Distributed Tunnel Endpoints for LAN Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controller-based LAN architectures face scalability issues when moving the LAN controller to the cloud, as it leads to congestion and impracticality due to the need for all network traffic to transit through a tunnel, especially in large networks with thousands of access points.

Innovation Solution

A network function orchestrator (NFO) configures multiple tunnel endpoints within the LAN based on observed network traffic, determining optimal positions for these endpoints to minimize transit and back-and-forth traffic, allowing traffic to be forwarded directly to its destination without passing through a central controller, thereby reducing latency and compute costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network traffic is forced to transit through a tunnel to the cloud, then security enforcement and policy control are maintained, but network congestion and latency increase significantly

Engineering Contradiction:
Improvesecurity enforcementVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the centralized tunnel architecture into multiple distributed tunnel endpoints within the LAN. Instead of all traffic going through a single cloud-based controller, the system creates multiple tunnel endpoints at different network devices (switches, routers, access points) that can locally terminate tunnels and forward traffic directly to destinations, reducing latency while maintaining security through distributed policy enforcement

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (tunnel endpoint selector) that determines the optimal tunnel endpoint for each traffic flow based on destination, current network conditions, and load balancing considerations. This intermediary enables intelligent traffic routing that maintains security requirements while avoiding congestion at any single point

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a central LAN controller is used to manage all access points, then centralized control and policy enforcement are achieved, but scalability becomes difficult for large networks with thousands of access points

Engineering Contradiction:
Improvecentralized controlVSAvoidnetwork scalability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent divides the centralized controller function into multiple distributed tunnel endpoints across different network devices. Each endpoint can independently handle tunnel termination and traffic forwarding, allowing the system to scale to thousands of access points without requiring a single centralized controller to process all traffic, thus improving scalability while maintaining operational simplicity through automated selection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes multiple network devices (switches, routers, access points) universally capable of functioning as tunnel endpoints. Instead of requiring a specialized centralized controller, any network device can be configured to terminate tunnels and forward traffic, providing flexibility and scalability across diverse network topologies and device types

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multiple tunnel endpoints are configured based on traffic destinations, then traffic flow efficiency and latency are improved, but system complexity increases

Engineering Contradiction:
Improvetraffic flow efficiencyVSAvoidtunnel configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where tunnel endpoint selectors monitor network conditions, traffic patterns, and endpoint performance metrics. This feedback enables dynamic adjustment of tunnel endpoint selections and configurations, optimizing traffic flow efficiency while automatically adapting to changing network conditions without manual intervention, thus managing complexity through automation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240388996A1Traffic-based tunnel endpoint assignment for local area networks
Publication Date: 2024.11.21 CISCO TECHNOLOGY INC
  • US20240388996A1 patent drawing
  • US20240388996A1 patent drawing
  • US20240388996A1 patent drawing

AI summary

A network function orchestrator (NFO) of a local area network (LAN) controller can configure multiple different tunnel endpoints in the LAN based on network traffic observed within the LAN. The NFO can monitor network traffic communicated from client devices and through access points in the LAN. The network traffic can be associated with multiple different destinations. The NFO can determine, based on the network traffic and using network topology data, network devices to serve as tunnel endpoints within the LAN. Different tunnel endpoints can be configured for use in connection with different traffic destinations. The NFO can communicate with the network devices and the access points to configure the LAN to use the different tunnel endpoints.