Tunnel-in-Tunnel Source Address Correction for Virtual Service Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computer networks, tunnel-in-tunnel traffic poses challenges due to the difficulty in distinguishing and optimizing traffic flows, especially when business and non-business critical applications use the same protocols like HTTP/HTTPS, leading to complications in network performance optimization and source address translation issues within virtual service platforms (VSPs).
Innovation Solution
A device identifies and translates the source network address for tunnel-in-tunnel packets, including the translated address within the packet header, allowing for accurate source address correction during encapsulation and decapsulation processes, ensuring proper routing through virtual private networks (VPNs) and virtual service platforms (VSPs).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tunnel-in-tunnel encapsulation is used to route traffic through virtual service platforms, then traffic can be securely routed through VPN tunnels, but the source address in the inner tunnel header becomes incorrect after NAT translation, causing routing failures
Solution Approach 1:
The patent performs source address correction in advance by identifying the translated source address from the outer tunnel header and updating the inner tunnel header before the packet reaches the destination. This preliminary action prevents routing failures that would occur if the incorrect source address remained in the inner header.
Solution Approach 2:
The patent introduces an intermediary correction mechanism that acts between the NAT translation process and the final packet delivery. The intermediary identifies the mismatch between outer and inner source addresses and performs the necessary correction, serving as a mediator that resolves the conflict caused by double encapsulation.
2Adaptability or versatility
If business and non-business critical applications use the same HTTP/HTTPS protocols, then protocol compatibility is maintained, but the ability to distinguish and optimize specific traffic flows is lost
Solution Approach 1:
The patent uses tunnel-in-tunnel encapsulation where an inner tunnel (carrying the actual application traffic) is nested within an outer tunnel (used for routing through VSPs). This nested structure allows multiple applications using the same HTTP/HTTPS protocols to be distinguished by their unique inner tunnel identifiers while maintaining protocol compatibility.
Solution Approach 2:
The patent segments traffic identification into two layers: the outer tunnel header for routing purposes and the inner tunnel header for application-specific identification. This segmentation allows the network to optimize traffic flows based on inner tunnel identifiers while the outer tunnel ensures proper routing through virtual service platforms.
Data Source
AI summary
In one embodiment, a device in a network identifies a translated source network address for a tunnel source of a tunnel-in-tunnel packet. The device includes the translated source network address within a header of the packet. The header of the packet identifies an inner tunnel that is encapsulated within an outer tunnel during transmission of the packet within the network. The device sends the packet with the translated source network address within the header of the packet.


