestrator.

3. The method according to claim 1 or 2, wherein The network orchestrator receives the peer data message and associates the first connection with the second connection.

4. The method according to claim 1 or 2, wherein The identification of the first connection occurs during a process challenge phase of Datagram Transport Layer Security (DTLS) session initialization.

5. The method according to claim 1 or 2, wherein The network orchestrator uses a single connection to notify the network edge device of the second address of the network controller.

6. The method according to claim 5, wherein Notifying the network edge device of the second address of the network controller via the first connection prevents leakage of routes associated with network address translation.

7. The method according to claim 1 or 2, wherein The network controller is located in a first region, and the network orchestrator is located in a second region different from the first region.

8. The method according to claim 7, wherein A network address converter converts an IP address associated with the second region into an IP address associated with the first region.

9. The method according to claim 1 or 2, wherein The network controller is connected to a second network orchestrator in a different region.

10. The method according to claim 1 or 2, wherein The first connection is an IPv4 connection, and the second connection is an IPv6 connection; or wherein the first connection is an IPv6 connection, and the second connection is an IPv4 connection.

11. A method for a network orchestrator, comprising: receiving a message, the message including a peer data message indicating that a first connection is related to a second connection, wherein the message is received when establishing the first connection and the second connection with a network controller; transmitting, via the second connection, a message to the network controller, the message including the second address of the network controller; receiving, via the first connection, the second address of the network controller associated with the second connection from the network controller; associating the first connection and the second connection; in response to receiving a request to connect a network edge device, transmitting, via a single connection, a message to the network edge device, the message identifying the second address and a first address of the network controller associated with the first connection.

12. The method according to claim 11, further comprising: Analyze each connection of each network controller managed by a network orchestrator associated with a first type of address, and analyze each connection of each network controller associated with a second type of address and not associated with the first type of address.

13. A network controller, comprising: A transceiver; A processor configured to execute instructions and cause the processor to: Identify a first connection with the network orchestrator during establishment of a second connection with the network orchestrator from the network controller, Establish a peer session at a control plane that links the second connection and the first connection, Insert a peer data message identifying the peer session into a control message, Receive a message from the network orchestrator via the second connection, the message including a second address of the network controller associated with the second connection; Transmit the second address of the network controller to the network orchestrator via the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and wherein the network orchestrator is configured to transmit the second address and a first address of the network controller associated with the first connection during setup of a network edge device.

14. The network controller according to claim 13, wherein the peer session is identified based on identification of a universally unique identifier (UUID) of the network orchestrator.

15. The network controller according to claim 13 or 14, wherein the network orchestrator receives the peer data message and associates the first connection with the second connection.

16. The network controller according to claim 13 or 14, wherein the identification of the first connection occurs during a process challenge phase of DTLS session initialization.

17. The network controller according to claim 13 or 14, wherein the network orchestrator uses a single connection to notify a network edge device of the second address of the network controller.

18. The network controller according to claim 17, notifying the network edge device of the second address of the network controller via the first connection prevents leakage of routes associated with network address translation.

19. The network controller according to claim 13 or 14, wherein the network controller is located in a first region and the network orchestrator is located in a second region different from the first region.

20. The network controller according to claim 19, wherein a network address converter converts an IP address associated with the second region into an IP address associated with the first region.

21. A network controller, comprising: A module for identifying a first connection with the network orchestrator during establishment of a second connection with the network orchestrator from the network controller, A module for establishing a peer session at a control plane that links the second connection and the first connection, A module for inserting a peer data message identifying the peer session into a control message, A module for receiving a message from the network orchestrator via the second connection, the message including a second address of the network controller associated with the second connection A module for transmitting the second address of the network controller to the network orchestrator via the first connection, wherein the network orchestrator receives the second address of the network controller and associates the first connection and the second connection as a single logical connection, and wherein the network orchestrator is configured to transmit the second address and a first address of the network controller associated with the first connection during the setup of the network edge device.

22. The network controller according to claim 21, further comprising a module for implementing the method according to claim 2.

23. A network orchestrator, comprising: A module for receiving a message, the message including a peer data message indicating that a first connection is related to a second connection, wherein the message is received when establishing the first connection and the second connection with a network controller; A module for transmitting a message to the network controller via the second connection, the message including the second address of the network controller; A module for receiving, from the network controller via the first connection, the second address of the network controller associated with the second connection; A module for associating the first connection and the second connection; A module for transmitting, in response to receiving a request to connect a network edge device, a message to the network edge device via a single connection, the message identifying the second address and a first address of the network controller associated with the first connection.

24. The network orchestrator according to claim 23, further comprising a module for implementing the method according to claim 12.

25. A computer program product or a computer-readable medium, comprising instructions which, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Container network management system and method with high scalability

    CN105591820A

  • System, apparatus and method for providing aggregated network connections

    US20100118886A1