WO2020198306A1 - System and method for virtual private network connectivity - Google Patents
System and method for virtual private network connectivity Download PDFInfo
- Publication number
- WO2020198306A1 WO2020198306A1 PCT/US2020/024623 US2020024623W WO2020198306A1 WO 2020198306 A1 WO2020198306 A1 WO 2020198306A1 US 2020024623 W US2020024623 W US 2020024623W WO 2020198306 A1 WO2020198306 A1 WO 2020198306A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network
- bandwidth
- request
- bandwidth allocation
- change
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0806—Configuration setting for initial configuration or provisioning, e.g. plug-and-play
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0896—Bandwidth or capacity management, i.e. automatically increasing or decreasing capacities
- H04L41/0897—Bandwidth or capacity management, i.e. automatically increasing or decreasing capacities by horizontal or vertical scaling of resources, or by migrating entities, e.g. virtual resources or entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/70—Admission control; Resource allocation
- H04L47/74—Admission control; Resource allocation measures in reaction to resource unavailability
- H04L47/748—Negotiation of resources, e.g. modification of a request
Definitions
- the present disclosure relates to a system, method and computer program for developing virtual private network connectivity between client devices in a network system, including controlling bandwidth allocation for one or more connectivity links in a virtual private network.
- the Internet is a worldwide network of interconnected computer networks that use the Transmission Control Protocol/Internet Protocol (TCP/IP) to link communicating devices worldwide.
- TCP/IP Transmission Control Protocol/Internet Protocol
- the Internet includes private, public, academic, business, and government networks, all of which are interlinked by arrays of electronic, wireless, wired, and optical networking technologies.
- the Internet carries a broad range of information resources and services, including the World Wide Web (WWW), electronic mail, telephony, and file sharing.
- WWW World Wide Web
- VPNs virtual private networks
- a VPN can extend a private network across a public network such as the Internet and provide secure communication between communicating devices by establishing a secure point-to-point connection between the devices.
- VPNs typically implement tunneling and encryption technologies to prevent unauthorized access to the data carried between the communicating devices.
- IP-based technologies such as MPLS
- MPLS have become benchmarks for VPN technology solutions, providing secure data transmission over public networks at significant cost-reduction and increased bandwidth.
- implementation of these IP-based technologies has resulted in network systems that are inflexible and inefficient when developing virtual private network connectivity.
- the disclosure provides an IP-based technology solution, including a method, a system, and a computer program therefor, that provides flexible and efficient virtual private network connectivity in a network.
- a method is provided for provisioning a network connectivity link to a node in a virtual private network.
- the method comprises: receiving a connectivity link change request that includes a request to change a bandwidth allocation for the network connectivity link; retrieving network connectivity information that includes an aggregate bandwidth value for the virtual private network and bandwidth values for all network connectivity links in the virtual private network, including a current bandwidth value for said network connectivity link; applying the request to change the bandwidth allocation to the current bandwidth value and changing the bandwidth allocation for said connectivity link to an updated bandwidth allocation; evaluating the bandwidth values for all network connectivity links in the virtual private network, including the updated bandwidth allocation, to determine a sum of band widths; comparing the sum of bandwidths to the aggregate bandwidth value; determining whether the sum of bandwidths exceeds the aggregate bandwidth value; and configuring a router with the updated bandwidth allocation to effectuate the updated bandwidth allocation in said network connectivity link.
- the configuring the router with the updated bandwidth allocation can occur when the sum of bandwidths is equal to, or less than the aggregate bandwidth value.
- the connectivity link change request can be received from a network router located in the node.
- the connectivity link change request can be received from a server in the node.
- the method can further comprise sending a notification to the node, wherein the notification includes a confirmation that the request to change the bandwidth allocation for said network connectivity link is effectuated.
- the notification can include a router configuration that effectuates the request to change the bandwidth allocation.
- the method can further comprise updating VPN network connectivity bundle information in a database, the updating being based on the request to change the bandwidth allocation.
- a system for provisioning a network connectivity link to a node in a virtual private network.
- the system comprises: a database that stores network connectivity information for the virtual private network; and a controller that: receives a connectivity link change request that includes a request to change a bandwidth allocation for said network connectivity link; retrieves an aggregate bandwidth value for the virtual private network and bandwidth values for all network connectivity links in the virtual private network from the database, including a current bandwidth value for said network connectivity link; applies the request to change the bandwidth allocation to the current bandwidth value and changes the bandwidth allocation for said connectivity link to an updated bandwidth allocation; evaluates the bandwidth values for all network connectivity links in the virtual private network, including the updated bandwidth allocation, to determine a sum of bandwidths; compares the sum of bandwidths to the aggregate bandwidth value; determines whether the sum of bandwidths exceeds the aggregate bandwidth value; and sends via a network interface a router configuration with the updated bandwidth allocation to effectuate the updated bandwidth allocation in said network connectivity link.
- the controller can generate the router configuration when the sum of bandwidths is equal to, or less than the aggregate bandwidth value.
- the connectivity link change request can be received from a network router located in the node.
- the connectivity link change request can be received from a server in the node.
- the controller can send a notification to the node that includes a confirmation that the request to change the bandwidth allocation for said network connectivity link is effectuated.
- the notification can include a router configuration that effectuates the request to change the bandwidth allocation.
- the network connectivity information in the database can comprise VPN network connectivity bundle information that is updated based on the request to change the bandwidth allocation.
- a non-transitory computer readable storage medium stores network connectivity link provisioning program instructions for causing a network connectivity link to be provisioned to a node in a virtual private network.
- the program instructions comprise the steps of: receiving a connectivity link change request that includes a request to change a bandwidth allocation for the network connectivity link; retrieving network connectivity information that includes an aggregate bandwidth value for the virtual private network and bandwidth values for all network connectivity links in the virtual private network, including a current bandwidth value for said network connectivity link; applying the request to change the bandwidth allocation to the current bandwidth value and changing the bandwidth allocation for said connectivity link to an updated bandwidth allocation; evaluating the bandwidth values for all network connectivity links in the virtual private network, including the updated bandwidth allocation, to determine a sum of bandwidths; comparing the sum of bandwidths to the aggregate bandwidth value; determining whether the sum of bandwidths exceeds the aggregate bandwidth value; and configuring a router with the updated bandwidth allocation to effectuate the updated bandwidth allocation in said network connectivity link.
- the program instructions can comprise an additional step of sending a notification to the node, wherein the notification includes a confirmation that the request to change the bandwidth allocation for said network connectivity link is effectuated.
- the program instructions can comprise an additional step of updating VPN network connectivity bundle information in a database, the updating being based on the request to change the bandwidth allocation.
- FIG. 1 shows an example of an Internet Protocol virtual private network system.
- FIG. 2 shows an example of a network system that is constructed according to the principles of the disclosure.
- FIG. 3 shows a representation of the seven-layer OSI model.
- FIG. 4 shows an example of a virtual private network bandwidth manager that can be included in a server in the network system shown in FIG. 2.
