Virtual Bridge for Autonomous System Interconnection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Telecommunication networks face challenges in connecting autonomous systems across different regions due to restrictions on direct Layer 3 BGP connections, which can lead to insecure or unencrypted data transmission, failing to meet customer requirements for redundancy and synchronization.
Innovation Solution
A virtual bridge is instantiated within the network using virtual routers, establishing both Layer 2 and Layer 3 connections between autonomous systems, allowing for secure communication paths even when direct connections are prohibited, by assigning a unique ASN to the bridge and facilitating communication through Interior Gateway Protocol (IGP) information exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct Layer 3 BGP connections are established between autonomous systems, then communication simplicity is improved, but security and compliance are worsened due to unencrypted data transmission
Solution Approach 1:
The patent introduces a Layer 2 connection as an intermediary mechanism between autonomous systems. Instead of allowing direct Layer 3 BGP connections, the system establishes Ethernet bridging at Layer 2, which then connects to cloud regions through controlled paths. This intermediary Layer 2 connection enables security policies, encryption, and compliance measures to be applied while maintaining connectivity between AS instances.
2Reliability
If cloud regions are connected for redundancy service, then reliability is improved, but network security is worsened when connections must pass through public or unencrypted networks
Solution Approach 1:
The Layer 2 connection acts as a secure intermediary that enables redundancy services between cloud regions without exposing data to public or unencrypted networks. The bridging mechanism creates a controlled communication path that maintains security while enabling backup and synchronization operations.
Solution Approach 2:
The patent segments the network communication into distinct layers: Layer 2 Ethernet bridging for secure regional connectivity and Layer 3 BGP for autonomous system routing. This segmentation allows security policies to be applied at the Layer 2 level while maintaining standard routing protocols at Layer 3, enabling redundancy without compromising security.
3Object-affected harmful factors
If direct AS connections are prohibited for business considerations, then compliance is improved, but connectivity is worsened
Solution Approach 1:
The Layer 2 connection serves as a compliant intermediary that enables AS instances to communicate without establishing prohibited direct Layer 3 BGP connections. The bridging mechanism satisfies business compliance requirements while maintaining necessary connectivity through an approved communication path.
Data Source
AI summary
Methods and systems for facilitating communication between two or more autonomous system instances include the instantiation of a bridge between the autonomous system (AS) instances. The bridge includes multiple virtual routers each of which is connected using a Layer 2 and a Layer 3 connection to a respective one of the AS instances. For example, each router may be connected to a respective AS instance by each of a virtual local area network (VLAN) connection and a Border Gateway Protocol (BGP) session. To facilitate the BGP session, the bridge may be assigned an AS number (ASN) different than that of each of the AS instances and that is exchanged between the routers and the AS instances. Routing within the bridge may be facilitated by the exchange of interior gateway protocol (IGP) information between the virtual routers.


