Virtual Network Devices for Multi-AS Overlay Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices, such as edge routers, have a limited supply of sub-interfaces and bridge domains, making it costly and complex to manage multiple autonomous systems (AS) and their associated overlay networks, as additional hardware is required to isolate and scale these networks, increasing power consumption and maintenance needs.

Innovation Solution

Implementing virtualized network devices and services, including virtual routers and border gateway protocol (BGP) speakers, which are AS-aware, allowing for the management of multiple overlay networks over shared underlay networks without merging them, using virtual tunnel endpoints (VTEPs) and virtual infrastructure managers (VIMs) to isolate traffic and enforce policies, thereby avoiding the need for additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional hardware is added to isolate underlay networks, then network isolation and security are improved, but cost and device complexity increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of network functions through virtual network devices that can be instantiated multiple times to provide network isolation. Instead of adding physical hardware for each isolated network, virtual instances are created in software, allowing multiple autonomous systems to be isolated logically while sharing the same physical infrastructure. This resolves the contradiction by providing isolation without proportional increases in physical hardware complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transitions from physical hardware-based isolation to a virtual/software dimension for network isolation. By introducing virtual network devices and overlay networks, isolation is achieved in the virtualization layer rather than requiring separate physical hardware for each autonomous system. This dimensional shift allows multiple isolated networks to coexist on shared infrastructure without increasing physical device complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If edge routers are used to support routing within one autonomous system, then network security and isolation are improved, but scalability and adaptability worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidmulti-AS support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes network devices universal by enabling them to support multiple autonomous systems simultaneously through virtualization. Virtual network devices can be configured to handle routing for different ASes, and a single physical router can host multiple virtual instances, each managing a different autonomous system. This multi-functionality allows edge routers to maintain security isolation while gaining the adaptability to support multiple ASes, resolving the contradiction between security and versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments network device functions into virtual components that can be independently configured for different autonomous systems. By dividing the routing function into separate virtual network devices or virtual instances, each can maintain strict isolation for its assigned AS while the overall physical device supports multiple ASes. This functional segmentation resolves the contradiction by allowing security isolation at the virtual instance level while enabling multi-AS support at the physical device level.

Inventive Principle:
Principle #1Segmentation

3Productivity

If multiple overlay networks are run over shared underlay networks, then resource utilization is improved, but network complexity and difficulty of management increase

Engineering Contradiction:
Improveresource utilizationVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces virtual network devices as intermediary components between the overlay networks and the shared underlay network. These virtual devices provide a standardized interface that simplifies management by abstracting the complexity of multiple overlay networks. Instead of directly managing complex interactions between multiple overlays on shared infrastructure, administrators manage virtual network devices that handle the complexity internally, thus improving resource utilization while reducing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements partial virtualization where only the necessary network functions are virtualized to support multiple overlay networks, rather than fully virtualizing the entire infrastructure. This selective approach allows shared underlay networks to be utilized efficiently while keeping management complexity manageable by virtualizing only the components that need isolation and multi-tenant support, rather than over-virtualizing the entire system.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11469997B2Supporting overlay networks for multiple autonomous systems and underlays
Publication Date: 2022.10.11 CISCO TECHNOLOGY INC
  • US11469997B2 patent drawing
  • US11469997B2 patent drawing
  • US11469997B2 patent drawing

AI summary

A network management method includes a controller receiving an underlay network identifier and a network segment identifier. The underlay network identifier and network segment identifier can be associated with entries in a forwarding information base and border gateway protocol speakers may be deployed in association with the entries. A virtual network can be associated with the underlay network and network traffic can be forwarded to the virtual network according to the entries.