Multi-Tunnel VPN for QoS Differentiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual Private Networks (VPNs) face challenges in providing Quality-of-Service (QoS) features due to encryption that prevents transport networks from inspecting application messages, resulting in all VPN traffic being assigned to a single QoS level, which limits the ability to differentiate service levels based on application types or properties.
Innovation Solution
Establishing multiple VPN tunnels between VPN endpoints, each associated with a different QoS bearer, and applying VPN policies at the endpoints to assign application data to specific tunnels, with indicators specifying the QoS bearer for encapsulation, allowing for differentiated QoS levels within the VPN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to secure VPN traffic, then security is improved, but the transport network cannot inspect application messages to provide differentiated QoS levels
Solution Approach 1:
The patent segments the single VPN tunnel into multiple tunnels, each associated with a different QoS bearer. This allows the transport network to provide differentiated QoS levels to different application types while maintaining security through encryption in each tunnel. The segmentation principle resolves the contradiction by enabling both security (through encrypted tunnels) and QoS differentiation (through separate tunnels for different QoS bearers).
Solution Approach 2:
The patent introduces an intermediary mechanism at the VPN endpoint that inspects application messages before encryption and assigns them to appropriate VPN tunnels based on QoS requirements. This intermediary function allows the system to differentiate QoS levels without compromising the encryption security, as the inspection and assignment occur before the encryption layer.
2Device complexity
If all VPN traffic is assigned to a single QoS level, then device complexity is reduced, but the ability to provide differentiated service levels based on application types is lost
Solution Approach 1:
The patent segments QoS configuration into multiple VPN tunnels, each associated with a specific QoS bearer. This segmentation allows differentiated service levels for different application types while managing complexity through standardized tunnel-QoS bearer associations. The complexity is controlled by establishing multiple tunnels during VPN setup rather than configuring complex policies for each application type dynamically.
Solution Approach 2:
The patent performs preliminary action by establishing multiple VPN tunnels associated with different QoS bearers during the VPN setup phase. This preliminary configuration allows the system to provide differentiated QoS levels without requiring complex real-time decision-making, as the tunnel-QoS bearer mappings are pre-established.
Data Source
AI summary
Systems and methods for controlling Quality-of-Service (“QoS”) in a Virtual Private Network (“VPN”) in a transport network providing a plurality of QoS bearers. The methods involve: establishing, between two VPN endpoints, a plurality of VPN tunnels through the transport network, including at least a default VPN tunnel associated with a first QoS bearer and an alternate VPN tunnel associated with a second QoS bearer; receiving and analyzing a data block; applying a VPN policy to assign the data block to either default VPN tunnel or alternate VPN tunnel; and encapsulating the data block in a transport data block including at least one indicator. The indicator specifies whether the transport data block is to be communicated by the transport network using the first QoS bearer or second QoS bearer.


