Hub Clustering for Dynamic Transit Paths in SD-WAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SD-WAN solutions lack dynamic transit paths within a VPN between branches connected to different hubs in a hub cluster, leading to security vulnerabilities and manual forwarding that breaks end-to-end secure connectivity.

Innovation Solution

A method where a network controller assigns a master hub to establish VPN tunnels between hubs and advertises routes through the master hub, allowing data to transit between branches without leaving the VPN tunnel, thereby maintaining end-to-end secure connectivity and reducing the need for external routing protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual forwarding through underlay network is used to enable communication between branches of different hubs, then connectivity between branches is achieved, but end-to-end secure connectivity is broken and security vulnerabilities arise

Engineering Contradiction:
Improveconnectivity between branchesVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces hub-to-hub VPN tunnels as an intermediary mechanism to enable secure communication between branches of different hubs. Instead of manually forwarding traffic through the underlay network, the system establishes encrypted VPN tunnels between hubs, allowing traffic to remain within the secure overlay network while still achieving inter-hub connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extends the VPN tunneling concept from the traditional branch-to-branch dimension to include hub-to-hub connections. By adding this new dimension of tunneling at the hub level, the system maintains security while enabling communication between branches that don't share a common hub.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Object-affected harmful factors

If hub-to-hub VPN tunnels are established to maintain secure connectivity, then end-to-end security is preserved, but network complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The network controller automatically performs hub-to-hub tunnel establishment, route advertisement, and traffic engineering. This self-service approach eliminates the need for manual configuration of complex VPN tunnels and routing policies, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The hub-to-hub VPN tunnel mechanism serves multiple functions: it provides secure connectivity between hubs, enables inter-hub traffic engineering, and maintains end-to-end VPN coverage. This multi-functionality reduces the need for separate mechanisms for each function, simplifying the overall system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If L3 switches are used to advertise overlay prefixes through underlay network, then routing between hubs is enabled, but SD-WAN overlay routes are exposed leading to security vulnerabilities

Engineering Contradiction:
Improverouting between hubsVSAvoidroute leakage vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses hub-to-hub VPN tunnels as an intermediary to carry overlay traffic, preventing the need to advertise overlay prefixes through L3 switches in the underlay network. This intermediary mechanism allows routing to occur within the secure overlay, eliminating route leakage vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the routing function from the underlay L3 switches and moves it to the overlay VPN tunnel endpoints. By taking out the overlay prefix advertisement from the underlay network, the system eliminates the security vulnerability of route exposure while maintaining routing capability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If full mesh VPN tunnel system is implemented to connect all branches, then maximum connectivity is achieved, but resource usage increases significantly

Engineering Contradiction:
Improvebranch connectivityVSAvoidnetwork resource consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent segments the network into hub clusters and uses hierarchical tunneling where branches connect to their local hub, and hubs connect to each other through selected tunnel pairs. This segmentation avoids the need for every branch to establish tunnels with every other branch, significantly reducing resource consumption while maintaining connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hubs as intermediary nodes that aggregate traffic from multiple branches. Instead of direct branch-to-branch tunnels, traffic is routed through the intermediary hub, reducing the total number of tunnels required while maintaining full connectivity between all branches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12009987B2Methods to support dynamic transit paths through hub clustering across branches in SD-WAN
Publication Date: 2024.06.11 VELOCLOUD NETWORKS LLC
  • US12009987B2 patent drawing
  • US12009987B2 patent drawing
  • US12009987B2 patent drawing

AI summary

Some embodiments provide a method of transmitting data in a logical network that includes multiple hubs in a hub cluster and multiple branches. Each branch connects to a hub of the cluster through a virtual private network (VPN) tunnel. The method is performed by a network controller. The method assigns one of the hubs as a master hub. The method then sends a command to each of the other hubs in the hub cluster to establish a VPN tunnel between the other hub and the master hub. The method then advertises, to the other hubs, routes between the other hubs through the master hub. Each branch, in some embodiments is connected to only one hub in the hub cluster.