End Controller Routing via IPSec and OSPF LSAs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing routing protocols in wide area networks, such as OSPF, lead to exponential growth of routing information in databases, limiting the number of branches an end controller can manage due to finite storage space, resulting in inefficient management of network connectivity.
Innovation Solution
Implementing the OSPF protocol once for route configuration and using IPSec messages for communication between the end controller and branch devices, which results in a linear relationship between data storage and the number of branches, allowing for more efficient storage and management of routing information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If OSPF protocol is used for routing communication between end controller and branch devices, then routing information can be exchanged, but the quantity of data stored in the database grows quadratically with the number of branch devices, limiting the number of manageable branches
Solution Approach 1:
The patent segments the routing information storage by introducing intermediate controllers that each manage routing data for a specific subset of branch devices. Instead of one end controller storing all routing information quadratically, multiple intermediate controllers divide the routing data into smaller linear portions, reducing the data burden on each individual controller while maintaining overall network connectivity.
Solution Approach 2:
The patent introduces a hierarchical dimension to the controller architecture, adding intermediate controllers between the end controller and branch devices. This creates a multi-level routing information structure where routing data is organized and stored across multiple hierarchical levels, transforming the quadratic growth problem into a series of linear relationships at each hierarchical level.
2Reliability
If end controller stores routing information for all branch devices in a single database, then complete routing information is available, but storage space requirements increase quadratically, limiting scalability
Solution Approach 1:
The patent divides the single centralized routing database into multiple distributed routing databases across end controllers and intermediate controllers. Each controller stores routing information for its specific domain, segmenting the total routing data while maintaining completeness through the hierarchical structure that allows any controller to reach any branch device via intermediate controllers.
Solution Approach 2:
The patent introduces intermediate controllers as intermediary components between the end controller and branch devices. These intermediate controllers store and manage routing information for their respective subsets of branch devices, acting as mediators that reduce the direct routing data burden on end controllers while ensuring complete routing information is available through the hierarchical path.
3Device complexity
If a single end controller manages all branch devices directly, then simplified controller architecture is achieved, but the controller must store quadratic amounts of routing data, reducing productivity
Solution Approach 1:
The patent segments the monolithic end controller architecture into a hierarchical structure with end controllers and intermediate controllers. Each intermediate controller manages a subset of branch devices, dividing the overall management task into smaller segments. This segmentation reduces the routing data burden on each controller while maintaining manageable architectural complexity through standardized interfaces and protocols.
Solution Approach 2:
The patent adds a hierarchical dimension to the controller architecture, transforming the flat single-controller structure into a multi-level hierarchy. This dimensional change allows the system to manage more branch devices by distributing routing data across multiple hierarchical levels, effectively increasing productivity without proportionally increasing individual controller complexity.
Data Source
AI summary
An end controller, comprising: a processing resource; and a memory resource storing machine-readable instructions to cause the processing resource to: receive, using internet protocol security (IPSec) messages, a plurality of subnetworks that form a route to a branch device via a branch gateway; transfer the plurality of subnetworks to a layer-2-layer-3 module; transfer the plurality of subnetworks to an open shortest path first (OSPF) module; and publish the plurality of subnetworks that form the route to the branch device to a core router using OSPF link state advertisements (LSAs).


