Automatically provisioning endpoint devices using managed connections

CN117678208BActive Publication Date: 2026-09-25CISCO TECHNOLOGY INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202280050964.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-11-19
Filing Date
2022-07-18
Publication Date
2026-09-25
Estimated Expiration
2042-07-18

Smart Images

  • Figure CN117678208B_ABST
    Figure CN117678208B_ABST
Patent Text Reader

Abstract

Techniques are provided for automating provisioning of network devices, configuring network devices, and onboarding network devices to a cloud management platform. The cloud management platform can be used to manage network devices provisioned in on-premise, cloud, and / or hybrid environments. However, it can be a tedious and error-prone process for a user to manually configure each network device with the connection settings required to manage it with the cloud management platform. The techniques described herein provide an automated process of distributing connection information to network devices to allow them to be managed by the cloud management platform. The techniques described herein also include an automated process of connecting network devices to the appropriate user account registered with the cloud management platform once connected to the cloud management platform.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims priority to U.S. Patent Application No. 17 / 531,193, filed November 19, 2021, which claims priority to U.S. Provisional Patent Application No. 63 / 223,475, filed July 19, 2021, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This disclosure generally relates to a cloud management platform that implements technologies for configuring network devices in a network structure and establishing connections between the cloud management platform and the network devices. Background Technology

[0004] Cloud management platforms provide visualization, optimization, and orchestration for applications and infrastructure in on-premises, cloud, and / or hybrid environments. A cloud management platform can be a Software-as-a-Service (SaaS) platform that automates many tasks on behalf of users and optimizes traditional and cloud-native applications and infrastructure. For example, a cloud management platform can provide lifecycle management for distributed infrastructure and workloads in data centers, remote sites, branch offices, and edge environments, allowing users to analyze, update, remediate, and automate application environments.

[0005] A cloud management platform can be used to provide centralized management capabilities for a unified computing system (UCS) domain across one or more data centers. In order to communicate with devices in these domains, each device can run a software agent (referred to as an "agent" in this document) that helps configure and manage network devices (e.g., servers, input / output (I / O) modules, application devices, virtual machines (VMs), switches, routers, etc.) in the data center.

[0006] To configure network devices within a domain, agents running on the network devices typically initiate web socket connections to the cloud management platform, either directly or through an agent. Because the connection to the cloud management platform originates from within the data center, a secure web socket connection (e.g., a Transport Layer Security (TLS) connection) can be established without interfering with any firewalls. Once the connection is established, the device is registered with the cloud management platform's loading account, and users can then claim their network device to their user accounts using a time-limited one-time token obtained from their device (e.g., via a command-line interface (CLI), user interface (UI) dashboard, etc.) to authenticate access to the network device.

[0007] In some instances, a UCS domain may include one or more infrastructure interconnects (FIs) (e.g., a pair of switches) that connect to server racks and / or chassis with blade components within the domain. In such an architecture, the cloud management platform can handle the discovery, setup, and configuration of devices within the domain. However, each UCS domain may include a relatively large number of devices (e.g., hundreds of servers, dozens of switches, etc.), making it operationally challenging, time-consuming, and tedious for users to manually configure various connectivity settings on each device. Similarly, it is error-prone and cumbersome for users to declare each network device to their user account registered using the cloud management platform. Attached Figure Description

[0008] A detailed description is given below with reference to the accompanying drawings. In the drawings, the leftmost number(s) of the reference numerals identify the drawing in which that reference numeral first appears. The same reference numerals are used in different figures to indicate similar or identical items. The systems depicted in the drawings are not drawn to scale, and the components in the drawings may not be drawn to scale with each other.

[0009] Figure 1 A system architecture diagram of an example switching architecture is shown, in which server devices are automatically provisioned and configured for management by a cloud management platform.

[0010] Figure 2 Example Link Local Discovery Protocol (LLDP) packets are shown with one or more Type Length Values ​​(TLVs) or sub-TLVs that transmit contact information for use in communicating with endpoint discovery services associated with the switching structure.

[0011] Figure 3 A system architecture diagram of an example switching architecture is shown, in which server devices are automatically configured and loaded using a cloud management platform.

[0012] Figure 4 A flowchart is shown as an example method for automatically configuring and setting up endpoints for management by a cloud management platform.

[0013] Figure 5 A flowchart is shown as an example method for automatically configuring and loading endpoints using a cloud management platform.

[0014] Figure 6 A computing system diagram is shown, illustrating the configuration of a data center that can be used to implement various aspects of the techniques disclosed herein.

[0015] Figure 7 A computer architecture diagram is shown illustrating an example computer hardware architecture for implementing a computing device that can be used to implement various aspects of the various technologies presented herein. Detailed Implementation

[0016] Overview

[0017] Various aspects of the invention are set forth in the independent claims, and preferred features are set forth in the dependent claims. A feature of one aspect may be applied alone to any aspect or in combination with other aspects.

[0018] This disclosure describes techniques for automating the provisioning of network devices, configuring network devices, and loading network devices into a cloud management platform.

[0019] This technology may include a first method performed by an endpoint device (e.g., a server, an I / O module architecture extender, etc.). The first method may include generating an Internet Protocol version 6 (IPv6) link-local address at the endpoint device using the endpoint device's Media Access Control (MAC) address, and receiving an announcement message at the endpoint device, the announcement message being sent using a discovery protocol. The first method may also include identifying contact information from the announcement message, the contact information being associated with a discovery service associated with the network architecture. Typically, the discovery service provides connectivity information for connecting to a cloud management platform. Furthermore, the first method may include: obtaining connectivity information from the discovery service using the contact information; and establishing a connection between the endpoint device and the cloud management platform using the connectivity information and the IPv6 link-local address.

