Virtual Transport Interfaces for Multi-Tenant WAN Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to enforce per-tenant contract terms and restrictions on WAN connections between sites in multi-tenant networks, making it difficult to guarantee service level agreements and enforce bandwidth or routing restrictions for individual tenants.

Innovation Solution

Implementing a Software-Defined Networking (SDN) controller to virtualize tenant transport interfaces and enforce network routing attributes based on a defined tenant tier model, using pairwise key generation hierarchies to generate and manage unique interface mappings for each tenant, ensuring compliance with their specific network requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional shared WAN transport is used, then cost reduction and effective utilization are achieved, but per-tenant contract terms and restrictions cannot be enforced

Engineering Contradiction:
Improveeffective utilizationVSAvoidper-tenant contract enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared WAN transport into multiple virtual transport interfaces, each dedicated to a specific tenant. The network controller creates tenant-specific virtual interfaces that logically divide the shared physical transport, enabling per-tenant policy enforcement while maintaining shared infrastructure utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network controller acts as an intermediary between the shared WAN transport and individual tenants. It receives tenant identification from edge devices, determines appropriate virtual transport interfaces based on tenant policies, and enforces per-tenant contract terms by routing traffic through the correct virtual interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If per-tenant virtual transport interfaces are implemented, then service level agreements and restrictions are enforced, but system complexity increases

Engineering Contradiction:
Improveservice level agreement enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network controller centralizes the complexity of managing multiple virtual transport interfaces and per-tenant policies. Edge devices only need to send tenant identification information to the controller, which then handles the complex tasks of determining appropriate virtual interfaces and enforcing policies, keeping edge device complexity low.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes network parameters (virtual transport interface selection, routing attributes, bandwidth allocations) based on tenant identification. The network controller adjusts these parameters in real-time according to per-tenant policies without requiring complex local decision-making at edge devices.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple virtual transport interfaces are created for different tenants, then per-tenant routing attributes are differentiated, but resource allocation complexity increases

Engineering Contradiction:
Improveper-tenant routing differentiationVSAvoidresource allocation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network controller serves as the central authority for resource allocation across multiple virtual transport interfaces. It maintains tenant policy information and automatically determines the appropriate virtual interface for each tenant, eliminating the need for complex distributed resource allocation algorithms at edge devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring virtual transport interfaces and their associated routing attributes in the network controller based on tenant policies. This advance preparation allows for rapid, simple interface selection at runtime without complex real-time resource allocation decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250274304A1Sharing transport interfaces between tenants on multi-tenant edge devices
Publication Date: 2025.08.28 CISCO TECHNOLOGY INC
  • US20250274304A1 patent drawing
  • US20250274304A1 patent drawing
  • US20250274304A1 patent drawing

AI summary

Techniques for virtualizing tenant transport interfaces configured to implement per-tenant network routing attribute differentiation in each tenant overlay of a multisite wide area network (WAN) and share the virtual transport interfaces between multi-tenant edge (MTE) devices providing transport services to tenant devices based on a defined tenant tier model. A Software-Defined Networking (SDN) controller may receive a physical transport interface and/or a device type associated with a tenant device. The SDN controller may determine a virtual transport interface for the tenant device based on a tier associated with the tenant. MTE device(s) may utilize the physical transport interface to establish sessions with other MTE device(s) in the WAN. The virtual transport interface may be utilized by MTE devices to implement and/or enforce network routing attributes when forwarding network traffic associated with the tenant via the sessions established between the MTE devices through the WAN.