IP Library Granted Patent US 12,745,294
Granted Patent B2
US 12,745,294 · App. 17/645,010 · Granted Sep 22, 2026

Onboarding virtualized network devices to cloud-based network assurance system

Inventors: Kaushik Adesh Agrawal (Chelmsford, MA); Keh-Ming Luoh (Fremont, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04W76/10G06F9/45558H04L69/22H04W12/04H04W40/02H04W48/18H04W60/00G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,745,294
App. No.
17/645,010
Granted
Sep 22, 2026
Kind
B2
Abstract

Techniques are described for onboarding virtualized network devices to a cloud-based WAN assurance system. For example, a virtualized network device receives, from a network device conductor that manages a plurality of network devices, a registration code for registering with the cloud-based WAN assurance system. In response to receiving the registration code and instructions, the network device sends the registration code to the cloud-based WAN assurance system. The cloud-based WAN assurance system verifies the network device based on the registration code, and assigns a distinct (e.g., unique) device identifier to the network device, and sends the distinct device identifier and a secret key to the network device. The network device uses the secret key to create a new secure connection with the cloud-based WAN assurance system, for streaming telemetry data to the WAN assurance system. The cloud-based WAN assurance system analyzes the network device telemetry data to provide WAN assurance.

Claims (63)

1 . A method comprising:

automatically registering, by a virtualized network device of a plurality of virtualized network devices of a Wide Area Network (WAN), with a cloud-based WAN assurance system using an organization-wide registration code received by the virtualized network device from a conductor device that created the virtualized network device, wherein the conductor device is external to the cloud-based WAN assurance system, wherein automatically registering comprises:

obtaining, by the virtualized network device, from a physical device executing two or more of the plurality of virtualized network devices including the virtualized network device, an identifier of the physical device, wherein the physical device is separate and distinct from the conductor device;

sending, by the virtualized network device and to the cloud-based WAN assurance system based on receiving the registration code, identification data that includes: (1) an organization identifier from the registration code and associated with the cloud-based WAN assurance system, (2) an identifier for the conductor device, wherein the identifier for the conductor device is not obtained from the registration code, and (3) the identifier for the physical device;

receiving, by the virtualized network device and from the cloud-based WAN assurance system, a distinct identifier for the virtualized network device, generated by the cloud-based WAN assurance system in response to receiving the identification data and based on at least a portion of the identification data, wherein the distinct identifier for the virtualized network device distinguishes the virtualized network device from any of the plurality of virtualized network devices executed by the physical device; and

sending, by the virtualized network device and subsequent to the registering, to the cloud-based WAN assurance system, telemetry data to be associated with the distinct identifier for the virtualized network device.

2 . The method of claim 1 , further comprising:

receiving, from the cloud-based WAN assurance system and based on at least some of the identification data, a secret key for creating a secure connection between the virtualized network device and the cloud-based WAN assurance system.

3 . The method of claim 1 , further comprising:

receiving, by the virtualized network device and from the conductor device, a secret key;

sending, by the virtualized network device and to the cloud-based WAN assurance system via a first connection to the cloud-based WAN assurance system established using the secret key, the identification data; and

receiving, by the virtualized network device and from the cloud-based WAN assurance system via the first connection, the distinct identifier for the virtualized network device and a cryptographic key for use in securely sending the telemetry data.

4 . The method of claim 3 , further comprising:

creating, by the virtualized network device, a secure connection with the cloud-based WAN assurance system using the cryptographic key,

wherein sending the telemetry data comprises sending the telemetry data to the cloud-based WAN assurance system via the secure connection.

5 . The method of claim 1 , wherein the virtualized network device is configured to perform session-based routing by modifying a first packet of at least one of a forward packet flow and a reverse packet flow of a session between a source device and a destination device to include:

a header comprising a source address of the virtualized network device and a destination address of a second virtualized network device of the plurality of virtualized network devices to which the virtualized network device forwards the first packet; and

a portion of metadata specifying a session identifier for the session.

6 . The method of claim 1 , further comprising:

receiving, by each of the plurality of virtualized network devices from the conductor device, the registration code, wherein the registration code is the same for each of the virtualized network devices,

wherein automatically registering with the cloud-based WAN assurance system comprises automatically registering, by each of the plurality of virtualized network devices, with the cloud-based WAN assurance system using the registration code received by each of the plurality of virtualized network devices from the conductor device, and

wherein sending the telemetry data to the cloud-based WAN assurance system comprises sending, by each of the plurality of virtualized network devices, corresponding telemetry data to the cloud-based WAN assurance system.