- FIG. 5 shows an example of a master node bandwidth manager that can be included in a controller in the network system shown in FIG. 2.
- FIG. 6 shows an example of a virtual private network provisioning process, according to the principles of the disclosure.
- FIG. 7 shows an example of a virtual private network updating process, according to the principles of the disclosure.
- FIGS. 8 A and 8B show an example of displays that can be rendered by a graphic user interface (GUI), according to the principles of the disclosure.
- GUI graphic user interface
- FIG. 1 shows an example of an Internet Protocol (IP) virtual private network (VPN) system.
- IP Internet Protocol
- VPN virtual private network
- the IP VPN system includes a headquarters building 1, a plurality of routers 2, a public network 3, and a plurality of remotely located branch buildings 4 (including buildings 4-1, 4-2, 4-3, 4-4, 4-5).
- the headquarters building 1 and branch buildings 4 can each include one or more private networks.
- the IP VPN system facilitates secure connectivity between the headquarters building 1 and the plurality of branch buildings 4 via the plurality of routers 2 over a plurality of connectivity links 6 and 9 (including connectivity links 9-1, 9-2, 9-3, 9-4, 9- 5).
- the IP VPN system (shown in FIG. 1) can be facilitated by a service provider (not shown).
- the service provider can assign the headquarters building 1 a bandwidth of 10 Mbps (or megabytes-per-second) for the connectivity link 6 and an aggregate bandwidth of 10 Mbps for all of the branch connectivity links 9, with a bandwidth of 2 Mbps for each of connectivity links 9-1 and 9-3, a bandwidth of 4 Mbps for connectivity link 9-2, and a bandwidth of 1 Mbps for each connectivity links 9-4 and 9-5.
- an enterprise network system acquires individual IP VPN connectivity links with specific bandwidth allocations for each connectivity link from the service provider.
- the service provider sets the acquired bandwidth allocations for each connectivity link and stores the settings.
- the bandwidth allocations can be memorialized in a contract between the enterprise network (e.g., headquarters building 1) and the service provider (not shown), and monthly subscriptions can be paid to the service provider pursuant to the contracts for each connectivity link.
- the IP VPN system has significant disadvantages, including a requirement that the enterprise network communicate repeatedly with the service provider over protracted periods of time for each change in bandwidth allocation for a connectivity link.
- the enterprise network must communicate with the service provider to modify the bandwidth allocations, which can require negotiation of new contracts for each modified connectivity link. Then, based on the terms of each contract, the service provider must update its billing system, perform configuration changes to the connectivity links, and communicate with the enterprise network when the connectivity link changes have been implemented, so that the enterprise network can perform required changes on its network routers.
- a request must be communicated to the service provider to accommodate the required upgrade or downgrade in bandwidth; a new contract must be negotiated and executed with the service provider, including new contract terms and conditions; the service provider must perform a new design package with the requested bandwidth change once the contract is approved and accepted; the service provider must communicate the bandwidth change to the service provider’s internal finance system to effectuate the change, including updating bill information for the connectivity link(s); the services provider must perform the configuration changes on connectivity links by sending a configuration request to commission a technical team; the service provider must provide information about the change in bandwidth allocation for the connectivity link and confirmation that the change has been implemented; and the change must be carried out at the enterprise network router.
- the foregoing process must be carried out separately each time a bandwidth allocation change is to be made for a connectivity link, and for each connectivity link in a network system that might be affected by such bandwidth allocation change.
- the IP VPN system is very inefficient in large scale network systems that can involve changes to numerous connectivity links, which require numerous reconfigurations, amendments to each existing contract associated with a respective connectivity link, including negotiations for each connectivity link between the enterprise network and the service provider.
- the billing process must be adjusted each time any changes are made to subscription payment details (such as, for example, payment amount, payment date, or billing contact). Both contract and payment changes are limited and restricted to the terms and conditions in the contracts between enterprise network and service provider. Resultantly, any changes to bandwidth allocations are very expensive, time consuming, and challenging to implement, including implementations that need to be made in existing bill tracking systems.
- FIG. 2 shows an example of a network system 100 that is constructed according to the principles of the disclosure.
- the network system 100 includes a master node 10, a plurality of routers 30-0 to 30 -N, a controller 30, and a plurality branch nodes 40-1 to 40 -N ( N is a positive integer greater than 1), any one or more of which can be connected in or to a network 50 over communication links 5.
- each of the branch nodes 40-1 to 40 -N can be connected to the node 10 through a single virtual private network (VPN), thereby providing flexible and continuous data traffic exchange between the nodes, regardless of geographic location of the nodes.
- VPN virtual private network
- the network 50 can include a network provisioned by a service provider, such as, for example, an Internet service provider (ISP).
- ISP Internet service provider
- One or more of the routers 30-1 to 30-/V can be provisioned by the service provider.
- the network 50 can include a private or a public network.
- the network system 100 can include a database 60, which can be connected to the controller 30 via a communication link 5 or included in the controller 30.
- the node 10 includes a communicating device (not shown) or a network of communicating devices, such as, for example, a private enterprise network in the headquarters building 1 (shown in FIG. 1).
- the node 10 can include a server 15, or the server 15 can be located external to the node 10 and connected to the node 10 via a communication link.
- the node 10 can include a router 20-0.
- the server 15 comprises a virtual private network (VPN) bandwidth manager 200 (shown in FIG. 4).
- the VPN bandwidth manager 200 can adjust and control bandwidth restrictions on one or more connectivity links provisioned by service provider network equipment, including, for example, the routers 30-0 to 30 -N.
- the connectivity link(s) can be provisioned at the physical layer (for example, layer 7 of the OSI model, shown in FIG. 3) or the data link layer (for example., OSI layer 6, shown in FIG. 3).
- the connectivity link(s) can include leased lines, provisioned by the service provider.
- the VPN bandwidth manager 200 can adjust and control bandwidth restrictions such that the sum of all bandwidths on all connectivity links to the node 10 and the branch nodes 40 equals a constant aggregate bandwidth value BTOTAL.
- the connectivity links can carry all kinds of data traffic, including, for example, IP traffic, Voice over IP (VoIP), OSI-layer 7 traffic, or OSI-layer 6 traffic.
- the connectivity links can be implemented to consolidate ATM, Frame Relay, Voice, and IP networks into one unified network infrastructure that includes the node 10 and all of the branch nodes 40.
- Each router 20-0 to 20 -N or 30-0 to 30 -N can include an edge router, a subscriber edge router, an inter-provider border router, a core router, a label switch router (LSR), a switch, a gateway server, an access server, or any combination of the foregoing.
- the router 20-0 can be included in the node 10 and linked to the router 30-0, which can be provided by the service provider.
- the routers 30-1 to 30 -N can be provided by the service provider.
- one or more of the routers 20-1 to 20 -N can be included in one or more of the branch nodes 40-1 to 40 -N, respectively.
- the router 20-0 can operate as a proxy for instruction and data signals between the server 15 and routers 20-1 to 20 -N.
