IP Library › Granted Patent US 12,598,126
Granted Patent B2
US 12,598,126 · App. 18/623,444 · Granted Apr 7, 2026

Dial-out telemetry for network management

Inventors: Ravi Halappa (San Jose, CA); Sijie Lin (Santa Clara, CA)
Assignee: Ciena Corporation
H04L43/103H04L12/4633H04L41/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,126
App. No.
18/623,444
Granted
Apr 7, 2026
Kind
B2
Abstract

Dial-out telemetry for network management includes a tunnel client configured to form a tunnel service for telemetry inside a dialed-out tunnel from the tunnel client to a tunnel server, wherein the tunnel service is between a network element, communicatively coupled to the tunnel client, and a network management system communicatively coupled to the tunnel server, and preserve the tunnel service via keepalives including during a software upgrade associated with any of the network management system and the network element and with the tunnel service itself.

Claims (38)

1 . A tunnel client implemented by circuitry configured to:

form a tunnel service for telemetry inside a dialed-out tunnel from the tunnel client to a tunnel server, wherein the tunnel service is between a network element, communicatively coupled to the tunnel client, and a network management system communicatively coupled to the tunnel server, wherein the dialed-out tunnel comprises a remote procedure call (gRPC) tunnel that transports a transparent, bi-directional transmission control protocol (TCP)-over-gRPC channel initiated by the network element toward the tunnel server, and wherein forming the tunnel service includes establishing a long-lived bi-directional Register remote procedure call (RPC) between the tunnel client and the tunnel server that remains open while both the tunnel client and the tunnel server are alive, and

preserve the tunnel service via keepalives including during a software upgrade associated with any of the network management system and the network element and with the tunnel service itself, wherein preserving comprises (i) overriding default gRPC keepalive parameters using tunnel-stack keepalive attributes, and (ii) exchanging tunnel-control messages indicating upgrade-start and upgrade-finished states for an in-service software upgrade (ISSU) of the tunnel client or the tunnel server or for an in-service tunnel software upgrade (ISTSU) of the tunnel service, such that the established dialed-out tunnel and the tunnel service remain connected without teardown during the software upgrade.

2 . The tunnel client of claim 1 , wherein the circuitry is further configured to

signal a beginning and an end of any software update.

3 . The tunnel client of claim 1 , wherein the circuitry is further configured to

detect an upgraded ability of the tunnel server and perform an upgrade of the tunnel service based thereon, wherein detecting comprises receiving, during tunnel registration or during a life of an established tunnel session, bidirectional capability information identifying (i) a set of tunnel ser es supported by the tunnel server and (ii) service-type capabilities for at least one tunnel service, and wherein performing the upgrade comprises dynamically enabling, disabling, or updating operation of the tunnel service in-line with the established tunnel session based on the received capability information without disconnecting the tunnel session.

4 . The tunnel client of claim 1 , wherein the tunnel service is a gRPC Network Management Interface (gNMI) service.

5 . The tunnel client of claim 4 , wherein the circuitry is further configured to

implement a tunnel-based Authentication, Authorization, and Accounting (AAA) framework utilizing gRPC.

6 . The tunnel client of claim 5 , wherein the AAA framework utilizes existing security in the gRPC along with remote Authentication, service Authorization and Accounting provided as tunnel-service(s).

7 . The tunnel client of claim 4 , wherein the circuitry is further configured to

implement Remote Authentication Dial-in User Service (RADIUS) over gRPC.

8 . A tunnel server implemented by circuitry configured to:

form a tunnel service for telemetry inside a dialed-out tunnel from a tunnel client to the tunnel server, wherein the tunnel service is between a network management system, communicatively coupled to the tunnel server, and a network element communicatively coupled to the tunnel client, wherein the dialed out tunnel comprises a gRPC tunnel that transports a transparent, bi-directional TCP-over-gRPC channel initiated by the network element toward the tunnel server, and wherein forming the tunnel service includes establishing a long-lived bi-directional Register RPC between the tunnel client and the tunnel server that remains open while both the tunnel client and the tunnel server are alive, and

preserve the tunnel service via keepalives including during a software upgrade associated with any of the network management system and the network element and with the tunnel service itself, wherein preserving comprises (i) overriding default gRPC keepalive parameters using tunnel-stack keepalive attributes, and (ii) exchanging tunnel-control messages indicating upgrade-start and upgrade-finished states for an ISSU of the tunnel client or the tunnel server or for an ISTSU of the tunnel service, such that the established dialed-out tunnel and the tunnel service remain connected without teardown during the software upgrade.

9 . The tunnel server of claim 8 , wherein the circuitry is further configured to

signal a beginning and an end of any software update.

10 . The tunnel server of claim 8 , wherein the circuitry is further configured to

provide an upgraded ability of the tunnel server to the tunnel client which performs an upgrade of the tunnel service based thereon.

11 . The tunnel server of claim 8 , wherein the tunnel service is a gRPC Network Management Interface (gNMI) service.

12 . The tunnel server of claim 11 , wherein the circuitry is further configured to

implement a tunnel-based Authentication, Authorization, and Accounting (AAA) framework utilizing gRPC.

13 . The tunnel server of claim 12 , wherein the AAA framework utilizes existing security in the gRPC.

14 . The tunnel server of claim 11 , wherein the circuitry is further configured to

implement Remote Authentication Dial-in User Service (RADIUS) over gRPC.

