Shared Virtualized Service for Overlapping IP Address VPNs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN technologies face challenges in supporting multiple private virtual networks with overlapping IP addresses, requiring multiple NAT devices and infrastructure, which is costly and difficult to manage, and limits the ability to provide value-added services like message routing and content-based networking across different VPNs.
Innovation Solution
Implementing a virtualized service at Layer 7 simultaneously to multiple independent virtual private networks using shared infrastructure, with logically separate routing tables and a single logical instance of the service, allowing communication between VPNs based on pre-established entitlements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple NAT devices are deployed to support overlapping IP addresses in multiple VPNs, then IP address translation capability is improved, but device complexity and infrastructure cost increase
Solution Approach 1:
The patent combines multiple NAT device functions into a single shared infrastructure platform that can handle overlapping IP addresses across multiple VPNs simultaneously. The virtualized service consolidates what would otherwise require separate NAT devices for each VPN, reducing overall infrastructure complexity while maintaining the necessary address translation capabilities.
Solution Approach 2:
The shared infrastructure is designed to perform multiple functions: it provides NAT capabilities for multiple different VPNs, supports overlapping IP address spaces, and enables value-added services across VPN boundaries. This universal platform replaces the need for dedicated NAT devices for each VPN, reducing device complexity while improving adaptability.
2Adaptability or versatility
If separate NAT devices are used for each VPN, then IP address management is improved, but ease of operation and management deteriorate
Solution Approach 1:
The patent merges the management of multiple VPN IP address spaces into a single unified management plane. The shared infrastructure provides centralized control for configuring and managing NAT rules across multiple VPNs, eliminating the need to separately manage each NAT device while maintaining proper isolation and addressing for each VPN.
3Device complexity
If a common infrastructure supports multiple VPNs with overlapping addresses, then infrastructure cost is reduced, but the ability to handle overlapping IP addresses deteriorates
Solution Approach 1:
The patent segments the shared infrastructure into logically separate routing tables and address spaces for each VPN. This allows the physical infrastructure to be shared and cost-effective while the logical segmentation maintains the ability to handle overlapping IP addresses by keeping each VPN's address space isolated and properly routed.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the shared physical infrastructure and the multiple VPNs. This virtualization layer provides the necessary address translation and routing functions, enabling the common infrastructure to support overlapping IP addresses by mediating between different VPN address spaces and the underlying network.
4Adaptability or versatility
If NAT is used for value-added services, then service delivery capability is improved, but device complexity and management difficulty increase
Solution Approach 1:
The patent combines NAT functionality with value-added services into a unified shared infrastructure. Instead of requiring separate NAT devices and separate service delivery mechanisms, the virtualized platform integrates both functions, reducing infrastructure complexity while maintaining the ability to deliver value-added services across multiple VPNs.
Data Source
AI summary
A method of providing a shared application infrastructure simultaneously to multiple independent virtual private networks with potentially overlapping IP addresses, involves connecting to an underlying layer 1, 2 or 3 virtual private network offering one or more virtual private networks, determining which virtual private network traffic is being received from or sent into, maintaining logically separate routing tables per VPN to allow overlapping addresses, and providing an application which provides a logical instance of the service to each VPN.