- the routers 20-0 ... 20 -V, 30-0 ... 30 -V can create pathways for data traffic between the node 10 and branch nodes 40, directly across physical links or virtual circuits provisioned by the service provider, thereby providing a VPN.
- One or more of the routers 20-0 to 20-V can be configured and controlled by the server 15.
- the routers 20-0 to 20 -V can be configured to initiate communication and facilitate transmission of data packets to/from the controller 30.
- Any one of the routers 20-0 to 20-V (or any of routers 30-0 to 30-V) can atomically send a request signal to the controller 30 to request a change to the bandwidth allocated for a connectivity link, including, for example, a request to increase or decrease a bandwidth allocation for the connectivity link.
- One or more of the routers 30-1 to 30-V can be configured by the controller 30.
- Each of the routers 20-0 to 20-V, 30-0 to 30-V can include, for example, a routing table, a routing daemon, a signaling daemon, a routing policy, a packet scheduler, a packet classifier, or a programmable interface. Each router can be reconfigurable.
- the routers 20-0 to 20-V, 30-0 to 30-V can receive and forward data packets between nodes in the network system 100.
- the data packets can include encrypted data.
- the controller 30 can include a server (not shown), a router (not shown), and a switch (not shown).
- the controller 30 can be located in a service provider (SP) network 70, or external to the service provider network 70 and connected to the service provider network 70 via a communication link. Although shown as a separate entity, the service provider network 70 can be part of, or include the network 50.
- the SP network 70 can include the database 60, which can be connected to the controller 30 via a communication link, or the database 60 can be included in the controller 30.
- the controller 30 can include a master node (MN) bandwidth manager 300 (shown in FIG. 5). The MN bandwidth manager 300 can communicate with the node 10.
- the controller 30 can communicate with each of the routers 30-0 to 30-V.
- the controller 30 can include a network router interface (not shown) that can communicate with each of the routers 20-0 to 20-V (and routers 30-0 to 30-V).
- the controller 30 can automate operations for the routers 20-0 to 20-V (and 30-0 to 30-V). For instance, any one or more of the routers 20-0 to 20-V can communicate with the controller 30 and atomically request a change to the bandwidth allocated for a connectivity link to the particular router(s), including requested bandwidth upgrades or downgrades, which can be based on usage of the connectivity link.
- a request can be generated by the associated router(s) and atomically communicated to the controller 30 to request an increase in the bandwidth allocation for the connectivity link consistent with the increased bandwidth demand.
- the request can be processed within the controller 30, which can assess the requested bandwidth change (for example, upgrade or downgrade), calculate the sum of bandwidth allocations (with the requested change) for all connectivity links provisioned in the VPN (for example, by the controller 30), and, based on a comparison of the calculated sum of bandwidths to the aggregate bandwidth allocated to the VPN, either approve the request and send the new configuration(s) to the appropriate one or more of the routers 30-0 to 30 -N, or reject the request.
- one or more of the routers 20-0 to 20- N can communicate with, for example, an application program interface (API) in the server 15 (for example, an API unit 260 in the VPN bandwidth manager 200, shown in FIG. 4) or in the controller 30 (for example, the API unit 260 in the MN bandwidth manager 300, shown in FIG. 5).
- the API can include an XML API, such as, for example, an API compatible with Extensible Markup Language (XML) processing.
- the XML API can support available transport layers such as terminal-based protocols, including, for example, Telnet, Secure Shell (SSH), dedicated-TCP connection, or Secure Sockets Layer (SSL) dedicated TCP connection.
- the API can configure one or more of the routers 20-0 to 20 -N, or request information about configuration, management or operation of the router(s).
- the API can facilitate building a custom end-user interface for configuration and information retrieval and display.
- the API can provide an interface to a router 20 -N that can be used to develop client applications and scripts (for example, a Perl script) to manage or monitor the router 20 -N.
- the interface can include an XML interface that can be specified by XML schemas.
- the API can exchange formatted request or response streams for configuring or monitoring the router 20 -N.
- the router 20 -N can process a request and send the request to the controller 30.
- the controller can comprise a secure router.
- the controller 30 can relay the request to the server 15 (or respond to the router 20-N).
- the server 15 (or controller 30) can respond by, for example, encoding a response in XML API tags, which can be received by the router 20 -N to update or change the router configuration, including bandwidth.
- a top level of a request sent by the router 20 -N to the controller 30 can begin with an XML declaration tag, followed by a request tag and one or more operation type tags.
- every response returned to the router 20 -N can begin with an XML declaration tag followed by a response tag, one or more operation type tags, and a result summary tag with an error count.
- a response can contain operation tags for each supported operation type.
- the operation type tags contained in the response can correspond to those contained in the router request.
- the router 20-/V can enclose each request stream within a pair of ⁇ Request> start and ⁇ /Request> end tags.
- the controller 30 can enclose each XML response within a pair of ⁇ Response> start and ⁇ /Response> end tags.
- Major and minor version numbers can be carried on the ⁇ Request> and ⁇ Response> elements to indicate the overall XML API version in use by the controller 30 and router 20 -N, respectively.
- the MN bandwidth manager 300 (shown in FIG. 5) can create, configure and communicate with the VPN bandwidth manager 200 (shown in FIG. 4) to provision the master node 10 (shown in FIG. 2) with a VPN connectivity bundle to create a VPN.
- the VPN connectivity bundle can include a plurality of provisioned links between the node 10 and the plurality of branch nodes 40 that form the VPN.
- the MN bandwidth manager 300 can change bandwidth allocations for any one or more of the plurality of provisioned links, such that the sum of all the allocated bandwidths remains constant and equal to, or less than the aggregate bandwidth value BTOTAL allocated for the VPN connectivity bundle, thereby providing flexibility in adding, removing, upgrading or downgrading the assigned bandwidth per node, without necessitating changes to systems or information in the service provider network 70, such as, for example, contracts, billing information, etc.
- the MN bandwidth manager 300 can configure, store and manage the aggregate bandwidth value BTOTAL for all connectivity links provisioned to the node 10 and branch nodes 40-1 to 40 -N.
- the MN bandwidth manager 300 can configure, store and manage the aggregate bandwidths for additional connectivity links between another master node (not shown) and its branch nodes (not shown).
- the MN bandwidth manager 300 can receive instructions and data from any of the routers 30-0 to 30 -N (or 20-0 to 20-/V) or the VPN bandwidth manager 200 and store bandwidth assignments Bo to B ⁇ for the respective connectivity links to the node 10 and each of the branch nodes 1 to N, where bandwidth Bo is the bandwidth allocated to the connectivity link to the node 10, and bandwidths Br to B ⁇ are the bandwidths allocated to the connectivity links to the branch nodes 40-1 to 40 -N, respectively.
- the relationship between the aggregate bandwidth BTOTAL and the bandwidth allocations Bo to B ⁇ is represented by the following equation.
- Each of the branch nodes 40-1 to 40 -N can include a communicating device (not shown) or a network of communicating devices, such as, for example, a private network in one or more of the branch buildings 4 (shown in FIG. 1).
