Overlay Fabric Internet Access via Extranet Policy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking technologies face challenges in dynamically provisioning and managing internet access across multiple service providers with varying policies, especially in multi-site overlay networks, where seamless integration and adaptability of internet access policies are required.

Innovation Solution

The implementation of a system that creates an isolated Internet Virtual Network spanning across multiple domains, utilizing a combination of local and remote extranet policies within a Software-Defined Access network, allowing for dynamic routing and traffic redirection while decoupling internet traffic identification from routing policies, enabling flexible and adaptable internet access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If internet access is provided across multiple service providers with varied policies, then service provider policy compliance is improved, but device complexity increases

Engineering Contradiction:
Improveservice provider policy complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that sits between multiple service providers and the overlay fabric, acting as a mediator that translates and enforces varied service provider policies into a unified framework. This intermediary layer handles policy compliance without requiring each network component to independently manage complex multi-provider policies, thus maintaining reliability while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments policy management into distinct layers: service provider-specific policy rules are separated from the overlay fabric routing decisions. By dividing the policy enforcement mechanism into modular components that can be independently configured for each service provider, the system achieves policy compliance without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If dynamic provisioning is implemented across multiple domains, then adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedynamic provisioning capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal policy framework that can handle multiple service providers, domains, and traffic types through a single standardized interface. This multi-functional system allows dynamic provisioning across diverse scenarios without requiring separate management procedures for each case, thereby maintaining adaptability while improving ease of operation through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables dynamic provisioning by allowing flexible modification of routing parameters and policy attributes without changing the underlying system architecture. Operators can adjust service provider-specific parameters, traffic engineering parameters, and policy conditions dynamically, achieving high adaptability through parameter flexibility rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If traffic redirection is implemented for internet access, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveinternet access efficiencyVSAvoidrouting complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of multi-provider traffic redirection from the core routing infrastructure and places it in a dedicated policy enforcement layer. By separating the traffic redirection logic from standard routing operations, the system achieves improved internet access productivity through optimized traffic paths while containing routing complexity in a specialized module rather than propagating it throughout the entire network.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10735217B2Distributed internet access in an overlay fabric using combined local and remote extranet policies
Publication Date: 2020.08.04 CISCO TECHNOLOGY INC
  • US10735217B2 patent drawing
  • US10735217B2 patent drawing
  • US10735217B2 patent drawing

AI summary

The present technology provides a system, method, and computer-readable medium directed to dynamic implementation and management of multi-provider internet access featuring multiple access points across a multi-site overlay network fabric. An aspect of the technology is directed to the implementation of a common fabric-wide Virtual Network (VN) with a unique Internet Instance Identifier (Internet IID) that is dedicated to internet access traffic. Default access routes from multiple service providers (SP) are leaked into the VN with the Internet IID at exit points of the fabric using local Extranet policies. Internet-bound traffic generated from any point within the overlay fabric network is then redirected into the Internet IID, using remote Extranet policies. Internet-bound traffic, once in the Internet IID, follows the SP default access route(s) towards the exit points where SP specific access policies may be applied to the traffic which is then forwarded to the corresponding SP network.