End Controller Routing via IPSec and OSPF LSAs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing routing protocols in wide area networks, such as OSPF, lead to exponential growth of routing information in databases, limiting the number of branches an end controller can manage due to finite storage space, resulting in inefficient management of network connectivity.

Innovation Solution

Implementing the OSPF protocol once for route configuration and using IPSec messages for communication between the end controller and branch devices, which results in a linear relationship between data storage and the number of branches, allowing for more efficient storage and management of routing information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OSPF protocol is used for routing communication between end controller and branch devices, then routing information can be exchanged, but the quantity of data stored in the database grows quadratically with the number of branch devices, limiting the number of manageable branches

Engineering Contradiction:
Improvenumber of branch devices that can be managedVSAvoidquantity of routing data stored in database
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the routing information storage by introducing intermediate controllers that each manage routing data for a specific subset of branch devices. Instead of one end controller storing all routing information quadratically, multiple intermediate controllers divide the routing data into smaller linear portions, reducing the data burden on each individual controller while maintaining overall network connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the controller architecture, adding intermediate controllers between the end controller and branch devices. This creates a multi-level routing information structure where routing data is organized and stored across multiple hierarchical levels, transforming the quadratic growth problem into a series of linear relationships at each hierarchical level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If end controller stores routing information for all branch devices in a single database, then complete routing information is available, but storage space requirements increase quadratically, limiting scalability

Engineering Contradiction:
Improvecompleteness of routing informationVSAvoidstorage space on end controller
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent divides the single centralized routing database into multiple distributed routing databases across end controllers and intermediate controllers. Each controller stores routing information for its specific domain, segmenting the total routing data while maintaining completeness through the hierarchical structure that allows any controller to reach any branch device via intermediate controllers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate controllers as intermediary components between the end controller and branch devices. These intermediate controllers store and manage routing information for their respective subsets of branch devices, acting as mediators that reduce the direct routing data burden on end controllers while ensuring complete routing information is available through the hierarchical path.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single end controller manages all branch devices directly, then simplified controller architecture is achieved, but the controller must store quadratic amounts of routing data, reducing productivity

Engineering Contradiction:
Improvecontroller architecture complexityVSAvoidnumber of branches that can be managed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the monolithic end controller architecture into a hierarchical structure with end controllers and intermediate controllers. Each intermediate controller manages a subset of branch devices, dividing the overall management task into smaller segments. This segmentation reduces the routing data burden on each controller while maintaining manageable architectural complexity through standardized interfaces and protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a hierarchical dimension to the controller architecture, transforming the flat single-controller structure into a multi-level hierarchy. This dimensional change allows the system to manage more branch devices by distributing routing data across multiple hierarchical levels, effectively increasing productivity without proportionally increasing individual controller complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11349808B2Internet protocol security messages for subnetworks
Publication Date: 2022.05.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11349808B2 patent drawing
  • US11349808B2 patent drawing
  • US11349808B2 patent drawing

AI summary

An end controller, comprising: a processing resource; and a memory resource storing machine-readable instructions to cause the processing resource to: receive, using internet protocol security (IPSec) messages, a plurality of subnetworks that form a route to a branch device via a branch gateway; transfer the plurality of subnetworks to a layer-2-layer-3 module; transfer the plurality of subnetworks to an open shortest path first (OSPF) module; and publish the plurality of subnetworks that form the route to the branch device to a core router using OSPF link state advertisements (LSAs).