Network management system for dialing out a communication session
By providing certificates with identification information to endpoint devices and performing load balancing, the problem of uneven identification and resource allocation of outgoing communication sessions in multi-tenant SaaS environments is solved, thereby improving system performance and resource utilization efficiency.
Patent Information
- Application Number
- CN202210529155.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-29
- Filing Date
- 2022-05-16
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2042-05-16
AI Technical Summary
In a multi-tenant SaaS environment, the establishment of outgoing communication sessions cannot accurately identify the device and tenant, leading to uneven resource allocation and affecting system performance and latency.
The Network Management System (NMS) provides certificates to endpoint devices, containing identification information for the devices and tenants, and performs load balancing across multiple connectivity service instances to ensure balanced allocation and utilization of resources.
It enables accurate identification of devices and tenants, reduces latency, improves system performance and resource utilization efficiency, and prevents connectivity service instances from overloading.
Smart Images

Figure CN116319936B_ABST
Abstract
Description
[0001] Related Applications Cross Reference To
[0002] This application claims priority to Indian Patent Application No. 202141059289, filed December 20, 2021, entitled “NETWORK MANAGEMENT SYSTEM FOR DIAL-OUT COMMUNICATION SESSIONS,” the entire contents of which are expressly incorporated herein by reference. BACKGROUND
[0003] Software as a Service (SaaS) is a cloud service that hosts an application or service. In some cases, a multi-tenant SaaS environment can provide resources to be shared by different tenants (e.g., different groups of subscribers or customers) of the environment. SUMMARY
[0004] Some implementations described herein relate to a system. The system can include one or more memories and one or more processors. The system can be configured to receive, from an endpoint device associated with a tenant of the system, activation information associated with the endpoint device. The system can be configured to determine, based on the activation information, identification information associated with the endpoint device and the tenant. The system can be configured to generate a credential that includes the identification information. The system can be configured to transmit the credential to the endpoint device.
[0005] Some implementations described herein relate to a non-transitory computer- readable medium storing a set of instructions for a system. The set of instructions, when executed by one or more processors of the system, can cause the system to receive, from an endpoint device associated with a tenant of the system and as part of an attempt by the endpoint device to initiate a dial-out communication session with the system, a credential. The set of instructions, when executed by the one or more processors of the system, can cause the system to establish the dial-out communication session based on the credential. The set of instructions, when executed by the one or more processors of the system, can cause the system to process the credential to determine identification information associated with the endpoint device and the tenant. The set of instructions, when executed by the one or more processors of the system, can cause the system to receive, from the endpoint device and via the dial-out communication session, one or more messages. The set of instructions, when executed by the one or more processors of the system, can cause the system to modify the one or more messages to include the identification information. The set of instructions, when executed by the one or more processors of the system, can cause the system to provide the modified one or more messages after the modification to facilitate provisioning to the endpoint device, to a service or resource associated with the system.
[0006] Some implementations described herein relate to a method. The method can include identifying, by a system, a plurality of connectivity service instances of the system, where each connectivity service instance of the plurality of connectivity service instances supports one or more dial-out communication sessions. The method can include determining, by the system, respective instance weights of the plurality of connectivity service instances. The method can include causing, by the system, one or more load balancing actions to be performed based on the respective instance weights of the plurality of connectivity service instances. BRIEF DESCRIPTION OF DRAWINGS
[0007] Figures 1A-1H is an illustration of example implementations described herein.
[0008] Figure 2 is an illustration of an example environment in which systems and / or methods described herein can be implemented.
[0009] Figures 3-4 is an illustration of example components of one or more devices of Figure 2
[0010] Figures 5-7 is a flow diagram of an example process related to management of dial-out communication sessions. DETAILED DESCRIPTION
[0011] The following detailed description of example implementations refers to the accompanying drawings. The same reference numbers in different drawings can identify the same or similar elements.
[0012] A typical SaaS system (e.g., that provides security services) communicates with respective devices of tenants of a multi-tenant SaaS environment. A device of a tenant can initiate a “dial-out” communication session (e.g., such as a Transport Layer Security (TLS) communication session) with the SaaS system (e.g., to obtain particular services and / or resources from the SaaS system). However, in many cases, establishment of the dial-out communication session does not allow the device and the tenant (or a hierarchy of tenants) to be identified (uniquely) to the SaaS system. Thus, in some cases, the SaaS system is unable to determine which tenant is associated with the device, and thus refrains from providing particular services and / or resources to the device via the dial-out communication session.
[0013] Furthermore, when too many devices connect to a dial-out connectivity service instance, or too much information is communicated to or from a dial-out connectivity service instance, the dial-out connectivity service instance of the SaaS system (e.g., that facilitates establishment and maintenance of dial-out communication sessions) becomes overloaded, which impacts performance of the SaaS system. For example, computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) of the SaaS can not be allocated and / or utilized in a balanced manner, which causes delays and / or other issues associated with providing particular services and / or resources to devices connected to the SaaS system via the dial-out connectivity service instance.
[0014] Some implementations described herein provide a Network Management System (NMS). The NMS provides a certificate to a tenant's endpoint device, which includes identification information associated with the endpoint device (e.g., an identifier associated with the endpoint device) and identification information associated with the tenant (e.g., one or more identifiers associated with the tenant and / or the tenant's hierarchy). The endpoint device then initiates an outgoing communication session with the NMS and provides the certificate to the NMS for authentication and verification. Therefore, the NMS appends the identification information associated with the endpoint device and the tenant to messages sent by the endpoint device via the outgoing communication session. In this way, the NMS ensures that the identification information associated with the endpoint device and the tenant is transmitted to upstream services, which use this information to provide the endpoint device with tenant-specific resources and / or services.
[0015] In some implementations, NMS can provide multiple connectivity service instances to facilitate the establishment and maintenance of multiple outgoing communication sessions with multiple endpoint devices. Furthermore, NMS can provide load balancing across multiple outgoing communication sessions among the multiple connectivity service instances to ensure that one or more specific connectivity service instances do not become overloaded. In this way, NMS performance is improved (e.g., compared to a typical SaaS system). For example, due to load balancing, NMS's computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) are allocated and utilized in a balanced manner (e.g., across multiple connectivity service instances), which reduces and / or prevents latency and / or other issues associated with endpoint devices providing specific services and / or resources to connect to multiple connectivity service instances via multiple outgoing communication sessions.
[0016] Figures 1A-1H This is an illustration of one or more example implementations 100 described in this document. The example implementations 100(s) may include a network management system (NMS), a network device, and / or one or more endpoint devices, which will be discussed below. Figures 2-4 Describe them in more detail. For example, an NMS can be a multi-tenant, cloud-hosted network management SaaS system, and one or more endpoint devices and network devices can be associated with a tenant in the multi-tenant SaaS environment provided by the NMS. Figures 1A-1G As shown, NMS can include a load balancer, a certificate coordinator, and / or multiple connectivity service instances (in... Figure 1A The table shows connectivity service instances 1 to M, where M ≥ 2. Figures 1A-1B As shown, the certificate coordinator may include a tenant data structure, a device activation component, and / or a certificate manager.