- FIG. 3 shows a representation of the seven-layer OSI model.
- the various communicating devices including the routers 20-0 to 20 -N and 30-0 to 30-/V) in the network system 100 can operate at the application layer 1 , presentation layer 2, session layer 3, transport layer 4, network layer 5, link layer 6, or physical layer 7.
- the application layer 1 is the OSI layer in a communicating device (not shown) that is closest to the user.
- the application layer 1 interacts with software applications in the communicating device that implement a communicating component.
- the application layer 1 can include, for example, a graphic user interface (GUI) or other computing resource with which the user can interact with to carry out a functionality.
- GUI graphic user interface
- the presentation layer 2 establishes context between software applications, which might use different syntax and semantics.
- the presentation layer 2 transforms data into a form that each software application can accept.
- An operating system is an example of the presentation layer 2.
- the session layer 3 controls the connections between communicating devices in the network system 100, including, for example, the server 15, routers 20-0 to 20-N, 30-0 to 30 -N, the controller 30, and the database 60 (shown in FIG. 2).
- This layer is responsible for establishing, managing and terminating connections between local and remote applications.
- the layer can provide for full-duplex, half-duplex, or simplex operations, and is responsible for establishing checkpointing, adjournment, termination, and restart procedures.
- the transport layer 4 provides the functional and procedural mechanisms for transferring variable-length data packets (or sequences) from one communicating device to another communicating device, while maintaining quality-of-service (QoS).
- QoS quality-of-service
- the transport layer 4 controls the reliability of a given connectivity link through flow control, segmentation and desegmentation, and error control.
- the transport layer 4 can include, for example, tunneling protocols, the Transmission Control Protocol (TCP) and the User Datagram Protocol (UDP).
- the network layer 5 provides the functional and procedural mechanisms for transferring data packets from a node on a network to another node on a different network.
- the node can include the node 10 or any of the branch nodes 40-1 to 40 -N, or a node in the node 10 or in any of the branch nodes 40-1 to 40 -N. If the data to be transmitted is too large, the network layer 5 can facilitate splitting the data into a plurality of segments at the node and sending the fragments independently to the other node, where the segments can be reassembled to recreate the transmitted data.
- the network layer 5 can include one or more layer- management protocols such as, for example, routing protocols, multicast group management, network layer information and error, and network layer address assignment.
- the link layer 6 is responsible for node-to-node transfer between nodes in the network system 100.
- the link layer 6 is divided into two sublayers, consisting of a medium access control (MAC) layer and a logical link control (LLC) layer.
- the MAC layer is responsible for controlling how devices in a network gain access to a medium and permission to transmit data.
- the LLC layer is responsible for identifying and encapsulating network layer protocols, and for controlling error checking and frame synchronization.
- the physical layer 7 includes the hardware that connects the communicating devices in the network system 100, including, for example, the server 15, routers 20-0 to 20- A, 30-1 to 30-A, controller 30, or database 60.
- the hardware can include for example connectors, cables, switches, and the like, that provide for transmission and reception of instruction and data streams between the computing devices.
- each node can be identified by a unique identifier such as, for example, an Internet Protocol (IP) address, a MAC address, a network address, a geolocation, and the like.
- IP Internet Protocol
- the IP address can include a 32-bit number (e.g., IPv4) or a 128-bit number (IPv6).
- IPv4 IP version 4
- IPv6 IP version 6
- the IP address can serve two primary functions. First, the IP address can identify the node, such as, for example, the identity of the server 15, routers 20- 0 to 20-A, 30-0 to 30-A, controller 30 or communicating devices (not shown) in the node 10 or branch nodes 40-1 to 40- A. Second, the IP address can identify the location of the node, such as, for example, the geolocation of the server 15, routers 20-0 to 20-A, 30-0 to 30- A, controller 30, or database 60 in the network system 100.
- FIG. 4 shows an example of the VPN bandwidth manager 200, which can be included in the server 15 (shown in FIG. 2).
- the VPN bandwidth manager 200 can be configured to implement the various aspects of the disclosure.
- the VPN bandwidth manager 200 can include a processor 210, a storage 220, a hard disk drive (HDD) 230A, an optical disk drive (ODD) 230B, a network interface 240, an input/output (I/O) interface 250, the API unit 260, a link capacity allocation (LCA) unit 270, and a system bus 205 that can be communicatively linked to each of the components in the VPN bandwidth manager 200 by a communication link.
- HDD hard disk drive
- ODD optical disk drive
- I/O input/output
- LCA link capacity allocation
- the system bus 205 can be any of several types of bus structures that can further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures.
- the processor 210 can be any of various commercially available processors. Dual microprocessors and other multi-processor architectures can be employed as the processor.
- the VPN bandwidth manager 200 includes a computer-readable medium that can hold executable or interpretable computer code (or instructions) that, when executed by the processor 210, cause the steps, processes and methods described herein to be carried out.
- the computer-readable medium can be provided in the storage 220, HDD 230A, or ODD 230B.
- the computer readable medium can include sections of computer code that, when executed by, for example, the processor 210, the API unit 260, and/or the LCA unit 270, can cause the VPN bandwidth manager 200 to carry out the VPN updating process 500 (shown in FIG. 7), and other processes described or contemplated herein.
- the storage 220 includes a read only memory (ROM) 220A and a random-access memory (RAM) 220B.
- the storage 220 can store data and indexing data that links the stored data to a computing resource.
- a basic input/output system (BIOS) can be stored in the non volatile memory 220A, which can include, for example, a ROM, an EPROM, an EEPROM, or the like.
- the BIOS can contain the basic routines that help to transfer information between components within the VPN bandwidth manager 200, such as during start-up.
- the RAM 220B can include a high-speed RAM such as static RAM for caching data.
- the HDD 230A can include, for example, an enhanced integrated drive electronics (EIDE) drive, a serial advanced technology attachments (SATA) drive, or the like; and, the ODD 230B can read/write from/to a CD-ROM disk (not shown), or, read from or write to other high capacity optical media such as the DVD.
- the HDD 230A can be configured for external use in a suitable chassis (not shown).
- the HDD 230A and ODD 230B can be connected to the system bus 205 by a hard disk drive interface (not shown) and an optical drive interface (not shown), respectively.
- the hard disk drive interface (not shown) can include a Universal Serial Bus (USB) (not shown), an IEEE 1394 interface (not shown), and the like, for external applications.
- USB Universal Serial Bus
- the HDD 230A and/or ODD 230B can provide nonvolatile storage of data, data structures, computer-executable instructions, and the like.
- the HDD 230A and/or ODD 230B can accommodate the storage of any data in a suitable digital format.
- the storage 220, HDD 230A, and/or ODD 230B can include one or more apps that are used to execute aspects of the architecture described herein.
- a number of program modules can be stored in the HDD 230A, ODD 230B, and/or RAM 220B, including an operating system (not shown), one or more application programs (not shown), other program modules (not shown), and program data (not shown). Any (or all) of the operating system, application programs, program modules, and program data can be cached in the RAM 220B as executable sections of computer code.
