MPLS VPN Traffic Separation via Virtual Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network providers face challenges in providing network application services, such as application acceleration, to virtual private networks (VPNs) with overlapping address spaces, which can lead to performance issues due to geographical distances and shared physical resources.

Innovation Solution

The implementation of a system that associates packets and flows with VPNs based on local area networks (LANs) or virtual LANs (VLANs), using provider edge routers and application complexes to convert and route packets, thereby keeping traffic separate and accelerating applications by caching data and responding to messages closer to the source.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MPLS is used to provide VPN services over shared physical networks, then network resource utilization and service scalability are improved, but traffic separation and application performance are worsened due to geographical distances and shared resources

Engineering Contradiction:
Improveservice scalabilityVSAvoidtraffic separation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments VPN traffic by creating separate virtual switching instances for each VPN, allowing multiple VPNs to share physical infrastructure while maintaining logical traffic separation. This enables service scalability through resource sharing while preserving traffic isolation through virtualization boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization dimension by implementing virtual switching instances that operate alongside physical network infrastructure. This additional layer enables simultaneous achievement of traffic separation (through virtual instance isolation) and resource utilization (through physical resource sharing across instances).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of time

If application complexes are placed geographically closer to VPN sources, then response time and application performance are improved, but infrastructure complexity and deployment cost are worsened

Engineering Contradiction:
Improveresponse timeVSAvoidinfrastructure complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent creates universal virtual switching instances that can serve multiple VPNs and application complexes across different geographical locations. A single virtual switching instance can be instantiated at multiple sites, providing consistent traffic separation and application acceleration functionality without requiring unique complex infrastructure at each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables replication of virtual switching instances across geographical locations. Instead of deploying entirely new complex infrastructure systems at each site, the virtual switching functionality can be copied and instantiated at different locations, reducing deployment complexity while achieving geographical proximity benefits.

Inventive Principle:
Principle #26Copying

3Reliability

If virtual switching instances are used to separate VPN traffic, then traffic isolation and security are improved, but processing overhead and system complexity are worsened

Engineering Contradiction:
Improvetraffic isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple VPN traffic streams into a single virtual switching instance when appropriate, reducing the number of separate processing contexts needed. By combining traffic handling for multiple VPNs into one instance, the system achieves traffic isolation through virtualization while reducing overall system complexity compared to maintaining completely separate physical infrastructure for each VPN.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8588232B2Multiprotocol label switching (MPLS) interface with virtual private network (VPN) application
Publication Date: 2013.11.19 VERIZON PATENT & LICENSING INC
  • US8588232B2 patent drawing
  • US8588232B2 patent drawing
  • US8588232B2 patent drawing

AI summary

A method comprising receiving, from a first node, a first packet at a network application server via a first local area network (LAN); receiving, from a second node, a second packet at the network application server via a second LAN; associating the first packet with a first VPN based on receiving the first packet via the first LAN; and associating the second packet with a second VPN based on reception of the second packet via the second LAN, wherein the first VPN and the second VPN include overlapping network address spaces.