EP4581897A1 - Split control plane for private mobile network - Google Patents
Split control plane for private mobile networkInfo
- Publication number
- EP4581897A1 EP4581897A1 EP23773052.8A EP23773052A EP4581897A1 EP 4581897 A1 EP4581897 A1 EP 4581897A1 EP 23773052 A EP23773052 A EP 23773052A EP 4581897 A1 EP4581897 A1 EP 4581897A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- wan
- pmn
- pop
- entity
- physical location
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/50—Network service management, e.g. ensuring proper service fulfilment according to agreements
- H04L41/5041—Network service management, e.g. ensuring proper service fulfilment according to agreements characterised by the time relationship between creation and deployment of a service
- H04L41/5054—Automatic deployment of services triggered by the service manager, e.g. service implementation by automatic configuration of network components
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/40—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/28—Routing or path finding of packets in data switching networks using route fault recovery
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/74—Address processing for routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0895—Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/24—Traffic characterised by specific attributes, e.g. priority or QoS
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/164—Implementing security features at a particular protocol layer at the network layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
- H04W24/02—Arrangements for optimising operational condition
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
- H04W76/12—Setup of transport tunnels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/04—Large scale networks; Deep hierarchical networks
- H04W84/042—Public Land Mobile systems, e.g. cellular systems
- H04W84/045—Public Land Mobile systems, e.g. cellular systems using private Base Stations, e.g. femto Base Stations, home Node B
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/005—Data network PoA devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W88/00—Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
- H04W88/16—Gateway arrangements
Definitions
- Wi-Fi and other access technologies are utilized for providing private mobile networks deployed as a service for enterprise customers.
- these access technologies do not suffice.
- a private mobile network based on cellular technology e.g., 4G, 5G, etc.
- Current approaches to such private mobile networks however have not been seamlessly integrated into proven enterprise cloud-native technologies such as Software Defined WAN (SD-WAN), Edge compute and Secure Services Edge (SSE).
- SD-WAN Software Defined WAN
- SE Edge compute
- SE Secure Services Edge
- novel modifications of the basic architectural approach can be used to cover use cases such as Fixed Wireless Access for rural areas where macro service providers to not operate.
- Some embodiments of the invention provide a method implementing a software-defined private mobile network (SD-PMN) for an entity (e.g., a corporation, an educational institution, etc.).
- SD-PMN software-defined private mobile network
- the method first deploys, at a physical location of the entity, a first set of control plane components for the SD-PMN, including a security gateway, a user-plane function (UPF), an AMF (access and mobility management function), and an SMF (session management function).
- UPF user-plane function
- AMF access and mobility management function
- SMF session management function
- the method deploys a second set of control plane components for the SD-PMN, the second set of control plane components comprising a subscriber database that stores data associated with users of the SD-PMN.
- the method uses an SD-WAN edge router located at the physical location of the entity and a SD-WAN gateway located at the SD-WAN PoP to establish a connection (e.g., via a set of physical network links) from the physical location of the entity to the SD-WAN PoP.
- the security gateway is configured to establish an IPsec (Internet protocol security) tunnel with each access point in a set of access points deployed in the physical location.
- the access points provide a connection between user devices operating in the physical location and the SD-PMN.
- the access points receive data message traffic from the user devices as radio waves and convert the radio waves to bits and bytes which are encapsulated and sent to the security gateway via the IPsec tunnels.
- the security gateway forwards the encapsulated traffic to the UPF, in some embodiments, which decapsulates the traffic and forwards the decapsulated traffic as IP (Internet protocol) traffic to the SD-WAN edge routers.
- IP Internet protocol
- the connection established by the SD-WAN edge router with the SD-WAN gateway at the SD-WAN PoP is a DMPO (dynamic multipath optimization) tunnel, according to some embodiments, that is established over a set of physical network links (e.g., MPLS, cable modem, 5G, etc.).
- the SD-WAN edge router is one of multiple SD-WAN edge routers at multiple physical locations (e.g., branch sites) of the entity
- the SD-WAN gateway is one of multiple SD-WAN gateways at multiple SD-WAN PoPs that each include an instance of the second set of control plane components.