[0020] In some instances, these techniques may include a second method performed by an endpoint device (e.g., a server, an I / O module architecture extender, etc.). The second method may include receiving, at the endpoint device, an announcement message sent using a discovery protocol from the architecture interconnect. The second method may also include receiving a signed secure digest from the architecture interconnect, the signed secure digest being signed by a private key associated with the architecture interconnect. The second method may further include identifying contact information from the announcement message, the contact information being associated with a discovery service associated with the network architecture. Typically, the discovery service provides connectivity information for connecting to a cloud management platform. Furthermore, the second method may include: obtaining connectivity information from the discovery service using the contact information; and establishing a connection between the endpoint device and the cloud management platform using the connectivity information. Additionally, the second method may include sending the signed secure digest to the cloud management platform.

[0021] Furthermore, the techniques described in this disclosure can be performed as a method and / or system having a non-transitory computer-readable medium storing computer-executable instructions, wherein the above techniques are performed when the computer-executable instructions are executed by one or more processors.

[0022] Exemplary embodiments

[0023] This disclosure describes techniques for automating the provisioning, configuration, and loading of network devices into a cloud management platform. A cloud management platform can be used to manage network devices configured in on-premises, cloud, and / or hybrid environments. However, manually configuring each network device to manage the required connectivity settings with a cloud management platform can be a tedious and error-prone process for users. The techniques described herein provide an automated process for distributing connectivity information to network devices to allow them to be managed by a cloud management platform. Once connected to the cloud management platform, the techniques also include an automated process for connecting network devices to the appropriate user accounts registered with the cloud management platform.

[0024] When a server connects to another device (such as a switch) in a UCS domain (such as a data center), connection settings need to be configured for the server to enable the server to communicate with the cloud management platform.

[0025] To automate the process of configuring and registering network devices using a cloud management platform, network devices connected to the network infrastructure can self-assign IPv6 link-local addresses using their Media Access Control (MAC) addresses. For example, when a server or host starts up, it can create an IPv6 link-local address from the server's MAC identifier based on various techniques described in Request for Comments (RFC) 4291 issued by the Internet Engineering Task Force (ETF).

[0026] Generally, a UCS domain in a data center may include one or more infrastructure interconnects (e.g., switches, I / O module infrastructure expanders, etc.) behind which multiple servers and / or blade servers are configured. When a server and / or blade server (referred to herein as a "server") connects to an infrastructure interconnect, the server can assign its own IPv6 link-local IPv6 address and listen for connections on the infrastructure interconnect. The infrastructure interconnect can utilize discovery protocols, such as Link Layer Discovery Protocol (LLDP), Satellite Discovery Protocol (SDP), etc., to advertise various information about the Endpoint Discovery Service (EPDS) operating on the switched network infrastructure. For example, the infrastructure interconnect can advertise one or more LLDP packets that include attributes such as one or more Type Length Values ​​(TLVs) and / or sub-TLVs, which are used to propagate or advertise contact information that can be used to contact the EPDS.

[0027] EPDS can run on any device in the switched infrastructure, including the infrastructure interconnect itself. Upon receiving one or more advertisement messages, the server can identify contact information that can be used to contact the EPDS, such as the network used to contact the EPDS (e.g., a Virtual Local Area Network (VLAN)), the EPDS's IP address, and / or the EPDS's port. In some instances, EPDS may be a web service embedded in a proxy running on the infrastructure interconnect; in other instances, EPDS may be hosted outside the infrastructure interconnect.

[0028] Generally, EPDS acts as a directory service, providing cloud management platform connectivity information to endpoints / devices connected within a switching infrastructure (e.g., connected to the infrastructure interconnect). Servers can access EPDS using contact information by configuring a management interface on the advertised VLAN and obtain connectivity information from EPDS that can be used to establish a connection with the cloud management platform. The server can then use the connectivity information received or obtained from EPDS to establish a connection with the cloud management platform.

[0029] In some instances, this disclosure may include techniques for automating and streamlining the loading of devices into user accounts registered with a cloud management platform. For example, when a server starts up, the server (e.g., a child server) can request “parent” configuration details from the interconnect. Parent configuration details may include the cloud management platform’s Domain Name Service (DNS), the IP and port information of the agent running on the interconnect, a unique identifier of the parent FI used by the cloud management platform, and a timed secure digest signed by the private key of the parent interconnect. This information allows the child / server to inherit connection information from the parent FI and means of authenticating itself to the cloud management platform. For example, the child / server uses the parent configuration to connect to the cloud management platform’s DNS via a agent. The child / server connects directly to or is attached to the parent FI and thus gains access to the parent FI’s configuration details.

[0030] The cloud management platform can then authenticate connection requests from child / servers using the parent FI's public key to verify the signed secure digest sent from the child / server. The child / server is then registered and declared to the same user account as the parent FI in the cloud management platform. In this way, each server or other network device introduced into the switching infrastructure can be registered and declared to the same user account as the parent FI device, eliminating the need for users to manually authenticate and declare the devices they are configuring. To manage all of a user's devices, devices must be loaded using the user account registered with the cloud management platform. It is crucial that the parent device (e.g., FI, switch, etc.) is loaded or registered using the same user account as the child device (e.g., server, blade server, etc.). To ensure that the cloud management platform installs, sets up, and manages devices on behalf of the user, devices need to be declared by the user account (e.g., loaded into the account). While users can manually declare devices, this can be time-consuming when many devices need to be declared. The techniques described herein include those for automatically loading devices using the correct user account (e.g., the user account used to load the parent device).

[0031] Certain embodiments and implementations of this disclosure will now be described more fully with reference to the accompanying drawings, in which various aspects are shown. However, these aspects may be implemented in many different forms and should not be construed as limited to the embodiments set forth herein. This disclosure includes variations of the embodiments as described herein. The same reference numerals refer to the same elements throughout the text.

