Core Network Application SLA Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software-defined wide area network (SD-WAN) deployments cannot accurately communicate and meet application service-level agreement (SLA) objectives due to limitations in traffic-profile and destination-based optimization techniques, especially with encrypted communications, leading to non-deterministic optimization and inability to map network behavior to application performance.
Innovation Solution
The techniques involve informing the network of an application's SLA objectives to establish deterministic SLA and application-based routing by creating application-mapped tunnels using core network infrastructure, allowing SLA-bound connections that meet specific service-level requirements without relying on network-based application recognition (NBAR) and compromising user privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic-profile and destination-based optimization techniques are used in SD-WAN deployments, then network configuration can be optimized for application requirements, but the optimization is non-deterministic and cannot map network behavior to application performance
Solution Approach 1:
The patent applies preliminary action by having applications declare their SLA objectives in advance through service level objective (SLO) requests before actual traffic flow occurs. The network controller receives these SLO requests and provisions network-domain connections with guaranteed service levels beforehand, enabling deterministic optimization rather than reactive best-effort optimization. This allows the network to prepare appropriate routing and resource allocation in advance based on known application requirements.
2Adaptability or versatility
If network-based application recognition (NBAR) is used to identify applications, then application-based routing can be implemented, but user privacy is compromised
Solution Approach 1:
The patent inverts the traditional approach by having applications self-identify and declare their SLA objectives directly to the network controller, rather than having the network controller identify applications through traffic analysis. This inversion eliminates the need for deep packet inspection and application recognition technologies like NBAR, thereby preserving user privacy while still enabling application-based routing and service level optimization.
3Loss of information
If encrypted communications are used to protect user privacy, then user data is secured, but traffic-profile based optimization becomes ineffective
Solution Approach 1:
The patent introduces an intermediary mechanism where applications act as mediators between their own SLA requirements and the network optimization process. Instead of requiring the network to inspect encrypted traffic to understand application needs, the application itself communicates its SLO requirements to the network controller through standardized interfaces. This intermediary approach allows network optimization to remain effective while encrypted communications continue to protect user privacy.
Data Source
AI summary
Techniques for informing a network of an application's service-level agreement (SLA) objective(s) so the network can ensure the SLA is met end-to-end, thereby allowing core network support of deterministic SLA and application-based routing without using network-based application recognition (NBAR) and/or compromising user privacy. The techniques may include receiving a first connection request to establish a network-domain connection between different network domains that meets or exceeds a service level objective. Based on the first connection request, the network-domain connection may be established between the different network domains to meet or exceed the service-level objective. In some examples, a second connection request may be received to establish a tunnel between a source application and a destination application, which are disposed in the different network domains. Based on the second connection request, the techniques may include establishing the tunnel between the source application and the destination application utilizing the network-domain connection.