- Each SD-WAN edge router at each physical location in some embodiments, is assigned at least a primary SD-WAN gateway associated with a first SD-
- the SD-PMN is centrally managed, in some embodiments, by a private mobile network orchestrator (PMNO).
- the PMNO receives (e.g., from a network administrator through a user interface (UI) provided by the PMNO) for each physical location in a set of physical locations spanned by the SD-PMN, a tracking area code (TAC) defined for the physical location, as well as a data network name (DNN) defined for each data network in a set of data networks within the SD-PMN. Each data network in the set of data networks span the set of physical locations, according to some embodiments.
- the PMNO After receiving the TACs and DNNs, stores the TACs and the DNNs in a core of the SD-PMN for use in managing data message traffic and user devices in the SD-PMN.
- Some embodiments of the invention also provide a method for deploying a private mobile network for an entity in particular geographic area. For each physical location in a set of physical locations within the particular geographic area (e.g., homes in a municipality), the method deploys an SD-WAN (software-defined wide area network) customer premise appliance, such as an SD- WAN edge router enabled with LTE, 4G, or 5G. The method establishes, via a RAN (radio access network), a set of connections between each SD-WAN customer premise appliance and at least one physical access point in a set of physical access points deployed in the particular geographic area.
- an SD-WAN software-defined wide area network
- Figure 3 conceptually illustrates a SD-PMN of some embodiments that includes multiple branch sites and multiple SD-WAN PoPs.
- Figure 4 conceptually illustrates an architecture diagram showing a data plane flow through an SD-PMN of some embodiments.
- Figure 6 conceptually illustrates a second example of an architecture diagram of a multitenant PMN of some embodiments.
- Figure 7 conceptually illustrates a process of some embodiments for establishing an SD- PMN such as the SD-PMN illustrated in the Figure 6.
- Figure 8 conceptually illustrates an architecture diagram in which a multi-tenant SD-PMN is implemented across customer premises of some embodiments that have a disaggregated RAN.
- Figure 9 conceptually illustrates a failover process performed by an SD-WAN edge router of some embodiments when connecting to an SD-WAN PoP.
- Figure 10 which conceptually illustrates a set of diagrams showing failover from a first PoP to a second PoP.
- Figure 11 conceptually illustrates a diagram of a SD-PMN having a centralized management plane, in some embodiments.
- Figure 12 conceptually illustrates a diagram of the 0AM architecture of some embodiments for a multi-tenant SD-PMN.
- Figure 13 conceptually illustrates an architecture diagram of a centrally managed SD-PMN of some embodiments.
- Figure 14 conceptually illustrates a process of some embodiments for centrally managing a SD-PMN.
- Figure 15 conceptually illustrates a process of some embodiments for implementing an SD-PMN as a fixed wireless network for a particular geographic location.
- Figure 17 conceptually illustrates a diagram of a joint orchestration platform of some embodiments that orchestrates applications end-to-end across an SD-PMN, SD-WAN, and edge compute stack.
- Figure 18 illustrates a joint orchestration platform diagram that includes a set of example intent-based APIs for orchestrating a video analytics application, in some embodiments, across an SD-PMN, SD-WAN, and edge compute stack.
- Figure 19 conceptually illustrates a computer system with which some embodiments of the invention are implemented.
- Some embodiments of the invention provide a method implementing a software-defined private mobile network (SD-PMN) for an entity (e.g., a corporation, an educational institution, etc.).
- SD-PMN software-defined private mobile network
- the method first deploys, at a physical location of the entity, a first set of control plane components for the SD-PMN, including a security gateway, a user-plane function (UPF), an AMF (access and mobility management function), and an SMF (session management function).
- UPF user-plane function
- AMF access and mobility management function
- SMF session management function
- the method deploys a second set of control plane components for the SD-PMN, the second set of control plane components comprising a subscriber database that stores data associated with users of the SD-PMN.
- the method uses an SD-WAN edge router located at the physical location of the entity and a SD-WAN gateway located at the SD-WAN PoP to establish a connection from the physical location of the entity to the SD- WAN PoP.
- the security gateway is configured to establish an IPsec (Internet protocol security) tunnel with each access point in a set of access points deployed in the physical location.
