Composed Virtual Private Network Orchestration for Cross-Domain Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack an effective management solution for end-to-end cross-domain and cross-technology VPN businesses, leading to segment-by-segment management and difficulty in estimating the impact of changes on business quality across multiple domains.

Innovation Solution

A method and apparatus for implementing a composed VPN, which includes an orchestrator and controller to automate resource allocation and business combination across different subnetworks, allowing users to understand correlations between businesses in different domains and estimate the impact of changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If segment-by-segment management is used for cross-domain VPN businesses, then each domain can be managed independently, but the overall management complexity increases and the impact of changes cannot be estimated

Engineering Contradiction:
ImproveIndependent domain managementVSAvoidOverall management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the cross-domain VPN business into multiple domain-specific VPN instances, each managed independently within its domain. The segmentation is achieved by decomposing the end-to-end VPN into domain-specific segments that can be configured and managed separately, while the system provides unified visibility and correlation tracking to prevent management complexity from escalating.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary management system that tracks and correlates VPN segments across domains. This intermediary maintains the relationships between domain-specific VPN instances and the overall end-to-end VPN, enabling impact estimation and unified management without requiring direct complex coordination between all domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If detailed configuration tracking is implemented across all domains, then the impact of changes can be estimated, but the management overhead and resource consumption increase

Engineering Contradiction:
ImproveImpact estimation accuracyVSAvoidManagement overhead
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing correlation tracking structures and relationship mappings between VPN segments across domains before changes occur. This allows the system to quickly estimate impact by querying pre-computed relationships rather than performing complex real-time analysis, reducing management overhead while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual coordination of resources across domains is performed, then resource allocation can be controlled, but the deployment time and operational efficiency decrease

Engineering Contradiction:
ImproveResource allocation controlVSAvoidDeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables self-service by allowing domain-specific VPN instances to be automatically configured and deployed based on predefined templates and policies. The system automatically coordinates resource allocation across domains using the established correlation tracking information, eliminating the need for manual coordination while maintaining control and reliability through automated validation and consistency checks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3734912B1Method and apparatus for establishing a composed virtual private network
Publication Date: 2023.04.05 HUAWEI TECH CO LTD
  • EP3734912B1 patent drawingFigure 1~2
  • EP3734912B1 patent drawingFigure 3
  • EP3734912B1 patent drawingFigure 4

AI summary

This application provides a method and an apparatus for implementing a composed VPN. The method includes: obtaining a business type and a customer site that are input by a user; determining an access point corresponding to the customer site; determining one or more segment VPNs according to the business type and the access point corresponding to the customer site; obtaining a composed VPN according to the one or more segment VPNs; and outputting an access point list and a segment VPN list of the composed VPN to the user. In the solutions provided in this application, a user can learn a correlation between businesses in different domains related to a composed VPN, and can readily estimate a range affected by a business change of the composed VPN.