Overlay Management Protocol for Secure Enterprise WAN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in building and controlling scalable, secure private wide area networks (WANs) due to the lack of control over significant network elements like routers and circuits managed by third-party service providers, limiting their ability to control routing within these networks.
Innovation Solution
The implementation of an overlay management protocol (OMP) to establish a secure network by creating an overlay domain with edge routers, where routing is controlled within the overlay domain and not shared with the underlying transport network, allowing enterprises to manage service routes and routing between edge routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If enterprises use traditional WAN routing controlled by third-party service providers, then network connectivity is provided, but enterprises lack control over routing and network security
Solution Approach 1:
The patent segments the network into two distinct layers: the underlying transport network (physical infrastructure controlled by service providers) and the overlay network (virtual network controlled by enterprises). This segmentation allows enterprises to control routing policies and security parameters within the overlay domain without needing to control the physical network elements, thus resolving the contradiction between routing control and infrastructure complexity.
Solution Approach 2:
The overlay network acts as an intermediary layer between enterprises and the underlying transport network. The overlay management protocol serves as a mediator that translates enterprise routing requirements into transport network routing decisions, enabling enterprises to control routing without directly managing transport network elements, thereby maintaining routing control while avoiding direct engagement with complex infrastructure.
2Reliability
If enterprises build secure private WANs on-demand, then network security and scalability are improved, but control over network elements managed by third parties remains limited
Solution Approach 1:
The patent introduces a new dimensional layer (overlay network) above the traditional single-layer WAN architecture. This dimensional change allows enterprises to implement security policies, routing controls, and service level agreements in the overlay domain while the underlying transport network handles only basic connectivity, thus improving security and control flexibility simultaneously without conflicting with third-party managed elements.
3Ease of operation
If routing is controlled within the overlay domain exclusively, then enterprises gain routing control and security, but the underlying transport network cannot utilize overlay routing information
Solution Approach 1:
The patent extracts sensitive routing information and control logic from the transport network domain and places them exclusively in the overlay domain. The overlay management protocol carries routing information only within the overlay domain, preventing exposure of enterprise routing policies to the transport network. This extraction maintains routing control and security while avoiding unnecessary information sharing with the underlying network.
Data Source
AI summary
A method for creating a secure network is provided. The method comprises establishing an overlay domain to control routing between overlay edge routers based on an underlying transport network, wherein said establishing comprises running an overlay management protocol to exchange information within the overlay domain; in accordance with the overlay management protocol defining service routes that exist exclusively within the overlay domain wherein each overlay route includes information on at least service availability within the overlay domain; and selectively using the service routes to control routing between the overlay edge routers; wherein the said routing is through the underlying transport network in a manner in which said overlay routes is shared with the overlay edge routers but not with the underlying transport network via the overlay management protocol.