- the access points provide a connection between user devices operating in the physical location and the SD-PMN.
- the access points receive data message traffic from the user devices as radio waves and convert the radio waves to bits and bytes which are encapsulated and sent to the security gateway via the IPsec tunnels.
- the security gateway forwards the encapsulated traffic to the UPF, in some embodiments, which decapsulates the traffic and forwards the decapsulated traffic as IP (Internet protocol) traffic to the SD-WAN edge routers.
- IP Internet protocol
- the connection established by the SD-WAN edge router with the SD-WAN gateway at the SD-WAN PoP is a DMPO (dynamic multipath optimization) tunnel, according to some embodiments.
- the SD-WAN edge router is one of multiple SD-WAN edge routers at multiple physical locations (e.g., branch sites) of the entity
- the SD-WAN gateway is one of multiple SD-WAN gateways at multiple SD-WAN PoPs that each include an instance of
- Each SD-WAN edge router at each physical location is assigned at least a primary SD-WAN gateway associated with a first SD- WAN PoP and a secondary SD-WAN gateway associated with a second SD-WAN PoP for accessing both the internet and components of the SD-WAN PoPs.
- the SD-PMN is centrally managed, in some embodiments, by a private mobile network orchestrator (PMNO).
- the PMNO receives (e.g., from a network administrator through a user interface (UI) provided by the PMNO) for each physical location in a set of physical locations spanned by the SD-PMN, a tracking area code (TAC) defined for the physical location, as well as a data network name (DNN) defined for each data network in a set of data networks within the SD-PMN. Each data network in the set of data networks span the set of physical locations, according to some embodiments.
- the PMNO After receiving the TACs and DNNs, stores the TACs and the DNNs in a core of the SD-PMN for use in managing data message traffic and user devices in the SD-PMN.
- Some embodiments of the invention also provide a method for deploying a private mobile network for an entity in particular geographic area. For each physical location in a set of physical locations within the particular geographic area (e.g., homes in a municipality), the method deploys an SD-WAN (software-defined wide area network) customer premise appliance, such as an SD- WAN edge router enabled with LTE, 4G, or 5G. The method establishes, via a RAN (radio access network), a set of connections between each SD-WAN customer premise appliance and at least one physical access point in a set of physical access points deployed in the particular geographic area.
- an SD-WAN software-defined wide area network
- FIG. 1 conceptually illustrates a first example of an architecture diagram of a multitenant PMN of some embodiments.
- this architecture diagram 100 components of the control plane are split between locations on customer premises 101 and 102 and the SD-WAN PoP 105.
- each customer premises 101 and 102 includes a security gateway 124, a UPF 126, and an AMF/SMF 128, while the SD-WAN PoP 105 includes the multi-tenant 5G unified data management (UDM) for storing user data.
- UDM multi-tenant 5G unified data management
- the components illustrated in the architecture in Figure 1 are components associated with a 5G network, and other embodiments of the invention can include components associated with other network types, such as MMEs (mobility management entities) for 4G and LTE solutions.
- MMEs mobility management entities
- the UPFs 126 and 156 handle data plane traffic, according to some embodiments, while the AMFs/SMFs 128 and 158 are responsible for control plane traffic. Additional details regarding the UPFs, AMFs, and SMFs will be provided below by reference to Figures 4-5.
- the UPFs 126 and 156 and the AMFs/SMFs 128 and 158 forward the data message traffic to the SD-WAN edge routers 140 and 145.
- the SD-WAN edge routers 140 and 145 each connect to the SD-WAN gateway 110 to provide connections between the customer premises 101 and 102 and the SD- WAN PoP 105, as shown.
- the SD-WAN edge routers 140 and 145 of some embodiments establish DMPO tunnels to the SD-WAN gateway 110, as well as to other SD-WAN gateways (not shown), and, in some embodiments, with each other and other SD-WAN components (e.g., other SD-WAN edge routers at other physical locations of the entity, and SD-WAN hubs).
- each other and other SD-WAN components e.g., other SD-WAN edge routers at other physical locations of the entity, and SD-WAN hubs.
- the SD-WAN gateway 110 can identify real public IP addresses of WAN links in cases where a NAT (network address translation) or PAT (port address translation) device sits in front of the SD-WAN edge router, or where the WAN link is a private link, according to some embodiments.