[0017] like Figure 1AAs shown, and via reference numeral 102, the NMS can receive activation information from a tenant's endpoint device. For example, the endpoint device can be activated (e.g., can be turned on, can become operational, and / or can connect to a network device, thereby enabling communication with the NMS via the network device, etc.), and can initiate a communication session with the NMS, such as a Network Configuration (NETCONF) protocol communication session. Therefore, the endpoint device can send activation information to the NMS (e.g., via a communication session), and as... Figure 1A As shown, the device activation component of the NMS certificate coordinator can receive activation information. Activation information may include, for example, information identifying the endpoint device (e.g., a universally unique identifier (UUID) of the endpoint device, a media access control (MAC) address associated with the endpoint device, and / or a device name associated with the endpoint device, etc.) and / or information instructing the endpoint device to communicate with the NMS to obtain services and / or resources from the NMS (e.g., from one or more system components associated with the NMS).
[0018] like Figure 1A As shown, and via reference numeral 104, the NMS can determine identification information associated with endpoint devices and tenants. For example, the tenant data structure can be a database, an electronic file, or another data structure storing information identifying the association between endpoint devices and tenants. The NMS (e.g., using a device activation component) can search the tenant data structure (e.g., based on activation information received from the endpoint device by the NMS) to identify entries associated with the endpoint device, and can process (e.g., parse) the entry to obtain information identifying the tenant (e.g., the tenant's UUID) and / or information identifying the tenant's hierarchical structure (e.g., the tenant's organization's UUID, the corresponding UUIDs of one or more organizational units of the tenant, the corresponding UUIDs of one or more organizational subunits of the tenant, etc.). Regarding the tenant's hierarchical structure, the tenant's organization may include, for example, a Management Service Provider (MSP); organizational units may include, for example, subscribers to services and / or resources provided by the MSP (e.g., a company); and organizational subunits may include, for example, groups within a subscriber that want to access services and / or resources (e.g., departments or subsidiaries of a company). Therefore, NMS may include at least one of the following in the identification information associated with endpoint devices and tenants: information identifying the endpoint device, information identifying the tenant, or information identifying the tenant's hierarchical structure.
[0019] like Figure 1BAs shown, and via reference numeral 106, the NMS can generate a certificate that includes identification information associated with the endpoint device and the tenant. For example, the NMS's certificate manager could be a Certificate Authority (CA) that issues certificates (e.g., public key certificates, such as X.509 certificates, or other authentication certificates) to endpoint devices that can be used to authenticate the endpoint device with the NMS. Therefore, the NMS's device activation component can provide the certificate manager with the identification information associated with the endpoint device and the tenant, and the certificate manager can generate a certificate that includes this identification information. For example, as... Figure 1B As shown, the NMS can generate a sample certificate that includes identification information associated with the endpoint device and the tenant, such that the information identifying the endpoint device (shown as ED UUID) is included in the certificate's Common Name (CN) field, the information identifying the tenant (shown as T UUID) is included in the certificate's Organization (O) field, and the information identifying the tenant's hierarchical structure (shown as (multiple) HS UUIDs) is included in the certificate's Organizational Unit (OU) field. As indicated by reference numeral 108, the NMS can send the certificate to the endpoint device. For example, the NMS (e.g., using a device activation component) can send the certificate to the endpoint device via a communication session established between the NMS and the endpoint device.
[0020] like Figure 1C As shown, and via reference numeral 110, the NMS can receive a certificate from the endpoint device. For example, an endpoint device may attempt to initiate an outgoing communication session with the NMS (e.g., a secure communication session, such as a Transport Layer Security (TLS) communication session) (e.g., to obtain services and / or resources from the NMS), thereby sending a certificate to the NMS (e.g., as part of the attempt to initiate the outgoing communication session). In some implementations, the load balancer can select a connectivity service instance from multiple connectivity service instances of the NMS (in... Figure 1C The example shown is a connectivity service instance (M) that communicates with the endpoint device to determine whether to establish an outgoing communication session and, once established, supports the outgoing communication session. Therefore, the connectivity service instance can receive certificates (e.g., as part of an attempt to initiate an outgoing communication session).
[0021] As shown by reference number 112, the NMS can authenticate the endpoint device (e.g., based on the certificate). For example, the NMS (e.g., using the connectivity service instance) can use a certificate authentication technique to process the certificate to authenticate the endpoint device (e.g., determine that a certificate manager of a certificate orchestrator of the NMS issued the certificate and / or determine that the endpoint device is approved to communicate with the NMS via a dial-out communication session). As shown by reference number 114, when the NMS successfully authenticates the certificate, the NMS (e.g., using the connectivity service instance) can cause the dial-out communication session to be established (e.g., by sending one or more dial-out communication session acceptance messages to the endpoint device) and can perform any other processing steps described herein in connection with Figures 1D-1E establishing a dial-out communication session. Otherwise, the NMS can cause the dial-out communication session not to be established (e.g., by sending one or more dial-out communication session rejection messages to the endpoint device) and can not perform any other processing steps described herein in connection with Figures 1D-1E establishing a dial-out communication session.
[0022] As Figure 1D shown, and by reference number 116, the NMS can determine identification information associated with the endpoint device and the tenant (e.g., included in the certificate received from the endpoint device). For example, the NMS (e.g., using the connectivity service instance) can process (e.g., parse) the certificate to determine the identification information associated with the endpoint device and the tenant (e.g., included in the CN field, the O field, and / or the OU field of the example certificate shown). The NMS can use the identification information to facilitate providing services and / or resources to the endpoint device via the dial-out communication session, as described further herein. Figure 1B
[0023] As shown by reference number 118, the NMS can receive one or more messages from the endpoint device (e.g., via the dial-out communication session). For example, the endpoint device can send one or more messages to the NMS via the dial-out communication session to obtain services and / or resources associated with the NMS, and as Figure 1D shown, the connectivity service instance of the NMS can receive the one or more messages. As shown by reference number 120, the NMS can modify the one or more messages. For example, the NMS (e.g., using the connectivity service instance) can modify the one or more messages to include the identification information associated with the endpoint device and the tenant (e.g., append the identification information to at least one of the one or more messages).
[0024] As Figure 1E As shown and by reference numeral 122, after modification, the NMS can provide one or more modified messages to facilitate the provision of services and / or resources associated with the NMS to an endpoint device. For example, the NMS (e.g., using a connectivity service instance) can provide one or more modified messages to system elements associated with the system (e.g., included in the NMS and / or accessible by the NMS). Thus, the system elements can provide services and / or resources to the endpoint device based on the identification information associated with the endpoint device and tenant included in the one or more modified messages. For example, the system elements can determine that the endpoint device is associated with a tenant, the tenant's organization, the tenant's organizational unit, an organizational subunit, etc. that is permitted to access the services and / or resources based on the identification information, and thus can provide services and / or resources to the endpoint device. In some implementations, to provide services and / or resources to the endpoint device, the system elements can provide one or more additional messages associated with the services and / or resources to a connectivity service instance. Thus, as shown by reference numeral 124, the NMS (e.g., using a connectivity service instance) can send one or more additional messages to the endpoint device (e.g., via an outgoing communication session) to facilitate the provision of services and / or resources to the endpoint device.