[0032] Figure 1 A system architecture diagram 100 is shown for an example network architecture 102 (e.g., a switching architecture), in which server devices are automatically provisioned and configured for management by a cloud management platform.

[0033] Generally, network architecture 102 may include devices housed or located in one or more data centers 104 that may be located in different physical locations. For example, network architecture 102 may be supported by a network of devices from a public cloud computing platform, a private / enterprise computing platform, a hybrid computing platform, and / or any combination thereof. One or more data centers 104 may be physical facilities or buildings located in a geographic area designated for storing networked devices as part of network architecture 102. Data center 104 may include various networked devices as well as redundant or backup components and infrastructure for power supply, data communication connectivity, environmental control, and various security devices. In some examples, data center 104 may include one or more virtual data centers, which are pools or collections of cloud infrastructure resources specifically designed for enterprise needs and / or the needs of cloud-based service providers. Generally, data center 104 (physical and / or virtual) may provide basic resources such as processors (CPU), memory (RAM), storage devices (disks), and networks (bandwidth). However, in some examples, devices in network architecture 102 may not be located in a explicitly defined data center 104, but may be located in other locations or buildings.

[0034] Switching fabric 102 may include network device domains located in one or more data centers 104, including various hardware devices and / or virtualization components. For example, switching fabric 102 may include one or more interconnects 108A, 108B, etc., where interconnects 108 provide network connectivity and management capabilities to attached devices. Attached devices may include one or more servers located in one or more server racks 110, or one or more blade servers 116 disposed in one or more chassis 114. Interconnects 108 may be various types of devices, such as switches, network extenders, etc.

[0035] Generally, devices in one or more domains of data center 104 can each run agents 118A-118D, where the agents act as device connectors, enabling the devices to communicate with and be managed by cloud management platform 106. Agent 118 typically enables devices in the UCS domain (e.g., interconnect 108, server 112, blade server 116, etc.) to be managed and monitored by cloud management platform 106. Cloud management platform 106 can typically be a management system or platform that provides visualization, optimization, and orchestration for applications and infrastructure in a user's computing environment.

[0036] To register devices (one or more) in data center 104 with cloud management platform 106, devices typically need to be configured with various connectivity settings, such as proxy settings, and are provided with connectivity information. To automate the process of configuring and registering servers 112 / 116 (and / or other network devices) with cloud management platform 106, servers 112 / 116 connected in switching structure 102 can automatically assign IPv6 link-local addresses using their respective MAC addresses. For example, when a server or host starts up, it can create an IPv6 link-local address from the server's MAC identifier according to the various techniques described in Request for Comments (RFC) 4291 issued by the Internet Engineering Task Force (ETF).

[0037] When servers 112 / 116 connect to the infrastructure interconnect 108, servers 112 / 116 can assign themselves IPv6 link-local IPv6 addresses and listen for connections on the infrastructure interconnect 108. The infrastructure interconnect 108 can utilize discovery protocols, such as Link Layer Discovery Protocol (LLDP) 124 (e.g., for server 112), Satellite Discovery Protocol (SDP) 126 (e.g., for blade servers), etc., to advertise various information about the Endpoint Discovery Service (EPDS) 120A / 120B running on the switching infrastructure 102. For example, agents 118A / 118B running on the switching infrastructure interconnect 108 can advertise one or more LLDP packets including attributes such as one or more Type Length Values ​​(TLVs) and / or sub-TLVs, which are used to propagate or advertise contact information that can be used to contact the discovery service 120.

[0038] Discovery service 120 can run on any device in switching fabric 102, including the fabric interconnect 108 itself (e.g., running in agent 118). Upon receiving one or more advertisement messages, servers 112 / 116 can identify contact information that can be used to contact discovery service 120, such as the network (e.g., VLAN) used to contact EPDS, the IP address of discovery service 120, and / or the port of discovery service 120. In some instances, discovery service 120 may be a web service embedded in agent 118 running on fabric interconnect 108; however, in other instances, discovery service 120 may reside outside of fabric interconnect 108.

[0039] Generally, the discovery service 120 acts as a directory service, providing cloud management platform 106 connection information to endpoints / devices connected in the switching fabric 102 (e.g., connected to the fabric interconnect 108). Servers 112 / 116 can reach the discovery service 120 using contact information by configuring a management interface on the advertised VLAN, and obtain connection information from the discovery service 120 that can be used to establish a connection with the cloud management platform 106. Servers 112 / 116 can then use the connection information received or obtained from the discovery service 120 to establish a connection with the cloud management platform 106.

[0040] Generally, to establish a connection to the cloud management platform 106, servers 112 / 116 can utilize local proxies 122A / 122B running in or embedded in proxy 118. Proxy 122A / 122B can extend web socket and TLS connections to one or more external networks 128, thereby providing connectivity to the cloud management platform 106. Proxy 122A / 122B can convert link-local addressing from switching fabric 102 to proxy communication for communication over one or more external networks 128. In some examples, proxy 122A / 122B can be linked behind a Hypertext Transfer Protocol (HTTP) proxy that provides access outside the data center 102 in a constrained environment.

[0041] One or more external networks 128 include one or more networks implemented using any feasible communication technology (e.g., wired and / or wireless modes and / or technologies). One or more external networks 128 may include any combination of: Personal Area Network (PAN), Local Area Network (LAN), Campus Network (CAN), Metropolitan Area Network (MAN), Extranet, Intranet, Internet, Short-Range Wireless Communication Network (e.g., ZigBee, Bluetooth, etc.), Wide Area Network (WAN) – centralized and / or distributed – and / or any combination, arrangement, and / or aggregation thereof. One or more external networks 128 may include devices, virtual resources, or other nodes that relay packets from one network segment to another via nodes in a computer network.