- NAT network address translation
- PAT port address translation
- DMPO performs unidirectional performance metric measurements for metrics such as loss, latency, and jitter, for every data message on every DMPO tunnel between two DMPO endpoints (i.e., the SD-WAN edge routers 140-145 and the SD-WAN gateway 110).
- the DMPO tunnel header used to encapsulate each packet sent through the DMPO tunnel includes performance metrics such as loss, latency, and jitter.
- WO 10 as sequence number and timestamp to enable the DMPO endpoints to identify lost packets and out-of-order packets, as well as to compute jitter and latency bi-directionally.
- These performance metrics are communicated between the DMPO endpoints at an order of every 100ms, according to some embodiments, and when there is no active data message traffic being sent through the DMPO tunnels, the DMPO endpoints instead send active probes every 100ms, or every 500ms after a certain period (e.g., 5 minutes) of no high-priority data message traffic.
- DPMO is configured in some embodiments to take the CoS agreement into account for all traffic steering decisions (e.g., monitoring traffic, data plane application traffic, etc.).
- DMPO can also add Forward Error Correction (FEC) for certain classes of traffic, according to some embodiments.
- FEC Forward Error Correction
- the SD-WAN gateway 110 determines whether the data message traffic is application traffic or control plane traffic, and either forwards the data message traffic to the internet or to the UDM 112. In some embodiments, before forwarding internet traffic to the internet, the SD-WAN gateway 110 forwards the traffic to the SASE services 114 for processing.
- the SASE services 114 are provided by a third-party vendor and can include services such as firewall as a service, secure web gateway, zero-trust network access, and other threat detection services.
- FIG. 2 conceptually illustrates a process of some embodiments performed to implement an SD-PMN such as the SD-PMN described above for Figure 1.
- the process 200 starts when the process deploys (at 210) a security gateway, UPF, AMF, and SMF to each physical location in a set of physical locations across which the SD-PMN is being deployed.
- Each physical location of the entity also includes a SD-WAN edge router deployed to the physical location in order to provide a connection between the physical location and SD-WAN PoPs of the provider of the SD- PMN, as well as between the physical location and other physical locations and hub datacenters of the entity.
- the SD-WAN edge routers and SD-WAN gateways utilize SD- WAN services such as DMPO, in some embodiments, to optimize the data message traffic sent between SD-WAN devices implemented in the SD-PMN.
- SD-WAN edge routers and SD-WAN gateways utilize SD- WAN services such as DMPO, in some embodiments, to optimize the data message traffic sent between SD-WAN devices implemented in the SD
- the process 200 deploys (at 220) a subscriber database (i.e., UDM) that stores data associated with users of the PMN that belong to the particular entity for which the PMN is being deployed to each of a set of SD-WAN PoPs belonging to a provider of the PMN.
- a subscriber database i.e., UDM
- UDM subscriber database
- the UDM 112 is located in the PoP 105 while the security gateways 124 and 154, UPFs 126 and 156, and AMFs/SMFs 128 and 158 are located on the customer premises 101 and 102.
- the user data stored by the UDM includes customer profile information, customer authentication information, and, in some embodiments, a set of encryption keys for the information.
- the SD-WAN edge routers can connect to any SD-WAN gateway for any of the SD-WAN PoPs.
- FIG. 3 conceptually illustrates a SD-PMN 300 that includes multiple branch sites 310, 312, and 314 and multiple SD-WAN PoPs 320, 322, and 324.
- Each branch site 310-314 includes a respective SD-WAN edge router 330, 332, and 324 and set of machines 350, 352, and 354 (e.g., user devices and other network devices deployed to the branch sites), as shown.
- Each of the SD-WAN PoPs 320-324 includes a respective SD-WAN gateway 340, 342, and 344, and a set of resources 360, which are the same for each SD-WAN PoP.
- FIG. 4 conceptually illustrates an architecture diagram showing a data plane flow through an SD-PMN of some embodiments.
- the diagram 400 includes a customer premises 401 and an SD-WAN PoP 405.
