Virtual Bridge for Autonomous System Interconnection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunication networks face challenges in connecting autonomous systems across different regions due to restrictions on direct Layer 3 BGP connections, which can lead to insecure or unencrypted data transmission, failing to meet customer requirements for redundancy and synchronization.

Innovation Solution

A virtual bridge is instantiated within the network using virtual routers, establishing both Layer 2 and Layer 3 connections between autonomous systems, allowing for secure communication paths even when direct connections are prohibited, by assigning a unique ASN to the bridge and facilitating communication through Interior Gateway Protocol (IGP) information exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct Layer 3 BGP connections are established between autonomous systems, then communication simplicity is improved, but security and compliance are worsened due to unencrypted data transmission

Engineering Contradiction:
Improvecommunication simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Layer 2 connection as an intermediary mechanism between autonomous systems. Instead of allowing direct Layer 3 BGP connections, the system establishes Ethernet bridging at Layer 2, which then connects to cloud regions through controlled paths. This intermediary Layer 2 connection enables security policies, encryption, and compliance measures to be applied while maintaining connectivity between AS instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud regions are connected for redundancy service, then reliability is improved, but network security is worsened when connections must pass through public or unencrypted networks

Engineering Contradiction:
Improveredundancy serviceVSAvoidnetwork security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The Layer 2 connection acts as a secure intermediary that enables redundancy services between cloud regions without exposing data to public or unencrypted networks. The bridging mechanism creates a controlled communication path that maintains security while enabling backup and synchronization operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication into distinct layers: Layer 2 Ethernet bridging for secure regional connectivity and Layer 3 BGP for autonomous system routing. This segmentation allows security policies to be applied at the Layer 2 level while maintaining standard routing protocols at Layer 3, enabling redundancy without compromising security.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If direct AS connections are prohibited for business considerations, then compliance is improved, but connectivity is worsened

Engineering Contradiction:
ImprovecomplianceVSAvoidconnectivity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The Layer 2 connection serves as a compliant intermediary that enables AS instances to communicate without establishing prohibited direct Layer 3 BGP connections. The bridging mechanism satisfies business compliance requirements while maintaining necessary connectivity through an approved communication path.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10608841B2Autonomous system bridge connecting in a telecommunications network
Publication Date: 2020.03.31 LEVEL 3 COMMUNICATIONS LLC
  • US10608841B2 patent drawing
  • US10608841B2 patent drawing
  • US10608841B2 patent drawing

AI summary

Methods and systems for facilitating communication between two or more autonomous system instances include the instantiation of a bridge between the autonomous system (AS) instances. The bridge includes multiple virtual routers each of which is connected using a Layer 2 and a Layer 3 connection to a respective one of the AS instances. For example, each router may be connected to a respective AS instance by each of a virtual local area network (VLAN) connection and a Border Gateway Protocol (BGP) session. To facilitate the BGP session, the bridge may be assigned an AS number (ASN) different than that of each of the AS instances and that is exchanged between the routers and the AS instances. Routing within the bridge may be facilitated by the exchange of interior gateway protocol (IGP) information between the virtual routers.