USRE49485E

Overlay management protocol for secure routing based on an overlay network

Claim Score by NHIP

Read claim 13, the broadest

Abstract

A method for creating a secure network is provided. The method comprises establishing an overlay domain to control routing between overlay edge routers based on an underlying transport network, wherein said establishing comprises running an overlay management protocol to exchange information within the overlay domain; in accordance with the overlay management protocol defining service routes that exist exclusively within the overlay domain wherein each overlay route includes information on at least service availability within the overlay domain; and selectively using the service routes to control routing between the overlay edge routers; wherein the said routing is through the underlying transport network in a manner in which said overlay routes is shared with the overlay edge routers but not with the underlying transport network via the overlay management protocol.

USRE49485E, drawing sheet 1
Sheet 1 of 11

Term

7.2 yearsleft in the term

Expires 18 December 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

46 claims: 6 independent, 40 dependent

  1. 1
    A method comprising:at an overlay network comprising an overlay controller and a plurality of overlay edge routers that are within control of an enterprise: provisioning the overlay controller and the plurality of overlay edge routers with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establishing a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establishing a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collecting, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information wherein the routing information is carried by an overlay management protocol;and transmitting, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  2. 7
    A non-transitory computer-readable medium having stored instructions which when executed by a system cause the system to:provision an overlay controller and a plurality of overlay edge routers that are within control of an enterprise with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establish a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establish a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collect, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information wherein the routing information is carried by an overlay management protocol;and transmit, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  3. 13
    Broadest claimClaim Score 31, narrow(NHIP)A controller, comprising:a processor;and a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to: provision an overlay controller and a plurality of overlay edge routers that are within control of an enterprise with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establish a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establish a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collect, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information;wherein the routing information is carried by an overlay management protocol;and transmit, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  4. 18
    An overlay network system, comprising:a controller and a plurality of overlay network devices configured to use transport parameters to connect to an underlying transport network that is not within control of an enterprise network, the controller comprising: a processor;a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to: create a secure overlay control plane by establishing, over the underlying transport network, secure control connections with the plurality of overlay network devices, and transmit, over corresponding ones of the secure control connections, messages including overlay routing information to the overlay network devices thereby preventing exposure of the overlay routing information to the underlying transport network, wherein the transmitted overlay routing information includes policy data that affects how each overlay network device of the plurality of overlay network devices forwards network traffic to the other overlay network devices;each of the plurality of overlay network devices operative to: establish, over the underlying transport network, secure network layer tunnels with one or more of the other overlay network devices, wherein the secure network layer tunnels form a secure overlay data plane, collect route information including network reachability information for endpoints available at a physical site associated with the corresponding overlay network device, distribute the collected route information to the controller over a corresponding secure control connection, maintain the overlay routing information received from the controller, and forward, based on the overlay routing information, network traffic to selected ones of the overlay network devices using corresponding ones of the secure network layer tunnels.
  5. 27
    An overlay network device, comprising a processor; a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the overlay network device to:create a secure overlay control plane by establishing, over an underlying transport network, a secure control connection with a controller;and receive, over the secure control connection thereby preventing exposure of overlay routing information to the underlying transport network, messages from the controller, the messages including the overlay routing information, wherein the overlay routing information includes policy data for one or more overlay routes;establish, over the underlying transport network, secure network layer tunnels with one or more other overlay network devices of an overlay network, wherein the secure network layer tunnels form a secure overlay data plane, collect route information including network reachability information for endpoints available at a physical site associated with the overlay network device;distribute the collected route information to the controller over a corresponding secure control connection;and maintain in the memory the overlay routing information received from the controller, and a forwarding component operative to: forward, based on the overlay routing information and policy data, network traffic to selected ones of the overlay network devices using corresponding ones of the secure network layer tunnels, wherein the overlay network device and the controller are configured to use transport parameters to connect to the underlying transport network that is not within control of an enterprise network.
  6. 38
    An overlay network controller, comprising a processor; a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to:creating a secure overlay control plane by establishing, over an underlying transport network, secure control connections with a plurality of overlay network devices of an overlay network, and transmit, over corresponding ones of the secure control connections, messages including overlay routing information to the overlay network devices thereby preventing exposure of the overlay routing information to the underlying transport network, wherein the transmitted overlay routing information includes policy data that affects how each overlay network device of the plurality of overlay network devices forwards network traffic to the other overlay network devices within the overlay network;wherein the plurality of overlay network devices are each operative to: establish, over the underlying transport network, secure network layer tunnels with one or more of the other overlay network devices, wherein the secure network layer tunnels form a secure overlay data plane, collect route information including network reachability information for endpoints available at a physical site associated with the corresponding overlay network device;distribute the collected route information to the controller over a corresponding secure control connection, maintain the overlay routing information received from the controller, and forward, based on the overlay routing information, network traffic to selected ones of the overlay network devices using corresponding ones of the secure network layer tunnels, wherein the controller and the plurality of overlay network devices are configured to use transport parameters to connect to the underlying transport network that is not within control of an enterprise network.