- the customer premises 401 includes user devices 430, a local RAN 420 that includes at least one access node 422, a security gateway 424, a UPF 426, an AMF/SMF
- the SD-WAN PoP 405 includes an SD-WAN gateway 410, a multi-tenant 5G UDM 412, and SASE services 414.
- the data message traffic sent from these devices is transmitted via radio waves from the user devices 430 to the access nodes 422 that are part of the local RAN 420.
- the access node 422 processes the received data message traffic radio waves and converts the radio waves into bits and bytes, and encapsulates the data to be transmitted to the security gateway 424 via an IPsec tunnel established by the security gateway 424 between the access node 422 and security gateway 424.
- the security gateway 424 decapsulates the traffic and forwards the decapsulated traffic to the UPF 426.
- the decapsulated traffic is GTP traffic.
- the UPF 426 When the UPF 426 receives the GTP traffic from the security gateway 424, the UPF 426 then removes the GTP header from the data message traffic and sends the data message traffic out as IP traffic. In some embodiments, data messages having destinations within the customer premises 401 are sent directly from the UPF 426 to their intended destinations. In other embodiments, the UPF 426 sends the data message traffic to the SD-WAN edge router 440, which then forwards the data message traffic to, e.g., an on-premise destination 450.
- the user device When a new user device attempts to access the SD-PMN, the user device communicates via radio waves with the local RAN 820 and 850, which converts the radio waves to bits and bytes, encapsulates the bits and bytes, and transmits the encapsulated bits and bytes through a tunnel to the UPF 860 and 865.
- the UPF 860 and 865 then transmit the authentication request to the SD- WAN edge router 840 and 845 as IP traffic, and the SD-WAN edge router 840 and 845 uses the DMPO tunnel to the SD-WAN gateway 810 to forward the request to the SD-WAN PoP 805.
- the data plane components are located on customer premises, the control plane components are split between customer premises and the SD-WAN PoPs, and, as will be described below, the management plane components are centrally located in the cloud.
- the data plane components and control plane components are located on customer premises, and the management plane components are centrally located it the cloud (or multiple clouds such as in the case of multiple RAN vendors as will be described further below).
- the core network management plane components and the RAN management plane components of some embodiments are located in separate clouds that connect to a unified and centralized management system for the SD-PMN.
- WO 20 OAM server based on both the type of access point associated and the site at which that access point is deployed.
- the PMNO 1205 Based on the selected RAN vendor template(s), the PMNO 1205 associates the RAN 0AM server’s IP address with the customer and site, according to some embodiments. Once the associations have been made, any subsequent changes to the 5G core and/or RAN deployment from a user portal would trigger the PMNO 1205, in some embodiments, to invoke vendor-specific APIs against the 0AM server endpoints 1210a-1214b.
- the parameters assigned by the centralized management system include TACs for different customer premise locations, and DNNs for the different data networks operating in the SD-PMN.
- Figure 13 conceptually illustrates an architecture diagram of a centrally managed SD-PMN of some embodiments after TACs and DNNs have been assigned. As shown, the diagram 1300 includes multiple sites 1330, 1332, and 1334 each having a respective UPF 1340, 1342, and 1344 deployed for the site and at least one respective access point 1350, 1352, and 1354.
- multiple multi -tenant 5G control planes 1320, 1322, and 1324 are deployed to PoPs 1360, 1362, and 1364 throughout the SD-PMN and that connect to a single core 1310 that is centrally managed by a PMN orchestrator 1305.
- the single core 1310 is a master source for the control plane instances 1320-1324 and syncs with each control plane instance 1320-1324 as indicated.
- the diagram 1300 will be further described below by reference to Figure 14, which conceptually illustrates a process of some embodiments for centrally managing a SD-PMN.
- the process 1400 is performed in some embodiments by a centralized management server for the SD- PMN, such as the PMN orchestrator 1305 in the diagram 1300.
- the process 1400 starts when for each physical location spanned by the SD-PMN, the process receives (at 1410) a TAC defined for the physical location.
- the PMN orchestrator 1305 is a server that provides a user interface (UI) through which a user (e.g., network administrator) can provide input such as TACs defined for physical locations spanned by the SD-PMN.