[0025] In some implementations, the NMS can have multiple ports, where each port is associated with a set of connectivity service instances (e.g., one or more connectivity service instances) of the multiple connectivity service instances. For example, as Figure 1F shown, a first set of connectivity service instances (shown as connectivity service instances 1 to K, where 1 ≤ K < M) can be associated with port A of the NMS, and a second set of connectivity service instances (shown as connectivity service instances L to M, where K < L ≤ M) can be associated with port B of the NMS. Each set of connectivity service instances can be associated with a specific type of outgoing communication session. For example, the first set of connectivity service instances can support a first type of outgoing communication session (e.g., for transmitting system logs), and the second set of connectivity service instances can support a second type of outgoing communication session (e.g., for transmitting interface telemetry information). Thus, each type of connectivity service instance can be associated with a specific port of the NMS. For example, the first type of outgoing communication session can be associated with port A, and the second type of outgoing communication session can be associated with port B.
[0026] In some implementations, each set of connectivity service instances among the multiple connectivity service instances of the NMS can support one or more outgoing communication sessions (e.g., associated with the type of connectivity service instance and associated with a specific port of the NMS). Thus, as Figure 1FAs shown and by reference number 126, the NMS can identify a set of connectivity service instances (e.g., including more than one connectivity service instance) associated with the connectivity service instance type, e.g., to facilitate load balancing of dial-out communication sessions associated with the connectivity service instance type over the set of connectivity service instances. For example, the NMS (e.g., using a load balancer) can identify currently running connectivity service instances of the NMS that are associated with the connectivity service instance type. Accordingly, as shown by reference number 128, the NMS can determine respective instance weights (e.g., indicative of respective “processing loads” of the set of connectivity service instances) for the set of connectivity service instances. In some implementations, the NMS (e.g., using a load balancer) can determine an instance weight (e.g., greater than or equal to 0 and less than or equal to 1) for each connectivity service instance of the set of connectivity service instances based on a current processing rate (e.g., measured in events per second (EPS)) of the connectivity service instance. For example, the instance weight can be a combination of the current processing rate of the connectivity service instance and a threshold processing rate (e.g., a maximum processing rate for providing optimal performance related to dial-out communication sessions supported by the connectivity service instance) of the connectivity service instance, such as the current processing rate of the connectivity service instance divided by the threshold processing rate of the connectivity service instance. The NMS (e.g., using a load balancer) can determine the instance weight for each connectivity service instance based on a schedule, e.g., at regular time intervals, such as less than or equal to every 5 minutes, every 1 hour, or every 3 hours.
[0027] In some implementations, as shown by reference number 130, for each connectivity service instance of the set of connectivity service instances, the NMS can determine a respective session weight (e.g., indicative of respective “session loads” of the one or more dial-out communication sessions) for the one or more dial-out communication sessions (e.g., having the connectivity service instance type) supported by the connectivity service instance. In some implementations, the NMS (e.g., using a load balancer) can determine a session weight (e.g., greater than or equal to 0 and less than or equal to 1) for each dial-out communication session supported by the connectivity service instance based on a current processing rate (e.g., measured in EPS) of the connectivity service instance due to the dial-out communication session. For example, the session weight can be a combination of the current processing rate of the connectivity service instance due to the dial-out communication session, a maximum processing rate of the dial-out communication session due to a representative dial-out communication session, and / or a minimum processing rate of the dial-out communication session due to a representative dial-out communication session, e.g., according to the following formula:
[0028] SWi = (SRi - SRmin) / (SRmax - SRmin),
[0029] Where SWi is the session weight of outgoing communication session i, SRi is the current processing rate of the connectivity service instance due to outgoing communication session i, SRmin is the minimum processing rate of the outgoing communication session due to the representative outgoing communication session, and SRmax is the maximum processing rate of the outgoing communication session due to the representative outgoing communication session. NMS (e.g., using a load balancer) can determine the session weight of each outgoing communication session based on scheduling, such as at regular time intervals, such as less than or equal to every 5 minutes, every 1 hour, or every 3 hours.
[0030] like Figure 1G As shown, NMS can cause one or more load balancing actions (e.g., based on the corresponding instance weights of the connectivity service instance set and / or the corresponding session weights of one or more outgoing communication sessions supported by each connectivity service instance) to be performed. For example, as shown by reference numeral 132, NMS can cause additional connectivity service instances (e.g., associated with the connectivity service instance type) to be added to the connectivity service instance set (and thus added to multiple connectivity service instances). NMS (e.g., using a load balancer) can determine that the corresponding instance weights of at least a certain number of connectivity service instances in the connectivity service instance set (e.g., the corresponding instance weights of all connectivity service instances, a majority of connectivity service instances, or at least a minimum number of connectivity service instances) satisfy (e.g., greater than or equal to) an instance weight threshold (e.g., greater than or equal to 0.5, 0.7, or 0.9, etc.). Thus, as Figure 1G As shown, NMS (e.g., using a load balancer) can enable additional connectivity service instances (in...) Figure 1G A connectivity service instance (denoted as N) is added to the set of connectivity service instances (and thus to multiple connectivity service instances). Additional connectivity services can support new outgoing communication sessions associated with the connectivity service instance type and / or outgoing communication sessions associated with the connectivity service instance type that are discarded by other connectivity service instances in the set of connectivity service instances (e.g., as further described herein with respect to reference numeral 134). NMS can use connectivity service instances to deploy models (e.g., as described herein with respect to reference numeral 134). Figure 1H (Further description) to generate additional connectivity service instances.
[0031] As another example, as shown by reference number 134, the NMS can cause a dial-out communication session supported by a connectivity service instance of the set of connectivity service instances to be dropped from the connectivity service instance. In some implementations, for each connectivity service instance of the set of connectivity service instances, the NMS (e.g., using a load balancer) can determine whether an instance weight of the connectivity service instance satisfies (e.g., is greater than or equal to) an instance weight threshold (e.g., greater than or equal to 0.5, 0.7, or 0.9, among other examples). When the NMS (e.g., using a load balancer) determines that the instance weight of the connectivity service instance satisfies the instance weight threshold, the NMS can select a set of one or more dial-out communication sessions of the connectivity service instance and can drop the set of one or more dial-out communication sessions from the connectivity service instance. For example, the NMS can select the set of one or more dial-out communication sessions of the connectivity service instance that has the greatest session weight (e.g., respective session weights of the set of one or more dial-out communication sessions are greater than respective session weights of other dial-out communication sessions of the connectivity service instance), or that has a session weight that satisfies (e.g., is greater than or equal to) a session weight threshold (e.g., greater than or equal to 0.5, 0.7, or 0.9, among other examples).
