Dynamic SIA-IPSec Mapping for VPN Service Differentiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of Service Insertion Architecture (SIA) and Virtual Private Network (VPN) technologies faces challenges due to duplication of tasks, inefficiencies, and complexities in forwarding packets between different forwarding domains, leading to difficulties in providing differentiated services to VPN users, especially when IPSec tunnels are involved.
Innovation Solution
The method involves dynamically mapping SIA services to IPSec VPN tunnel users during authentication, using authentication logic to request and receive mapping information, and selectively providing differentiated services by forwarding IPSec packets to appropriate SIA service nodes based on the mapping information, thereby integrating SIA and VPN frameworks for improved traffic forwarding and service delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SIA and VPN are integrated by maintaining separate forwarding domains, then each domain can operate independently, but packet forwarding becomes complex and inefficient
Solution Approach 1:
The patent merges SIA and VPN forwarding domains by establishing that an SIA service path is tunneled within the VPN tunnel. The service path header is inserted into the VPN packet, allowing both domains to operate independently in terms of policy control while sharing the same physical infrastructure for packet forwarding, thereby reducing overall system complexity.
Solution Approach 2:
The patent implements nesting by placing the SIA service path inside the VPN tunnel structure. The service path header is embedded within the VPN packet, creating a nested architecture where the SIA service layer is contained within the VPN transport layer, enabling efficient packet forwarding without requiring separate independent paths.
2Adaptability or versatility
If mapping information is requested during authentication, then service differentiation can be achieved, but authentication time increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring mapping relationships between VPN users and SIA service paths before actual authentication occurs. The authentication logic contains pre-established mapping information that can be quickly retrieved and applied during authentication, avoiding the need for complex real-time mapping requests and reducing authentication time.
Solution Approach 2:
The patent uses copying by creating a simplified authentication flow where the authentication logic copies relevant mapping information from pre-established configurations rather than performing complex real-time queries. This allows service differentiation to be maintained while significantly reducing the time required for authentication processing.
3Adaptability or versatility
If service paths are instantiated for each user, then differentiated services can be provided, but system resources are consumed
Solution Approach 1:
The patent implements universality by designing the service path instantiation mechanism to serve multiple users simultaneously. The service path is instantiated once and then shared by multiple VPN users who are mapped to this service path, allowing differentiated services to be provided without requiring separate service path instances for each user, thereby reducing system resource consumption.
Data Source
AI summary
Apparatus, methods, and other embodiments associated with providing service insertion architecture (SIA) differentiated services in a virtual private network (VPN) environment are described. Embodiments may provision an authentication, authorization, and accounting (AAA) server with user-to-SIA service-context mapping information. With the AAA server provisioned, embodiments may acquire, in an IPSec VPN hub, during IPSec tunnel user authentication, from the AAA server, the user-to-SIA service-context mapping information. With the mapping information available, embodiments may dynamically map an SIA service to an IPSec VPN tunnel user based on the service information acquired from the Service Broker or Pseudo-Service Broker. The dynamic mapping facilitates providing differentiated services in the SIA by facilitating forwarding an IPSec packet received on the IPSec VPN tunnel from the user to a service node associated with the SIA service based, at least in part, on the IPSec SADB entry modified using the service information.


