IP Library › Granted Patent US 12,375,349
Granted Patent B2
US 12,375,349 · App. 18/451,864 · Granted Jul 29, 2025

Identifying out-of-band configuration changes to validate intent files

Inventors: Pradeep H. Krishnamurthy (Bangalore, IN); F N U Nadeem (Fremont, CA); Raviraj Satish Deshmukh (Pune, IN)
Assignee: Juniper Networks, Inc.
H04L41/0816H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,349
App. No.
18/451,864
Granted
Jul 29, 2025
Kind
B2
Abstract

A controller device manages a plurality of network devices. The controller device includes a memory comprising a configuration database including a set of stored network device configurations, wherein each stored network device configuration of the set of stored network device configurations corresponds to a network device of the set of network devices. Additionally, the controller device includes processing circuitry configured to receive an intent file corresponding to an intended configuration for the set of network devices; receive a message from a network device of the set of network devices indicating an out-of-band configuration change at the network device; and determine, based on a stored network device configuration corresponding to the network device and an actual configuration of the network device, whether the intent file is compatible with the out-of-band configuration change.

Claims (79)

1. A controller device that manages a set of network devices, the controller device comprising:

a memory; and

processing circuitry in communication with the memory, wherein the processing circuitry is configured to:

translate a high-level intended configuration for each network device of the set of network devices to a low-level configuration;

process data representative of characteristics of the high-level intended configuration that, if changed by out-of-band configuration changes, would be incompatible with the high-level intended configuration;

output the low-level configuration to each network device of the set of network devices to implement the high-level intended configuration;

identify, based on the characteristics of the high-level intended configuration, one or more characteristics of one or more out-of-band configuration changes made to the low-level configuration of one or more network devices of the set of network devices, wherein the out-of-band configuration changes correspond to instructions separate from the low-level configuration output to each network device of the set of network devices by the processing circuitry; and

determine, based on the one or more characteristics, whether the high-level intended configuration is compatible with each of the one or more out-of-band configuration changes.

2. The controller device of claim 1 , wherein the processing circuitry is further configured to receive an intent file corresponding to the high-level intended configuration for the set of network devices.

3. The controller device of claim 1 , wherein the processing circuitry is further configured to:

receive a message from a network device of the set of network devices indicating an out-of-band configuration change of the set of one or more out-of-band configuration changes at the network device; and

determine, based on the message and the one or more characteristics, whether the high-level intended configuration is compatible with the out-of-band configuration change of the one or more out-of-band configuration changes.

4. The controller device of claim 3 , wherein the message is a first message, wherein the memory is configured to store a set of stored network device configurations, wherein each stored network device configuration of the set of stored network device configurations corresponds to a network device of the set of network devices, and wherein the processing circuitry is further configured to:

output, to the network device based on the message from the network device, a second message requesting an actual configuration of the network device;

receive, from the network device, information indicative of the actual configuration of the network device;

retrieve, from the memory, the stored network device configuration corresponding to the network device;

determine a difference between the actual configuration of the network device and the stored network device configuration; and

determine, based on the difference between the actual configuration of the network device and the stored network device configuration corresponding to the network device and based on the one or more characteristics, whether the high-level intended configuration is compatible with the out-of-band configuration change of the one or more out-of-band configuration changes.

5. The controller device of claim 1 , wherein to identify the one or more characteristics of the out-of-band configuration changes, the processing circuitry is further configured to:

generate, based on an intent file corresponding to the high-level intended configuration, one or more flagged XML Path Language (XPath) operations representing XPath operations to check for in out-of-band configuration changes, and wherein the processing circuitry is further configured to:

store the one or more flagged XPath operations in the memory; and

determine whether the high-level intended configuration is compatible with each out-of-band configuration change of the one or more out-of-band configuration changes based on the one or more flagged XPath operations.

6. The controller device of claim 5 , wherein the processing circuitry is further configured to:

receive the intent file via a user interface, wherein the intent file includes user input defining the one or more flagged XPath operations;

identify the one or more flagged XPath operations in a schema of the intent file; and

extract, from the schema of the intent file, the one or more flagged XPath operations.

7. The controller device of claim 5 , wherein to determine whether the high-level intended configuration is compatible with each out-of-band configuration change of the one or more out-of-band configuration changes, the processing circuitry is configured to:

identify, for each out-of-band configuration change of the one or more out-of-band configuration changes, one or more XPath operations associated with the out-of-band configuration change; and

determine, for each out-of-band configuration change of the one or more out-of-band configuration changes, whether any of the one or more flagged XPath operations match any of the one or more XPath operations associated with the out-of-band configuration change.

8. The controller device of claim 7 , wherein the processing circuitry is configured to determine, for each out-of-band configuration change of the one or more out-of-band configuration changes, that the intent file is not compatible with the out-of-band configuration change based on at least one of the one or more flagged XPath operations matching at least one of the one or more XPath operations are associated with the out-of-band configuration change.

