Multi-Domain VPN Orchestration via Label Stack Stitching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Network Management Systems (NMS) are limited to monitoring a single domain at a time, making it complex and time-consuming to manage Virtual Private Network (VPN) services that span across multiple domains, such as Service Provider Networks (SPN) and Data Centers (DCs), necessitating a solution for end-to-end monitoring and orchestration.
Innovation Solution
Implementing a system that uses gateway devices to stitch multiple domains together, enabling end-to-end VPN route computation by performing label stack stitching and route target stitching, and employing a closed-loop automation process for discovery, modeling, provisioning, and monitoring of VPN services across multiple domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single NMS monitors only one domain at a time, then the monitoring function is simple and reliable, but managing VPN services across multiple domains becomes complex and time-consuming
Solution Approach 1:
The patent merges multiple domain monitoring capabilities into a single NMS by implementing a unified monitoring framework that aggregates topology information, traffic data, and service status from multiple domains through standardized interfaces, enabling centralized end-to-end visibility without requiring separate monitoring systems for each domain
Solution Approach 2:
The patent introduces intermediary components such as domain agents and information exchange interfaces that mediate between individual domains and the central NMS, allowing the NMS to monitor multiple domains without direct complex interactions with each domain's internal systems, thus simplifying the monitoring architecture
2Reliability
If manual monitoring of multiple domains is performed, then individual domain monitoring remains simple, but the overall system complexity and administrative burden increase significantly
Solution Approach 1:
The patent segments the monitoring system into hierarchical layers: a central NMS for end-to-end service monitoring and domain-specific agents for local domain monitoring. Each layer handles specific monitoring tasks independently, maintaining simplicity at the domain level while achieving comprehensive multi-domain visibility through standardized information exchange interfaces
Solution Approach 2:
The patent implements universal monitoring interfaces and standardized data models that enable the NMS to monitor multiple different domain types (e.g., IPVPN, EVPN) through a single unified system, reducing administrative burden while maintaining reliable monitoring across diverse domain architectures
3Adaptability or versatility
If VPN services span multiple domains without unified orchestration, then each domain can be managed independently, but end-to-end service optimization and automated provisioning cannot be achieved
Solution Approach 1:
The patent implements preliminary action by having domain agents continuously discover and model domain topology, resources, and service status before end-to-end VPN provisioning is requested. This pre-established information model enables the NMS to rapidly compute optimal end-to-end routes and automatically provision services across multiple domains without manual intervention
Solution Approach 2:
The patent implements feedback mechanisms where domain agents continuously report service status, traffic metrics, and topology changes to the NMS, which uses this feedback to dynamically optimize end-to-end VPN routes and trigger automated re-provisioning when service constraints are violated, enabling closed-loop automation across multi-domain environments
Data Source
AI summary
Systems and methods are described herein for monitoring and orchestrating an autonomous system. A process, according to one implementation, includes a step of monitoring an autonomous system that spans across multiple domains. The process also includes obtaining one or more ingress endpoints associated with Virtual Private Network (VPN) traffic used for conducting one or more VPN services through the autonomous system. Also, the process includes the step of obtaining one or more egress endpoints associated with the VPN traffic, wherein the one or more ingress endpoints and the one or more egress endpoints are located in the multiple domains. The process further includes using the one or more ingress endpoints and the one or more egress endpoints to compute one or more end-to-end VPN traffic paths through the autonomous system.