- the UI includes multiple selectable UI items for providing the input and configuring other aspects of the SD-PMN through, e.g., drop down menus, radio buttons, selection boxes, text fields, etc.
- the UI includes a particular text field or set of text fields for defining TACs for each of the physical locations.
- the UI in some embodiments, requires the TACs to follow a particular format, such as by using hexadecimal values that is two octets in length.
- each of the sites 1330-1334 includes a unique TAC.
- the first site 1330 is assigned the TAC 315010: 10008, the second site 1332 is assigned the TAC
- Each TAC is an identifier of the physical location area within the SD-PMN and is unique across all of the physical locations.
- the TACs in some embodiments, are also associated with the access points 1350-1354 deployed in the respective physical locations such that the TACs can be used to identify a physical location and/or one or more access points in a physical location.
- the process 1400 receives (at 1420) a DNN defined for the data network.
- multiple VLANs virtual local area networks
- the UI provided by the management server of some embodiments includes multiple UI items for defining the DNNs in addition to the multiple UI items for defining the TACs as mentioned above.
- a portion of the DNN is determined by the type of data network being named (e.g., “VLAN”), and a text field is provided to enable the user to further define the DNN by, e.g., adding a number or series of numbers.
- VLAN type of data network
- an updated TAC or set of TACs is subsequently assigned to the user device based on the new location of the user device.
- a user device of some embodiments can join the SD-PMN while being primarily located at the first site 1330 in the diagram 1300, and later change its primary location to the last site 1334.
- the TAC associated with the user device would be updated from 315010: 10008 to 315010:10nnn in some such embodiments.
- the process 1400 ends.
- an SD-PMN may be implemented as a fixed wireless network for a particular geographic location.
- a rural area might require internet access, while managed service providers (e.g., internet service providers, mobile network service providers, etc.) decline to deploy service for that rural area due to factors such as cost to the service provider.
- Figure 15 conceptually illustrates a process of some embodiments for implementing an SD-PMN as a fixed wireless network for a particular geographic location. The process 1500 will be described below with references to Figure 16, which conceptually illustrates the architecture of a fixed wireless network of some embodiments.
- the process 1500 starts when for each physical location in a set of physical locations within the particular geographic area, the process deploys (at 1510) an SD-WAN customer premise appliance.
- SD-WAN edge routers 1610 are deployed to homes 1615 within a particular geographic area for which the SD-PMN is being implemented.
- the SD- WAN edge routers 1610 are enabled with LTE (long term evolution), 4G, or 5G SIM, according to some embodiments.
- LTE long term evolution
- 4G 4G
- 5G SIM 5G SIM
- the process 1500 establishes (at 1520), via a RAN, a set of connections between each SD-WAN customer premise appliance and at least one physical access point deployed to the particular geographic area.
- Each of the SD-WAN edge routers 1610 at the home premises 1615 has a connection to the network of towers 1620 in the diagram 1600, as shown.
- the connections between the SD-WAN edge routers 1610 and the towers (i.e., access points) 1620 are LTE, 4G, or 5G connections via CBRS (citizens broadband radio service), in some embodiments.
- the SD-WAN edge routers deployed to home premises are provided by the service provider of the SD-PMN and act
- WO 24 as general residential broadband customer premise equipment (CPEs), while the access points (i.e. base stations, antennas, towers, etc.) deployed to the geographic area are provided by a third-party network equipment vendor and paid for by the entity for which the SD-PMN is being implemented.
- CPEs general residential broadband customer premise equipment
- the access points i.e. base stations, antennas, towers, etc.
- Examples of such entities can include corporations, educational campuses, and municipalities (e.g., towns, cities, etc.), according to some embodiments.
- the process 1500 connects (at 1530) each physical access point deployed to the particular geographic area to a central aggregation point to enable internet access for the particular geographic area.
- the network of towers 1620 connects to the UPF 1630 that is part of the edge compute stack 1625.
- the access points in the network of towers 1620 in some embodiments, aggregate layer 2 (L2) traffic that terminates at the distributed UPF 1630. From the UPF 1630, the traffic goes through an aggregator SD-WAN edge router 1635 toward the SD-WAN gateway 1650 at the SASE PoP 1640, which also includes a 5G core 1655.
