CE Network Element VRF Segregation for IPSec VPN Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing customer-provisioned IPSec VPNs face scalability issues due to the need for multiple security associations between CE devices, which complicates traffic segregation and management as the number of VPN sites increases.

Innovation Solution

Implementing multiple Virtual Routing and Forwarding (VRF) processes on CE network elements, with a single MPBGP peering session to the GCKS/RR for secure data channels, and applying per-VRF import policies to segregate traffic, allowing for secure and efficient exchange of routing information across VPNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security associations are established between CE devices for customer-provisioned IPSec VPNs, then traffic segregation between different VPNs is achieved, but the complexity of managing security associations increases significantly as the number of VPN sites grows

Engineering Contradiction:
Improvetraffic segregationVSAvoidsecurity association management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security association management by introducing Virtual Routing and Forwarding (VRF) instances that isolate routing and forwarding tables for different VPNs. Each VRF maintains separate security associations, allowing traffic segregation while reducing the management overhead by organizing SAs in isolated logical containers rather than managing all SAs globally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a Key Server as an intermediary that automates the establishment and management of security associations. The Key Server mediates between CE devices, automatically generating and distributing cryptographic keys and security parameters, thereby reducing the manual configuration and management complexity of security associations as VPN sites scale.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If multiple MPBGP peering sessions are established between CE devices to exchange routing information for multiple VPNs, then complete routing information exchange is achieved, but the control channel complexity and resource consumption increase

Engineering Contradiction:
Improverouting information exchangeVSAvoidcontrol channel management
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple MPBGP peering sessions into a single peering session between the CE device and the Key Server. This single control channel carries routing information for multiple VPNs by utilizing VRF-specific routing tables and route targets, thereby reducing control channel complexity while maintaining complete routing information exchange across all VPNs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single MPBGP peering session is designed with multi-functionality to handle routing information for multiple different VPNs simultaneously. The Key Server and CE device use universal routing protocols and data structures that can accommodate multiple VRFs, allowing one control channel to perform the work of multiple dedicated channels while maintaining proper routing information segregation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If a single secure control channel is used for routing information exchange across multiple VPNs, then control channel complexity is reduced, but traffic segregation and security between different VPNs may be compromised

Engineering Contradiction:
Improvecontrol channel managementVSAvoidtraffic segregation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the routing information within the single control channel by implementing separate Virtual Routing and Forwarding (VRF) instances for different VPNs. Each VRF maintains its own routing table and forwarding information base, ensuring that routing information for one VPN is logically isolated from others even though they share the same physical control channel. This is enforced through route targets and import/export policies that prevent cross-VPN route leakage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning specific security attributes and routing policies to each VRF instance individually. Each VPN's routing information is tagged with unique route targets and imported only into the appropriate VRF based on local quality filters. This ensures that while the control channel is shared, the routing information exchange maintains proper segregation and security boundaries for each individual VPN.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7643488B2Method and apparatus for supporting multiple customer provisioned IPSec VPNs
Publication Date: 2010.01.05 PULSELINK SYSTEMS LLC
  • US7643488B2 patent drawing
  • US7643488B2 patent drawing
  • US7643488B2 patent drawing

AI summary

Customer Traffic may be segregated using customer provisioned IPSec VPNs implemented using group security association for IPSec tunnels, by causing the CE network element to implement multiple VRFs for the several VPNs, each of which may be used for a different segment of the customer's traffic. The CE network element may implement a single MPBGP peering session with the GCKS/RR for all VPNs, and may establish secure data channels for each of the VPNs based on the group security associations for each of the VPNs. Although a common MPBGP peering session may be used, routing information for the several VRFs may be separated by applying per-VRF import policies at the CE, so that each VPN only has access to routes intended to be advertised to that VPN.