[0042] In some examples, the switching structure 102 may include various types of devices configured to communicate over one or more external networks 128 using various communication protocols (e.g., VPN, SSL, TLS, DTLS, and / or any other protocols). For example, endpoints may include personal user devices (e.g., desktop computers, laptops, telephones, tablets, wearable devices, entertainment devices such as televisions, etc.), network devices (e.g., servers, routers, switches, access points, etc.), and / or any other type of computing device.

[0043] Figure 2 An example Link Local Discovery Protocol (LLDP) packet 200 is shown, which has one or more Type Length Values ​​(TLVs) or sub-TLVs that transmit contact information for communicating with the endpoint discovery service associated with the switching structure.

[0044] Generally, LLDP packets 200 (or more packets) can be used to advertise identity information, connectivity information, capability information, and / or other information to other devices. Typically, each LLDP packet 200 can be sent between devices at fixed intervals from each interface of the device in the form of Ethernet frames. Each Ethernet frame contains one LLDP data unit (LLDPDU), which is a series of Type Length Values ​​(TLV) structures.

[0045] According to the techniques described herein, the LLDP mechanism can be used and / or modified to allow the use of TLVs (and / or sub-TLVs) in LLDP packets 200 to provide information for contacting the discovery service 120. As shown in the figure, LLDP packets 200 may include sub-TLVs, which include a network indication (VLAN) 202 that can reach the discovery service 120, a sub-TLV indicating an IP address 204 that can reach the discovery service 120, and a sub-TLV indicating a port 206 that can reach the discovery service.

[0046] Therefore, sub-TLVs and / or TLVs can be used to propagate connection information of servers 112 / 116 to contact discovery service 120 to obtain connection information to connect to cloud management platform 106. Although not shown, in the case of using SDP, SDP can be similarly extended for communication with FI 108 and blade server 116.

[0047] Figure 3 A system architecture diagram 300 of an example switching architecture is shown, in which server devices are automatically provisioned, configured, and loaded into the cloud management platform 102. For Figure 3 The technical requirements for streaming devices are for the process of attaching a pair of FI 108 devices to form a domain.

[0048] Agent 118C running on a device connected to FI 108 is considered a child agent. Logical agents 118A / 118B running on a pair of clustered FI 108s are considered parent agents 118C. Child agent 118C receives advertisements from FI 108 via LLDP or DCBXTLV, containing the FI agent's IP address, port number, and underlying VLAN, through which it communicates with FI agents 118A / 118B (see reference). Figure 1 and Figure 2 (Describe it).

[0049] Upon startup, sub-agent 118C requests a "parent configuration" from FI agents 118A / 118B. The parent configuration includes the cloud management platform 106DNS (which can be a cloud or application device), the FI agent IP / port, the parent agent 118's unique identifier (e.g., the parent agent's unique identifier in the cloud management platform 106), and a timed security digest 304 signed by the parent agent 118's private key 302.

[0050] At "1", the agent 118B running on the interconnect 108B can use private key 302 to sign the security digest and create a signed security digest 304. In some instances, server 112 (e.g., a child) can request parent configuration information from FI 108, and FI 108 can provide the signed security digest 304 to server 112 at "2". In other examples, the signed security digest 304 can be provided to server 112 in response to a request for the parent.

[0051] At point “3”, server 112 (e.g., agent 118C) can send a signed secure digest 304 to cloud management platform 106 as a means of authenticating itself with the cloud management platform and inheriting connection information from the interconnect 108. The connection information in the signed secure digest 304 is used for DNS connection to cloud management platform 106 via agent 122B, and the signed secure digest 304 is also used to authenticate server 112, which is actually a sub-device of FI 108B. The device of sub-agent 118C (e.g., server 112, IOM, etc.) is directly attached to the device of parent agent 118B (FI 108B), and only sub-agent 118C can obtain access to the parent configuration.

[0052] At point “4”, the cloud management platform 106 can authenticate the connection request of the sub-agent 118C by using the public key 306 of the parent agent 118B to verify the security digest 304 of the sub-agent 118C. At this time, the sub-agent 118C is registered and automatically declared directly to the user account 310 of the parent agent 118C (and / or from the loading account 308 in some examples). As shown, the endpoint identifier 312N (corresponding to server 112 / agent 118C) can be moved from the general loading account 308 to the same user account 310 as the structure interconnection identifier 314 (e.g., corresponding to FI 108B / agent 118B). In this way, a time-limited signed security digest 304 can be used to distribute endpoint connection information to connect to the cloud management platform, and this can also authenticate itself as a sub-agent of FI 108B by having a signed data segment that can be verified by the cloud management platform 106 when signed by a specific FI 108.

[0053] Figure 4and Figure 5 A flowchart illustrating example methods demonstrating various aspects of the techniques disclosed herein is shown. This document references... Figure 4 and Figure 5 The logical operation is Figure 4 and 5 It can be implemented as (1) a sequence of computer-implemented actions or program modules running on a computing system and / or (2) interconnected machine logic circuits or circuit modules within a computing system.

[0054] The implementation of the various components described herein depends on the performance and other requirements of the computing system. Therefore, the logical operations described herein are referred to differently as operations, structural devices, actions, or modules. These operations, structural devices, actions, and modules can be implemented using software, firmware, dedicated digital logic, and any combination thereof. It should also be understood that more advanced technologies can be implemented... Figure 4 and Figure 5 The operations shown and described herein may include more or fewer operations. These operations may also be performed in parallel or in a different order than those described herein. Some or all of these operations may also be performed by components other than those specifically identified. Although the techniques described in this disclosure refer to specific components, in other examples, these techniques may be implemented with fewer components, more components, different components, or any component configuration.

[0055] Figure 4 A flowchart of an example method 400 for automatically configuring and setting up endpoints for management by a cloud management platform is shown.