7 . A method comprising:

receiving, by a conductor device for a plurality of virtualized network devices configured to perform session-based routing, an organization-wide registration code generated by a cloud-based Wide-Area Network (WAN) assurance system and comprising an organization identifier associated with the cloud-based WAN assurance system;

instantiating, by the conductor device, a first virtualized network device of the plurality of virtualized network devices;

sending, by the conductor device and to the first virtualized network device, the registration code;

obtaining, by the first virtualized network device, from a physical device executing two or more of the plurality of virtualized network devices including the first virtualized network device, an identifier of the physical device, wherein the physical device is separate and distinct from the conductor device;

sending, by the first virtualized network device and to the cloud-based WAN assurance system, identification data comprising: (1) the organization identifier from the registration code, (2) an identifier for the conductor device, wherein the identifier for the conductor device is not obtained from the registration code, and (3) the identifier for the physical device; and

based on receiving the identification data from the first virtualized network device:

adding, by the cloud-based WAN assurance system, an entry for the first virtualized network device into a device database;

sending, by the cloud-based WAN assurance system and to the first virtualized network device via a first connection, a distinct identifier for the first virtualized network device and a cryptographic key, wherein the cloud-based WAN assurance system generates the distinct identifier for the first virtualized network device based at least in part on the organization identifier, the identifier of the conductor device, and the identifier for the physical device executing the first virtualized network device, wherein the distinct identifier for the first virtualized network device distinguishes the first virtualized network device from any of the plurality of virtualized network devices executed by the physical device; and

sending, by the first virtualized network device and to the cloud-based WAN assurance system via a second connection to the cloud-based WAN assurance system established using the cryptographic key, telemetry data for the first virtualized network device to be associated with the distinct identifier for the virtualized network device.

8 . The method of claim 7 , further comprising associating, by the cloud-based WAN assurance system, the telemetry data for the virtualized network device with the distinct identifier for the first virtualized network device.

9 . The method of claim 8 , further comprising applying, by the cloud-based WAN assurance system and to the telemetry data, artificial intelligence (AI)-based analytics to provide WAN assurance services.

10 . The method of claim 7 , wherein the first virtualized network device is configured to perform session-based routing by modifying a first packet of at least one of a forward packet flow and a reverse packet flow of a session between a source device and a destination device to include:

a header comprising a source address of the first virtualized network device and a destination address of a second virtualized network device of the plurality of virtualized network devices to which the virtualized network device forwards the first packet; and

a portion of metadata specifying a session identifier for the session.

11 . The method of claim 7 , further comprising instantiating, by the conductor device, each virtualized network device of the plurality of virtualized network devices; and

sending, by the conductor device and to each of the plurality of virtualized network devices, the registration code and the secret key.

12 . The method of claim 11 , further comprising: in response to receiving corresponding identification data from each of the plurality of virtualized network devices:

generating a corresponding distinct device identifier for each of the plurality of virtualized network devices;

adding, by the cloud-based WAN assurance system, a corresponding entry for each of the virtualized network devices into a device database, wherein each of the corresponding entries includes the corresponding distinct device identifier; and

sending, by the cloud-based WAN assurance system and to each of the virtualized network devices, the corresponding distinct identifier for the virtualized network device and a corresponding distinct cryptographic key for use in securely sending telemetry data to the cloud-based WAN assurance system.

13 . The method of claim 11 , wherein the registration code is generated by a portal for the cloud-based WAN assurance system, the registration code further comprising a secret key for initial communication with the cloud-based WAN assurance system, and

wherein sending the identification data comprises sending the identification data via a first connection to the cloud-based WAN assurance system established using the secret key.

14 . A method comprising:

based on receiving corresponding identification data from each of a plurality of virtualized network devices created by a conductor device, generating, by a cloud-based Wide Area Network (WAN) assurance system, a corresponding distinct identifier for use in identifying each of the plurality of virtualized network devices in the cloud-based WAN assurance system,

wherein the corresponding identification data from each of the plurality of virtualized network devices includes: (1) an organization identifier obtained from a registration code associated with the cloud-based WAN assurance system, (2) an identifier for the conductor device that is not obtained from the registration code, and (3) an identifier for a physical device executing the virtualized network device, the identifier for the physical device having been obtained by the virtualized network device from the physical device, wherein the physical device executes two or more of the plurality of virtualized network devices including the virtualized network device, wherein the physical device is separate and distinct from the conductor device;

adding, by the cloud-based WAN assurance system, a corresponding entry for each of the virtualized network devices into a device database, wherein each of the corresponding entries includes the corresponding distinct identifier and at least some of the identification data, and wherein the distinct identifier for the virtualized network device distinguishes the virtualized network device from any of the plurality of virtualized network devices executed by the physical device;

sending, by the cloud-based WAN assurance system and to each of the virtualized network devices, the corresponding distinct identifier for the virtualized network device and a corresponding distinct cryptographic key for use in sending telemetry data to the cloud-based WAN assurance system; and

receiving, by the cloud-based WAN assurance system and from a first virtualized network device of the plurality of virtualized network devices, via a connection established using the corresponding distinct cryptographic key sent to the first virtualized network device, telemetry data for the first virtualized network device.

15 . The method of claim 14 , wherein the same registration code is provided for each of the plurality of virtualized network devices.

16 . The method of claim 14 , further comprising:

associating, by the cloud-based WAN assurance system, the telemetry data received from the first virtualized network device of the plurality of virtualized network devices with the distinct identifier for the first virtualized network device; and

applying, by the cloud-based WAN assurance system and to the telemetry data, artificial intelligence (AI)-based analytics to provide WAN assurance services.

