Overlay Fabric Internet Access via Extranet Policy Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networking technologies face challenges in dynamically provisioning and managing internet access across multiple service providers with varying policies, especially in multi-site overlay networks, where seamless integration and adaptability of internet access policies are required.
Innovation Solution
The implementation of a system that creates an isolated Internet Virtual Network spanning across multiple domains, utilizing a combination of local and remote extranet policies within a Software-Defined Access network, allowing for dynamic routing and traffic redirection while decoupling internet traffic identification from routing policies, enabling flexible and adaptable internet access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If internet access is provided across multiple service providers with varied policies, then service provider policy compliance is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary system that sits between multiple service providers and the overlay fabric, acting as a mediator that translates and enforces varied service provider policies into a unified framework. This intermediary layer handles policy compliance without requiring each network component to independently manage complex multi-provider policies, thus maintaining reliability while managing complexity.
Solution Approach 2:
The system segments policy management into distinct layers: service provider-specific policy rules are separated from the overlay fabric routing decisions. By dividing the policy enforcement mechanism into modular components that can be independently configured for each service provider, the system achieves policy compliance without proportionally increasing overall system complexity.
2Adaptability or versatility
If dynamic provisioning is implemented across multiple domains, then adaptability is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements a universal policy framework that can handle multiple service providers, domains, and traffic types through a single standardized interface. This multi-functional system allows dynamic provisioning across diverse scenarios without requiring separate management procedures for each case, thereby maintaining adaptability while improving ease of operation through consolidation.
Solution Approach 2:
The system enables dynamic provisioning by allowing flexible modification of routing parameters and policy attributes without changing the underlying system architecture. Operators can adjust service provider-specific parameters, traffic engineering parameters, and policy conditions dynamically, achieving high adaptability through parameter flexibility rather than structural complexity.
3Productivity
If traffic redirection is implemented for internet access, then productivity is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complexity of multi-provider traffic redirection from the core routing infrastructure and places it in a dedicated policy enforcement layer. By separating the traffic redirection logic from standard routing operations, the system achieves improved internet access productivity through optimized traffic paths while containing routing complexity in a specialized module rather than propagating it throughout the entire network.
Data Source
AI summary
The present technology provides a system, method, and computer-readable medium directed to dynamic implementation and management of multi-provider internet access featuring multiple access points across a multi-site overlay network fabric. An aspect of the technology is directed to the implementation of a common fabric-wide Virtual Network (VN) with a unique Internet Instance Identifier (Internet IID) that is dedicated to internet access traffic. Default access routes from multiple service providers (SP) are leaked into the VN with the Internet IID at exit points of the fabric using local Extranet policies. Internet-bound traffic generated from any point within the overlay fabric network is then redirected into the Internet IID, using remote Extranet policies. Internet-bound traffic, once in the Internet IID, follows the SP default access route(s) towards the exit points where SP specific access policies may be applied to the traffic which is then forwarded to the corresponding SP network.


