Source-Independent Distributed Advertisements for Flexible VPN Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN services require complex routing protocols like BGP and IGP, leading to increased processing overhead, deployment difficulties, and additional costs due to the need for distinct routing protocol stacks and multiple TCP sessions, making it challenging to manage and deploy VPNs across large networks.
Innovation Solution
Implementing source-independent distributed advertisements that extend existing client reachability advertisements in routing protocols, such as IGP, to include VPN membership information, allowing for flexible administration and minimizing the need for new routing protocols or additional software upgrades, by carrying information about VPN IDs, service classes, and connection permissions within existing advertisements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional VPN services use BGP or IGP routing protocols, then VPN membership discovery and isolation are achieved, but processing overhead and device complexity increase significantly
Solution Approach 1:
The patent merges VPN membership advertisement with existing IGP routing advertisements by extending the IGP protocol to carry VPN-specific TLV structures. This combines multiple functions (routing and VPN membership discovery) into a single protocol mechanism, eliminating the need for separate BGP sessions and reducing processing overhead while maintaining reliable VPN membership discovery
Solution Approach 2:
The extended IGP protocol serves multiple functions simultaneously: it performs standard routing advertisement while also carrying VPN membership information, service class details, and connection permissions through additional TLV structures. This multi-functionality reduces the need for separate specialized protocols and decreases overall system complexity
2Adaptability or versatility
If multiple BGP sessions are established for VPN support, then VPN information exchange is enabled, but deployment difficulty and cost increase
Solution Approach 1:
The patent combines VPN information exchange with existing IGP advertisement mechanisms, merging multiple protocol functions into a single unified approach. By extending IGP to carry VPN-specific TLVs, the system enables comprehensive VPN information exchange without establishing separate BGP sessions, significantly simplifying deployment procedures and reducing costs
3Productivity
If source-independent distributed advertisements are used, then processing overhead is reduced, but compatibility with existing routing protocols must be maintained
Solution Approach 1:
The patent implements source-independent distributed advertisements by nesting VPN-specific TLV structures within existing IGP advertisement protocols. The VPN membership information is embedded as optional fields within the standard IGP message format, allowing receiving nodes to process standard IGP advertisements efficiently while extracting VPN-specific information when present, thus maintaining protocol compatibility while improving processing efficiency
Solution Approach 2:
The patent modifies IGP advertisement parameters by adding optional TLV structures that carry VPN-specific information. These parameter extensions allow the protocol to adapt to VPN requirements while maintaining backward compatibility with existing IGP implementations, enabling efficient processing without sacrificing protocol versatility
Data Source
AI summary
The present invention provides a mechanism for distributing client Virtual Private Network (VPN)-related information within a network using a source-independent distributed advertisement that includes incorporating client VPN-related information related to a node of a network into a source-independent distributed advertisement associated with a routing protocol, distributing the source-independent distributed advertisement from the node of the network to at least one other node of the network, or from another node of the network or a centralized management system to the at least one other node of the network, and updating other VPN-related information with the client VPN-related information related to the node of the network at the at least one other node of the network, wherein the client VPN-related information related to the node of the network is distributed to the at least one other node of the network without requiring the establishment of a Transmission Control Protocol (TCP) session specifically for the distribution of the client VPN-related information.