15 . A method comprising steps of:

forming a tunnel service for telemetry inside a dialed-out tunnel from a tunnel client to a tunnel server, wherein the tunnel service is between a network element, communicatively coupled to the tunnel client, and a network management system communicatively coupled to the tunnel server, wherein the dialed-out tunnel comprises a gRPC tunnel that transports a transparent, bi-directional TCP-over-QRPC channel initiated by the network element toward the tunnel server, and wherein forming the tunnel service includes establishing a long-lived bi-directional Register RPC between the tunnel client and the tunnel server that remains open while both the tunnel client and the tunnel server are alive; and

preserving the tunnel service via keepalives including during a software upgrade associated with any of the network management system and the network element and with the tunnel service itself, wherein preserving comprises (D) overriding default gRPC keepalive parameters using tunnel-stack keepalive attributes, and (ii) exchanging tunnel-control messages indicating upgrade-start and upgrade-finished states for an ISSU of the tunnel client or the tunnel server or for an ISTSU of the tunnel service, such that the established dialed-out tunnel and the tunnel service remain connected without teardown during the software upgrade.

16 . The method of claim 15 , wherein the steps further include

signaling a beginning and an end of any software update.

17 . The method of claim 15 , wherein the steps further include

detecting an upgraded ability of the tunnel service at either the tunnel server or the tunnel client and performing an upgrade of the tunnel service based thereon.

18 . The method of claim 15 , wherein the tunnel service is a gRPC Network Management Interface (gNMI) service.

19 . The method of claim 15 , wherein the steps further include

implementing a tunnel-based Authentication, Authorization, and Accounting (AAA) framework utilizing gRPC.

20 . The method of claim 15 , wherein the steps further include

implementing Remote Authentication Dial-in User Service (RADIUS) over gRPC.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2024
From: HALAPPA, RAVI; LIN, SIJIE
To: CIENA CORPORATION
Reel/Frame 066966/0140 →
Continuity (2)
Provisional Application 63457204 · Apr 5, 2023
Related Publication 20240340231A1 · Oct 10, 2024
References Cited (32)
US 7835379B2 · Dravida et al. · 2010 [cited by applicant]
US 8462626B2 · Desai et al. · 2013 [cited by applicant]
US 11171853B2 · Holness · 2021 [cited by examiner]
US 11323305B1 · Liu · 2022 [cited by examiner]
US 11363116B2 · Tomkins · 2022 [cited by applicant]
US 11388492B2 · Frankel et al. · 2022 [cited by applicant]
US 11457086B1 · McIntosh · 2022 [cited by examiner]
US 11777811B2 · Tomkins et al. · 2023 [cited by applicant]
US 20080033908A1 · Cooper et al. · 2008 [cited by applicant]
US 20190222491A1 · Tomkins et al. · 2019 [cited by applicant]
US 20210075618A1 · Stephenson · 2021 [cited by examiner]
US 20210091874A1 · Agarwal · 2021 [cited by examiner]
US 20220078081A1 · Mahdi et al. · 2022 [cited by applicant]
US 20220138278A1 · Shribman · 2022 [cited by examiner]
US 20220166500A1 · Bownass et al. · 2022 [cited by applicant]
US 20230019374A1 · Mestery · 2023 [cited by examiner]
US 20230110199A1 · Gupta · 2023 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20230333839A1 · Koike · 2023 [cited by examiner]
US 20230379391A1 · Langer · 2023 [cited by examiner]
US 20240223439A1 · Lo · 2024 [cited by examiner]
US 20240273157A1 · Kol · 2024 [cited by examiner]
US 20240340231A1 · Halappa · 2024 [cited by examiner]
GRPC, “Authentication,” https://grpc.io/docs/guides/auth/, Jan. 12, 2024, pp. 1-7. [cited by applicant]
J. Protzman et al., “# TCP over gRPC Tunnel,” https://raw.githubusercontent.com/openconfig/grpctunnel/main/doc/grpctunnel_design.md, Jul. 2022, Pags 1-7. [cited by applicant]
C. Rigney et al., “Remote Authentication Dial in User Service (RADIUS),” Network Working Group, Obsoletes: 2138, Category: Standards Track, Jun. 2000, pp. 1-76. [cited by applicant]
C. Rigney, “RADIUS Accounting,” Network Working Group, Category: Informational, Obsoletes: 2139, Jun. 2000, pp. 1-28. [cited by applicant]
C. de Laat et al., “Generic AAA Architecture,” Network Working Group, Category: Experimental, Aug. 2022, pp. 1-26. [cited by applicant]
J. Vollbrecht et al., “AAA Authorization Framework,” Network Working Group, Category: Informational, Aug. 2000, pp. 1-35. [cited by applicant]
P. Calhoun et al., “Diameter Base Protocol,” Network Working Group, Category: Standards Track, Sep. 2003, pp. 1-147. [cited by applicant]
T. Dierks et al., “The Transport Layer Security (TLS) Protocol Version 1.2,” Network Working Group, Obsoletes: 3268, 4346, 4366, Category: Standards Track, Aug. 2008, pp. 1-104. [cited by applicant]
S. Winter et al., “Transport Layer Security (TLS) Encryption for RADIUS,” Internet Engineering Task Force (IETF), Category: Experimental, ISSN: 2070-1721, May 2012, pp. 1-22. [cited by applicant]