[0032] Dropping the set of one or more dial-out communication sessions can cause an endpoint device associated with the set of one or more dial-out communication sessions to initiate one or more new dial-out communication sessions associated with the connectivity service instance type (e.g., associated with one or more other connectivity service instances of the set of connectivity service instances). For example, for each attempt by the endpoint device to initiate a new dial-out communication session associated with the connectivity service instance type, the NMS (e.g., using a load balancer) can select (e.g., using a random or pseudo-random selection policy) a connectivity service instance of the set of connectivity service instances (e.g., different from the connectivity service instance from which the set of one or more dial-out communication sessions was dropped). As another example, for each attempt by the endpoint device to initiate a new dial-out communication session associated with the connectivity service instance type, the NMS (e.g., using a load balancer) can select a connectivity service instance of the set of connectivity service instances that has a minimum session weight (e.g., a session weight that is less than or equal to respective session weights of other connectivity service instances of the set of connectivity service instances). Thus, the selected connectivity service instance can communicate with the endpoint device to determine whether to establish a new dial-out communication session and to support the new dial-out communication session once established (e.g., as described herein with reference to FIG. 1). Figures 1C-1D
[0033] Figure 1H An example connectivity service instance deployment model is shown, which can be used to add connectivity service instances (e.g., associated with a specific connectivity service instance type) to an NMS (e.g., to populate an NMS with multiple connectivity service instances and / or to add additional connectivity service instances to the NMS, as described in this article). Figure 1G (As described in Figure 132). Figure 1H As shown, and by reference numeral 136, for a connectivity service instance to be deployed, the example connectivity service instance deployment model may include a name field (e.g., indicating the name of the connectivity service instance), a description field (e.g., providing a description of the connectivity service instance), a type field (e.g., indicating a specific connectivity service instance type), a port field (e.g., indicating the port of the NMS on which the connectivity service instance will communicate), an upstream field (e.g., identifying whether the connectivity service instance will communicate with a system element that provides services and / or resources associated with the NMS), a name subfield of the upstream field (e.g., indicating the name of the system element), a type subfield of the upstream field (e.g., indicating the type of the system element, such as whether the system element is a coordination system (e.g., a Kubernetes system or another coordination system)), and / or an attribute subfield of the upstream field (e.g., indicating one or more attributes of the system element, such as one or more coordination attributes), which may be indicated by a keyword string subfield and / or a value subfield of the attribute subfield. Therefore, an NMS (e.g., using a load balancer or another element of the NMS) can deploy a connectivity service instance using the example connectivity service instance deployment model, as described elsewhere herein. For example, NMS can use a configuration deployment language (e.g., YAML) to apply a sample connectivity service instance deployment model to deploy connectivity service instances.
[0034] As mentioned above, Figures 1A-1H This is provided as one or more examples only. Other examples may differ from the reference. Figures 1A-1H As described.
[0035] Figure 2 This is a diagram of an example environment 200 that can implement the systems and / or methods described herein. (See diagram for example.) Figure 2 As shown, environment 200 may include network management system 201, which may include one or more components of cloud computing system 202 and / or may execute within cloud computing system 202. Cloud computing system 202 may include one or more components 203-212, as described in more detail below. Figure 2 As further shown, environment 200 may include network 220, network device 230, and / or one or more endpoint devices 240. The devices and / or components of environment 200 may be interconnected via wired and / or wireless connections.
[0036] Cloud computing system 202 includes computing hardware 203, resource management component 204, host operating system (OS) 205, and / or one or more virtual computing systems 206. Cloud computing system 202 can execute on, for example, the Amazon Web Services platform, the Microsoft Azure platform, or the Snowflake platform. Resource management component 204 can perform virtualization (e.g., abstraction) of computing hardware 203 to create one or more virtual computing systems 206. Using virtualization, resource management component 204 enables a single computing device (e.g., a computer or server) to operate like multiple computing devices, for example, by creating multiple isolated virtual computing systems 206 from the computing hardware 203 of that single computing device. In this way, computing hardware 203 can operate more efficiently with lower power consumption, higher reliability, higher availability, higher utilization, greater flexibility, and lower cost than using separate computing devices.
[0037] Computing hardware 203 includes hardware and corresponding resources from one or more computing devices. For example, computing hardware 203 can include hardware from a single computing device (e.g., a single server) or from multiple computing devices (e.g., multiple servers), such as multiple computing devices in one or more data centers. As shown, computing hardware 203 can include one or more processors 207, one or more memories 208, and / or one or more networking components 209. Examples of processors, memories, and networking components (e.g., communication components) are described elsewhere herein.
[0038] Resource management component 204 includes a virtualization application (e.g., executing on hardware such as computing hardware 203) that is capable of virtualizing computing hardware 203 to launch, stop, and / or manage one or more virtual computing systems 206. For example, resource management component 204 can include a hypervisor (e.g., a bare-metal or type 1 hypervisor, a managed or type 2 hypervisor, or another type of hypervisor) or a virtual machine monitor, for example, when virtual computing systems 206 are virtual machines 210. Additionally or alternatively, resource management component 204 can include a container manager, for example, when virtual computing systems 206 are containers 211 (e.g., including one or more threads). In some implementations, resource management component 204 executes within and / or in coordination with host operating system 205. In some implementations, resource management component 204 includes a load balancer, a certificate orchestrator (e.g., that includes a tenant data structure, a device activation component, and / or a certificate manager), and / or multiple connectivity service instances described herein with reference to Figures 1A-1H In some implementations, resource management component 204 can include multiple connectivity service instances described herein with reference to Figures 1A-1HThe described system elements, or alternatively, can be in communication with the system elements (e.g., via network 220).
[0039] Virtual computing system 206 includes a virtual environment that implements cloud-based execution of the operations and / or processes described herein using computing hardware 203. As shown, virtual computing system 206 can include virtual machines 210, containers 211, or a hybrid environment 212 that includes virtual machines and containers, among other examples. Virtual computing system 206 can execute one or more applications using a file system that includes binary files, software libraries, and / or other resources needed to execute an application on a guest operating system (e.g., within virtual computing system 206) or host operating system 205.
[0040] Although network management system 201 can include one or more elements 203-212 of cloud computing system 202, can be executed within cloud computing system 202, and / or can be hosted within cloud computing system 202, in some implementations, network management system 201 can not be cloud-based (e.g., can be implemented outside of a cloud computing system), or can be partially cloud-based. For example, network management system 201 can include one or more devices that are not part of cloud computing system 202, such as Figure 3 device 300, which can include a standalone server or another type of computing device. Network management system 201 can perform one or more operations and / or processes described in greater detail elsewhere herein. In some implementations, the event log management system can provide a multi-tenant SaaS environment to one or more tenants (e.g., where the tenants include network devices 230 and one or more endpoint devices 240).
[0041] Network 220 includes one or more wired and / or wireless networks. For example, network 220 can include a cellular network, a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a private network, the Internet, and / or a combination of such or other types of networks. Network 220 facilitates communications between the devices of environment 200.
[0042] The network devices 230 include one or more devices capable of receiving, processing, storing, routing, and / or providing business (e.g., packets or other information or metadata) in the manner described herein. For example, the network devices 230 can include routers, such as label-switched routers (LSRs), label edge routers (LERs), ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, or another type of router. Additionally or alternatively, the network devices 230 can include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, or data center servers), load balancers, and / or the like. In some implementations, the network devices 230 can be physical devices implemented within an enclosure, such as a chassis. In some implementations, the network devices 230 can be virtual devices implemented by one or more computer devices of a cloud computing environment or data center. In some implementations, a group of the network devices 230 can be a group of data center nodes for routing traffic flows through the network 220. In some implementations, the network devices 230 can be associated with a tenant of a multi-tenant SaaS environment provided by the network management system 201.
