MPLS VPN Access Router Protection via Label Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Fast Reroute techniques in MPLS VPN networks fail to provide adequate protection for access routers, particularly in terms of scalability and deterministic rerouting, as they require extensive tunnel meshing and cannot handle failures quickly enough to meet the availability demands of real-time services like VoIP and telemedicine.
Innovation Solution
A system and method that involves a core router detecting failures and rerouting traffic through a back-up access router by replacing nominal VPN labels with back-up labels in MPLS packets, allowing traffic to bypass the nominal access router using pre-configured tunnels, with mechanisms to manage label spaces and avoid collisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS Fast Reroute mode with end-to-end MPLS-TE primary tunnels is used to protect access routers, then deterministic rerouting performance is achieved, but the number of tunnels required becomes proportional to the square of the number of access routers, making it unsuitable for large networks
Solution Approach 1:
The invention segments the protection mechanism by introducing intermediate protector routers that handle label replacement functions. Instead of requiring every access router to have direct backup tunnels to every other access router, the system divides the protection function between nominal access routers, protector routers, and back-up access routers. This segmentation reduces the tunnel complexity from O(n²) to a manageable level while maintaining deterministic rerouting capability.
Solution Approach 2:
The invention introduces protector routers as intermediary elements between nominal access routers and back-up access routers. These protector routers perform the critical function of replacing nominal VPN labels with back-up VPN labels during failure scenarios. This intermediary mechanism enables fast rerouting without requiring direct tunnel connections between all pairs of access routers, thus resolving the scalability issue.
2Device complexity
If IP Fast Reroute technique is used to protect access routers, then scalability is improved, but deterministic rerouting performance within 100 milliseconds cannot be guaranteed
Solution Approach 1:
The invention applies preliminary action by pre-configuring back-up tunnels and pre-installing back-up VPN labels in protector routers before failures occur. When a nominal access router fails, the rerouting action is already prepared and can be executed immediately by switching to the pre-configured back-up path, ensuring deterministic performance within 100 milliseconds while maintaining scalability.
Solution Approach 2:
The invention uses copying by creating back-up VPN labels that replicate the functionality of nominal VPN labels. Instead of requiring complex route calculations during failure, the system copies the label replacement function to protector routers, which can immediately substitute nominal labels with back-up labels, enabling fast and scalable rerouting.
3Reliability
If MPLS-TE tunnels are established between client routers to protect access routers, then protection capability is achieved, but the number of tunnels becomes proportional to the square of the number of client routers, limiting practical applicability
Solution Approach 1:
The invention extracts the label replacement function from the access routers themselves and relocates it to dedicated protector routers. This extraction allows the system to achieve protection capability without requiring each access router to establish extensive tunnel connections. The protector routers handle the complex label management, simplifying the overall tunnel structure while maintaining protection capability.
Data Source
AI summary
A system for securing the access to a destination of a virtual private network (VPNA) connected to a nominal access router (PE3) includes at least one core router (P2) adapted to: detect a failure affecting communication with the nominal access router (PE3); and switch the traffic to a protector access router (PE6) in a back-up tunnel bypassing the nominal access router (PE3). The protector access router (PE6) is adapted: to replace, in an MPLS packet, a nominal VPN label specific to the nominal access router (PE3) by a back-up VPN label specific to a back-up access router (PE4) connected to that destination; and to redirect said packet to the back-up access router (PE4) in a tunnel bypassing the nominal access router (PE3).