- the network interface 240 can be connected to the network 50 (shown in FIG. 2) via the router 20-0 and/or router 30-0 (shown in FIG. 2).
- the network interface 240 can include a wired or a wireless communication network interface (not shown) and/or a modem (not shown).
- the network interface 240 can receive and transmit data packets between the VPN bandwidth manager 200 and one or more computing devices, including, for example the controller 30 (shown in FIG. 2).
- the VPN bandwidth manager 200 When used in a local area network (LAN), the VPN bandwidth manager 200 can be connected to the LAN network through the wired and/or wireless communication network interface, and, when used in a wide area network (WAN), it can be connected to the WAN network through the modem.
- the modem (not shown) can include an internal or external, or a wired or wireless modem.
- the modem can be connected to the system bus 205 via, for example, a serial port interface (not shown).
- the (I/O) interface 250 can receive commands and data from an operator via the I/O interface, which can be communicatively coupled to one or more input/output devices, including, for example, a keyboard (not shown), a mouse (not shown), a pointer (not shown), a microphone (not shown), a speaker (not shown), a display (not shown), and/or the like.
- the received commands and data can be forward to the processor 210 from the I/O interface 250 as instruction and data signals via the bus 205.
- the API unit 260 can include one or more application program interfaces (APIs).
- APIs can include, for example, web APIs, simple object access protocol (SOAP) APIs, remote procedure call (RPC) APIs, representation state transfer (REST) APIs, or other utilities and services APIs.
- SOAP simple object access protocol
- RPC remote procedure call
- REST representation state transfer
- the LCA unit 270 can be one or more devices or one or more modules that are separate from the processor 210, as seen in FIG. 4, or integrated with the processor 210.
- the LCA unit 270 can include one or more computing devices (not shown) or communicating devices (not shown).
- the LCA unit 270 can be connected to the system bus 205 and configured to receive at one or more inputs (not shown) and transmit at one or more outputs data and instruction signals.
- the LCA unit 270 can include one or more modules that can be configured to carry out changes to and control of bandwidth restrictions on one or more provisioned connectivity links, such as, for example, at the physical layer (e.g. layer 7 of the OSI model, shown in FIG.
- the LCA unit 270 can adjust and control bandwidth restrictions such that the sum of all bandwidths on all connectivity links in the VPN network connectivity bundle, including, e.g., any leased lines, is equal to, or less than the allocated aggregate bandwidth value BTOTAL.
- the LCA unit 270 can be configured to carry out the VPN updating process 500, shown in FIG. 7.
- FIG. 5 shows an example of the MN bandwidth manager 300, which can be included in the controller 30 (shown in FIG. 2).
- the MN bandwidth manager 300 can include components 205 through 260 that are similar to, or substantially the same as correspondingly numbered components in the VPN bandwidth manager 200 (shown in FIG. 4). In order to avoid redundancy, the description provided above, with respect to components 205 through 260, is herein incorporated by reference in its entirety.
- the MN bandwidth manager 300 also includes a master node traffic capacity provisioning (MNTCP) unit 370.
- MNTCP master node traffic capacity provisioning
- the MN bandwidth manager 300 includes a computer-readable medium that can hold executable or interpretable computer code (or instructions) that, when executed by the processor 210, causes the steps, processes and methods described herein to be carried out.
- the computer-readable medium can be provided in the storage 220, HDD 230A, or ODD 230B.
- the computer-readable medium can include sections of computer code that, when executed by, for example, the processor 210, the API unit 260, and/or the MNTCP unit 370, cause the MN bandwidth manager 300 to carry out the VPN provisioning process 400 (shown in FIG. 6), and other processes described or contemplated herein.
- the MNTCP unit 370 can be one or more devices or one or more modules that are separate from the processor 210, as seen in FIG. 5, or integrated with the processor 210.
- the MNTCP unit 370 can include one or more computing devices (not shown).
- the MNTCP unit 370 can be configured to carry out the VPN provisioning process 400 shown in FIG. 6.
- the MNTCP unit 370 can configure, set, and control connectivity links to/from the node 10 (shown in FIG. 2) and each of the branch nodes 40 (shown in FIG. 2).
- the MNTCP unit 370 can communicate with the server 15 (shown in FIG.
- the MNTCP unit 370 can change bandwidth allocations Bi to B ⁇ for any of the plurality of provisioned connectivity links, such that the sum of all the allocated bandwidths remains constant, equal to, or less than the aggregate bandwidth value BTOTAL allocated to all of the connectivity links in the VPN network connectivity bundle.
- FIG. 6 shows an example of the VPN provisioning process 400, according to the principles of the disclosure.
- the VPN provisioning process 400 can be carried out by the controller 30 (shown in FIG. 2), and, more particularly, by the MN bandwidth manager 300 (shown in FIG. 5).
- a network connectivity instruction (or request) signal can be received from any one or more of the routers 30-0 to 30 -N (or any of routers 20-0 to 20- A by the controller 30 (Step 410).
- the signal can be received from the server 15.
- a determination can be made by the controller 30 whether the received signal includes a request relating to a new VPN network connectivity bundle or a modification to be made to an existing VPN network connectivity bundle (Step 420).
- the VPN network connectivity bundle can be determined for all nodes to be included in the VPN, including node 10 and branch nodes 40-1 to 40 -N (Step 430).
- the determined VPN network connectivity bundle can include an aggregate bandwidth BTOTAL allocation for all connectivity links in the VPN network connectivity bundle, as well as the individual bandwidth allocations Bo to BA? for the connectivity links to the node 10 and to the branch nodes 40-1 to 40 -N, respectively.
- VPN network connectivity information can be determined for the VPN network connectivity bundle (Step 435).
- the VPN network connectivity information can include all information necessary for proper bandwidth allocation, connectivity between the node 10 and each branch node 40, and monitoring and management of connectivity usage data for all provisioned connectivity links.
- the connectivity usage data can be transmitted to a billing management system (not shown) located in the SP network 70 (or elsewhere) to carry out billing related to provisioning connectivity links to the node 10 and to each of the branch nodes 40-1 to 40 -N.
- the VPN network connectivity information can be stored in the database 60 (Step 440).
- the stored VPN network connectivity information can include the aggregate bandwidth BTOTAL value and each of the bandwidth Bo to B ⁇ values allocated to the connectivity links to the node 10 and to each of the branch nodes 40-1 to 40 -N, respectively.
- the stored information can include IP addresses for the routers 20-0 to 20 -N and/or routers 30- 0 to 30 -N, IP addresses for the node 10 and branch nodes 40-1 to 40 -N, geolocations for the routers 20-0 to 20 -N and/or routers 30-0 to 30 -N, geolocations for the node 10 and branch nodes 40-1 to 40 -N, user identification, class of service information, and the like.
- the database 60 can include a storage area dedicated to the VPN network connectivity bundle, including all records and files associated with the VPN that includes the node 10 and branch nodes 40-1 to 40 -N, including all provisioned connectivity links.
