Multipath Hub Cluster Gateway for Scalable VPN Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale VPN networks with a single hub face practical limitations in scaling, making it impractical to manage individual hubs for large deployments, necessitating a dynamic expansion of hub capacity through clustering for resiliency and redundancy.
Innovation Solution
A method and system for connecting to a multipath hub in a cluster, where a gateway receives a request from a branch edge, determines the least-loaded edge within the cluster, and configures a tunnel for connectivity, utilizing logical identifiers and dynamic tunneling protocols to manage network traffic and maintain redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single hub is used in a VPN network, then the network structure is simple and easy to manage, but the network cannot scale to large deployments of 20,000 sites
Solution Approach 1:
The patent divides a single large-scale hub into multiple smaller hub nodes organized in clusters. Each hub node manages a portion of the total sites, enabling the network to scale to 20,000 sites while maintaining manageable individual node complexity. The segmentation allows distributed management where each node operates independently but contributes to the overall network functionality.
Solution Approach 2:
Multiple hub nodes are merged into logical clusters that function as a unified system. The patent combines several physical hubs into cluster groups where they collectively provide the capacity of a single large hub while maintaining the benefits of distributed architecture. This merging enables scalability without proportionally increasing management complexity.
2Adaptability or versatility
If individual hubs are managed separately for large deployments, then each hub can be optimized independently, but the management overhead becomes impractical for 20,000 sites
Solution Approach 1:
The patent creates universal hub node templates that can be deployed across multiple locations with consistent configuration. Each hub node in the cluster uses standardized software and management interfaces, allowing individual optimization while maintaining uniform management procedures. This universality enables centralized management of 20,000 sites through replicated functional units.
Solution Approach 2:
Hub nodes automatically discover and register themselves with the centralized management system, eliminating manual configuration overhead. The nodes self-configure their cluster memberships and routing relationships, reducing the operational burden on administrators while maintaining individual node optimization capabilities.
3Productivity
If a cluster of edges is created to expand hub capacity, then the network can scale dynamically, but the system complexity increases with multiple communicating nodes
Solution Approach 1:
The patent introduces a centralized management system as an intermediary that handles cluster coordination, node discovery, and resource allocation. This mediator abstracts the complexity of managing multiple cluster nodes, allowing dynamic capacity expansion while presenting a simplified interface to administrators. The intermediary manages the bookkeeping of cluster membership and traffic routing without requiring complex peer-to-peer coordination between nodes.
4Reliability
If Active/Active HA topology is implemented in a cluster, then resiliency is improved, but the complexity of maintaining multiple active nodes increases
Solution Approach 1:
The patent implements continuous health monitoring and automatic failover mechanisms where hub nodes exchange status information and dynamically adjust traffic routing based on real-time conditions. When a node fails, the system receives feedback about the failure and automatically redistributes its workload to remaining active nodes, maintaining resiliency without requiring complex manual intervention. This feedback-driven approach simplifies Active/Active HA management by making failover automatic rather than manual.
Data Source
AI summary
In one aspect, a computerized method useful for connecting to a multipath hub in a cluster includes the step of, with a gateway in a same network as the cluster, receiving, from a branch edge, a request to connect to a logical identifier (ID) of the multipath hub. The gateway recognizes a logical ID representing a cluster. The gateway determines a least-loaded edge in the cluster to be the multipath hub. The gateway returns a connectivity information for the multipath hub. The branch edge configures a tunnel to the multipath hub.


