Elastic VPN Orchestration for Branch Office Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual networking techniques struggle to scale effectively when managing thousands of branch office networks, leading to unpredictable delays, bandwidth issues, and security challenges due to the high volume of IPsec tunnels required, which limits network scalability and maintains incomplete end-to-end security between islands and data centers.
Innovation Solution
Implementing an elastic VPN managed by a software-defined network (SDN) controller that uses enhanced next hop resolution protocol (eNHRP) to orchestrate connections through provider edge (PE) devices, minimizing exposure to public internet and allowing asymmetric connections over multiple communication media, thereby reducing the burden on customer premises equipment (CPE) and enabling end-to-end security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional virtual networking techniques are used to manage thousands of branch office networks, then security can be maintained between networks, but network scalability deteriorates and unpredictable delays increase
Solution Approach 1:
The patent segments the network into customer premises equipment (CPE) and network edge (NE) components, allowing distributed tunnel endpoints while centralizing control through the SDN controller. This segmentation enables scalable management of thousands of branch offices by dividing the tunnel management function across multiple NE devices rather than requiring full mesh connections between all CPE devices.
Solution Approach 2:
The patent introduces an intermediary SDN controller that mediates between CPE devices and the core network. The controller receives NHRP requests from CPE, determines appropriate NE endpoints, and orchestrates tunnel establishment. This intermediary eliminates the need for direct peer-to-peer tunnel management between all network nodes, enabling scalable deployment.
2Reliability
If full mesh IPsec tunnel connections are established between all branch offices, then complete end-to-end security is achieved, but device complexity and management burden increase significantly
Solution Approach 1:
The patent extracts the tunnel management complexity from individual CPE devices and concentrates it in the SDN controller. The controller handles NHRP message processing, NE endpoint selection, and tunnel orchestration, while CPE devices only need to establish tunnels to designated NE endpoints. This extraction reduces device complexity at the network edge while maintaining security.
Solution Approach 2:
The patent implements partial mesh connectivity where CPE devices connect to NE endpoints rather than requiring full mesh connections between all CPE devices. The SDN controller orchestrates selective tunnel establishment based on traffic flow requirements, implementing only the necessary connections rather than all possible pairs, thereby reducing complexity while maintaining security coverage.
3Extent of automation
If CPE devices directly manage IPsec tunnels to all other branch offices, then autonomous operation is achieved, but the burden on CPE processing power increases
Solution Approach 1:
The SDN controller acts as an intermediary that handles the computationally intensive NHRP message processing and tunnel orchestration. CPE devices send simple NHRP requests to the controller and receive tunnel endpoint information, avoiding the need to process complex routing decisions locally. This intermediary approach maintains automation while significantly reducing CPE processing burden.
Solution Approach 2:
The system maintains a degree of self-service where CPE devices autonomously initiate tunnel establishment by sending NHRP requests when traffic flow is needed. The devices don't require manual configuration and can dynamically request tunnel creation based on traffic patterns, while the heavy lifting of tunnel management is handled by the controller.
4Adaptability or versatility
If asymmetric connections are allowed over multiple communication media, then network adaptability improves, but connection management complexity increases
Solution Approach 1:
The SDN controller provides universal management capabilities that handle multiple connection media (wired, wireless, optical, etc.) through a single control plane. The controller receives NHRP requests and determines appropriate NE endpoints regardless of the underlying transport medium, allowing CPE devices to use diverse communication media without increasing local device complexity. The controller abstracts the media-specific details from the tunnel management process.
Data Source
AI summary
A network device employs a transmitter configured to transmit a registration request to a software defined network (SDN) controller. The network device employs a receiver to receive a reply from the SDN controller. The reply indicates a plurality of provider edge (PE) devices coupled to a carrier network. The network device employs a processor to cause the transmitter and receiver to establish a plurality of asymmetric connections to a virtual private network (VPN) operating over a wide area network (WAN) via the PE devices.


