SD-WAN Edge Router Multi-Tenancy With Shared Control Plane
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SD-WAN edge routers lack efficient multi-tenancy solutions that do not require restructuring the software stack, leading to resource fragmentation and increased overhead, while service providers seek a less complex, single-box solution for tenant abstraction.
Innovation Solution
Implementing a shared control plane infrastructure across tenants in SD-WAN edge devices, using a flat configuration to map tenant VPNs to unique device VPNs, and maintaining VPN maps in a centralized management system to achieve multi-tenancy with minimal overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional multi-tenancy solutions are implemented on SD-WAN edge routers, then tenant isolation and resource sharing are achieved, but the software stack requires complex restructuring leading to resource fragmentation and increased overhead
Solution Approach 1:
The patent implements a universal control plane that serves multiple tenants through a single shared infrastructure. The control plane maintains separate forwarding tables for each tenant while using common CPU resources, memory, and processing logic, eliminating the need for separate virtual instances for each tenant and thereby reducing software stack complexity while maintaining multi-tenancy capability
Solution Approach 2:
The patent segments the control plane and data plane functions. The control plane operates as a single shared instance that manages all tenants, while the data plane maintains separate forwarding tables and pipelines for each tenant. This segmentation allows tenant isolation in the data plane while sharing resources in the control plane, reducing overall system complexity
2Reliability
If separate virtual instances are created for each tenant, then tenant isolation is ensured, but resource fragmentation and increased overhead occur
Solution Approach 1:
The patent merges the control plane instances for all tenants into a single shared control plane process. This consolidation eliminates resource fragmentation by having one control plane instance serve all tenants through multiplexing, while maintaining tenant isolation through separate forwarding tables in the data plane. The shared control plane reduces CPU, memory, and process overhead compared to separate virtual instances
3Productivity
If a shared control plane infrastructure is used across tenants, then resource utilization efficiency improves, but implementing multi-tenancy becomes more complex
Solution Approach 1:
The patent segments forwarding state information into separate forwarding tables for each tenant within the shared control plane. Each tenant has its own forwarding table that is independently managed, allowing the shared control plane to maintain tenant isolation and simplify the architecture by avoiding the need for complex virtualization layers while achieving efficient resource utilization
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment, a method includes identifying, by a router, a first tenant. The first tenant is associated with a first tenant virtual private network (VPN). The method also includes determining, by the router, a mapping of the first tenant VPN to a first device VPN and generating, by the router, a first label representing the first device VPN. The method further includes adding, by the router, the first label to a first network packet and communicating, by the router, the first network packet with the first label to a controller.