9. The controller device of claim 1 , wherein the processing circuitry is further configured to:

output the low-level configuration to each network device of the set of network devices with a first message including an identification tag indicating that the low-level configuration is pushed from the controller device; and

receive, from each network device of the set of network devices, a second message indicating that the low-level configuration is implemented on the network device, wherein the second message includes the identification tag.

10. The controller device of claim 9 , wherein the processing circuitry is further configured to:

receive, from a network device of the set of network devices, a third message, wherein the third message omits the identification tag; and

determine, based on the third message omitting the identification tag, that the third message indicates an out-of-band configuration change of the one or more out-of-band configuration changes at the network device.

11. A method comprising:

translating, by processing circuitry of a controller device that manages a set of network devices, a high-level intended configuration for each network device of the set of network devices to a low-level configuration;

processing data representative of characteristics of the high-level intended configuration that, if changed by out-of-band configuration changes, would be incompatible with the high-level intended configuration;

outputting, by the processing circuitry, the low-level configuration to each network device of the set of network devices to implement the high-level intended configuration;

identifying, by the processing circuitry based on the characteristics of the high-level intended configuration, one or more characteristics of one or more out-of-band configuration changes made to the low-level configuration of one or more network devices of the set of network devices, wherein the out-of-band configuration changes correspond to instructions separate from the low-level configuration output to each network device of the set of network devices by the processing circuitry; and

determining, by the processing circuitry based on the one or more characteristics, whether the high-level intended configuration is compatible with each of the one or more out-of-band configuration changes.

12. The method of claim 11 , further comprising receiving, by the processing circuitry, an intent file corresponding to the high-level intended configuration for the set of network devices.

13. The method of claim 11 , further comprising:

receiving, by the processing circuitry, a message from a network device of the set of network devices indicating an out-of-band configuration change of the one or more out-of-band configuration changes at the network device; and

determining, by the processing circuitry based on receiving the message and based on the one or more characteristics, whether the high-level intended configuration is compatible with the out-of-band configuration change of the one or more out-of-band configuration changes.

14. The method of claim 13 , wherein the message is a first message, wherein each stored network device configuration of a set of stored network device configurations corresponds to a network device of the set of network devices, and wherein the method further comprises:

outputting, by the processing circuitry to the network device based on receiving the message from the network device, a second message requesting an actual configuration of the network device;

receiving, by the processing circuitry from the network device, information indicative of the actual configuration of the network device;

retrieving, by the processing circuitry from the memory, the stored network device configuration corresponding to the network device;

determining, by the processing circuitry, a difference between the actual configuration of the network device and the stored network device configuration; and

determining, by the processing circuitry based on the difference between the actual configuration of the network device and the stored network device configuration corresponding to the network device and based on the one or more characteristics, whether the high-level intended configuration is compatible with the out-of-band configuration change of the one or more out-of-band configuration changes.

15. The method of claim 11 , wherein identifying the one or more characteristics of the out-of-band configuration changes comprises:

generating, by the processing circuitry based on an intent file corresponding to the high-level intended configuration, one or more flagged XML Path Language (XPath) operations representing XPath operations to check for in out-of-band configuration changes, and wherein the method further comprises:

storing, by the processing circuitry, the one or more flagged XPath operations; and

determining, by the processing circuitry, whether the high-level intended configuration is compatible with each out-of-band configuration change of the one or more out-of-band configuration changes based on the one or more flagged XPath operations.

16. The method of claim 15 , further comprising:

receiving, by the processing circuitry, the intent file via a user interface, wherein the intent file includes user input defining the one or more flagged XPath operations;

identifying, by the processing circuitry, the one or more flagged XPath operations in a schema of the intent file; and

extracting, by the processing circuitry from the schema of the intent file, the one or more flagged XPath operations.

17. The method of claim 15 , wherein determining whether the high-level intended configuration is compatible with each out-of-band configuration change of the one or more out-of-band configuration changes comprises:

identifying, by the processing circuitry for each out-of-band configuration change of the one or more out-of-band configuration changes, one or more XPath operations associated with the out-of-band configuration change; and

determining, by the processing circuitry for each out-of-band configuration change of the one or more out-of-band configuration changes, whether any of the one or more flagged XPath operations match any of the one or more XPath operations associated with the out-of-band configuration change.

18. The method of claim 11 , further comprising:

outputting, by the processing circuitry, the low-level configuration to each network device of the set of network devices with a first message including an identification tag indicating that the low-level configuration is pushed from a controller device; and

receiving, by the processing circuitry from each network device of the set of network devices, a second message indicating that the low-level configuration is implemented on the network device, wherein the second message includes the identification tag.

19. The method of claim 18 , further comprising:

receiving, by the processing circuitry from a network device of the set of network devices, a third message, wherein the third message omits the identification tag; and

determining, by the processing circuitry based on the third message omitting the identification tag, that the third message indicates an out-of-band configuration change of the one or more out-of-band configuration changes at the network device.

