SD-WAN Edge Traffic Steering Across Hybrid Underlay Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SD-WAN technologies struggle with unpredictable flow paths, especially when unsecured networks like the Internet are part of the underlay, leading to increased latency and security risks, and existing traffic steering methods are ineffective for mixed administrative control environments.

Innovation Solution

Implementing a method for SD-WAN Traffic Engineering (TE) that includes edge discovery processes, secure connection establishment, and packet encapsulation using GENEVE headers to steer traffic flows through optimized SD-WAN paths, even in hybrid networks with mixed underlay types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unsecured networks like the Internet are used in the underlay, then network flexibility and cost-effectiveness are improved, but latency increases and security risks worsen

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network is segmented into secured and unsecured segments. Secured segments use encrypted tunnels for critical traffic, while unsecured segments handle non-critical traffic. This allows the system to leverage the flexibility of unsecured networks for cost-effective routing while maintaining security for sensitive data flows through dedicated encrypted paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary security layer is introduced between the unsecured network and the data traffic. This intermediary layer provides encryption and authentication mechanisms that allow unsecured networks to be used for transport while maintaining security guarantees for the actual data communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If unsecured networks are used in the underlay, then network flexibility is improved, but latency increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Different quality characteristics are applied locally to different network segments. Critical traffic receives prioritized handling with lower latency through secured segments, while non-critical traffic utilizes unsecured segments for flexibility. This local differentiation allows the system to optimize latency where needed without sacrificing overall network flexibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network dynamically adjusts traffic routing based on real-time conditions. When latency is critical, traffic is steered through secured segments with guaranteed paths. When flexibility is prioritized, traffic utilizes unsecured segments. This dynamic adaptation allows the system to optimize performance based on instantaneous network state.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If existing traffic steering methods are used, then implementation simplicity is maintained, but effectiveness in hybrid networks with mixed administrative control deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoideffectiveness in hybrid networks
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The traffic steering mechanism is designed to be universal across different network types and administrative domains. It can handle secured and unsecured networks, single-domain and multi-domain scenarios, and various administrative control models through a unified approach. This multi-functionality enables the system to adapt to hybrid networks without requiring separate steering mechanisms for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes key parameters such as encryption status, administrative domain, and policy requirements to adapt traffic steering behavior. By dynamically adjusting these parameters based on the network environment, the system maintains simplicity in implementation while achieving effectiveness in complex hybrid scenarios.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If secure overlay tunnels are established, then security is improved, but processing demands at transit nodes increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing demands
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The security processing functions are extracted from the transit nodes and consolidated at the edge nodes. Transit nodes only handle forwarding operations, while security-related encryption and decryption are performed at edge nodes where the traffic originates and terminates. This extraction significantly reduces the processing burden on transit nodes while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An intermediary security architecture is introduced where security functions are centralized at edge nodes rather than being distributed at every transit node. This intermediary approach allows secure tunnel establishment without imposing heavy processing demands on intermediate transit infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260081849A1Sd-wan traffic engineering
Publication Date: 2026.03.19 HUAWEI TECH CO LTD
  • US20260081849A1 patent drawing
  • US20260081849A1 patent drawing
  • US20260081849A1 patent drawing

AI summary

A method implemented by a first edge node of a software-defined wide area network (SD-WAN) for steering traffic over an SD-WAN path. The first edge node receives, on a control plane, first gateway (GW) properties of a first adjacent SD-WAN gateway of a second edge node of the SD-WAN, wherein the first edge node is an authorized peer of the second edge node, and the first adjacent SD-WAN gateway satisfies a first policy of the second edge node. The first edge node generates, based on the first GW properties, a data packet containing header information for steering the data packet to the second edge node over an SD-WAN path comprising the first adjacent SD-WAN gateway. The first edge node transmits, on a data plane, the data packet to a next hop along the SD-WAN path as indicated by an outer Internet Protocol (IP) destination address of the data packet.