Virtual Transport Interfaces for Multi-Tenant WAN Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to enforce per-tenant contract terms and restrictions on WAN connections between sites in multi-tenant networks, making it difficult to guarantee service level agreements and enforce bandwidth or routing restrictions for individual tenants.
Innovation Solution
Implementing a Software-Defined Networking (SDN) controller to virtualize tenant transport interfaces and enforce network routing attributes based on a defined tenant tier model, using pairwise key generation hierarchies to generate and manage unique interface mappings for each tenant, ensuring compliance with their specific network requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional shared WAN transport is used, then cost reduction and effective utilization are achieved, but per-tenant contract terms and restrictions cannot be enforced
Solution Approach 1:
The patent segments the shared WAN transport into multiple virtual transport interfaces, each dedicated to a specific tenant. The network controller creates tenant-specific virtual interfaces that logically divide the shared physical transport, enabling per-tenant policy enforcement while maintaining shared infrastructure utilization.
Solution Approach 2:
The network controller acts as an intermediary between the shared WAN transport and individual tenants. It receives tenant identification from edge devices, determines appropriate virtual transport interfaces based on tenant policies, and enforces per-tenant contract terms by routing traffic through the correct virtual interface.
2Reliability
If per-tenant virtual transport interfaces are implemented, then service level agreements and restrictions are enforced, but system complexity increases
Solution Approach 1:
The network controller centralizes the complexity of managing multiple virtual transport interfaces and per-tenant policies. Edge devices only need to send tenant identification information to the controller, which then handles the complex tasks of determining appropriate virtual interfaces and enforcing policies, keeping edge device complexity low.
Solution Approach 2:
The system dynamically changes network parameters (virtual transport interface selection, routing attributes, bandwidth allocations) based on tenant identification. The network controller adjusts these parameters in real-time according to per-tenant policies without requiring complex local decision-making at edge devices.
3Adaptability or versatility
If multiple virtual transport interfaces are created for different tenants, then per-tenant routing attributes are differentiated, but resource allocation complexity increases
Solution Approach 1:
The network controller serves as the central authority for resource allocation across multiple virtual transport interfaces. It maintains tenant policy information and automatically determines the appropriate virtual interface for each tenant, eliminating the need for complex distributed resource allocation algorithms at edge devices.
Solution Approach 2:
The system performs preliminary actions by pre-configuring virtual transport interfaces and their associated routing attributes in the network controller based on tenant policies. This advance preparation allows for rapid, simple interface selection at runtime without complex real-time resource allocation decisions.
Data Source
AI summary
Techniques for virtualizing tenant transport interfaces configured to implement per-tenant network routing attribute differentiation in each tenant overlay of a multisite wide area network (WAN) and share the virtual transport interfaces between multi-tenant edge (MTE) devices providing transport services to tenant devices based on a defined tenant tier model. A Software-Defined Networking (SDN) controller may receive a physical transport interface and/or a device type associated with a tenant device. The SDN controller may determine a virtual transport interface for the tenant device based on a tier associated with the tenant. MTE device(s) may utilize the physical transport interface to establish sessions with other MTE device(s) in the WAN. The virtual transport interface may be utilized by MTE devices to implement and/or enforce network routing attributes when forwarding network traffic associated with the tenant via the sessions established between the MTE devices through the WAN.