20. A system comprising:

a set of network devices; and

a controller device that manages the set of network devices, the controller device comprising:

a memory; and

processing circuitry in communication with the memory, wherein the processing circuitry is configured to:

translate a high-level intended configuration for each network device of the set of network devices to a low-level configuration;

process data representative of characteristics of the high-level intended configuration that, if changed by out-of-band configuration changes, would be incompatible with the high-level intended configuration;

output the low-level configuration to each network device of the set of network devices to implement the high-level intended configuration;

identify, based on the characteristics of the high-level intended configuration, one or more characteristics of one or more out-of-band configuration changes made to the low-level configuration of one or more network devices of the set of network devices, wherein the out-of-band configuration changes correspond to instructions separate from the low-level configuration output to each network device of the set of network devices by the processing circuitry; and

determine, based on the one or more characteristics, whether the high-level intended configuration is compatible with each of the one or more out-of-band configuration changes.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2025
From: KRISHNAMURTHY, PRADEEP H.; NADEEM, FNU; DESHMUKH, RAVIRAJ SATISH
To: JUNIPER NETWORKS, INC.
Reel/Frame 072820/0958 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2023
From: KRISHNAMURTHY, PRADEEP H.; NADEEM, FNU; DESHMUKH, RAVIRAJ SATISH
To: JUNIPER NETWORKS, INC
Reel/Frame 064629/0952 →
Priority Claims (1)
IN 202141028381 · Jun 24, 2021 · national
Continuity (2)
Continuation 17449601 · Sep 30, 2021
Related Publication 20230396494A1 · Dec 7, 2023
References Cited (32)
US 7493528B1 · Reichert · 2009 [cited by examiner]
US 10382265B1 · Anburose et al. · 2019 [cited by applicant]
US 11032213B1 · Hussain et al. · 2021 [cited by applicant]
US 11140031B2 · R et al. · 2021 [cited by applicant]
US 11451451B2 · Ratkovic et al. · 2022 [cited by applicant]
US 11777800B2 · Krishnamurthy · 2023 [cited by examiner]
US 20140156816A1 · Lopez et al. · 2014 [cited by applicant]
US 20190238410A1 · Kang et al. · 2019 [cited by applicant]
US 20200195501A1 · Shenoy et al. · 2020 [cited by applicant]
US 20200351167A1 · Sharma · 2020 [cited by applicant]
US 20200374192A1 · Leijon · 2020 [cited by examiner]
US 20210028980A1 · R · 2021 [cited by examiner]
US 20220166679A1 · Hafeez et al. · 2022 [cited by applicant]
CN 112104473A · 2020 [cited by applicant]
CN 112311583A · 2021 [cited by applicant]
EP 3522452A1 · 2019 [cited by applicant]
EP 3771150A1 · 2021 [cited by applicant]
Raghavachari, Mukund, and Oded Shmueli. “Conflicting XML updates.” International Conference on Extending Database Technology. Berlin, Heidelberg: Springer Berlin Heidelberg. (Year: 2006). [cited by examiner]
Response to Communication pursuant to Article 94(3) EPC dated Nov. 2, 2023, from counterpart European Application No. 22177871.5 filed Jan. 2, 2024, 18 pp. [cited by applicant]
First Office Action and Search Report, and translation thereof, from counterpart Chinese Application No. 202210654532.1 dated Mar. 28, 2024, 16 pp. [cited by applicant]
Bjorklund et al., “Network Management Datastore Architecture (NMDA)”, Internet Engineering Task Force (IETF) ; rfc8342, Mar. 2018, 44 pp. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 22177871.5 dated Nov. 2, 2023, 5 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 22177871.5 dated Nov. 17, 2022, 10 pp. [cited by applicant]
Kodeswaran et al., “Utilizing Semantic Tags for Policy Based Networking”, IEEE Globecom 2007—IEEE Global Telecommunications Conference, IEEE, Nov. 2007, 5 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/449,601, dated Oct. 18, 2022 through Aug. 30, 2023, 82 pp. [cited by applicant]
Response to Extended Search Report dated Nov. 17, 2022, from counterpart European Application No. 22177871.5 filed Jun. 28, 2023, 34 pp. [cited by applicant]
Scheid et al., “INSpIRE: Integrated NFV-based Intent Refinement Environment”, 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), IEEE, May 2017, 83 pp. [cited by applicant]
Wei, Yiming, Mugen Peng, and Yaqiong Liu. “Intent-based networks for 6G: Insights and challenges.” Digital Communications and Networks 6.3: 270-280. (Year: 2020). [cited by applicant]
Ya et al. English translation of CN 112104473 A. (Year: 2020). [cited by applicant]
Second Office Action, and translation thereof, from counterpart Chinese Application No. 202210654532.1 dated Sep. 27, 2024, 6 pp. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 22177871.5 dated Jan. 21, 2025, 44 pp. [cited by applicant]
Notice of Intent to Grant from counterpart Chinese Application No. 202210654532.1 dated Jan. 24, 2025, 3 pp. [cited by applicant]