Automated IP VPN Configuration via Network Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network designs using connection-oriented technologies are inefficient, and manual management of VPNs is costly and labor-intensive, particularly in assigning Route Distinguishers (RDs) and Route Targets (RTs), and generating and updating access lists, which hampers scalability and network resource management.

Innovation Solution

A network controller identifies basic components of VPNs and generates routing data, including RDs and RTs for MPLS-based VPNs, and access lists for VR-based VPNs, automating the configuration and assignment of these parameters to optimize network management and resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual management of RDs and RTs is used, then configuration flexibility is maintained, but labor intensity and error rate increase significantly

Engineering Contradiction:
Improvemanual configuration flexibilityVSAvoidconfiguration efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system enables automatic self-configuration of RDs and RTs through algorithmic generation based on network topology and requirements, eliminating manual intervention while maintaining optimal configuration decisions. The network controller automatically calculates and assigns these parameters without human input.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual mechanical configuration processes are replaced with automated computational systems that use algorithms to generate RDs and RTs. This substitution transforms the manual operation into an automated information processing task, dramatically improving efficiency while maintaining configuration quality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Manufacturing precision

If manual generation of access lists is performed, then configuration accuracy can be verified, but time consumption and labor costs increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system incorporates validation mechanisms that automatically verify generated access lists against network requirements and policies. This feedback loop ensures configuration accuracy is maintained while eliminating the time-consuming manual verification process, as the system self-validates its outputs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Access lists are generated and validated in advance before deployment, with the system performing all necessary checks and optimizations beforehand. This preliminary automated action ensures accuracy is built-in from the start, eliminating the need for time-consuming post-configuration verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional VPN configuration methods are used, then network security is maintained, but scalability is limited due to manual management overhead

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transforms static manual configuration into a dynamic automated process that can adapt to changing network conditions and requirements in real-time. This enables the network to scale flexibly as new VPNs are added or modified, while automated security validation maintains reliability throughout the dynamic changes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8656050B2Methods and systems for efficiently configuring IP-based, virtual private networks
Publication Date: 2014.02.18 WSOU INVESTMENTS LLC
  • US8656050B2 patent drawing
  • US8656050B2 patent drawing
  • US8656050B2 patent drawing

AI summary

Internet-protocol based, virtual private networks are configured by first identifying the basic components of such networks and then efficiently assigning MPLS-based RD and RTs to each component or efficiently generating VR-based access lists for each component.