- the SASE PoP 1640 provides optimized internet connectivity, according to some embodiments.
- the process 1500 uses (at 1540) the established set of connections to provide SD-PMN service to the particular geographic area. That is, once the connections have been established, user devices at the home premises 1615 can access the internet 1660 through the series of connections that start from the SD-WAN edge routers 1610. The SD-PMN is controlled and managed as described in the embodiments above. Following 1540, the process 1500 ends.
- the fixed wireless solution described above differs from the architectures described by other embodiments of the invention in that the fixed wireless network 1600 uses an SD-WAN edge router as customer premise equipment to connect to the network, thus creating two layers of SD- WAN.
- the first layer provides the connection (e.g., a VCMP (VeloCloud multipath) tunnel) between the SD-WAN edge routers 1610 at the home premises 1615 (or other premises types for other entities) and the SD-WAN gateway 1650 at the SD-WAN/SASE PoP 1640 of the SD-PMN provider
- the second layer provides the connection between the SD-WAN edge router 1635 that is part of the edge compute stack 1625 and the SD-WAN gateway 1650 at the SD-WAN/SASE PoP 1640 of the SD-PMN provider.
- the SD-WAN edge router 1635 that is part of the edge compute stack 1625 does not utilize double tunneling and instead uses the first tunnel established by the SD-WAN edge routers 1610 on the underlay, while still protecting against failures on multiple WAN links and providing optimized fixed wireless access for WAN users.
- the tunnel established from the SD-WAN edge routers 1610 to the SD-WAN gateway 1650 is optimized, in some embodiments, using DMPO, like in the other embodiments described above.
- the SD-WAN edge router 1635 only sends traffic for which DMPO or any other optimization is desired to the SD-WAN gateway 1650, and sends any other traffic to its destination without going through the SD-WAN gateway 1650, while in other embodiments, all traffic is sent to its destination through the SD-WAN gateway 1650.
- sending all traffic through the SD-WAN gateway 1650 is desirable based on the 5G core 1655 for the SD-PMN also being located in the PoP 1640.
- Some embodiments of the invention implement joint orchestration across an SD-PMN, SD-WAN, and edge compute stacks to enable customers to describe desired edge applications to be deployed alongside connectivity and QoS requirements, and to use the provided descriptions to orchestrate the edge application, connectivity, and QoS requirements across the SD-PMN, SD- WAN, and edge compute stack to yield the desired end-to-end connectivity and QoS for the desired edge application and any devices accessing the desired edge application.
- Figure 17 conceptually illustrates a diagram of a joint orchestration platform of some embodiments that orchestrates applications end-to-end across an SD-PMN, SD-WAN, and edge compute stack.
- the joint orchestration platform diagram 1700 includes a PMN orchestrator (PMNO) 1705, an edge compute stack (ECS) management system 1710, aRAN/Core management system 1720, an SD-WAN management plane 1730, and a SASE management plane 1740.
- PMNO PMN orchestrator
- ECS edge compute stack
- RAN/Core management system 1720 a Radio Access Network
- SD-WAN management plane 1730 an SD-WAN management plane 1730
- SASE management plane 1740 examples of an ECS management system, in some embodiments, include VMware Telco Cloud Automation (TCA) and VMware Tanzu Kubernetes Grid (TKG).
- TCA VMware Telco Cloud Automation
- TKG VMware Tanzu Kubernetes Grid
- VCO VeloCloud Orchestrator
- the PMNO 1705 has northbound intent-based APIs 1750 (application programming interfaces) to collect edge application connectivity requirements.
- the northbound APIs 1750 can include edge application connectivity requirements such as edge application workload compute, storage, and networking requirements; device groups that need connectivity to the application and at what QoS level; and any QoS requirements needed between the edge application and the cloud.
- the northbound intent-based APIs 1750 are defined by a user (e.g., network administrator) that manages the joint orchestration platform 1700, according to some embodiments.
- the PMNO 1705 takes these requirements and uses southbound APIs in some embodiments to deploy the workload on the ECS, make a subscriber group for devices that need connectivity to the edge application and configure appropriate data networking for that subscriber group (e.g., VLAN, QoS, etc.), and program business policies in the orchestrator (e.g., management server) for the SD-WAN.