[0043] The endpoint device(s) 240 include one or more devices capable of receiving, generating, storing, processing, and / or providing information, such as that described herein. For example, the endpoint device(s) 240 can include a mobile phone (e.g., a smartphone or wireless phone), a laptop computer, a tablet computer, a desktop computer, a handheld computer, a gaming device, a wearable communication device (e.g., a smartwatch, a pair of smart glasses, a heart rate monitor, a fitness tracker, smart clothing, smart jewelry, or a head-mounted display), a network device, or a similar type of device. In some implementations, the endpoint device(s) 240 can receive network traffic from and / or can provide network traffic to the network management system 201 and / or the network devices 230 via the network 220. In some implementations, the endpoint device(s) 240 can be associated with a tenant of a multi-tenant SaaS environment provided by the network management system 201.
[0044] Figure 2 The number and arrangement of devices and networks shown is provided as an example. In practice, there can be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks than those shown in Figure 2 FIG. 1. Additionally, two or more devices shown in FIG. 1 can be implemented within a single device, or a single device shown in FIG. 1 can be implemented as multiple, distributed devices. Similarly, a portion of the functionality of a device can be implemented by multiple devices. Figure 2 Figure 2 The individual devices shown in the environment 200 can be implemented as multiple distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of the environment 200 can perform one or more functions described as being performed by another set of devices of the environment 200.
[0045] Figure 3 FIG. 3 is a diagram of an example component of a device 300, which can correspond to the network management system 201, the computing hardware 203, the network device 230, and / or the endpoint device 240. In some implementations, the network management system 201, the computing hardware 203, the network device 230, and / or the endpoint device 240 include one or more devices 300 and / or one or more components of the device 300. As shown, the device 300 can include a bus 310, a processor 320, a memory 330, an input component 340, an output component 350, and a communication component 360. Figure 3
[0046] The bus 310 includes one or more components that enable wired and / or wireless communication among the components of the device 300. The bus 310 can couple two or more components of the device 300 together, such as via operational coupling, communicative coupling, electronic coupling, and / or electrical coupling. The processor 320 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field programmable gate array, an application specific integrated circuit, and / or another type of processing component. The processor 320 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the processor 320 includes one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein. Figure 3
[0047] The memory 330 includes volatile and / or non-volatile memory. For example, the memory 330 can include random access memory (RAM), read only memory (ROM), a hard disk drive, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory). The memory 330 can include internal memory (e.g., RAM, ROM, or a hard disk drive) and / or removable memory (e.g., removable via a universal serial bus connection). The memory 330 can be a non-transitory computer-readable medium. The memory 330 stores information, instructions, and / or software (e.g., one or more software applications) related to the operation of the device 300. In some implementations, the memory 330 includes one or more memories coupled to one or more processors (e.g., the processor 320), such as via the bus 310.
[0048] The input component 340 enables the device 300 to receive input, such as user input and / or sensory input. For example, the input component 340 can include a touch screen, a keyboard, a keypad, a mouse, a button, a microphone, a switch, a sensor, a global positioning system sensor, an accelerometer, a gyroscope, and / or an actuator. The output component 350 enables the device 300 to provide outputs, such as via a display, a speaker, and / or a light emitting diode. The communication component 360 enables the device 300 to communicate with other devices via wired and / or wireless connections. For example, the communication component 360 can include a receiver, a transmitter, a transceiver, a modem, a network interface card, and / or an antenna.
[0049] The device 300 can perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., the memory 330) can store a set of instructions (e.g., one or more instructions or code) for execution by the processor 320. The processor 320 can execute the set of instructions to perform one or more operations or processes described herein. In some implementations, execution of the set of instructions by one or more processors 320 causes the one or more processors 320 and / or the device 300 to perform one or more operations or processes described herein. In some implementations, one or more operations or processes described herein are performed using hardwired circuitry, instead of or in combination with
[0050] Figure 3 The number and arrangement of components shown in FIG. 4 are provided as an example. Device 400 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 can perform one or more functions described as being performed by another set of components of device 400. Figure 3 As an example and not by way of limitation, one or more blocks of an example method described herein can be implemented as one or more modules of the device 400. As used herein, a module of a device is a tangible, but possibly non-transient, unit of hardware that has a set of related
[0051] Figure 4 FIG. 4 is a diagram of example components of a device 400. Device 400 can correspond to network management system 201, computing hardware 203, network device 230, and / or endpoint device 240. In some implementations, network management system 201, computing hardware 203, network device 230, and / or endpoint device 240 can include one or more devices 400 and / or one or more components of device 400. As Figure 4As shown, the device 400 can include one or more input components 410-1 through 410-B (B > 1) (hereinafter collectively referred to as input components 410, and individually as input component 410), a switching component 420, one or more output components 430-1 through 430-C (C > 1) (hereinafter collectively referred to as output components 430, and individually as output component 430), and a controller 440.
[0052] The input components 410 can be one or more attachment points for physical links and can be one or more entry points for incoming traffic such as packets. The input components 410 can process incoming traffic, for example, by performing data link layer encapsulation or decapsulation. In some implementations, the input components 410 can transmit and / or receive packets. In some implementations, the input components 410 can include input line cards that include one or more packet processing components (e.g., in the form of integrated circuits), such as one or more interface cards (IFCs), packet forwarding components, line card controller components, input ports, processors, memories, and / or input queues. In some implementations, the device 400 can include one or more input components 410.
[0053] The switching component 420 can interconnect the input components 410 with the output components 430. In some implementations, the switching component 420 can be implemented via one or more crossbars, via buses, and / or with shared memory. Shared memory can be used as a temporary buffer to store packets from the input components 410 before the packets are finally scheduled for delivery to the output components 430. In some implementations, the switching component 420 can enable the input components 410, the output components 430, and / or the controller 440 to communicate with one another.
[0054] The output components 430 can store packets and can schedule packets for transmission on output physical links. The output components 430 can support data link layer encapsulation or decapsulation and / or various higher layer protocols. In some implementations, the output components 430 can transmit packets and / or receive packets. In some implementations, the output components 430 can include output line cards that include one or more packet processing components (e.g., in the form of integrated circuits), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, the device 400 can include one or more output components 430. In some implementations, the input components 410 and the output components 430 can be implemented by the same set of components (e.g., an input / output component can be a combination of the input components 410 and the output components 430).
[0055] The controller 440 includes a processor, such as a CPU, GPU, APU, microprocessor, microcontroller, DSP, FPGA, ASIC, and / or other processing component(s). The processor is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the controller 440 can include one or more processors that can be programmed to perform functions.
[0056] In some implementations, the controller 440 can include RAM, ROM, and / or another type of dynamic or static storage device (e.g., flash memory, magnetic storage, optical storage, etc.) that stores information and / or instructions for use by the controller 440.
