Aggregation Edge Router for Inter-AS VPN Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current VPN services between Autonomous Systems face scalability issues due to the need for separate logical or physical connections for each VPN and security risks associated with label switched paths between edge routers.
Innovation Solution
Implementing aggregation edge routers that act as Autonomous System Border Routers, using Multiprotocol internal and external Border Gateway Protocols to distribute IP-VPN routes, and rewriting route distinguisher and route target attributes to eliminate the need for direct reachability information between ingress and egress routers, allowing for MPLS networks between Autonomous Systems without label switched paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate logical or physical connections are established for each VPN between Autonomous Systems, then VPN service reliability is improved, but network complexity and scalability deteriorate
Solution Approach 1:
The patent introduces ASBR (Autonomous System Border Router) as an intermediary device between different Autonomous Systems. The ASBR establishes BGP peering sessions with other ASBRs to exchange VPN routing information, eliminating the need for direct PE-PE connections across AS boundaries. This intermediary approach maintains VPN reliability while significantly reducing network complexity by centralizing inter-AS routing functions.
2Productivity
If label switched paths are established between ingress and egress edge routers for VPN services, then packet forwarding efficiency is improved, but security risks increase
Solution Approach 1:
The patent extracts the label switched path requirement from the inter-AS VPN architecture. Instead of establishing LSPs between PE routers across different Autonomous Systems, the solution uses BGP routing with next-hop resolution to PE routers within the same AS. This extraction eliminates the security risks associated with end-to-end LSPs while maintaining efficient packet forwarding through standard BGP routing mechanisms.
3Measurement precision
If ingress edge routers maintain reachability information to egress edge routers across Autonomous Systems, then routing precision is improved, but information security deteriorates
Solution Approach 1:
The patent segments the routing information architecture into two distinct layers: inter-AS routing information exchanged between ASBRs via BGP, and intra-AS routing information maintained by PE routers. Ingress PE routers only need reachability information to their local ASBR, not to remote egress PE routers. This segmentation maintains routing precision for VPN traffic while improving information security by limiting the scope of routing information each router must maintain.
Data Source
AI summary
The present invention relates to providing virtual private network (VPN) services between two or more Autonomic Systems (AS). An aggregation edge router (ASBR) is provided in two or more autonomous systems (Asx,Asy). The aggregation edge routers are configured such that routing peering between the two or more autonomous systems is done between the aggregation edge routers in these autonomous systems. Each aggregation edge router is a routing peer of other edge routers (PE) in its own autonomous system. The Multi-Protocol Label Switching (MPLS) network is used between the different autonomous systems.


