Tunnel-in-Tunnel Source Address Correction for Virtual Service Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks, tunnel-in-tunnel traffic poses challenges due to the difficulty in distinguishing and optimizing traffic flows, especially when business and non-business critical applications use the same protocols like HTTP/HTTPS, leading to complications in network performance optimization and source address translation issues within virtual service platforms (VSPs).

Innovation Solution

A device identifies and translates the source network address for tunnel-in-tunnel packets, including the translated address within the packet header, allowing for accurate source address correction during encapsulation and decapsulation processes, ensuring proper routing through virtual private networks (VPNs) and virtual service platforms (VSPs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunnel-in-tunnel encapsulation is used to route traffic through virtual service platforms, then traffic can be securely routed through VPN tunnels, but the source address in the inner tunnel header becomes incorrect after NAT translation, causing routing failures

Engineering Contradiction:
Improverouting reliabilityVSAvoidsource address information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs source address correction in advance by identifying the translated source address from the outer tunnel header and updating the inner tunnel header before the packet reaches the destination. This preliminary action prevents routing failures that would occur if the incorrect source address remained in the inner header.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary correction mechanism that acts between the NAT translation process and the final packet delivery. The intermediary identifies the mismatch between outer and inner source addresses and performs the necessary correction, serving as a mediator that resolves the conflict caused by double encapsulation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If business and non-business critical applications use the same HTTP/HTTPS protocols, then protocol compatibility is maintained, but the ability to distinguish and optimize specific traffic flows is lost

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidtraffic flow distinction
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses tunnel-in-tunnel encapsulation where an inner tunnel (carrying the actual application traffic) is nested within an outer tunnel (used for routing through VSPs). This nested structure allows multiple applications using the same HTTP/HTTPS protocols to be distinguished by their unique inner tunnel identifiers while maintaining protocol compatibility.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments traffic identification into two layers: the outer tunnel header for routing purposes and the inner tunnel header for application-specific identification. This segmentation allows the network to optimize traffic flows based on inner tunnel identifiers while the outer tunnel ensures proper routing through virtual service platforms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9729348B2Tunnel-in-tunnel source address correction
Publication Date: 2017.08.08 CISCO TECHNOLOGY INC
  • US9729348B2 patent drawing
  • US9729348B2 patent drawing
  • US9729348B2 patent drawing

AI summary

In one embodiment, a device in a network identifies a translated source network address for a tunnel source of a tunnel-in-tunnel packet. The device includes the translated source network address within a header of the packet. The header of the packet identifies an inner tunnel that is encapsulated within an outer tunnel during transmission of the packet within the network. The device sends the packet with the translated source network address within the header of the packet.