[0057] In some implementations, the controller 440 can communicate with other devices, networks, and / or systems connected to the device 400 to exchange information about a network topology. The controller 440 can create a routing table based on the network topology information, can create a forwarding table based on the routing table, and can forward the forwarding table to the input component 410 and / or the output component 430. The input component 410 and / or the output component 430 can use the forwarding table to perform route lookups for incoming and / or outgoing packets.
[0058] The controller 440 can perform one or more processes described herein. The controller 440 can perform these processes in response to execution of software instructions stored by a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes a single physical storage location, or multiple physical storage locations, within a single physical organization or distributed across multiple physical organizations.
[0059] The software instructions can be read into the memory and / or storage components associated with the controller 440 from another computer-readable medium or from another device via a communication interface. When executed, the software instructions stored in the memory and / or storage components associated with the controller 440 can cause the controller 440 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry can be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, implementations described herein are not limited to any specific combination of hardware circuitry and software.
[0060] Figure 4 The number and arrangement of components shown in FIG. 4 are provided as an example. In practice, device 400 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 can perform one or more functions described as being performed by another set of components of device 400. Figure 4 As an example, a set of components (e.g., one or more components) of device 400 can perform one or more functions of another set of components of device 400.
[0061] Figure 5 is a flow diagram of an example process 500 related to management of a dial-out communication session. In some implementations, Figure 5 one or more process blocks of are performed by a system (e.g., the event network management system 201). In some implementations, Figure 5 one or more process blocks of are performed by another device or group of devices separate from the system or including the system, such as computing hardware (e.g., the computing hardware 203), a network device (e.g., the network device 230), and / or an endpoint device (e.g., the endpoint device 240). Additionally or alternatively, Figure 5 one or more process blocks of can be performed by one or more components of the device 300, such as the processor 320, the memory 330, the input component 340, the output component 350, and / or the communication component 360; one or more components of the device 400, such as the input component 410, the toggle component 420, the output component 430, and / or the controller 440; and / or one or more components of another device.
[0062] As shown in Figure 5 the process 500 can include receiving, from an endpoint device associated with a tenant of the system, activation information associated with the endpoint device (block 510). For example, the system can receive, from an endpoint device associated with a tenant of the system, activation information associated with the endpoint device, as described above.
[0063] As further shown in Figure 5 the process 500 can include determining, based on the activation information, identification information associated with the endpoint device and the tenant (block 520). For example, the system can determine, based on the activation information, identification information associated with the endpoint device and the tenant, as described above.
[0064] As further shown in Figure 5 the process 500 can include generating a certificate including the identification information (block 530). For example, the system can generate a certificate including the identification information, as described above.
[0065] As further shown in Figure 5 the process 500 can include sending the certificate to the endpoint device (block 540). For example, the system can send the certificate to the endpoint device, as described above. In some implementations, the endpoint device will provide the certificate to the system when attempting to initiate a dial-out communication session with the system.
[0066] The process 500 can include additional implementations, such as any single implementation described below or any combination of the implementations described below in conjunction with one or more other processes described elsewhere herein.
[0067] In a first implementation, the identification information includes at least one of information identifying the tenant or information identifying a hierarchy of the tenant.
[0068] In a second implementation, the process 500 includes receiving, from the endpoint device and as part of an attempt by the endpoint device to initiate a dial-out communication session with the system, a certificate; authenticating the endpoint device based on the certificate; processing the certificate to determine identification information based on authenticating the endpoint device; causing the dial-out communication session to be established based on authenticating the endpoint device; receiving one or more messages from the endpoint device and via the dial-out communication session; modifying the one or more messages to include the identification information; and providing the modified one or more messages after the modification to facilitate provisioning to the endpoint device, a service or a resource associated with the system.
[0069] In a third implementation, the process 500 includes identifying a plurality of connectivity service instances of the system that are associated with a connectivity service instance type, wherein each connectivity service instance of the plurality of connectivity service instances supports one or more dial-out communication sessions associated with the connectivity service instance type; determining respective instance weights for the plurality of connectivity service instances; and causing one or more load balancing actions to be performed based on the respective instance weights for the plurality of connectivity service instances.
[0070] In a fourth implementation, causing the one or more load balancing actions to be performed includes causing a dial-out communication session supported by a connectivity service instance of the plurality of connectivity service instances to be dropped from the connectivity service instance.
[0071] In a fifth implementation, causing the one or more load balancing actions to be performed includes determining that respective instance weights for at least a particular number of connectivity service instances of the plurality of connectivity service instances satisfy an instance weight threshold; and causing an additional connectivity service instance associated with the connectivity service instance type to be added to the plurality of connectivity service instances based on determining that the respective instance weights for the at least the particular number of connectivity service instances satisfy the instance weight threshold.
[0072] In a sixth implementation, causing the one or more load balancing actions to be performed includes generating, using a connectivity service instance deployment model, an additional connectivity service instance associated with the connectivity service instance type to be added to the plurality of connectivity service instances.
[0073] In the seventh implementation, process 500 includes identifying multiple connectivity service instances of the system associated with a connectivity service instance type, wherein each of the multiple connectivity service instances supports one or more outgoing communication sessions associated with the connectivity service instance type; determining the corresponding instance weights of the multiple connectivity service instances; for each of the multiple connectivity service instances, determining the corresponding session weights of the one or more outgoing communication sessions supported by the connectivity service instance; and causing one or more load balancing actions to be performed based on the corresponding instance weights of the multiple connectivity service instances and the corresponding session weights of the one or more outgoing communication sessions supported by each connectivity service instance.
[0074] In the eighth implementation, causing one or more load balancing actions to be performed includes: determining that the instance weight of a connectivity service instance among a plurality of connectivity service instances meets an instance weight threshold; based on determining that the instance weight of a connectivity service instance meets an instance weight threshold, identifying an outgoing communication session whose session weight meets a session weight threshold among one or more outgoing communication sessions supported by the connectivity service instance; and causing the outgoing communication session to be dropped from the connectivity service instance.
[0075] although Figure 5 An example box of process 500 is shown, but in some implementations, process 500 includes... Figure 6 Compared to the boxes shown, there may be additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Alternatively or concurrently, two or more boxes of process 500 may be executed in parallel.
[0076] Figure 6 This is a flowchart of an example process 600 related to the management of outgoing communication sessions. In some implementations, Figure 6 One or more process frames are executed by the system (e.g., event network management system 201). In some implementations, Figure 6 One or more process frames are executed by another device or group of devices that are separate from or include the system, such as computing hardware (e.g., computing hardware 203), network devices (e.g., network device 230), and / or endpoint devices (e.g., endpoint device 240). Additionally or alternatively, Figure 6 One or more process frames may be executed by: one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350 and / or communication component 360; one or more components of device 400, such as input component 410, switch component 420, output component 430 and / or controller 440; and / or one or more components of another device.
[0077] like Figure 6As shown, process 600 can include receiving a certificate from an endpoint device associated with a tenant of the system and as part of an attempt by the endpoint device to initiate an outbound communication session with the system (block 610). For example, the system can receive a certificate from an endpoint device associated with a tenant of the system and as part of an attempt by the endpoint device to initiate an outbound communication session with the system, as described above.
[0078] As Figure 6 Further shown, process 600 can include causing the outbound communication session to be established based on the certificate (block 620). For example, the system can cause the outbound communication session to be established based on the certificate, as described above.
