IP Library › Granted Patent US 12,457,267
Granted Patent B2
US 12,457,267 · App. 18/473,422 · Granted Oct 28, 2025

Systems and methods for sharing a control connection

Inventors: Srilatha Tangirala (San Jose, CA); Rahul Hardikar (San Ramon, CA); Sheikh Qumruzzaman (Santa Clara, CA); Ravi Kiran Chintallapudi (Pleasanton, CA); Samir Thoria (Saratoga, CA); Ajeet Pal Singh Gill (Fremont, CA); Vivek Agarwal (Campbell, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L67/141H04L41/122H04L45/76H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,267
App. No.
18/473,422
Granted
Oct 28, 2025
Kind
B2
Abstract

In one embodiment, a method includes onboarding, by an edge router, a first tenant from a network management system and determining, by the edge router, a mapping of a tenant identifier associated with the first tenant to a controller identifier associated with a controller. The method also includes reserving, by the edge router, a port number in a kernel for the first tenant and inserting, by the edge router, the tenant identifier into a first control packet. The method further includes communicating, by the edge router, the first control packet to the controller via an encrypted control connection during a first peering session. The first peering session shares the encrypted control connection with a second peering session.

Claims (38)

1. A network component comprising one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and including instructions that, when executed by the one or more processors, cause the network component to perform operations comprising:

determining a mapping of a tenant identifier associated with a tenant to a controller identifier associated with a controller, wherein the tenant identifier is a global identifier that uniquely identifies the tenant;

establishing, by a daemon installed on the network component, an encrypted control connection with the controller;

inserting the tenant identifier into a control packet; and

communicating the control packet to the controller via the encrypted control connection during a peering session.

2. The network component of claim 1 , the operations further comprising notifying, by the daemon, an Overlay Management Protocol (OMP) of the encrypted control connection.

3. The network component of claim 1 , the operations further comprising:

reserving a port number for the tenant; and

communicating, by the OMP, an association between the port number and the tenant identifier to the daemon.

4. The network component of claim 1 , wherein the tenant is associated with a virtual routing and forwarding (VRF) instance.

5. The network component of claim 1 , the operations further comprising initiating a plurality of peering sessions with the controller via the encrypted control connection.

6. The network component of claim 1 , wherein the encrypted control connection is a Datagram Transport Layer Security (DTLS) control connection.

7. The network component of claim 1 , wherein the network component is a multi-tenant software-defined wide area network (SD-WAN) network component.

8. A method, comprising:

determining a mapping of a tenant identifier associated with a tenant to a controller identifier associated with a controller, wherein the tenant identifier is a global identifier that uniquely identifies the tenant;

establishing, by a daemon installed on a network component, an encrypted control connection with the controller;

inserting the tenant identifier into a control packet; and

communicating the control packet to the controller via the encrypted control connection during a peering session.

9. The method of claim 8 , further comprising notifying, by the daemon, an Overlay Management Protocol (OMP) of the encrypted control connection.

10. The method of claim 8 , further comprising:

reserving a port number for the tenant; and

communicating, by the OMP, an association between the port number and the tenant identifier to the daemon.

11. The method of claim 8 , wherein the tenant is associated with a virtual routing and forwarding (VRF) instance.

12. The method of claim 8 , further comprising initiating a plurality of peering sessions with the controller via the encrypted control connection.

13. The method of claim 8 , wherein the encrypted control connection is a Datagram Transport Layer Security (DTLS) control connection.

14. The method of claim 8 , wherein the network component is a multi-tenant software-defined wide area network (SD-WAN) network component.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

determining a mapping of a tenant identifier associated with a tenant to a controller identifier associated with a controller, wherein the tenant identifier is a global identifier that uniquely identifies the tenant;

establishing, by a daemon installed on a network component, an encrypted control connection with the controller;

inserting the tenant identifier into a control packet; and

communicating the control packet to the controller via the encrypted control connection during a peering session.

16. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising notifying, by the daemon, an Overlay Management Protocol (OMP) of the encrypted control connection.

17. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

reserving a port number for the tenant; and

communicating, by the OMP, an association between the port number and the tenant identifier to the daemon.

18. The one or more computer-readable non-transitory storage media of claim 15 , wherein the tenant is associated with a virtual routing and forwarding (VRF) instance.

19. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising initiating a plurality of peering sessions with the controller via the encrypted control connection.

20. The one or more computer-readable non-transitory storage media of claim 15 , wherein the encrypted control connection is a Datagram Transport Layer Security (DTLS) control connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2023
From: TANGIRALA, SRILATHA; HARDIKAR, RAHUL; QUMRUZZAMAN, SHEIKH; CHINTALLAPUDI, RAVI KIRAN; THORIA, SAMIR; GILL, AJEET PAL SINGH; AGARWAL, VIVEK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 065006/0569 →
Continuity (3)
Continuation 17709877 · Mar 31, 2022
Provisional Application 63265385 · Dec 14, 2021
Related Publication 20240015225A1 · Jan 11, 2024
References Cited (12)
US 9467478B1 · Khan · 2016 [cited by examiner]
US 10826775B1 · Moreno et al. · 2020 [cited by applicant]
US 20130287026A1 · Davie · 2013 [cited by examiner]
US 20150146736A1 · Kawai · 2015 [cited by applicant]
US 20180109493A1 · Khan et al. · 2018 [cited by applicant]
US 20190273681A1 · Williams et al. · 2019 [cited by applicant]
US 20200177503A1 · Hooda et al. · 2020 [cited by applicant]
US 20210067442A1 · Sundararajan et al. · 2021 [cited by applicant]
WO 2021211949A1 · 2021 [cited by applicant]
CISCO: “Cisco SD-WAN Design Guide”, Cisco Public, Sep. 1, 2020, p. 5-p. 26, p. 41-p. 89, XP093028951, pp. 1-102. [cited by applicant]
International Search Report and Written Opinion corresponding to PCT Application No. PCT/US2022/080876, mailed Mar. 15, 2023, 28 pages. [cited by applicant]
Office Action for Indian Application No. 202447053029, dated Aug. 5, 2025, 6 Pages. [cited by applicant]