Multi-Domain VPN Orchestration via Label Stack Stitching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Network Management Systems (NMS) are limited to monitoring a single domain at a time, making it complex and time-consuming to manage Virtual Private Network (VPN) services that span across multiple domains, such as Service Provider Networks (SPN) and Data Centers (DCs), necessitating a solution for end-to-end monitoring and orchestration.

Innovation Solution

Implementing a system that uses gateway devices to stitch multiple domains together, enabling end-to-end VPN route computation by performing label stack stitching and route target stitching, and employing a closed-loop automation process for discovery, modeling, provisioning, and monitoring of VPN services across multiple domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single NMS monitors only one domain at a time, then the monitoring function is simple and reliable, but managing VPN services across multiple domains becomes complex and time-consuming

Engineering Contradiction:
ImproveEase of monitoring VPN servicesVSAvoidTime required to manually monitor multiple domains
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple domain monitoring capabilities into a single NMS by implementing a unified monitoring framework that aggregates topology information, traffic data, and service status from multiple domains through standardized interfaces, enabling centralized end-to-end visibility without requiring separate monitoring systems for each domain

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces intermediary components such as domain agents and information exchange interfaces that mediate between individual domains and the central NMS, allowing the NMS to monitor multiple domains without direct complex interactions with each domain's internal systems, thus simplifying the monitoring architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual monitoring of multiple domains is performed, then individual domain monitoring remains simple, but the overall system complexity and administrative burden increase significantly

Engineering Contradiction:
ImproveReliability of domain-specific monitoringVSAvoidComplexity of multi-domain management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into hierarchical layers: a central NMS for end-to-end service monitoring and domain-specific agents for local domain monitoring. Each layer handles specific monitoring tasks independently, maintaining simplicity at the domain level while achieving comprehensive multi-domain visibility through standardized information exchange interfaces

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universal monitoring interfaces and standardized data models that enable the NMS to monitor multiple different domain types (e.g., IPVPN, EVPN) through a single unified system, reducing administrative burden while maintaining reliable monitoring across diverse domain architectures

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If VPN services span multiple domains without unified orchestration, then each domain can be managed independently, but end-to-end service optimization and automated provisioning cannot be achieved

Engineering Contradiction:
ImproveFlexibility of domain-independent managementVSAvoidAutomation of end-to-end VPN provisioning
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The patent implements preliminary action by having domain agents continuously discover and model domain topology, resources, and service status before end-to-end VPN provisioning is requested. This pre-established information model enables the NMS to rapidly compute optimal end-to-end routes and automatically provision services across multiple domains without manual intervention

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where domain agents continuously report service status, traffic metrics, and topology changes to the NMS, which uses this feedback to dynamically optimize end-to-end VPN routes and trigger automated re-provisioning when service constraints are violated, enabling closed-loop automation across multi-domain environments

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12081431B1Monitoring and orchestrating stitched VPN services across multiple domains
Publication Date: 2024.09.03 CIENA CORP
  • US12081431B1 patent drawing
  • US12081431B1 patent drawing
  • US12081431B1 patent drawing

AI summary

Systems and methods are described herein for monitoring and orchestrating an autonomous system. A process, according to one implementation, includes a step of monitoring an autonomous system that spans across multiple domains. The process also includes obtaining one or more ingress endpoints associated with Virtual Private Network (VPN) traffic used for conducting one or more VPN services through the autonomous system. Also, the process includes the step of obtaining one or more egress endpoints associated with the VPN traffic, wherein the one or more ingress endpoints and the one or more egress endpoints are located in the multiple domains. The process further includes using the one or more ingress endpoints and the one or more egress endpoints to compute one or more end-to-end VPN traffic paths through the autonomous system.