Elastic VPN Orchestration for Branch Office Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual networking techniques struggle to scale effectively when managing thousands of branch office networks, leading to unpredictable delays, bandwidth issues, and security challenges due to the high volume of IPsec tunnels required, which limits network scalability and maintains incomplete end-to-end security between islands and data centers.

Innovation Solution

Implementing an elastic VPN managed by a software-defined network (SDN) controller that uses enhanced next hop resolution protocol (eNHRP) to orchestrate connections through provider edge (PE) devices, minimizing exposure to public internet and allowing asymmetric connections over multiple communication media, thereby reducing the burden on customer premises equipment (CPE) and enabling end-to-end security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virtual networking techniques are used to manage thousands of branch office networks, then security can be maintained between networks, but network scalability deteriorates and unpredictable delays increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network into customer premises equipment (CPE) and network edge (NE) components, allowing distributed tunnel endpoints while centralizing control through the SDN controller. This segmentation enables scalable management of thousands of branch offices by dividing the tunnel management function across multiple NE devices rather than requiring full mesh connections between all CPE devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary SDN controller that mediates between CPE devices and the core network. The controller receives NHRP requests from CPE, determines appropriate NE endpoints, and orchestrates tunnel establishment. This intermediary eliminates the need for direct peer-to-peer tunnel management between all network nodes, enabling scalable deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full mesh IPsec tunnel connections are established between all branch offices, then complete end-to-end security is achieved, but device complexity and management burden increase significantly

Engineering Contradiction:
Improveend-to-end securityVSAvoidtunnel management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the tunnel management complexity from individual CPE devices and concentrates it in the SDN controller. The controller handles NHRP message processing, NE endpoint selection, and tunnel orchestration, while CPE devices only need to establish tunnels to designated NE endpoints. This extraction reduces device complexity at the network edge while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial mesh connectivity where CPE devices connect to NE endpoints rather than requiring full mesh connections between all CPE devices. The SDN controller orchestrates selective tunnel establishment based on traffic flow requirements, implementing only the necessary connections rather than all possible pairs, thereby reducing complexity while maintaining security coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Extent of automation

If CPE devices directly manage IPsec tunnels to all other branch offices, then autonomous operation is achieved, but the burden on CPE processing power increases

Engineering Contradiction:
Improveautonomous tunnel managementVSAvoidCPE processing burden
Core Design Contradiction:
Extent of automationVSUse of energy by moving object

Solution Approach 1:

The SDN controller acts as an intermediary that handles the computationally intensive NHRP message processing and tunnel orchestration. CPE devices send simple NHRP requests to the controller and receive tunnel endpoint information, avoiding the need to process complex routing decisions locally. This intermediary approach maintains automation while significantly reducing CPE processing burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system maintains a degree of self-service where CPE devices autonomously initiate tunnel establishment by sending NHRP requests when traffic flow is needed. The devices don't require manual configuration and can dynamically request tunnel creation based on traffic patterns, while the heavy lifting of tunnel management is handled by the controller.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If asymmetric connections are allowed over multiple communication media, then network adaptability improves, but connection management complexity increases

Engineering Contradiction:
Improveconnection media flexibilityVSAvoidconnection management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The SDN controller provides universal management capabilities that handle multiple connection media (wired, wireless, optical, etc.) through a single control plane. The controller receives NHRP requests and determines appropriate NE endpoints regardless of the underlying transport medium, allowing CPE devices to use diverse communication media without increasing local device complexity. The controller abstracts the media-specific details from the tunnel management process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11792045B2Elastic VPN that bridges remote islands
Publication Date: 2023.10.17 FUTUREWEI TECHNOLOGIES INC
  • US11792045B2 patent drawing
  • US11792045B2 patent drawing
  • US11792045B2 patent drawing

AI summary

A network device employs a transmitter configured to transmit a registration request to a software defined network (SDN) controller. The network device employs a receiver to receive a reply from the SDN controller. The reply indicates a plurality of provider edge (PE) devices coupled to a carrier network. The network device employs a processor to cause the transmitter and receiver to establish a plurality of asymmetric connections to a virtual private network (VPN) operating over a wide area network (WAN) via the PE devices.