[0056] In a 402, an endpoint can use its Media Access Control (MAC) address to generate an Internet Protocol version 6 (IPv6) link-local address. In other words, an endpoint can use its own MAC address to assign its own IPv6 link-local address, ensuring that no overlapping IPv6 link-local addresses exist within the endpoint's local domain.

[0057] In a 404 error, the endpoint device (e.g., server, blade server, IOM, etc.) can receive an announcement message sent using a discovery protocol. In some instances, the discovery protocol is LLDP, SDP, and / or any other type of discovery protocol.

[0058] At 406, the endpoint device can identify contact information from the notification message, which is associated with the discovery service linked to the network architecture. Generally, discovery service 120 provides connectivity information for connecting to cloud management platform 106. Contact information may include: an indication of the network (e.g., a VLAN) available for connecting to discovery service 120, the IP address associated with discovery service 120, and an indication of the port of discovery service 120.

[0059] At 408, an endpoint can use contact information to obtain connection information from the discovery service. At 410, an endpoint can use the connection information to establish a connection with the cloud management platform.

[0060] In some instances, method 400 may also include receiving a signed secure digest from the structure interconnect, which has been signed by a private key associated with the structure interconnect, and sending the signed secure digest from the endpoint to a cloud management platform for authentication when connecting to the structure interconnect.

[0061] Figure 5 A flowchart is shown for an example method 500 for automatically configuring and loading endpoints using a cloud management platform.

[0062] In a 502, an endpoint (e.g., a server, blade server, IOM, etc.) can receive an announcement message sent using a discovery protocol from the infrastructure interconnect. The discovery protocol can be LLDP, SDP, and / or any other discovery protocol running at any layer.

[0063] In a 504 event, an endpoint can receive a signed secure digest from the interconnect, which has been signed by the private key associated with the interconnect. In some instances, the signed secure digest may include, be enclosed in, or otherwise associated with an announcement message.

[0064] At 506, the endpoint can identify contact information from the notification message, which is associated with the discovery service linked to the network architecture. Generally, the discovery service provides connectivity information for connecting to the cloud management platform 106. The contact information may include: an indication of the network available for connecting to the discovery service, an Internet Protocol (IP) address associated with the discovery service, and an indication of the port of the discovery service.

[0065] At 508, an endpoint can use contact information to obtain connection information from the discovery service. For example, an endpoint can contact the discovery service running in the infrastructure to obtain connection information for connecting to the cloud management platform 106.

[0066] In 510, endpoints can establish a connection to the cloud management platform using connection information (e.g., by using one or more proxies and / or tunneling protocols (e.g., SSL, TLS, etc.)).

[0067] In step 512, the endpoint can send a secure signature digest to the cloud management platform. The cloud management platform 106 can then use the StructureInterconnect public key to verify that the secure signature digest was signed using the StructureInterconnect private key. The cloud management platform can then automatically register the endpoint with a StructureInterconnect user account. In this way, the endpoint will be automatically loaded into the appropriate user account without manual user intervention.

[0068] Figure 6 A computing system diagram is shown, illustrating the configuration of a data center 600 that can be used to implement various aspects of the techniques disclosed herein. Figure 6 The example data center 600 shown includes several server computers 602A-602F (which may be referred to herein in the singular as "server computer 602" or in the plural as "multiple server computers 602") for providing computing resources. In some examples, the resources and / or server computers 602 may include or correspond to any type of networking device described herein. Although described as a server, server computer 602 may include any type of networking device, such as a server, switch, router, hub, bridge, gateway, modem, repeater, access point, etc.

[0069] Server computer 602 may be a standard tower, rack-mount, or blade server computer appropriately configured to provide computing resources. In some examples, server computer 602 may provide computing resources 604, including data processing resources such as VM instances or hardware computing systems, database clusters, compute clusters, storage clusters, data storage resources, database resources, network resources, VPNs, etc. Some servers 602 may also be configured to execute a resource manager 606 capable of instantiating and / or managing computing resources. For example, in the case of VM instances, resource manager 606 may be a hypervisor or another type of program configured to enable the execution of multiple VM instances on a single server computer 602. Server computer 602 in data center 600 may also be configured to provide network services and other types of services.

[0070] exist Figure 6 In the example data center 600 shown, server computers 602A-602F are also interconnected using appropriate LAN 608. It should be understood that the configuration and network topology described herein have been greatly simplified, and more computing systems, software components, networks, and networking devices can be used to interconnect the various computing systems disclosed herein and provide the aforementioned functionality. Appropriate load balancing devices or other types of network infrastructure components can also be used to balance the load between data centers 600, the load between each server computer 602A-602F in each data center 600, and potentially the load between computing resources in each data center 600. It should be understood that references... Figure 6 The configuration of the data center 600 described is illustrative only and may be implemented using other methods.

[0071] In some examples, server computer 602 and / or resource 604 may each execute / host one or more tenant containers and / or virtual machines to perform the techniques described herein.

[0072] In some instances, data center 600 can provide computing resources, such as tenant containers, VM instances, VPN instances, and storage, either permanently or on demand. Among other types of functionality, computing resources provided by the cloud computing network can be used to implement the various services and technologies described above. Computing resources 604 provided by the cloud computing network can include various types of computing resources, such as data processing resources like tenant containers and VM instances, data storage resources, network resources, data communication resources, network services, VPN instances, etc.

[0073] Each type of computing resource 604 provided by the cloud computing network can be general-purpose or available in a variety of specific configurations. For example, data processing resources can be used as physical computers or VM instances in a variety of different configurations. VM instances can be configured to run applications, including web servers, application servers, media servers, database servers, some or all of the aforementioned network services, and / or other types of programs. Data storage resources can include file storage devices, block storage devices, etc. The cloud computing network can also be configured to provide other types of computing resources 604 not specifically mentioned herein.