- the intent-based API 1752 is sent to the ECS management system 1710
- the intent-based API 1754 is sent to the RAN/Core management system 1720
- the intent-based API 1756 is sent to the SD-WAN management plane 1730
- the intent-based API 1758 is sent to the SASE management plane 1740.
- end-to-end SLAs service-level agreements
- WO 27 definitions regarding URL filtering are directed to the SASE management plane, according to some embodiments.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (14)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US202263402057P | 2022-08-29 | 2022-08-29 | |
| US18/071,549 US11943101B2 (en) | 2022-08-29 | 2022-11-29 | Joint orchestration for private mobile network |
| US18/071,543 US12395843B2 (en) | 2022-08-29 | 2022-11-29 | SASE services for private mobile network |
| US18/071,542 US12549948B2 (en) | 2022-08-29 | 2022-11-29 | Multipath link optimization for private mobile network |
| US18/071,536 US20240073973A1 (en) | 2022-08-29 | 2022-11-29 | Split control plane for private mobile network |
| US18/071,554 US20240073692A1 (en) | 2022-08-29 | 2022-11-29 | Authentication and authorization in a private mobile network |
| US18/071,540 US12356191B2 (en) | 2022-08-29 | 2022-11-29 | Split control plane for private mobile network |
| US18/071,537 US20240073137A1 (en) | 2022-08-29 | 2022-11-29 | Split control plane for private mobile network |
| US18/071,547 US20240073126A1 (en) | 2022-08-29 | 2022-11-29 | Seamless failover for private mobile networks |
| US18/071,545 US20240073767A1 (en) | 2022-08-29 | 2022-11-29 | Seamless failover for private mobile networks |
| US18/071,552 US20240073700A1 (en) | 2022-08-29 | 2022-11-29 | Fixed wireless private mobile network |
| US18/071,553 US12452671B2 (en) | 2022-08-29 | 2022-11-29 | Split control plane for private mobile network |
| US18/071,544 US12587855B2 (en) | 2022-08-29 | 2022-11-29 | Unified cloud management for private mobile network |
| PCT/US2023/031449 WO2024049853A1 (en) | 2022-08-29 | 2023-08-29 | Split control plane for private mobile network |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4581897A1 true EP4581897A1 (en) | 2025-07-09 |
Family
ID=96014168
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23773052.8A Pending EP4581897A1 (en) | 2022-08-29 | 2023-08-29 | Split control plane for private mobile network |
Country Status (1)
| Country | Link |
|---|---|
| EP (1) | EP4581897A1 (en) |
-
2023
- 2023-08-29 EP EP23773052.8A patent/EP4581897A1/en active Pending
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12549948B2 (en) | Multipath link optimization for private mobile network | |
| US12199865B2 (en) | System, apparatus and method for providing a virtual network edge and overlay with virtual control plane | |
| US11777783B2 (en) | Network slicing with smart contracts | |
| US10454812B2 (en) | Service level agreement based next-hop selection | |
| EP2367320B1 (en) | Communicating Network Path and Status Information in Multi-Homed Networks | |
| KR101900536B1 (en) | Implementing a 3g packet core in a cloud computer with openflow data and control planes | |
| US20190036813A1 (en) | Service level agreement based next-hop selection | |
| EP3732833B1 (en) | Enabling broadband roaming services | |
| US20140351812A1 (en) | Recording medium, management device, and network system | |
| EP3675431A1 (en) | Core isolation for logical tunnels stitching multi-homed evpn and l2 circuit | |
| US20230254244A1 (en) | Path determining method and apparatus, and computer storage medium | |
| CN111245715A (en) | Message transmission method and system | |
| US20240414086A1 (en) | Dynamically associating mobile devices with different software-defined wide area networks implemented for different user groups of a single shared network fabric of a single entity | |
| US20240414520A1 (en) | Dynamically associating mobile devices with different logical networks implemented on a shared network fabric of a single entity | |
| EP4581897A1 (en) | Split control plane for private mobile network | |
| WO2024049853A1 (en) | Split control plane for private mobile network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250327 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: VELOCLOUD NETWORKS, LLC |