[0079] As Figure 6 Further shown, process 600 can include processing the certificate to determine identification information associated with the endpoint device and the tenant (block 630). For example, the system can process the certificate to determine identification information associated with the endpoint device and the tenant, as described above.
[0080] As Figure 6 Further shown, process 600 can include receiving one or more messages from the endpoint device and via the outbound communication session (block 640). For example, the system can receive one or more messages from the endpoint device and via the outbound communication session, as described above.
[0081] As Figure 6 Further shown, process 600 can include modifying the one or more messages to include the identification information (block 650). For example, the system can modify the one or more messages to include the identification information, as described above.
[0082] As Figure 6 Further shown, process 600 can include providing the modified one or more messages after the modifying to facilitate provisioning to the endpoint device, a service or resource associated with the system (block 660). For example, the system can provide the modified one or more messages after the modifying to facilitate provisioning to the endpoint device, a service or resource associated with the system, as described above.
[0083] Process 600 can include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere herein.
[0084] In a first implementation, process 600 includes receiving activation information associated with the endpoint device from the endpoint device and prior to receiving the certificate; determining the identification information associated with the endpoint device and the tenant based on the activation information; generating the certificate including the identification information; and sending the certificate to the endpoint device.
[0085] In the second implementation, process 600 includes: identifying a plurality of connectivity service instances of the system associated with a connectivity service instance type, wherein each of the plurality of connectivity service instances supports one or more outgoing communication sessions associated with the connectivity service instance type; determining the respective instance weights of the plurality of connectivity service instances; and causing one or more load balancing actions to be performed based on the respective instance weights of the plurality of connectivity service instances.
[0086] In the third implementation, causing one or more load balancing actions to be performed includes at least one of the following: causing an outgoing communication session supported by a connectivity service instance among multiple connectivity service instances to be dropped from the connectivity service instance, or causing an additional connectivity service instance associated with the connectivity service instance type to be added to the multiple connectivity service instances.
[0087] In the fourth implementation, causing one or more load balancing actions to be performed includes at least one of the following: for each of the multiple connectivity service instances, determining the corresponding session weight of one or more outgoing communication sessions supported by the connectivity service instance, and causing one or more load balancing actions to be performed based on the corresponding instance weights of the multiple connectivity service instances and the corresponding session weights of one or more outgoing communication sessions supported by each connectivity service instance.
[0088] although Figure 7 An example box of process 600 is shown, but in some implementations, process 600 includes... Figure 7 Compared to the boxes shown, there may be additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Alternatively or additionally, two or more boxes of process 600 may be executed in parallel.
[0089] Figure 7 This is a flowchart of an example process 700 related to the management of outgoing communication sessions. In some implementations, Figure 7 One or more process frames are executed by the system (e.g., event network management system 201). In some implementations, Figure 7 One or more process frames are executed by another device or group of devices that are separate from or include the system, such as computing hardware (e.g., computing hardware 203), network devices (e.g., network device 230), and / or endpoint devices (e.g., endpoint device 240). Additionally or alternatively, Figure 7One or more process blocks of the subject patent disclosure can be performed by one or more components of the device 300, such as the processor 320, the memory 330, the input component 340, the output component 350, and / or the communication component 360; one or more components of the device 400, such as the input component 410, the switch component 420, the output component 430, and / or the controller 440; and / or one or more components of another device.
[0090] As shown Figure 7 The process 700 can include identifying a plurality of connectivity service instances of a system that are associated with a connectivity service instance type (block 710). For example, the system can identify a plurality of connectivity service instances of the system that are associated with a connectivity service instance type, as described above. In some implementations, each connectivity service instance of the plurality of connectivity service instances supports one or more outbound communication sessions that are associated with the connectivity service instance type.
[0091] As further shown Figure 7 The process 700 can include determining respective instance weights of the plurality of connectivity service instances (block 720). For example, the system can determine respective instance weights of the plurality of connectivity service instances, as described above.
[0092] As further shown Figure 7 The process 700 can include causing one or more load balancing actions to be performed based on the respective instance weights of the plurality of connectivity service instances (block 730). For example, the system can cause one or more load balancing actions to be performed based on the respective instance weights of the plurality of connectivity service instances, as described above.
[0093] The process 700 can include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere in this document.
[0094] In a first implementation, causing one or more load balancing actions to be performed includes determining that respective instance weights of at least a particular number of connectivity service instances of the plurality of connectivity service instances satisfy an instance weight threshold, and causing an additional connectivity service instance associated with the connectivity service instance type to be added to the plurality of connectivity service instances based on determining that the respective instance weights of the at least the particular number of connectivity service instances satisfy the instance weight threshold.
[0095] In a second implementation, causing one or more load balancing actions to be performed includes generating, using a connectivity service instance deployment model, an additional connectivity service instance associated with the connectivity service instance type to be added to the plurality of connectivity service instances.
[0096] In the third implementation, causing one or more load balancing actions to be performed includes: for each of the multiple connectivity service instances, determining the corresponding session weight of one or more outgoing communication sessions supported by the connectivity service instance; determining that the instance weight of the connectivity service instance among the multiple connectivity service instances meets the instance weight threshold; based on determining that the instance weight of the connectivity service instance meets the instance weight threshold, identifying outgoing communication sessions among the one or more outgoing communication sessions supported by the connectivity service instance whose session weight meets the session weight threshold; and causing the outgoing communication sessions to be dropped from the connectivity service instance.
[0097] In the fourth implementation, process 700 includes: receiving activation information associated with an endpoint device from an endpoint device associated with a tenant of the system; determining identification information associated with the endpoint device and the tenant based on the activation information; generating a certificate including the identification information; and sending the certificate to the endpoint device, wherein the endpoint device will provide the certificate to the system when attempting to initiate an outgoing communication session with the system.
[0098] In the fifth implementation, process 700 includes: receiving a certificate from an endpoint device associated with a tenant of the system and as part of an attempt by the endpoint device to initiate a dial-out communication session with the system; enabling the dial-out communication session to be established based on the certificate and supported by a specific connectivity service instance of a plurality of connectivity service instances; processing the certificate to determine identification information associated with the endpoint device and the tenant; receiving one or more messages from the endpoint device and via the dial-out communication session; modifying one or more messages to include the identification information; and providing one or more modified messages after modification to facilitate provisioning to the endpoint device, to services or resources associated with the system.
[0099] although An example box of process 700 is shown, but in some implementations, process 700 includes... Compared to the boxes shown, there may be additional boxes, fewer boxes, different boxes, or boxes arranged differently. Additionally or alternatively, two or more boxes of process 700 may be executed in parallel.
[0100] The foregoing disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit implementation to the precise forms disclosed. Modifications and variations can be made based on the foregoing disclosure, or from practical implementation.
[0101] As used herein, traffic or content can include a set of packets. A packet can refer to a communication structure used to convey information, such as a protocol data unit (PDU), service data unit (SDU), network packet, datagram, segment, message, block, frame (e.g., an Ethernet frame), a portion of any of the above, and / or another type of formatted or unformatted data unit capable of being transported via a network.