17 . The method of claim 14 , wherein the first virtualized network device is configured to perform session-based routing by modifying a first packet of at least one of a forward packet flow and a reverse packet flow of a session between a source device and a destination device to include:

a header comprising a source address of the first virtualized network device and a destination address of a second virtualized network device of the plurality of virtualized network devices to which the first virtualized network device forwards the first packet; and

a portion of metadata specifying a session identifier for the session.

18 . The method of claim 7 , wherein the identification data further comprises (4) a name for the first virtualized network device, the method further comprising:

subsequent to adding the entry for the first virtualized network device into the device database, outputting, by the cloud-based WAN assurance system and for display via a graphical user interface, an inventory view of a network, wherein the inventory view includes the name for the first virtualized network device included in the identification data for the virtualized network device, wherein the name is obtained from the entry in the device database.

19 . The method of claim 14 , wherein the identification data further comprises (4) a name for the corresponding virtualized network device, the method further comprising:

subsequent to adding the corresponding entry for each of the virtualized network devices into the device database, outputting, by the cloud-based WAN assurance system and for display via a graphical user interface, an inventory view of a network, wherein the inventory view includes the name for each virtualized network device included in the corresponding identification data for each of the virtualized network devices for which a distinct device identifier was generated.

20 . The method of claim 1 , wherein the identification data further comprises (4) a name for the virtualized network device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2021
From: AGRAWAL, KAUSHIK ADESH; LUOH, KEH-MING
To: JUNIPER NETWORKS, INC.
Reel/Frame 058423/0385 →
Continuity (2)
Provisional Application 63178400 · Apr 22, 2021
Related Publication 20220346160A1 · Oct 27, 2022
References Cited (37)
US 9729439B2 · MeLampy et al. · 2017 [cited by applicant]
US 9729682B2 · Kumar et al. · 2017 [cited by applicant]
US 9762485B2 · Kaplan et al. · 2017 [cited by applicant]
US 9832082B2 · Dade et al. · 2017 [cited by applicant]
US 9871748B2 · Gosselin et al. · 2018 [cited by applicant]
US 9985883B2 · MeLampy et al. · 2018 [cited by applicant]
US 10200264B2 · Menon et al. · 2019 [cited by applicant]
US 10277506B2 · Timmons et al. · 2019 [cited by applicant]
US 10432522B2 · Kaplan et al. · 2019 [cited by applicant]
US 10958537B2 · Safavi · 2021 [cited by applicant]
US 10958585B2 · Safavi · 2021 [cited by applicant]
US 10985969B2 · Safavi · 2021 [cited by applicant]
US 11165863B1 · Timmons et al. · 2021 [cited by applicant]
US 11329912B2 · Kaplan · 2022 [cited by examiner]
US 20080120707A1 · Ramia · 2008 [cited by examiner]
US 20160197834A1 · Luft · 2016 [cited by examiner]
US 20170222981A1 · Srivastav · 2017 [cited by examiner]
US 20190268322A1 · Leblond et al. · 2019 [cited by applicant]
US 20200145304A1 · Wulff et al. · 2020 [cited by applicant]
US 20200314022A1 · Vasseur · 2020 [cited by examiner]
US 20200366589A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366590A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366598A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366599A1 · Kaplan et al. · 2020 [cited by applicant]
US 20210044623A1 · Bosch · 2021 [cited by examiner]
US 20210112034A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20220100862A1 · Vetter · 2022 [cited by examiner]
CN 105981443A · 2016 [cited by applicant]
WO WO2018232304A1 · 2018 [cited by examiner]
U.S. Appl. No. 17/303,222, entitled “Virtual Network Assistant Having Proactive Analytics and Correlation Engine Using Unsupervised ML Model,” Juniper Networks, Inc. (inventor: Safavi) filed May 24, 2021. [cited by applicant]
Extended Search Report from counterpart European Application No. 22160643.7 dated Aug. 19, 2022, 11 pp. [cited by applicant]
Anonymous, “Verizon Network Infrastructure Planning SDN-NFV Reference Architecture”, Feb. 2016, 220 pp., Retrieved from the Internet on May 15, 2020 from URL: https://m.iotone.com/files/pdf/vendor/Verizon_SDN-NFV_Refere… [cited by applicant]
Response to Extended Search Report dated Aug. 19, 2022, from counterpart European Application No. 22160643.7 filed Apr. 19, 2023, 30 pp. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 22160643.7 dated Aug. 2, 2024, 45 pp. [cited by applicant]
“Verizon Network Infrastructure Planning SDN-NFV Reference Architecture”, vol. 1, Verizon, Feb. 2016, 220 pp., URL: https://edwinhernandez.com/wp-content/uploads/2020/04/Verizon-5G-SDN-NFV-small.pdf. [cited by applicant]
Extended Search Report from counterpart European Application No. 25150540.0 dated May 7, 2025, 7 pp. [cited by applicant]
Response to Extended Search Report dated May 7, 2025, from counterpart European Application No. 25150540.0 filed Dec. 2, 2025, 23 pp. [cited by applicant]