[0074] In one embodiment, computing resources 604 provided by a cloud computing network may be enabled by one or more data centers 600 (which may be referred to herein as "data center 600" in the singular or in the plural as "multiple data centers 600"). A data center 600 is a facility for housing and operating computer systems and related components. A data center 600 typically includes redundant and backup power, communication, cooling, and security systems. Data centers 600 may also be located in geographically distinct locations. References will follow below. Figure 6 An illustrative embodiment of a data center 600 that can be used to implement the techniques disclosed herein is described.

[0075] Figure 7A computer architecture diagram is shown, illustrating an example computer hardware architecture 700 for implementing a computing device that can be used to implement various aspects of the technologies presented herein. Computer hardware architecture 700 can be a conventional server computer, computing resource, network device (e.g., router, load balancer, data storage, etc.), workstation, desktop computer, laptop computer, tablet computer, network device, e-reader, smartphone, or other computing device, and can be used to execute any of the software components presented herein. In some examples, computer 700 can correspond to at least one of a server 112, a blade server / component 116, and / or a system that can constitute a cloud management platform 106. Computer 700 may include networking devices such as servers, switches, routers, hubs, bridges, gateways, modems, repeaters, access points, etc.

[0076] Computer 700 includes a substrate 702 or “motherboard,” which is a printed circuit board to which multiple components or devices can be connected via a system bus or other electrical communication paths. In one illustrative configuration, one or more central processing units (“CPUs”) 704 operate in conjunction with a chipset 706. The CPU 704 may be a standard programmable processor that performs arithmetic and logical operations required for the operation of computer 700.

[0077] The CPU 704 performs operations by manipulating switching elements that distinguish and change these states, transitioning from one discrete physical state to the next. Switching elements typically include electronic circuitry (e.g., flip-flops) that maintains one of two binary states and electronic circuitry (e.g., logic gates) that provides an output state based on a logical combination of the states of one or more other switching elements. These basic switching elements can be combined to create more complex logic circuits, including registers, adder-subtractor units, arithmetic logic units, floating-point units, and more.

[0078] Chipset 706 provides an interface between CPU 704 and the remaining components and devices on substrate 702. Chipset 706 can provide an interface to RAM 708, which serves as the main memory in computer 700. Chipset 706 can also provide an interface to computer-readable storage media such as read-only memory (“ROM”) 710 or non-volatile RAM (“NVRAM”) for storing basic routines that help boot computer 700 and transfer information between various components and devices. ROM 710 or NVRAM can also store other software components required for the operation of computer 700 according to the configuration described herein.

[0079] Computer 700 can operate in a networked environment using logical connections to remote computing devices and computer systems via a network (e.g., network 106). For example, chipset 706 may include the ability to provide network connectivity via a network interface controller (NIC) 712 (e.g., a Gigabit Ethernet adapter). NIC 712 enables computer 700 to connect to other computing devices via a network. It should be understood that multiple NICs 712 may exist in computer 700, connecting the computer to other types of networks and remote computer systems. In some examples, NIC 712 may be configured to perform at least some of the techniques described herein, such as packet redirection and / or other techniques described herein.

[0080] Computer 700 can be connected to storage device 718, which provides non-volatile storage for the computer. Storage device 718 can store operating system 720, programs 722, and data, which have been described in more detail herein. Storage device 718 can be connected to computer 700 via storage controller 714 connected to chipset 706. Storage device 718 can consist of one or more physical storage units. Storage controller 714 can interface with physical storage units via a Serial Attached SCSI (“SAS”) interface, a Serial Advanced Technology Attachment (“SATA”) interface, a Fibre Channel (“FC”) interface, or other types of interfaces used for physical connection and data transfer between the computer and physical storage units.

[0081] Computer 700 can store data on storage device 718 by changing the physical state of physical storage units to reflect the stored information. In different embodiments of this specification, the specific changes in physical state can depend on various factors. Examples of these factors may include, but are not limited to, the technology used to implement the physical storage units, whether storage device 718 is characterized as primary or secondary storage, etc.

[0082] For example, computer 700 can issue instructions via storage controller 714 to store information in storage device 718 by altering the magnetic properties of a specific location within a disk drive unit, the reflection or refraction properties of a specific location within an optical storage unit, or the electrical properties of a specific capacitor, transistor, or other discrete component in a solid-state storage unit. Other transformations of the physical medium are possible without departing from the scope and spirit of this description; the foregoing examples are provided merely for the purpose of illustration. Computer 700 can also read information from storage device 718 by detecting the physical state or characteristics of one or more specific locations within the physical storage unit.

[0083] In addition to the aforementioned high-capacity storage device 718, computer 700 can also access other computer-readable storage media to store and retrieve information, such as program modules, data structures, or other data. Those skilled in the art will understand that computer-readable storage media are any available medium that provides non-transitory storage of data and can be accessed by computer 700. In some examples, operations performed by network 106 and / or any components included therein may be supported by one or more devices similar to computer 700. In other words, some or all of the operations performed by server 112, blade server 116, and / or any components included therein may be performed by one or more computer devices 700 operating in a cloud-based configuration.

[0084] By way of example and not limitation, computer-readable storage media can include volatile and non-volatile, removable and non-removable media implemented in any method or technology. Computer-readable storage media include, but are not limited to, RAM, ROM, erasable programmable ROM (“EPROM”), electrically erasable programmable ROM (“EEPROM”), flash memory or other solid-state storage technologies, optical disc ROM (“CD-ROM”), digital versatile optical disc (“DVD”), high-definition DVD (“HD-DVD”), Blu-ray or other optical storage, cassette tape, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information in a non-transitory manner.

