Multi-Cluster SDN Controller Proxy for Unified Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software-defined networking (SDN) solutions face challenges in efficiently configuring and managing SDN controllers across multiple cloud computing domains, requiring separate authentication and configuration for each domain, which increases complexity and latency.
Innovation Solution
A multi-cluster controller system that operates as a single interface to transparently proxy configuration requests across multiple clusters, authenticates users, and dynamically maintains a database of cluster objects, enabling efficient routing of configuration requests to the appropriate endpoints with minimal latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and configuration systems are used for each cloud domain, then security and domain independence are improved, but system complexity and configuration latency increase
Solution Approach 1:
The patent combines multiple separate SDN controller instances across different cloud domains into a single unified controller that manages all domains. This consolidation reduces system complexity by eliminating the need for separate authentication and configuration systems for each domain, while maintaining domain independence through logical segmentation within the unified controller architecture.
Solution Approach 2:
The unified SDN controller is designed to perform multiple functions across different cloud domains simultaneously. It provides universal authentication, configuration management, and network control capabilities that serve multiple domains through a single interface, thereby reducing complexity while maintaining the reliability and security requirements of each individual domain.
2Reliability
If separate authentication credentials are required for each SDN controller, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The unified SDN controller implements a universal authentication mechanism that accepts single credentials for accessing and configuring multiple cloud domains. This universal login system maintains security by implementing centralized authentication policies while dramatically simplifying operation, as users no longer need to manage separate credentials for each domain or controller instance.
3Adaptability or versatility
If multiple SDN controllers are deployed across clusters, then domain autonomy is improved, but configuration efficiency deteriorates
Solution Approach 1:
The patent merges the configuration management functions of multiple distributed SDN controllers into a single unified controller that manages all clusters and domains centrally. This approach maintains domain autonomy through logical separation of domain configurations while improving configuration efficiency by providing a single point of access and unified management interface, eliminating the need to configure each controller separately.
4Adaptability or versatility
If configuration requests are routed through multiple domains, then domain-specific control is improved, but latency increases
Solution Approach 1:
The patent extracts the domain-specific control logic from distributed controller instances and consolidates it into a unified controller that maintains separate domain configuration contexts. This extraction allows the system to route configuration requests efficiently through a single controller without the overhead of inter-domain communication and coordination, thereby reducing latency while preserving the ability to apply domain-specific control policies.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This disclosure describes techniques for configuring software defined network (SDN) controllers within different cloud computing domains and, in particular, a multi-cluster controller that operates and presents, in some examples, a single interface for seamlessly controlling and configuring SDN controllers in different cloud computing domains. In one example, this disclosure describes a system that includes a plurality of clusters, each of the plurality of clusters including a plurality of configurable endpoints; a storage system; and processing circuitry having access to the storage system and capable of communicating with each of the plurality of configurable endpoints. In some examples, the processing circuitry is configured to receive a plurality of requests, each specifying a configuration operation, identify, for each of the requests, a configuration cluster and a configuration endpoint within the configuration cluster, and perform, for each of the requests, the specified configuration operation.