Augmented Routing via OpenVPN Augmented Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional layered security systems in multi-tenant, mesh-linked networks face inefficiencies due to IP address conflicts and ambiguity when tunneling data, leading to challenges in managing and routing packets across different networks.

Innovation Solution

The implementation of an ultra-lightweight multi-tenant network virtualization model using OpenVPN Augmented Addresses (OAA) that augment the OSI layer 4 tuple with private gateway-specific source and destination addresses, creating a unique identifier for each device and inserting a packet shim with routing path information into packet headers for transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunneling technologies are used to transmit data through layered security systems, then security is improved, but addressing ambiguity occurs due to IP address conflicts between different enterprises

Engineering Contradiction:
ImprovesecurityVSAvoidaddressing information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements nested addressing by embedding the original IP address tuple within an augmented address structure. The OAA format nests the original 4-tuple (protocol, source IP, destination IP, source port, destination port) inside a larger address framework that includes enterprise-specific and gateway-specific identifiers, allowing the original addressing information to be preserved while adding the necessary context for unique identification across multi-tenant networks.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent transitions from traditional 4-tuple addressing to an augmented address space by adding new dimensions: enterprise identifier and gateway identifier. This dimensional expansion transforms the addressing system from a flat structure to a hierarchical multi-dimensional structure, enabling unique identification of packets across multiple enterprises while maintaining compatibility with existing IP addressing schemes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If each enterprise uses independent IP sub-networks, then enterprise autonomy is maintained, but managing multi-tenant networks becomes difficult due to address conflicts

Engineering Contradiction:
Improveenterprise autonomyVSAvoidnetwork management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the network addressing system into distinct hierarchical layers: enterprise identifier, gateway identifier, and original IP tuple. This segmentation allows each enterprise to maintain its own IP sub-network independently while the upper layers provide the necessary context for global uniqueness. The segmentation enables multi-tenant network management by clearly separating enterprise autonomy from global addressing requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The augmented address structure acts as an intermediary layer between independent enterprise IP sub-networks. It mediates the conflict between enterprise autonomy and global addressing by providing a translation mechanism that preserves original IP addresses while adding enterprise and gateway context, enabling seamless routing across multi-tenant networks without requiring changes to enterprise internal addressing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If packet encapsulation is used for tunneling, then secure transmission is achieved, but packets with same addressing information cannot be distinguished after decapsulation

Engineering Contradiction:
Improvesecure transmissionVSAvoidpacket identification
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by augmenting the address with enterprise and gateway identifiers before the encapsulation and decapsulation process. This pre-established contextual information is embedded in the OAA structure, ensuring that when packets are decapsulated, the augmented address remains intact and provides sufficient information for precise packet identification and routing, eliminating addressing ambiguity.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If conventional layered security systems are implemented, then security measures are in place, but processing inefficiencies and resource requirements increase

Engineering Contradiction:
Improvesecurity measuresVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The augmented address structure serves multiple functions simultaneously: it provides unique packet identification, enables routing decisions, carries enterprise context, and maintains compatibility with existing IP protocols. This multi-functionality consolidates what would otherwise require separate handling mechanisms, improving processing efficiency while maintaining comprehensive security measures across the layered system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11818035B2Augmented routing of data
Publication Date: 2023.11.14 OPENVPN INC
  • US11818035B2 patent drawing
  • US11818035B2 patent drawing

AI summary

Disclosed herein are systems and methods for creating an ultra-lightweight multi-tenant network virtualization model by augmenting an OSI layer 4 tuple (protocol, source IP address, destination IP address, source port, destination port) with additional private gateway-specific source and destination augmented addresses. A unique OpenVPN Augmented Address (OAA) may be created and assigned to each device on a network such as a mesh-linked system. This OAA may form part of a packet shim created with routing path information for both the source and the destination resources. Once created, the shim may be inserted into a packet header for transmission. Once the initial packet is transmitted, each hop creates its own resources for managing transmission of subsequent packets in this session. The packet shim operates to establish a communications session on layer 4 (Transport) between the requestor and the target resource which is intermediate-device agnostic.