SD-WAN Edge Router Multi-Tenancy via Shared Control Plane

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SD-WAN edge routers face challenges in achieving multi-tenancy without incurring high overhead, resource fragmentation, and complex configurations, which hinder efficient utilization of shared network resources and increase operational costs.

Innovation Solution

Implementing a shared control plane infrastructure across tenants, using a mapping of tenant VPNs to device VPNs, and generating labels for network packets to isolate and manage traffic, thereby enabling multi-tenancy with minimal overhead and resource sharing within a single router instance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate instances are deployed for each tenant, then tenant isolation and security are improved, but resource utilization efficiency deteriorates and operational costs increase

Engineering Contradiction:
Improvetenant isolationVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple tenant instances into a single shared router instance by implementing a unified control plane that handles multiple Virtual Routing and Forwarding (VRF) instances. The control plane processes packets for different tenants through a single instance, eliminating the need for separate router instances for each tenant while maintaining logical isolation through VRF mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The router instance is designed to perform multiple functions simultaneously by serving multiple tenants through a single shared instance. The control plane is configured to handle traffic for different VRF instances, allowing one router to perform the work of multiple dedicated routers while optimizing resource utilization across all tenants.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple independent instances are deployed, then tenant isolation is improved, but device complexity and configuration complexity increase

Engineering Contradiction:
Improvelogical segmentationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple independent instances into a single shared router by implementing a unified control plane architecture. This consolidation reduces configuration complexity while maintaining logical segmentation through VRF instances, as the control plane manages all tenant traffic through a single instance rather than requiring separate configurations for each tenant's dedicated instance.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If shared control plane infrastructure is implemented, then resource sharing and cost reduction are improved, but control over individual tenant resources may be compromised

Engineering Contradiction:
Improveresource sharing efficiencyVSAvoidtenant resource control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments tenant resources logically through VRF instances while sharing the physical router infrastructure. Each tenant is assigned a dedicated VRF instance that isolates their traffic and resources, allowing the shared control plane to maintain separate control over each tenant's resources while benefiting from physical resource sharing and cost reduction.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230188502A1Systems and Methods for Achieving Multi-tenancy on an Edge Router
Publication Date: 2023.06.15 CISCO TECHNOLOGY INC
  • US20230188502A1 patent drawing
  • US20230188502A1 patent drawing
  • US20230188502A1 patent drawing

AI summary

In one embodiment, a method includes identifying, by a router, a first tenant. The first tenant is associated with a first tenant virtual private network (VPN). The method also includes determining, by the router, a mapping of the first tenant VPN to a first device VPN and generating, by the router, a first label representing the first device VPN. The method further includes adding, by the router, the first label to a first network packet and communicating, by the router, the first network packet with the first label to a controller.