Distributed Tunnel Aggregation for MSR Capacity Scaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network service providers face capacity limitations in managing distributed denial of service (DDoS) attacks due to the limited number of encapsulation tunnels that can be supported by managed security routers (MSRs), leading to increased latency and burden on network resources.

Innovation Solution

The implementation of tunnel aggregator devices distributed across the provider's network, which receive clean return traffic from MSRs and route it to customer endpoints via encapsulation tunnels, alleviating MSR capacity constraints and enabling efficient scaling of network capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If managed security routers (MSRs) directly establish encapsulation tunnels to customer endpoints, then security filtering and traffic management are integrated, but the number of supported tunnels is limited and latency increases

Engineering Contradiction:
Improvetunnel management complexityVSAvoidtraffic delivery latency
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system segments tunnel management functions by introducing dedicated tunnel aggregator devices that handle encapsulation/decapsulation operations. This separates the tunnel establishment and maintenance functions from the MSRs, allowing MSRs to focus on security filtering while tunnel aggregators manage the tunnel infrastructure. The segmentation enables multiple tunnels to be distributed across multiple aggregator devices, increasing overall tunnel capacity and reducing latency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Tunnel aggregator devices serve as intermediary components between MSRs and customer endpoints. These aggregators receive clean traffic from MSRs, encapsulate it, and forward it through the appropriate tunnels to customer networks. This intermediary role allows the system to scale tunnel capacity independently of MSR capacity, as aggregators can be deployed in multiple locations and configured to handle specific tunnel traffic patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MSRs handle all encapsulation tunnel operations, then security and routing are centralized, but network capacity scaling becomes costly and complex

Engineering Contradiction:
Improvesecurity filtering reliabilityVSAvoidnetwork capacity scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention extracts the encapsulation/decapsulation functionality from MSRs and places it in dedicated tunnel aggregator devices. This extraction allows the MSR to maintain its primary security filtering function with high reliability, while the tunnel aggregation function can be independently scaled by adding more aggregator devices. The separation enables the network to scale capacity by deploying additional aggregators without modifying or replacing expensive MSR hardware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Tunnel aggregator devices provide multi-functionality by handling both encapsulation/decapsulation operations and serving as routing points for clean traffic. A single aggregator device can serve multiple customer networks and work with multiple MSRs, providing a universal platform for tunnel management that enhances network adaptability and scalability while maintaining security through the MSR-aggregator architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240146576A1Distributed tunnel termination
Publication Date: 2024.05.02 LEVEL 3 COMMUNICATIONS LLC
  • US20240146576A1 patent drawing
  • US20240146576A1 patent drawing
  • US20240146576A1 patent drawing

AI summary

One or more encapsulation tunnel aggregator devices are distributed across a provider's network. The tunnel aggregator device(s) may receive clean return traffic from a managed security router (MSR) and route the traffic to a customer endpoint via an encapsulation tunnel, thereby reducing the routing burden on the MSR. The tunnel aggregator device(s) may be deployed in physical or logical proximity to an MSR, which may facilitate the routing of return traffic from the MSR to the tunnel aggregator device(s), for ultimate transmission to a customer endpoint. In other examples, a tunnel aggregator device may be deployed in proximity to other provider network resources, such as a provider edge router.