Stateless Extranet Instantiation via CPE Control Plane
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional extranets are static and insecure, with fixed memberships and static routing tables, making them unsuitable for dynamic and secure communication in networks, especially for short-lived projects or customer-specific goals, and they lack a computationally efficient mechanism for secure communication.
Innovation Solution
A stateless extranet method is implemented using provider and consumer customer premises equipment (CPE) that transmit Network Hop (NHOP) with encryption keys to establish secure communication tunnels and instantiate stateless services through network address translation (NAT) IP, allowing for dynamic and secure network communication without exchanging extensive routing information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional extranets use static routing tables with fixed memberships, then routing information can be exchanged between networks, but security is compromised and the system cannot support dynamic short-lived memberships
Solution Approach 1:
The patent implements dynamic extranet memberships by allowing CPEs to join and leave extranets on-demand without permanent routing table entries. The stateless design enables memberships to be created and torn down dynamically, supporting short-lived projects and customer-specific goals while maintaining security through controlled plane separation.
Solution Approach 2:
The patent segments the network communication into control plane and data plane, where the control plane handles dynamic membership management and service definitions, while the data plane handles encrypted payload transmission. This segmentation allows dynamic memberships without exposing routing information, resolving the security adaptability contradiction.
2Ease of operation
If extensive routing information is stored on devices for extranet construction, then network connectivity is established, but computational costs increase and security attack vectors are opened
Solution Approach 1:
The patent extracts routing information from the data plane and places it exclusively in the control plane. The data plane only processes encrypted payloads without storing or processing routing tables, thereby reducing computational overhead and eliminating security risks associated with storing extensive routing information on data plane devices.
Solution Approach 2:
The control plane acts as an intermediary that manages all routing information and service definitions. It translates high-level service requests into data plane forwarding rules without requiring the data plane devices to store or process extensive routing tables, reducing their computational burden and attack surface.
3Stability of the object's composition
If traditional extranets use static constructs with fixed memberships, then routing information can be permanently exchanged, but dynamic short-lived memberships for specific projects cannot be supported
Solution Approach 1:
The patent implements dynamic extranet memberships by allowing CPEs to join and leave extranets on-demand without permanent routing table entries. The stateless design enables memberships to be created and torn down dynamically, supporting short-lived projects and customer-specific goals while maintaining security through controlled plane separation.
4Adaptability or versatility
If routing information is exchanged between existing networks through VPN, then extranet capabilities are provided, but participant sites are completely exposed from a routing perspective
Solution Approach 1:
The patent segments the network communication into control plane and data plane, where the control plane handles dynamic membership management and service definitions, while the data plane handles encrypted payload transmission. This segmentation allows dynamic memberships without exposing routing information, resolving the security adaptability contradiction.
Solution Approach 2:
The control plane acts as an intermediary that manages all routing information and service definitions. It translates high-level service requests into data plane forwarding rules without requiring the data plane devices to store or process extensive routing tables, reducing their computational burden and attack surface.
Data Source
AI summary
Methods for establishing a stateless extranet in a secure communication network include transmitting a consumer NHOP to a provider CPE from a consumer CPE in a control plane. The consumer NHOP is associated with at least one attribute of an NHOP, including an encryption key available with the consumer CPE, to establish a secure communication tunnel in a data plane. The consumer CPE receives a service definition over the control plane associated with a service available with the provider CPE. A service anchor point is created based on an identifier of the service definition. A network address translation (NAT) IP request is transmitted to the provider CPE. The consumer CPE receives a NAT IP from the provider CPE in response to the NAT IP request. The NAT IP is associated with the service anchor point of the consumer CPE. A stateless service is thereby instantiated on the consumer CPE.