- the stored records and files can include historical data, including usage data for each provisioned connectivity link.
- the database 60 can include other storage areas dedicated to records and files associated with other VPN network connectivity bundles, which include provisioned connectivity links to other nodes (not shown) and their branch nodes (not shown).
- a connectivity link change instruction and associated data can be parsed from the data packets that include the received VPN network connectivity instruction, or the connectivity link change instruction can be received in a separate communication from the router that atomically communicated with the controller 30 or from the server 15 (Step 450).
- the connectivity link change instruction can include a request for a connectivity link bandwidth change, which can include a bandwidth upgrade or downgrade, removal of a connectivity link or location, or addition of a connectivity link or location.
- the controller 30 can access the appropriate data in the database 60 (or locally in the controller 30) and retrieve VPN network connectivity information associated with received connectivity link change instruction, including the associated aggregated bandwidth BTOTAL and the current bandwidth allocations Bo to B ⁇ for all associated connectivity links in the VPN (Step 455).
- the requested connectivity link bandwidth change(s) can be applied to the current bandwidth allocations, and the resultant bandwidth allocations (with the applied change(s)) can be calculated (Step 460). Based on the calculated values, a determination can be made whether the sum of all allocated bandwidths Bo to B ⁇ (with the change(s) included) is greater than the aggregate bandwidth BTOTAL allocated for all connectivity links in the VPN (Step 465).
- a notification can be generated and sent to the router (or server 15) from which the connectivity link change instruction was received (Step 490), otherwise (NO at Step 465) the requested change can be made to the connectivity link in the VPN network connectivity bundle based on the received connectivity link change instruction (Step 470) and the associated VPN network connectivity information can be updated in the database 60 based on the modifications made to the connectivity link(s) in the VPN network connectivity bundle (Step 475).
- the notification can include, for example, a message signal that indicates denial of the requested connectivity link change.
- the controller 30 can generate and send configuration instructions to an appropriate one or more of the routers 30-1 to 30 -N (or routers 20-1 to 20 -N, or the server 15) to apply the bandwidth change(s) to appropriate connectivity links (Step 480).
- the configuration change instructions can include router settings that can be implemented to apply the changes to the appropriate connectivity link(s), thereby ensuring proper provisioning of connectivity links in the VPN network connectivity bundle, including links to the node 10 and to the branch nodes 40-1 to 40 -N.
- the controller 30 can request a confirmation signal from the reconfigured router(s) to ensure that each connectivity link bandwidth change has been implemented.
- the controller 30 can generate and send a notification to the server 15 (Step 490).
- the notification can include a confirmation that the connectivity link bandwidth change(s) has been implemented.
- the server 15, and, more particularly, the VPN bandwidth manager 200 (shown in FIG. 4) can apply the necessary changes to the appropriate one(s) of routers 20-1 to 20-V.
- the confirmation notification can include router configurations and settings for proper configuration of the router(s).
- FIG. 7 shows an example of a VPN updating process 500, according to the principles of the disclosure.
- the VPN updating process 500 can be carried out by the server 15 (shown in FIG. 2), and, more particularly, by the VPN bandwidth manager 200 (shown in FIG. 4).
- FIGS. 8 A and 8B show an example of displays 600A and 600B that can be rendered by a graphic user interface (GUI).
- GUI graphic user interface
- the displays 600A and 600B can be rendered by GUI in the server 15 (shown in FIG. 2), and, more particularly, by the I/O interface 250 in the VPN bandwidth manager 200 (shown in FIG. 4).
- the VPN updating process 500 can initiate and prepare to receive connectivity link change instructions by, for example, rendering a GUI (e.g., display screen 600A, shown in FIG. 8A) on a display device (not shown) (Step 510).
- the GUI can be rendered with a plurality of fields that are configured to receive VPN provisioning instructions.
- the GUI can be configured to receive requests and instructions relating to a request type field and an associated value field, and, depending on the type of request, the data can be retrieved from storage (e.g., RAM 220B or HDD 230 A or ODD230B, shown in FIG. 4) and additional type fields and associated values can be autocompleted in the GUI (Step 520).
- the bandwidth allocated to the connectivity link to the node 10 is Bo
- the bandwidths allocated to the connectivity links to the branch nodes 40-1 to 40-5 are Bi to Bs, respectively. Any of the values Bo to Bs can be changed.
- the notification can include a message (not shown) that is rendered by the GUI on the display device.
- the GUI can render an“ADD LOCATION” field and an“ADD VALUE” field, which can receive an instruction to add a new connectivity link for a location (e.g., a new location or one of the existing locations), as well as the bandwidth to be allocated to the new connectivity link.
- the GUI can receive an instruction to remove any of the locations (e.g., branch nodes 1 to 5) and, thereby, remove any connectivity link(s) to the removed location(s).
- a connectivity link change instruction can be received by the VPN bandwidth manager 200 (shown in FIG. 4), requesting that one or more of the connectivity links be upgraded, downgraded, removed, suspended, or added (Step 530).
- FIG. 8B shows an example where a request is received to upgrade the bandwidth allocated for the connectivity link to branch node 4 (i.e., branch node 40-4 in FIG. 2) from 3 Mbps to 4 Mbps.
- the request can be received via the GUI that renders the display 600B via router 20-0 (shown in FIG.2), or directly from the router 20-4 (shown in FIG. 2), which routes traffic to/from the branch node 40-4.
- the received request can include a downgrade to the bandwidth allocated to the connectivity link to branch node 3 (i.e., branch node 40-3 in FIG. 2) from 2 Mbps to 1 Mbps, as seen in FIG. 8B.
- the VPN network connectivity instruction can be sent from, for example, the VPN bandwidth manager 200 (shown in FIG. 4) via router 20-0 (shown in FIG.
- the notification can include a message that indicates that the changes cannot be accepted because the sum of the resultant bandwidth allocations exceed the aggregate bandwidth.
- the message signal can be rendered on the display device (not shown) by the GUI.
- the notification can include a prompt for further connectivity link change instructions to be provided, which can be received (Step 530).
- Step 560 After the VPN network connectivity instruction is sent to the controller 30 (Step 560), a determination can be made whether a notification is received from the controller 30 (Step 570). If a notification is received from the controller 30 and the notification includes a confirmation that the requested change(s) has been accepted and implemented (CONFIRMATION at Step 570), then the necessary configuration changes are made to the appropriate one or more routers 20-0 to 20 -N (Step 580). However, if the received notification includes a denial of the requested change (DENIAL at Step 570), then a notification can be generated and sent (or rendered) (Step 545) and Steps 530 to 570 carried out.
- the term“communicating device,” as used in this disclosure, means any computing device, hardware, firmware, or software that can transmit or receive data packets, instruction signals or data signals over a communication link.
- the hardware, firmware, or software can include, for example, a telephone, a smart phone, a personal data assistant (PDA), a smart watch, a tablet, a computer, a software defined radio (SDR), or the like, without limitation.
