Automated network discovery, secure network communications, and automated network configuration
The disclosure provides an approach for automated network discovery. Embodiments include generating and propagate a token containing identity information and a digital signature. Embodiments include receiving neighbor reports from a plurality of network nodes in response to the token, wherein each neighbor report includes neighbor relationship information, network status information, a device type, and a device identifier. Embodiments include constructing and maintaining a network topology based on the received neighbor reports.
1 . A system for automated network discovery, comprising:
a central control node implemented via one or more hardware processors configured to:
generate and propagate a token containing identity information and a digital signature;
receive neighbor reports from a plurality of network nodes in response to the token, wherein each neighbor report includes:
neighbor relationship information;
network status information;
a device type; and
a device identifier; and
construct and maintain a network topology based on the received neighbor reports wherein the plurality of network nodes are configured to:
report neighbor relationships to the central control node, including information about directly connected nodes;
initiate a registration process with the central control node upon booting up, reporting their own identity and neighbor node information; and
send departure signaling to the central control node and to corresponding neighbor nodes before disconnecting or network node departure, allowing the central control node and the corresponding neighbor nodes to update the network topology accordingly.
2 . The system of claim 1 , wherein the central control node is further configured to periodically broadcast the token to enable real-time updates of the network topology.
3 . The system of claim 1 , wherein the central control node is further configured to authenticate new network nodes discovered through the token propagation using pre-installed certificates.
4 . The system of claim 3 , wherein the central control node is further configured to deploy configuration templates to authenticated new network nodes.
5 . The system of claim 1 , wherein the corresponding neighbor nodes report received departure signaling to the central control node.
6 . The system of claim 1 , wherein the plurality of network nodes are further configured to periodically report information, comprising status and neighbor information, to the central control node.
7 . The system of claim 1 , wherein the central control node is further configured to identify and report topology changes detected through periodic token broadcasting, including potential reasons for the changes.
8 . The system of claim 7 , wherein the token comprises a payload section, wherein content of the payload section varies depending on a message type and includes at least one of a device identification, a public key, a certificate, a configuration component identifier, a configuration template reference, or configuration data.
9 . The system of claim 1 , wherein the central control node is further configured to leverage existing network protocols for initial configuration component discovery during token exchange.
10 . The system of claim 1 , wherein sensitive information within payloads of the tokens is encrypted to protect configuration data, configuration component identifiers, or device information.
11 . A method for automated network discovery, comprising:
generating and propagating a token containing identity information and a digital signature;
receiving neighbor reports from a plurality of network nodes in response to the token, wherein each neighbor report includes:
neighbor relationship information;
network status information;
a device type; and
a device identifier; and
constructing and maintain a network topology based on the received neighbor reports, wherein the plurality of network nodes are configured to:
report neighbor relationships to the central control node, including information about directly connected nodes;
initiate a registration process with the central control node upon booting up, reporting their own identity and neighbor node information; and
send departure signaling to the central control node and to corresponding neighbor nodes before disconnecting or network node departure, allowing the central control node and the corresponding neighbor nodes to update the network topology accordingly.
12 . The method of claim 11 , further comprising periodically broadcasting the token to enable real-time updates of the network topology.
13 . The method of claim 11 , further comprising authenticating new network nodes discovered through the token propagation using pre-installed certificates.
14 . The method of claim 13 , further comprising deploying configuration templates to authenticated new network nodes.
15 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a computing system, cause the computing system to:
generate and propagate a token containing identity information and a digital signature;
receive neighbor reports from a plurality of network nodes in response to the token, wherein each neighbor report includes:
neighbor relationship information;
network status information;
a device type; and
a device identifier; and
construct and maintain a network topology based on the received neighbor reports, wherein the plurality of network nodes are configured to:
report neighbor relationships to the central control node, including information about directly connected nodes;
initiate a registration process with the central control node upon booting up, reporting their own identity and neighbor node information; and
send departure signaling to the central control node and to corresponding neighbor nodes before disconnecting or network node departure, allowing the central control node and the corresponding neighbor nodes to update the network topology accordingly.
16 . The system of claim 1 , wherein secure communication channels are established through pre-installed certificates and configuration component authentication.