USRE50105E

Overlay management protocol for secure routing based on an overlay network

Claim Score by NHIP

Read claim 13, the broadest

Abstract

A method for creating a secure network is provided. The method comprises establishing an overlay domain to control routing between overlay edge routers based on an underlying transport network, wherein said establishing comprises running an overlay management protocol to exchange information within the overlay domain; in accordance with the overlay management protocol defining service routes that exist exclusively within the overlay domain wherein each overlay route includes information on at least service availability within the overlay domain; and selectively using the service routes to control routing between the overlay edge routers; wherein the said routing is through the underlying transport network in a manner in which said overlay routes is shared with the overlay edge routers but not with the underlying transport network via the overlay management protocol.

USRE50105E, drawing sheet 1
Sheet 1 of 10

Term

7.2 yearsleft in the term

Expires 18 December 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

44 claims: 6 independent, 38 dependent

  1. 1
    A method comprising:at an overlay network comprising an overlay controller and a plurality of overlay edge routers that are within control of an enterprise: provisioning the overlay controller and the plurality of overlay edge routers with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establishing a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establishing a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collecting, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information wherein the routing information is carried by an overlay management protocol;and transmitting, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  2. 7
    A non-transitory computer-readable medium having stored instructions which when executed by a system cause the system to:provision an overlay controller and a plurality of overlay edge routers that are within control of an enterprise with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establish a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establish a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collect, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information wherein the routing information is carried by an overlay management protocol;and transmit, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  3. 13
    Broadest claimClaim Score 31, narrow(NHIP)A controller, comprising:a processor;and a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to: provision an overlay controller and a plurality of overlay edge routers that are within control of an enterprise with transport parameters to allow respective connections to a public transport network that is not within control of the enterprise;establish a secure overlay control plane that includes a plurality of secure control channels between the overlay controller and respective overlay edge routers of the plurality of overlay edge routers;establish a secure overlay data plane that includes a plurality of secure tunnels between at least some of the plurality of overlay edge routers, wherein the plurality of secure tunnels go through the public transport network;collect, by the overlay controller, routing information comprising at least one of authentication information, service information, encryption information, policy information, and access control information;wherein the routing information is carried by an overlay management protocol;and transmit, by the overlay controller, the routing information to one or more of the plurality of overlay edge routers over the secure overlay control plane in order to mask the routing information from the public transport network.
  4. 18
    An overlay network system, comprising:a controller and a plurality of overlay network devices of an overlay network configured to use transport parameters to connect to an underlying transport network that is not within control of an enterprise network, the controller comprising: a processor;and a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to: create a secure overlay control plane by establishing secure control connections with the plurality of overlay network devices of the overlay network;transmit, over corresponding ones of the secure control connections, messages including overlay routing information to the plurality of overlay network devices thereby preventing exposure of the overlay routing information to the underlying transport network, wherein the transmitted overlay routing information includes one or more overlay routes that affects how each overlay network device of the plurality of overlay network devices forwards network traffic to other overlay network devices within the overlay network;and receive, over corresponding ones of the control connections, route information from one or more of the plurality of overlay network devices, the route information including network reachability information for endpoints available at a physical site associated with a corresponding overlay network device;wherein each of the plurality of overlay network devices is operative to: establish, over an underlying transport network, secure tunnels with one or more of the other overlay network devices, wherein the secure tunnels form a secure overlay data plane;collect route information including network reachability information for endpoints available at the physical site associated with the corresponding overlay network device;provide, using a corresponding one of the secure control connections to the controller, the collected route information;receive the overlay routing information transmitted by the controller over a corresponding one of the secure control connections;maintain in a memory the overlay routing information received from the controller, and forward, based on the overlay routing information maintained in the memory, network traffic to selected ones of the plurality of overlay network devices using corresponding ones of the secure tunnels.
  5. 26
    An overlay network device, comprising:a processor;a memory coupled to the processor, the memory storing instructions which when executed by the processor cause the overlay network device to: create a secure overlay control plane by establishing a secure control connection with a controller;receive, over the secure control connection thereby preventing exposure of overlay routing information to an underlying transport network, messages from the controller, the messages including the overlay routing information, wherein the overlay routing information includes one or more overlay routes that affects how the overlay network device forwards network traffic to other overlay network devices within an overlay network;establish, over an underlying transport network, secure tunnels with one or more other overlay network devices of the overlay network, wherein the secure tunnels form a secure overlay data plane;collect route information including network reachability information for endpoints available at a physical site associated with the overlay network device;distribute the collected route information to the controller over a corresponding secure control connection;and maintain in the memory the overlay routing information received from the controller;and a forwarding component operative to forward, based on the overlay routing information, network traffic to selected ones of the other overlay network devices using corresponding ones of the secure tunnels, wherein the overlay network device and the controller are configured to use transport parameters to connect to the underlying transport network that is not within control of an enterprise network.
  6. 36
    An overlay network controller, comprising:a processor;and a memory coupled to the processor, the memory storing instructions which when executed by the processor causes the controller to: create a secure overlay control plane by establishing secure control connections with a plurality of overlay network devices of an overlay network, and transmit, over corresponding ones of the secure control connections, messages including overlay routing information to the plurality of overlay network devices thereby preventing exposure of the overlay routing information to the underlying transport network, wherein the transmitted overlay routing information includes one or more overlay routes that affects how each overlay network device of the plurality of overlay network devices forwards network traffic to other overlay network devices within the overlay network;wherein each of the plurality of overlay network devices is operative to: establish, over an underlying transport network, secure tunnels with one or more of the other overlay network devices, wherein the secure tunnels form a secure overlay data plane;collect route information including network reachability information for endpoints available at a physical site associated with a corresponding overlay network device;distribute the collected route information to the controller over a corresponding secure control connection;maintain the overlay routing information received from the controller;and forward, based on the overlay routing information, network traffic to selected ones of the plurality of overlay network devices using corresponding ones of the secure tunnels, wherein the controller and the plurality of overlay network devices are configured to use transport parameters to connect to the underlying transport network that is not within control of an enterprise network.