Layered VPN Model Using Non-Specific Objects for Flexible Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network modeling technologies are limited by their specificity to particular network types or protocols, making them inflexible and requiring significant efforts to update and maintain as new features are added, which restricts their applicability across different networks and protocols.
Innovation Solution
A method and apparatus for logically representing and analyzing Virtual Private Networks (VPNs) using a plurality of functional representation layers, where physical and logical components are represented as configuration non-specific objects, allowing for horizontal and vertical relationships among layers, enabling flexible modeling and analysis across various VPNs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network models are designed specifically for a particular network type or protocol, then the model can accurately represent that specific network, but the model becomes inflexible and requires significant efforts to update and maintain when new features are added or when applied to different networks
Solution Approach 1:
The network model is segmented into multiple hierarchical layers (service layer, connection layer, transport layer, network layer, data link layer, physical layer), where each layer represents specific network components and functions. This segmentation allows the model to maintain detailed accuracy at each layer while enabling flexible reconfiguration by modifying individual layers without affecting the entire model structure.
Solution Approach 2:
The layered model structure serves multiple functions: it can represent different network types (VPN, MPLS, IP networks), support various protocols, and accommodate new features by adding or modifying layers. The same fundamental layered framework is universally applicable across diverse network scenarios, eliminating the need for completely redesigning models for different network types.
2Measurement precision
If network models are designed specifically for a particular network type or protocol, then the model can accurately represent that specific network, but additional efforts are required to update and maintain the models as new features are added
Solution Approach 1:
By segmenting the model into independent layers, maintenance efforts are reduced because updates can be confined to specific layers rather than requiring comprehensive model revisions. Each layer can be maintained and updated independently based on the specific network features being modified.
Solution Approach 2:
The layered model structure is dynamic and adaptable, allowing layers to be added, removed, or modified based on evolving network requirements. This dynamic structure simplifies maintenance as the model can evolve with the network without requiring complete redesigns.
3Reliability
If a network model includes detailed knowledge of underlying elements, then the model can provide comprehensive analysis, but the model becomes more complex and less adaptable to different networks
Solution Approach 1:
The model segments detailed network elements into appropriate layers, maintaining comprehensive analysis capability by distributing detail across layers while preventing excessive complexity at any single level. Each layer captures necessary details for its specific function without duplicating information from other layers.
Solution Approach 2:
The model transitions from a flat, monolithic structure to a multi-dimensional layered architecture. This dimensional change allows comprehensive representation of network elements by organizing them across multiple layers, thereby managing complexity through structured distribution rather than concentrated detail.
Data Source
AI summary
A method, apparatus and computer-program product for logically representing and analyzing a Virtual Private Network (VPN) in a plurality of functional representation layers is disclosed. The method, which is typical of the invention, comprises the steps of representing selected physical and logical components of said VPN as a plurality of configuration non-specific objects determined for each said functional representation layers, organizing selected ones of said objects within selected ones of said functional representation layers, wherein said object are selected from the group consisting of: VPNService, ServiceConnectionPath, ForwarderEndpoint, TunnelGroup, Tunnel, TunnelHop, TunnelIn/Out, SignalingProtocolEndpoint, SignalingProtocollSession and SignalingProtocolService, representing relationships among said physical and logical components as configuration non-specific representations within and among said functional representation layers, wherein Endpoint objects provide communication among said functional representation layers, which are among a group of Service, Service connection, Transport and Protocol layers.