- the communicating device can be portable or stationary.
- the term“communication link,” as used in this disclosure, means a wired and/or wireless medium that conveys data or information between at least two points.
- the wired or wireless medium can include, for example, a metallic conductor link, a radio frequency (RF) communication link, an Infrared (IR) communication link, an optical communication link, or the like, without limitation.
- the RF communication link can include, for example, WiFi, WiMAX, IEEE 802.11 , DECT, 0G, 1 G, 2G, 3G or 4G cellular standards, Bluetooth, or the like, without limitation.
- the terms“computer” or“computing device,” as used in this disclosure, means any machine, device, circuit, component, or module, or any system of machines, devices, circuits, components, modules, or the like, which are capable of manipulating data according to one or more instructions, such as, for example, without limitation, a processor, a microprocessor, a central processing unit, a general purpose computer, a super computer, a personal computer, a laptop computer, a palmtop computer, a notebook computer, a desktop computer, a workstation computer, a server, a server farm, a computer cloud, or the like, or an array of processors, microprocessors, central processing units, general purpose computers, super computers, personal computers, laptop computers, palmtop computers, notebook computers, desktop computers, workstation computers, servers, or the like, without limitation.
- computing resource means software, a software application, a web application, a web page, a computer application, a computer program, computer code, machine executable instructions, firmware, or the like.
- a computing resource can include an email account, a user account, a network account, or the like.
- Non-volatile media can include, for example, optical or magnetic disks and other persistent memory.
- Volatile media can include dynamic random access memory (DRAM).
- Computer-readable media include, for example, a floppy disk, a flexible disk, hard disk, magnetic tape, any other magnetic medium, a CD-ROM, DVD, any other optical medium, punch cards, paper tape, any other physical medium with patterns of holes, a RAM, a PROM, an EPROM, a FLASH-EEPROM, any other memory chip or cartridge, a carrier wave as described hereinafter, or any other medium from which a computer can read.
- the computer-readable medium can include a“Cloud,” which includes a distribution of files across multiple (e.g., thousands of) memory caches on multiple (e.g., thousands of) computers.
- sequences of instruction can be delivered from a RAM to a processor, (ii) can be carried over a wireless transmission medium, and/or (iii) can be formatted according to numerous formats, standards or protocols, including, for example, WiFi, WiMAX, IEEE 802.11, DECT, 0G, 1G, 2G, 3G, 4G, or 5G cellular standards, Bluetooth, or the like.
- the term“connectivity link,” as used in this disclosure, means a communication link or any combination of communication links that connects two or more nodes, carrying data packets between the nodes.
- a data packet can include an Internet Protocol (IP) data packet.
- IP Internet Protocol
- a data packet can include an instruction signal that, when received by a computing device or a computing resource, can cause the computing device or computing resource to carry out a predetermined function or task.
- the data packet can include a data signal that, when received by a computing device or a computing resource, can be implemented in carrying out a predetermined function or task, or processed to render information.
- the term“database,” as used in this disclosure, means any combination of software and/or hardware, including at least one application and/or at least one computer.
- the database can include a structured collection of records or data organized according to a database model, such as, for example, but not limited to at least one of a relational model, a hierarchical model, a network model or the like.
- the database can include a database management system application (DBMS) as is known in the art.
- the at least one application may include, but is not limited to, for example, an application program that can accept connections to service requests from clients by sending back responses to the clients.
- the database can be configured to run the at least one application, often under heavy workloads, unattended, for extended periods of time with minimal human direction.
- the term“network,” as used in this disclosure means, but is not limited to, for example, at least one of a personal area network (PAN), a local area network (LAN), a wireless local area network (WLAN), a campus area network (CAN), a metropolitan area network (MAN), a wide area network (WAN), a metropolitan area network (MAN), a wide area network (WAN), a global area network (GAN), a broadband area network (BAN), a cellular network, a storage-area network (SAN), a system-area network, a passive optical local area network (POLAN), an enterprise private network (EPN), a virtual private network (VPN), the Internet, or the like, or any combination of the foregoing, any of which can be configured to communicate data via a wireless and/or a wired communication medium.
- PAN personal area network
- LAN local area network
- WLAN wireless local area network
- CAN campus area network
- MAN metropolitan area network
- WAN wide area network
- MAN metropolitan area network
- WAN wide area
- These networks can run a variety of protocols, including, but not limited to, for example, Ethernet, IP, IPX, TCP, UDP, SPX, IP, IRC, HTTP, FTP, Telnet, SMTP, DNS, ARP, ICMP, etc.
- node means a communicating device and/or a computing resource, or a combination or a network of communicating devices and/or computing resources.
- the term“server,” as used in this disclosure, means any combination of software and/or hardware, including at least one application and/or at least one computer to perform services for connected clients as part of a client-server architecture.
- the at least one server application can include, but is not limited to, for example, an application program that can accept connections to service requests from clients by sending back responses to the clients.
- the server can be configured to run the at least one application, often under heavy workloads, unattended, for extended periods of time with minimal human direction.
- the server can include a plurality of computers configured, with the at least one application being divided among the computers depending upon the workload. For example, under light loading, the at least one application can run on a single computer. However, under heavy loading, multiple computers can be required to run the at least one application.
- the server, or any if its computers, can also be used as a workstation.
- transmission means the conveyance of signals via electricity, acoustic waves, light waves and other electromagnetic emissions, such as those generated with communications in the radio frequency (RF) or infrared (IR) spectra.
- Transmission media for such transmissions can include coaxial cables, copper wire and fiber optics, including the wires that comprise a system bus coupled to the processor.
- Devices that are in communication with each other need not be in continuous communication with each other, unless expressly specified otherwise.
- devices that are in communication with each other may communicate directly or indirectly through one or more intermediaries.
- process steps, method steps, algorithms, or the like may be described in a sequential or a parallel order, such processes, methods and algorithms may be configured to work in alternate orders.
- any sequence or order of steps that may be described in a sequential order does not necessarily indicate a requirement that the steps be performed in that order; some steps may be performed simultaneously.
- a sequence or order of steps is described in a parallel (or simultaneous) order, such steps can be performed in a sequential order.