[0085] As briefly mentioned above, storage device 718 may store operating system 720 for controlling the operation of computer 700. According to one embodiment, the operating system includes a Linux operating system. According to another embodiment, the operating system includes one from Microsoft Corporation, Redmond, Washington. SERVER operating system. According to another embodiment, the operating system may include one of the UNIX operating systems or variants thereof. It should be understood that other operating systems may also be used. Storage device 718 may store other systems or applications and data used by computer 700.

[0086] In one embodiment, storage device 718 or other computer-readable storage medium is encoded with computer-executable instructions that, when loaded into computer 700, transform the computer from a general-purpose computing system into a special-purpose computer capable of implementing the embodiments described herein. These computer-executable instructions transform computer 700 by specifying how CPU 704 transitions between states, as described above. According to one embodiment, computer 700 can access the computer-readable storage medium storing the computer-executable instructions, which, when executed by computer 700, perform the above-described... Figure 1-5The various processes described herein. The computer 700 may also include a computer-readable storage medium having instructions stored thereon for performing the operations of any other computer implementation described herein.

[0087] Computer 700 may also include one or more input / output controllers 716 for receiving and processing input from multiple input devices, such as a keyboard, mouse, touchpad, touchscreen, electronic pen, or other types of input devices. Similarly, input / output controllers 716 may provide output to a display, such as a computer monitor, flat panel display, digital projector, printer, or other types of output devices. It should be understood that computer 700 may not include... Figure 7 All components shown may include Figure 7 Other components not explicitly shown in the document, or those that can be utilized with Figure 7 The architecture shown is completely different.

[0088] As described herein, computer 700 may include one or more of the following: server 112, blade server 116, or device systems or network devices (e.g., server computers, computing resources, etc.) constituting cloud management platform 106. Computer 700 may include one or more hardware processors 704 (processors) configured to execute one or more stored instructions. The processors 704 may include one or more cores. Furthermore, computer 700 may include one or more network interfaces configured to provide communication between computer 700 and other devices, such as the communication performed by client device 106 and computing resource 114 as described herein. The network interface may include a device configured to couple to a personal area network (PAN), wired and wireless local area network (LAN), wired and wireless wide area network (WAN), etc. For example, the network interface may include interfaces with Ethernet, Wi-Fi, etc. TM Compatible devices.

[0089] Program 722 may include any type of program or process that performs the techniques described in this disclosure for determining connectivity in a multi-hop path using one or more BFD echo packets. Program 722 may enable computing resource 114 and / or the load balancer 112 of computing resource 114 to perform various operations.

[0090] In summary, techniques for automating the provisioning, configuration, and loading of network devices into a cloud management platform are described. A cloud management platform can be used to manage network devices configured in on-premises, cloud, and / or hybrid environments. However, manually configuring each network device to manage the required connectivity settings with a cloud management platform can be a tedious and error-prone process for users. The techniques described herein provide an automated process for distributing connectivity information to network devices to allow them to be managed by a cloud management platform. Once connected to the cloud management platform, the techniques also include an automated process for connecting network devices to the appropriate user accounts registered with the cloud management platform.

[0091] Although this disclosure describes specific examples, it should be understood that the scope of this disclosure is not limited to these specific examples. Since other modifications and variations made to suit specific operational requirements and environments will be apparent to those skilled in the art, this disclosure is not limited to the examples chosen for the purposes of this disclosure, but covers all changes and modifications that do not depart from the true spirit and scope of this disclosure.

[0092] Although this application describes embodiments with specific structural features and / or methodological actions, it should be understood that the claims are not necessarily limited to the specific features or actions described. Rather, the specific features and actions are merely illustrative of some embodiments falling within the scope of the claims of this application.

Claims

1. A computer-implemented method for configuring an endpoint device connected to a structural interconnect in a network structure, the computer-implemented method comprising: At the endpoint device, an Internet Protocol version 6 (IPv6) link-local address is generated using the Media Access Control (MAC) address of the endpoint device; At the endpoint device, an announcement message sent using a discovery protocol is received; Contact information is identified from the notification message, and the contact information is associated with a discovery service that is associated with the network structure, wherein the discovery service provides connection information for connecting to the cloud management platform; Using the contact information, obtain the connection information from the discovery service; and The connection information is used to establish a connection between the endpoint device and the cloud management platform.

2. The computer-implemented method according to claim 1, wherein, The contact information includes: Instructions for networks that can be used to connect to the discovery service; The IP address associated with the discovery service; and Indication of the port for the discovery service.

3. The computer-implemented method according to claim 1 or 2, wherein: The interconnection of the structures refers to the switches in the network structure; The endpoint device is a server connected to the switch; The discovery protocol is the Link Layer Discovery Protocol (LLDP), and the announcement message is an LLDP packet; and The contact information is included in one or more sub-TLVs of sub-type length values ​​included in the LLDP group.

4. The computer-implemented method according to claim 1 or 2, wherein: The endpoint device is an input / output module (IOM) structure extender associated with the network structure; The discovery protocol is the Satellite Discovery Protocol (SDP); and The contact information is included in the extension of the packets sent via the SDP.

5. The computer-implemented method according to claim 1 or 2, wherein, The discovery service runs on the interconnected architecture.

6. The computer-implemented method according to claim 1 or 2, further comprising: Receive a signed security digest from the structural interconnect, the signed security digest being signed by a private key associated with the structural interconnect; as well as The secure digest of the signature is sent from the endpoint to the cloud management platform.

