Shared Virtualized Service for Overlapping IP Address VPNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies face challenges in supporting multiple private virtual networks with overlapping IP addresses, requiring multiple NAT devices and infrastructure, which is costly and difficult to manage, and limits the ability to provide value-added services like message routing and content-based networking across different VPNs.

Innovation Solution

Implementing a virtualized service at Layer 7 simultaneously to multiple independent virtual private networks using shared infrastructure, with logically separate routing tables and a single logical instance of the service, allowing communication between VPNs based on pre-established entitlements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple NAT devices are deployed to support overlapping IP addresses in multiple VPNs, then IP address translation capability is improved, but device complexity and infrastructure cost increase

Engineering Contradiction:
ImproveIP address translation capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple NAT device functions into a single shared infrastructure platform that can handle overlapping IP addresses across multiple VPNs simultaneously. The virtualized service consolidates what would otherwise require separate NAT devices for each VPN, reducing overall infrastructure complexity while maintaining the necessary address translation capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared infrastructure is designed to perform multiple functions: it provides NAT capabilities for multiple different VPNs, supports overlapping IP address spaces, and enables value-added services across VPN boundaries. This universal platform replaces the need for dedicated NAT devices for each VPN, reducing device complexity while improving adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate NAT devices are used for each VPN, then IP address management is improved, but ease of operation and management deteriorate

Engineering Contradiction:
ImproveIP address management capabilityVSAvoidinfrastructure management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges the management of multiple VPN IP address spaces into a single unified management plane. The shared infrastructure provides centralized control for configuring and managing NAT rules across multiple VPNs, eliminating the need to separately manage each NAT device while maintaining proper isolation and addressing for each VPN.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If a common infrastructure supports multiple VPNs with overlapping addresses, then infrastructure cost is reduced, but the ability to handle overlapping IP addresses deteriorates

Engineering Contradiction:
Improveinfrastructure scaleVSAvoidoverlapping IP address support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the shared infrastructure into logically separate routing tables and address spaces for each VPN. This allows the physical infrastructure to be shared and cost-effective while the logical segmentation maintains the ability to handle overlapping IP addresses by keeping each VPN's address space isolated and properly routed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the shared physical infrastructure and the multiple VPNs. This virtualization layer provides the necessary address translation and routing functions, enabling the common infrastructure to support overlapping IP addresses by mediating between different VPN address spaces and the underlying network.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If NAT is used for value-added services, then service delivery capability is improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improvevalue-added service deliveryVSAvoidservice infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines NAT functionality with value-added services into a unified shared infrastructure. Instead of requiring separate NAT devices and separate service delivery mechanisms, the virtualized platform integrates both functions, reducing infrastructure complexity while maintaining the ability to deliver value-added services across multiple VPNs.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7889738B2Shared application inter-working with virtual private networks
Publication Date: 2011.02.15 SOLACE CORP
  • US7889738B2 patent drawing
  • US7889738B2 patent drawing
  • US7889738B2 patent drawing

AI summary

A method of providing a shared application infrastructure simultaneously to multiple independent virtual private networks with potentially overlapping IP addresses, involves connecting to an underlying layer 1, 2 or 3 virtual private network offering one or more virtual private networks, determining which virtual private network traffic is being received from or sent into, maintaining logically separate routing tables per VPN to allow overlapping addresses, and providing an application which provides a logical instance of the service to each VPN.