Hub Clustering for Dynamic Transit Paths in SD-WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SD-WAN solutions lack dynamic transit paths within a VPN between branches connected to different hubs in a hub cluster, leading to security vulnerabilities and manual forwarding that breaks end-to-end secure connectivity.
Innovation Solution
A method where a network controller assigns a master hub to establish VPN tunnels between hubs and advertises routes through the master hub, allowing data to transit between branches without leaving the VPN tunnel, thereby maintaining end-to-end secure connectivity and reducing the need for external routing protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual forwarding through underlay network is used to enable communication between branches of different hubs, then connectivity between branches is achieved, but end-to-end secure connectivity is broken and security vulnerabilities arise
Solution Approach 1:
The patent introduces hub-to-hub VPN tunnels as an intermediary mechanism to enable secure communication between branches of different hubs. Instead of manually forwarding traffic through the underlay network, the system establishes encrypted VPN tunnels between hubs, allowing traffic to remain within the secure overlay network while still achieving inter-hub connectivity.
Solution Approach 2:
The patent extends the VPN tunneling concept from the traditional branch-to-branch dimension to include hub-to-hub connections. By adding this new dimension of tunneling at the hub level, the system maintains security while enabling communication between branches that don't share a common hub.
2Object-affected harmful factors
If hub-to-hub VPN tunnels are established to maintain secure connectivity, then end-to-end security is preserved, but network complexity increases
Solution Approach 1:
The network controller automatically performs hub-to-hub tunnel establishment, route advertisement, and traffic engineering. This self-service approach eliminates the need for manual configuration of complex VPN tunnels and routing policies, reducing operational complexity while maintaining security.
Solution Approach 2:
The hub-to-hub VPN tunnel mechanism serves multiple functions: it provides secure connectivity between hubs, enables inter-hub traffic engineering, and maintains end-to-end VPN coverage. This multi-functionality reduces the need for separate mechanisms for each function, simplifying the overall system.
3Ease of operation
If L3 switches are used to advertise overlay prefixes through underlay network, then routing between hubs is enabled, but SD-WAN overlay routes are exposed leading to security vulnerabilities
Solution Approach 1:
The patent uses hub-to-hub VPN tunnels as an intermediary to carry overlay traffic, preventing the need to advertise overlay prefixes through L3 switches in the underlay network. This intermediary mechanism allows routing to occur within the secure overlay, eliminating route leakage vulnerabilities.
Solution Approach 2:
The patent extracts the routing function from the underlay L3 switches and moves it to the overlay VPN tunnel endpoints. By taking out the overlay prefix advertisement from the underlay network, the system eliminates the security vulnerability of route exposure while maintaining routing capability.
4Adaptability or versatility
If full mesh VPN tunnel system is implemented to connect all branches, then maximum connectivity is achieved, but resource usage increases significantly
Solution Approach 1:
The patent segments the network into hub clusters and uses hierarchical tunneling where branches connect to their local hub, and hubs connect to each other through selected tunnel pairs. This segmentation avoids the need for every branch to establish tunnels with every other branch, significantly reducing resource consumption while maintaining connectivity.
Solution Approach 2:
The patent introduces hubs as intermediary nodes that aggregate traffic from multiple branches. Instead of direct branch-to-branch tunnels, traffic is routed through the intermediary hub, reducing the total number of tunnels required while maintaining full connectivity between all branches.
Data Source
AI summary
Some embodiments provide a method of transmitting data in a logical network that includes multiple hubs in a hub cluster and multiple branches. Each branch connects to a hub of the cluster through a virtual private network (VPN) tunnel. The method is performed by a network controller. The method assigns one of the hubs as a master hub. The method then sends a command to each of the other hubs in the hub cluster to establish a VPN tunnel between the other hub and the master hub. The method then advertises, to the other hubs, routes between the other hubs through the master hub. Each branch, in some embodiments is connected to only one hub in the hub cluster.


