Dynamic SIA-IPSec Mapping for VPN Service Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Service Insertion Architecture (SIA) and Virtual Private Network (VPN) technologies faces challenges due to duplication of tasks, inefficiencies, and complexities in forwarding packets between different forwarding domains, leading to difficulties in providing differentiated services to VPN users, especially when IPSec tunnels are involved.

Innovation Solution

The method involves dynamically mapping SIA services to IPSec VPN tunnel users during authentication, using authentication logic to request and receive mapping information, and selectively providing differentiated services by forwarding IPSec packets to appropriate SIA service nodes based on the mapping information, thereby integrating SIA and VPN frameworks for improved traffic forwarding and service delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SIA and VPN are integrated by maintaining separate forwarding domains, then each domain can operate independently, but packet forwarding becomes complex and inefficient

Engineering Contradiction:
Improveindependent operation capabilityVSAvoidpacket forwarding complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges SIA and VPN forwarding domains by establishing that an SIA service path is tunneled within the VPN tunnel. The service path header is inserted into the VPN packet, allowing both domains to operate independently in terms of policy control while sharing the same physical infrastructure for packet forwarding, thereby reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements nesting by placing the SIA service path inside the VPN tunnel structure. The service path header is embedded within the VPN packet, creating a nested architecture where the SIA service layer is contained within the VPN transport layer, enabling efficient packet forwarding without requiring separate independent paths.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Adaptability or versatility

If mapping information is requested during authentication, then service differentiation can be achieved, but authentication time increases

Engineering Contradiction:
Improveservice differentiation capabilityVSAvoidauthentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring mapping relationships between VPN users and SIA service paths before actual authentication occurs. The authentication logic contains pre-established mapping information that can be quickly retrieved and applied during authentication, avoiding the need for complex real-time mapping requests and reducing authentication time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating a simplified authentication flow where the authentication logic copies relevant mapping information from pre-established configurations rather than performing complex real-time queries. This allows service differentiation to be maintained while significantly reducing the time required for authentication processing.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If service paths are instantiated for each user, then differentiated services can be provided, but system resources are consumed

Engineering Contradiction:
Improveservice differentiation capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements universality by designing the service path instantiation mechanism to serve multiple users simultaneously. The service path is instantiated once and then shared by multiple VPN users who are mapped to this service path, allowing differentiated services to be provided without requiring separate service path instances for each user, thereby reducing system resource consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8650618B2Integrating service insertion architecture and virtual private network
Publication Date: 2014.02.11 CISCO TECHNOLOGY INC
  • US8650618B2 patent drawing
  • US8650618B2 patent drawing
  • US8650618B2 patent drawing

AI summary

Apparatus, methods, and other embodiments associated with providing service insertion architecture (SIA) differentiated services in a virtual private network (VPN) environment are described. Embodiments may provision an authentication, authorization, and accounting (AAA) server with user-to-SIA service-context mapping information. With the AAA server provisioned, embodiments may acquire, in an IPSec VPN hub, during IPSec tunnel user authentication, from the AAA server, the user-to-SIA service-context mapping information. With the mapping information available, embodiments may dynamically map an SIA service to an IPSec VPN tunnel user based on the service information acquired from the Service Broker or Pseudo-Service Broker. The dynamic mapping facilitates providing differentiated services in the SIA by facilitating forwarding an IPSec packet received on the IPSec VPN tunnel from the user to a service node associated with the SIA service based, at least in part, on the IPSec SADB entry modified using the service information.