- the steps of the processes, methods or algorithms described herein may be performed in any order practical.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| SA521430371A SA521430371B1 (en) | 2019-03-27 | 2021-09-19 | System and Method for Virtual Private Network Connectivity |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/366,535 | 2019-03-27 | ||
| US16/366,535 US11201790B2 (en) | 2019-03-27 | 2019-03-27 | System and method for virtual private network connectivity |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020198306A1 true WO2020198306A1 (en) | 2020-10-01 |
Family
ID=70293131
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2020/024623 Ceased WO2020198306A1 (en) | 2019-03-27 | 2020-03-25 | System and method for virtual private network connectivity |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US11201790B2 (en) |
| SA (1) | SA521430371B1 (en) |
| WO (1) | WO2020198306A1 (en) |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10992550B2 (en) | 2016-09-28 | 2021-04-27 | Intel Corporation | Techniques to control quality of service for end-to-end paths in a compute environment |
| US10860390B2 (en) * | 2017-06-28 | 2020-12-08 | Intel Corporation | Microservices architecture |
| US11271828B2 (en) | 2018-11-15 | 2022-03-08 | Citrix Systems, Inc. | Real-time scalable virtual session and network analytics |
| US11627091B2 (en) * | 2019-05-20 | 2023-04-11 | Citrix Systems Inc. | Systems and methods for managing streams of packets via intermediary devices |
| WO2021247071A1 (en) * | 2020-05-30 | 2021-12-09 | Futurewei Technologies, Inc. | Network contracts in communication packets |
| US11606118B2 (en) * | 2020-08-27 | 2023-03-14 | Connectify, Inc. | Data transfer with multiple threshold actions |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030079043A1 (en) * | 2001-10-18 | 2003-04-24 | Ta-Wei Chang | VPN service management system and VPN service manager and VPN service agent comprising same |
| US20040028054A1 (en) * | 2002-08-12 | 2004-02-12 | Sumit Khurana | Dynamic bandwidth reallocation |
| CN104468408A (en) * | 2013-09-22 | 2015-03-25 | 中国电信股份有限公司 | Method for adjusting dynamically service bandwidth and control center server |
Family Cites Families (19)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6909700B1 (en) * | 1998-11-24 | 2005-06-21 | Lucent Technologies Inc. | Network topology optimization methods and apparatus for designing IP networks with performance guarantees |
| US6449650B1 (en) * | 1999-02-01 | 2002-09-10 | Redback Networks Inc. | Methods and apparatus for deploying quality of service policies on a data communication network |
| JP4657433B2 (en) * | 2000-10-02 | 2011-03-23 | 富士通株式会社 | Bandwidth control service management device |
| US20020075901A1 (en) * | 2000-12-19 | 2002-06-20 | Bruce Perlmutter | Bandwidth management for tunneling servers |
| US7787494B1 (en) * | 2004-12-07 | 2010-08-31 | Nortel Networks Limited | Method and apparatus for assigning and allocating network resources to packet-based virtual private networks |
| JP4484721B2 (en) * | 2005-02-09 | 2010-06-16 | アラクサラネットワークス株式会社 | Data transfer device |
| US7995500B2 (en) * | 2006-11-30 | 2011-08-09 | Cisco Technology, Inc. | Managing an amount of tunnels in a computer network |
| US7738492B2 (en) * | 2007-11-19 | 2010-06-15 | Avistar Communications Corporation | Network communication bandwidth management |
| US7852849B2 (en) * | 2008-03-04 | 2010-12-14 | Bridgewater Systems Corp. | Providing dynamic quality of service for virtual private networks |
| WO2010123268A2 (en) * | 2009-04-21 | 2010-10-28 | Samsung Electronics Co., Ltd. | Method and apparatus for using contents of wireless terminal in home network system |
| US8289870B2 (en) * | 2009-09-23 | 2012-10-16 | Avaya Inc. | Priority-based, dynamic optimization of utilized bandwidth |
| US8711880B2 (en) * | 2011-03-16 | 2014-04-29 | Telefonaktiebolaget L M Ericsson (Publ) | Method for reserving network bandwidth for versioned network services |
| US8909766B1 (en) * | 2011-10-04 | 2014-12-09 | Amazon Technologies, Inc. | Techniques for providing information about network connection status |
| US10469304B1 (en) * | 2013-01-16 | 2019-11-05 | Amazon Technologies, Inc. | Network visualization service |
| CN105556927B (en) * | 2013-07-17 | 2019-04-12 | 蜂巢流有限公司 | Distribute data content in private network |
| CN104703222B (en) * | 2013-12-10 | 2018-06-15 | 华为技术有限公司 | A kind of data transmission method and router |
| US20150304238A1 (en) * | 2014-04-17 | 2015-10-22 | Invent.ly LLC | Bandwidth Management in Local Premise Networks |
| US9515937B2 (en) * | 2014-09-25 | 2016-12-06 | International Business Machines Corporation | Predictive VPN bandwidth balancing based on weather data and social media sentiment |
| US10541855B2 (en) * | 2017-02-03 | 2020-01-21 | Ribbon Communications Operating Company, Inc. | Resource allocation methods and apparatus |
-
2019
- 2019-03-27 US US16/366,535 patent/US11201790B2/en active Active
-
2020
- 2020-03-25 WO PCT/US2020/024623 patent/WO2020198306A1/en not_active Ceased
-
2021
- 2021-09-19 SA SA521430371A patent/SA521430371B1/en unknown
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030079043A1 (en) * | 2001-10-18 | 2003-04-24 | Ta-Wei Chang | VPN service management system and VPN service manager and VPN service agent comprising same |
| US20040028054A1 (en) * | 2002-08-12 | 2004-02-12 | Sumit Khurana | Dynamic bandwidth reallocation |
| CN104468408A (en) * | 2013-09-22 | 2015-03-25 | 中国电信股份有限公司 | Method for adjusting dynamically service bandwidth and control center server |
Also Published As
| Publication number | Publication date |
|---|---|
| SA521430371B1 (en) | 2024-11-21 |
| US20200313970A1 (en) | 2020-10-01 |
| US11201790B2 (en) | 2021-12-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11201790B2 (en) | System and method for virtual private network connectivity | |
| US11558293B2 (en) | Network controller subclusters for distributed compute deployments | |
| US11895154B2 (en) | Method and system for virtual machine aware policy management | |
| US12609970B2 (en) | Dynamic reservation protocol for 5G network slicing | |
| CA3111399C (en) | Unique identities of endpoints across layer 3 networks | |
| US10673718B2 (en) | Traceroutes for discovering the network path of inbound packets transmitted from a specified network node | |
| US9485147B2 (en) | Method and device thereof for automatically finding and configuring virtual network | |
| JP5976942B2 (en) | System and method for providing policy-based data center network automation | |
| CN110226308B (en) | A network slice management method, management unit and system | |
| EP2961100A1 (en) | Graph database for services planning and configuration in network services domain | |
| CN114365454B (en) | Distribution of stateless security functions | |
| US9804907B2 (en) | Remote procedure call for a distributed system | |
| US20120117218A1 (en) | Network connection management using connection profiles | |
| CN112751947B (en) | Communication system and method | |
| US10142200B2 (en) | Methods and systems for a network appliance module enabling dynamic VDC aware span | |
| US9374308B2 (en) | Openflow switch mode transition processing | |
| EP4529120B1 (en) | Communication method based on alto protocol, and related apparatus | |
| EP4160394A1 (en) | Decentralized software upgrade image distribution for network device upgrades | |
| CN105577433B (en) | A kind of ACS cluster management method, device and system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20719881 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20719881 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 18/03/2022) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20719881 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 521430371 Country of ref document: SA |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 521430371 Country of ref document: SA |
|
| WWG | Wipo information: grant in national office |
Ref document number: 521430371 Country of ref document: SA |