[0102] As used herein, satisfying a threshold can refer to a value being greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, not equal to the threshold, etc., depending on the context.
[0103] As used herein, the term “component” is intended to be broadly construed as hardware, firmware, or a combination of hardware and software. It will be apparent that systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it being understood that software and hardware can be used to implement the systems and / or methods, based on the description herein.
[0104] Even if a particular combination is disclosed in the claims and / or in the specification, that combination is not intended to limit the disclosure of various implementations. In fact, many of these features can be combined in ways not specifically stated in the claims and / or in the specification. Although each dependent claim may
[0105] No element, act or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the article “a” is intended to include one or more items, and can be used interchangeably with “one or more.” Furthermore, as used herein, the article “the” is intended to include one or more items, and can be used interchangeably with “the one or more.” Furthermore, as used herein, the term “set” is intended to include one or more items (for example, related items, unrelated items, or a combination of related and unrelated items), and can be used interchangeably with “one or more.” Where only one item is intended, the phrase “only one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Also, as used herein, the term “or” is intended to be inclusive when used in a series and can be used interchangeably with “and / or,” unless explicitly stated otherwise (e.g., if used in combination with “either” or “only one of’).
Claims
1. A system for network management, comprising: One or more memory units; as well as One or more processors, used to: Receive activation information associated with the endpoint device from the endpoint device associated with the tenant of the system; Based on the activation information, identification information associated with the endpoint device and the tenant is determined. The identification information is associated with the tenant's hierarchical structure; Generate a certificate that includes the identification information; as well as Send the certificate to the endpoint device. When attempting to initiate an outgoing communication session with the system, the endpoint device will provide the certificate to the system.
2. The system according to claim 1, wherein the identification information further includes: Information identifying the tenant.
3. The system of claim 1, wherein the one or more processors are further configured to: The certificate is received from the endpoint device and as part of an attempt by the endpoint device to initiate an outgoing communication session with the system; The endpoint device is authenticated based on the certificate; Based on the authentication of the endpoint device, the certificate is processed to determine the identification information; The outgoing communication session is established based on the authentication of the endpoint device; Receive one or more messages from the endpoint device and via the outgoing communication session; Modify one or more messages to include the identification information; as well as After modification, the modified one or more messages are provided to facilitate the provision of services or resources associated with the endpoint device and the system.
4. The system of claim 1, wherein the one or more processors are further configured to: Identify multiple connectivity service instances associated with the connectivity service instance type of the system. Each of the plurality of connectivity service instances supports one or more outgoing communication sessions associated with the connectivity service instance type; Determine the corresponding instance weights of the plurality of connectivity service instances; as well as Based on the respective instance weights of the multiple connectivity service instances, one or more load balancing actions are executed.
5. The system of claim 4, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to: This causes outgoing communication sessions supported by a connectivity service instance among the plurality of connectivity service instances to be dropped from the connectivity service instance.
6. The system of claim 4, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to: Determine that at least a specific number of connectivity service instances among the plurality of connectivity service instances have instance weights that satisfy an instance weight threshold; and Based on the determination that the corresponding instance weights of the at least certain number of connectivity service instances satisfy the instance weight threshold, additional connectivity service instances associated with the connectivity service instance type are added to the plurality of connectivity service instances.
7. The system of claim 4, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to: The connectivity service instance deployment model generates additional connectivity service instances associated with the connectivity service instance type to be added to the plurality of connectivity service instances.
8. The system of claim 1, wherein the one or more processors are further configured to: Identify multiple connectivity service instances associated with the connectivity service instance type of the system. Each of the plurality of connectivity service instances supports one or more outgoing communication sessions associated with the connectivity service instance type; Determine the corresponding instance weights of the plurality of connectivity service instances; For each of the plurality of connectivity service instances, determine the corresponding session weight of the one or more outgoing communication sessions supported by the connectivity service instance; as well as Based on the respective instance weights of the plurality of connectivity service instances and the respective session weights of the one or more outgoing communication sessions supported by each connectivity service instance, one or more load balancing actions are performed.
9. The system of claim 8, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to: Determine that the instance weight of the connectivity service instance among the plurality of connectivity service instances meets the instance weight threshold; Based on determining that the instance weight of the connectivity service instance satisfies the instance weight threshold, identify outgoing communication sessions whose session weights among the one or more outgoing communication sessions supported by the connectivity service instance satisfy the session weight threshold; and This causes the outgoing communication session to be dropped from the connectivity service instance.
10. A non-transient computer-readable medium storing an instruction set, the instruction set comprising: One or more instructions, which, when executed by one or more processors of the system, cause the system to: Receive a certificate from the endpoint device associated with the tenant of the system and as part of an attempt to initiate a dial-out communication session with the system by the endpoint device. The certificate includes information associated with the tenant's hierarchical structure; The outgoing communication session is established based on the certificate. The certificate is processed to determine identification information associated with the endpoint device and the tenant; Receive one or more messages from the endpoint device and via the outgoing communication session; Modify one or more messages to include the identification information; as well as The modified one or more messages are provided after modification to facilitate the provision of services or resources associated with the system to the endpoint device.
11. The non-transient computer-readable medium of claim 10, wherein one or more instructions further cause the system to: Receive activation information associated with the endpoint device from the endpoint device and before receiving the certificate; Based on the activation information, identify information associated with the endpoint device and the tenant is determined; The certificate is generated to include the identification information; as well as Send the certificate to the endpoint device.
12. The non-transient computer-readable medium of claim 10, wherein one or more instructions further cause the system to: Identify multiple connectivity service instances associated with the connectivity service instance type of the system. Each of the plurality of connectivity service instances supports one or more outgoing communication sessions associated with the connectivity service instance type; Determine the corresponding instance weights of the plurality of connectivity service instances; as well as Based on the respective instance weights of the multiple connectivity service instances, one or more load balancing actions are executed.
13. The non-transient computer-readable medium of claim 12, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to perform at least one of the following: This causes outgoing communication sessions supported by a connectivity service instance among the plurality of connectivity service instances to be dropped from the connectivity service instance; or This causes additional connectivity service instances associated with the connectivity service instance type to be added to the plurality of connectivity service instances.
14. The non-transient computer-readable medium of claim 12, wherein, in order for the one or more load balancing actions to be performed, the one or more processors are configured to: For each of the plurality of connectivity service instances, determine the corresponding session weight of the one or more outgoing communication sessions supported by the connectivity service instance; and Based on the respective instance weights of the plurality of connectivity service instances and the respective session weights of the one or more outgoing communication sessions supported by each connectivity service instance, the one or more load balancing actions are executed.
15. A computer-readable medium comprising an instruction set that, when executed by one or more processors of a system, configures the system as any one of claims 1 to 9.
16. A method for network management, said method being performed by a system according to any one of claims 1 to 9, or by executing instructions stored in a computer-readable medium according to any one of claims 10 to 14.
Citation Information
Patent Citations
Certificate-based call identification and routing
US10581829B1
System and method for cloud aware application delivery controller
US20170230451A1
Non-transitory computer-readable recording medium, connection management method, and connection management device
US20180041497A1
User device validation at an application server
US20190394042A1