MPLS VPN Traffic Separation via Virtual Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network providers face challenges in providing network application services, such as application acceleration, to virtual private networks (VPNs) with overlapping address spaces, which can lead to performance issues due to geographical distances and shared physical resources.
Innovation Solution
The implementation of a system that associates packets and flows with VPNs based on local area networks (LANs) or virtual LANs (VLANs), using provider edge routers and application complexes to convert and route packets, thereby keeping traffic separate and accelerating applications by caching data and responding to messages closer to the source.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If MPLS is used to provide VPN services over shared physical networks, then network resource utilization and service scalability are improved, but traffic separation and application performance are worsened due to geographical distances and shared resources
Solution Approach 1:
The patent segments VPN traffic by creating separate virtual switching instances for each VPN, allowing multiple VPNs to share physical infrastructure while maintaining logical traffic separation. This enables service scalability through resource sharing while preserving traffic isolation through virtualization boundaries.
Solution Approach 2:
The patent introduces a virtualization dimension by implementing virtual switching instances that operate alongside physical network infrastructure. This additional layer enables simultaneous achievement of traffic separation (through virtual instance isolation) and resource utilization (through physical resource sharing across instances).
2Loss of time
If application complexes are placed geographically closer to VPN sources, then response time and application performance are improved, but infrastructure complexity and deployment cost are worsened
Solution Approach 1:
The patent creates universal virtual switching instances that can serve multiple VPNs and application complexes across different geographical locations. A single virtual switching instance can be instantiated at multiple sites, providing consistent traffic separation and application acceleration functionality without requiring unique complex infrastructure at each location.
Solution Approach 2:
The patent enables replication of virtual switching instances across geographical locations. Instead of deploying entirely new complex infrastructure systems at each site, the virtual switching functionality can be copied and instantiated at different locations, reducing deployment complexity while achieving geographical proximity benefits.
3Reliability
If virtual switching instances are used to separate VPN traffic, then traffic isolation and security are improved, but processing overhead and system complexity are worsened
Solution Approach 1:
The patent merges multiple VPN traffic streams into a single virtual switching instance when appropriate, reducing the number of separate processing contexts needed. By combining traffic handling for multiple VPNs into one instance, the system achieves traffic isolation through virtualization while reducing overall system complexity compared to maintaining completely separate physical infrastructure for each VPN.
Data Source
AI summary
A method comprising receiving, from a first node, a first packet at a network application server via a first local area network (LAN); receiving, from a second node, a second packet at the network application server via a second LAN; associating the first packet with a first VPN based on receiving the first packet via the first LAN; and associating the second packet with a second VPN based on reception of the second packet via the second LAN, wherein the first VPN and the second VPN include overlapping network address spaces.


