Distributed Tunnel Aggregation for MSR Capacity Scaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network service providers face capacity limitations in managing distributed denial of service (DDoS) attacks due to the limited number of encapsulation tunnels that can be supported by managed security routers (MSRs), leading to increased latency and burden on network resources.
Innovation Solution
The implementation of tunnel aggregator devices distributed across the provider's network, which receive clean return traffic from MSRs and route it to customer endpoints via encapsulation tunnels, alleviating MSR capacity constraints and enabling efficient scaling of network capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If managed security routers (MSRs) directly establish encapsulation tunnels to customer endpoints, then security filtering and traffic management are integrated, but the number of supported tunnels is limited and latency increases
Solution Approach 1:
The system segments tunnel management functions by introducing dedicated tunnel aggregator devices that handle encapsulation/decapsulation operations. This separates the tunnel establishment and maintenance functions from the MSRs, allowing MSRs to focus on security filtering while tunnel aggregators manage the tunnel infrastructure. The segmentation enables multiple tunnels to be distributed across multiple aggregator devices, increasing overall tunnel capacity and reducing latency.
Solution Approach 2:
Tunnel aggregator devices serve as intermediary components between MSRs and customer endpoints. These aggregators receive clean traffic from MSRs, encapsulate it, and forward it through the appropriate tunnels to customer networks. This intermediary role allows the system to scale tunnel capacity independently of MSR capacity, as aggregators can be deployed in multiple locations and configured to handle specific tunnel traffic patterns.
2Reliability
If MSRs handle all encapsulation tunnel operations, then security and routing are centralized, but network capacity scaling becomes costly and complex
Solution Approach 1:
The invention extracts the encapsulation/decapsulation functionality from MSRs and places it in dedicated tunnel aggregator devices. This extraction allows the MSR to maintain its primary security filtering function with high reliability, while the tunnel aggregation function can be independently scaled by adding more aggregator devices. The separation enables the network to scale capacity by deploying additional aggregators without modifying or replacing expensive MSR hardware.
Solution Approach 2:
Tunnel aggregator devices provide multi-functionality by handling both encapsulation/decapsulation operations and serving as routing points for clean traffic. A single aggregator device can serve multiple customer networks and work with multiple MSRs, providing a universal platform for tunnel management that enhances network adaptability and scalability while maintaining security through the MSR-aggregator architecture.
Data Source
AI summary
One or more encapsulation tunnel aggregator devices are distributed across a provider's network. The tunnel aggregator device(s) may receive clean return traffic from a managed security router (MSR) and route the traffic to a customer endpoint via an encapsulation tunnel, thereby reducing the routing burden on the MSR. The tunnel aggregator device(s) may be deployed in physical or logical proximity to an MSR, which may facilitate the routing of return traffic from the MSR to the tunnel aggregator device(s), for ultimate transmission to a customer endpoint. In other examples, a tunnel aggregator device may be deployed in proximity to other provider network resources, such as a provider edge router.