7. The computer-implemented method according to claim 6, further comprising: The cloud management platform receives a first request to register the interconnected structure using a user account associated with the cloud management platform. The first indication of the interconnection of the structures is stored in the loading account associated with the cloud management platform; Receive input from the user account instructing the structural interconnect to register using the user account; Upon connecting to the interconnected structure, a second request is received at the cloud management platform to register the endpoint with the user account, the second request including the signature security digest; The second indication of the endpoint is stored in the loading account associated with the cloud management platform; The public key associated with the interconnect structure is used to verify that the secure signature digest was signed using the private key of the interconnect structure; and Move the second indication of the endpoint to the user account, so that the endpoint is registered with the user account.

8. A system comprising endpoint devices connected to a structural interconnect in a network structure, the endpoint devices comprising: One or more processors; and One or more non-transitory computer-readable media store instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: Receive notification messages sent from the interconnect of the structures using a discovery protocol; Contact information is identified from the notification message. This contact information is associated with a discovery service that is linked to the network architecture. The discovery service provides connection information for connecting to the cloud management platform. The contact information includes: Instructions for networks that can be used to connect to the discovery service; The Internet Protocol (IP) address associated with the discovery service; and Indication of the port for the discovery service; Using the contact information, obtain the connection information from the discovery service; and The connection information is used to establish a connection between the endpoint device and the cloud management platform.

9. The system according to claim 8, wherein the operation further comprises: At the endpoint device, an Internet Protocol version 6 (IPv6) link-local address is generated using the Media Access Control (MAC) address of the endpoint device; as well as Provide the IPv6 link local address to obtain the cloud management platform.

10. The system according to claim 8 or 9, wherein: The interconnection of the structures refers to the switches in the network structure; The endpoint device is a server connected to the switch; The discovery protocol is the Link Layer Discovery Protocol (LLDP), and the announcement message is an LLDP packet; and The contact information is included in one or more sub-TLVs of sub-type length values ​​included in the LLDP group.

11. The system according to claim 8 or 9, wherein: The endpoint device is an input / output module (IOM) structure extender associated with the network structure; The discovery protocol is the Satellite Discovery Protocol (SDP); and The contact information is included in the extension of the packets sent via the SDP.

12. The system according to claim 8 or 9, wherein, The discovery service runs on the interconnected architecture.

13. The system according to claim 8 or 9, wherein the operation further comprises: Receive a signed security digest from the structural interconnect, the signed security digest being signed by a private key associated with the structural interconnect; as well as The secure digest of the signature is sent from the endpoint to the cloud management platform.

14. The system according to claim 13, further comprising the cloud management platform, the cloud management platform comprising: One or more second processors; and One or more second non-transitory computer-readable media store instructions that, when executed by the one or more second processors, cause the one or more second processors to perform a second operation including: Receive a first request to register the interconnected structure using a user account associated with the cloud management platform; The first indication of the interconnection of the structures is stored in the loading account associated with the cloud management platform; Receive input from the user account instructing the structural interconnect to register using the user account; Upon connecting to the interconnected structure, a second request is received at the cloud management platform to register the endpoint with the user account, the second request including the signature security digest; The second indication of the endpoint is stored in the loading account associated with the cloud management platform; The public key associated with the interconnect structure is used to verify that the secure signature digest was signed using the private key of the interconnect structure; and Move the second indication of the endpoint to the user account, so that the endpoint is registered with the user account.

15. An endpoint device connected to a structural interconnect in a network structure, the endpoint device comprising: One or more processors; and One or more non-transitory computer-readable media store instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: Receive notification messages sent using a discovery protocol from the interconnect structure; Receive a signed security digest from the structural interconnect, the signed security digest being signed by a private key associated with the structural interconnect; Contact information is identified from the notification message, and the contact information is associated with a discovery service that is associated with the network structure, wherein the discovery service provides connection information for connecting to the cloud management platform; Using the contact information, obtain the connection information from the discovery service; Using the connection information, a connection is established between the endpoint device and the cloud management platform; and Send the signature security digest to the cloud management platform.

16. The endpoint device of claim 15, further comprising: The Internet Protocol version 6 (IPv6) link-local address is generated using the Media Access Control (MAC) address of the endpoint device. Provide the IPv6 link local address to obtain the cloud management platform.

17. The endpoint device according to claim 15 or 16, wherein, The contact information includes: Instructions for networks that can be used to connect to the discovery service; The Internet Protocol (IP) address associated with the discovery service; and Indication of the port for the discovery service.

18. The endpoint device according to claim 15 or 16, wherein: The interconnection of the structures refers to the switches in the network structure; The endpoint device is a server connected to the switch; The discovery protocol is the Link Layer Discovery Protocol (LLDP), and the announcement message is an LLDP packet; and The contact information is included in one or more sub-TLVs of sub-type length values ​​included in the LLDP group.

19. The endpoint device according to claim 15 or 16, wherein: The endpoint device is an input / output module (IOM) structure extender associated with the network structure; The discovery protocol is the Satellite Discovery Protocol (SDP); and The contact information is included in the extension of the packets sent via the SDP.

20. The endpoint device according to claim 15 or 16, wherein, The discovery service runs on the interconnected architecture.

21. An endpoint device connected to a structural interconnect in a network structure, the endpoint device comprising: A module for receiving notification messages sent using a discovery protocol from the interconnect of the structures; A module for receiving a signed secure digest from the structural interconnect, the signed secure digest being signed by a private key associated with the structural interconnect; A module for identifying contact information from the notification message, the contact information being associated with a discovery service that is associated with the network structure, wherein the discovery service provides connection information for connecting to the cloud management platform; A module for obtaining the connection information from the discovery service using the contact information; A module for establishing a connection between the endpoint device and the cloud management platform using the connection information; and A module for sending the signature security digest to the cloud management platform.

22. The endpoint device of claim 21, further comprising a module for implementing the method of any one of claims 2 to 7.

23. A computer program product comprising instructions or a computer-readable medium storing instructions, which, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • System for provisioning racks autonomously in data centers

    US20200007394A1