SDN Orchestration for Multi-Domain Optical VPN Path Establishment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a path in an optical domain to couple Internet Protocol (IP) routing domains for Virtual Private Networks (VPNs) is a technical challenge that existing technologies have not effectively addressed.
Innovation Solution
A Software Defined Networking (SDN) based orchestration and control mechanism that interfaces multiple entities, including Customer Network Controllers, Multi-Domain Service Coordinators, and Optical Transport Network Controllers, to provide Virtual Private Networks (VPNs) across multiple Autonomous Systems (AS) environments through Multi-Protocol Border Gateway Protocol (MP-BGP), coordinating End-to-End (E2E) TE tunnel provisioning over IP/MPLS inter-domain networks, and supporting both soft shared and hard dedicated optical bypass options.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual configuration methods are used to establish optical paths for VPNs, then flexibility and adaptability are maintained, but operational efficiency and provisioning speed deteriorate
Solution Approach 1:
A domain controller is introduced as an intermediary entity that automatically establishes optical paths and TE tunnels between IP routing domains. The domain controller receives VPN establishment requests, determines optimal paths through the optical domain, configures appropriate TE tunnel parameters, and coordinates with network elements to create the end-to-end connection, thereby automating what would otherwise require manual configuration
Solution Approach 2:
The system enables automated self-provisioning of VPN services through the domain controller, which autonomously performs path computation, resource allocation, and configuration without human intervention. The domain controller automatically manages the entire lifecycle from receiving service requests to establishing and maintaining optical paths and TE tunnels, allowing the network to serve itself
2Adaptability or versatility
If abstraction of network resources is implemented across multiple domains, then network flexibility and dynamicity are improved, but control and management complexity increases
Solution Approach 1:
The control architecture is segmented into multiple domain controllers, each responsible for a specific IP routing domain or optical domain. Each domain controller independently manages its local resources and abstracts them appropriately, while coordinating with other domain controllers through standardized interfaces. This segmentation allows complex multi-domain abstraction to be broken down into manageable local decisions
Solution Approach 2:
The domain controller is designed as a universal control entity that can manage multiple types of network resources (optical paths, TE tunnels, IP routing) and support multiple VPN services across different domains. It provides a unified control plane that handles diverse networking requirements through a common architecture, reducing the need for domain-specific management complexity
3Extent of automation
If automated control mechanisms are introduced for multi-domain VPN provisioning, then operational efficiency is improved, but system complexity and coordination requirements worsen
Solution Approach 1:
The domain controller implements feedback mechanisms to monitor the status of optical paths, TE tunnels, and network resources across domains. It continuously receives status information from network elements, compares actual states with desired states, and automatically adjusts configurations to maintain optimal VPN service delivery. This feedback loop enables automated correction and adaptation without human intervention
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
A method is provided to establish a path in an optical domain to couple first and second IP routing domains for use by a VPN. A network controller (NC) receives an optical path setup command and, in response, determines an optical path ID identifying an optical path. The NC sends a mapping command to a domain controller (DC) associated with the first IP routing domain and receives routing information that includes a VPN label. The NC sends a forwarding command including the routing information to a DC associated with the second IP routing domain, the forwarding command configured to cause a termination point in the second IP routing domain to forward a packet to the optical path when the packet comprises elements of the routing information.