Virtual VPN Hub Node QoS Enforcement via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IPSec VPNs face limitations in handling multimedia traffic due to lack of quality of service (QoS) support, leading to network performance degradation, especially in worldwide deployments, and are not scalable or cost-effective compared to IP VPNs, affecting time-sensitive applications and user experience.

Innovation Solution

The implementation of a Virtual VPN solution that includes a Network Abstraction Layer (NAL) using multipoint GRE over the Internet, combined with a Network Virtualization Layer (NVL) based on GDOI protocol for advanced resource management and encryption key distribution, along with load-balanced certification authorities and WAN optimization techniques, to create a more efficient and scalable network architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec VPN is used to provide cheap alternative to IP VPN, then cost is reduced, but network performance and QoS support deteriorate

Engineering Contradiction:
Improvenetwork performanceVSAvoidQoS support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the VPN network into hub nodes and spoke nodes, where hub nodes perform encryption/decryption and spoke nodes handle traffic forwarding. This segmentation allows QoS policies to be applied at hub nodes before encryption, enabling QoS support in IPSec VPN while maintaining cost-effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hub nodes as intermediary devices that act as QoS enforcement points. These hubs receive unencrypted traffic, apply QoS classification and policies, then encrypt the traffic for transmission over the public network. This intermediary approach enables QoS support without requiring QoS capabilities throughout the entire encrypted path.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If IPSec VPN uses central point topology for traffic transit, then device complexity is reduced, but network latency and performance degradation increase

Engineering Contradiction:
Improvenetwork topology simplicityVSAvoidnetwork latency
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system establishes direct encrypted tunnels between spoke nodes and hub nodes before traffic needs to flow. Routing tables are pre-configured with hub node addresses, and security associations are pre-established, enabling traffic to flow directly through the hub without dynamic tunnel setup delays, thus reducing latency while maintaining simple topology.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IP VPN is used to provide strong SLA and performance, then network performance is improved, but cost increases significantly

Engineering Contradiction:
ImproveService Level AgreementVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes hub nodes universal resources that can serve multiple spoke nodes and multiple VPN networks simultaneously. A single hub node can handle encryption/decryption for numerous spokes, and spokes can route through different hubs based on destination. This multi-functionality provides IP VPN-like performance and SLA guarantees while reducing costs by eliminating the need for dedicated private network infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If IPSec VPN devices are deployed on per-customer basis, then security is improved, but scalability and cost-effectiveness deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system merges multiple customer VPN networks by allowing spoke nodes from different customers to connect to the same hub node. The hub node maintains separate security contexts and encryption keys for each customer while providing centralized resource sharing. This merging enables scalability and cost-effectiveness while maintaining security through isolated encryption domains.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9780965B2Methods and systems for communicating using a virtual private network
Publication Date: 2017.10.03 GLUWARE IP LLC
  • US9780965B2 patent drawing
  • US9780965B2 patent drawing
  • US9780965B2 patent drawing

AI summary

Systems and methods for communication. A network abstraction layer (NAL) is built on a public Internet; and a network virtualization layer (NVL) is built on the NAL.