Virtual VPN Hub Node QoS Enforcement via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IPSec VPNs face limitations in handling multimedia traffic due to lack of quality of service (QoS) support, leading to network performance degradation, especially in worldwide deployments, and are not scalable or cost-effective compared to IP VPNs, affecting time-sensitive applications and user experience.
Innovation Solution
The implementation of a Virtual VPN solution that includes a Network Abstraction Layer (NAL) using multipoint GRE over the Internet, combined with a Network Virtualization Layer (NVL) based on GDOI protocol for advanced resource management and encryption key distribution, along with load-balanced certification authorities and WAN optimization techniques, to create a more efficient and scalable network architecture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec VPN is used to provide cheap alternative to IP VPN, then cost is reduced, but network performance and QoS support deteriorate
Solution Approach 1:
The system segments the VPN network into hub nodes and spoke nodes, where hub nodes perform encryption/decryption and spoke nodes handle traffic forwarding. This segmentation allows QoS policies to be applied at hub nodes before encryption, enabling QoS support in IPSec VPN while maintaining cost-effectiveness.
Solution Approach 2:
The patent introduces hub nodes as intermediary devices that act as QoS enforcement points. These hubs receive unencrypted traffic, apply QoS classification and policies, then encrypt the traffic for transmission over the public network. This intermediary approach enables QoS support without requiring QoS capabilities throughout the entire encrypted path.
2Device complexity
If IPSec VPN uses central point topology for traffic transit, then device complexity is reduced, but network latency and performance degradation increase
Solution Approach 1:
The system establishes direct encrypted tunnels between spoke nodes and hub nodes before traffic needs to flow. Routing tables are pre-configured with hub node addresses, and security associations are pre-established, enabling traffic to flow directly through the hub without dynamic tunnel setup delays, thus reducing latency while maintaining simple topology.
3Reliability
If IP VPN is used to provide strong SLA and performance, then network performance is improved, but cost increases significantly
Solution Approach 1:
The patent makes hub nodes universal resources that can serve multiple spoke nodes and multiple VPN networks simultaneously. A single hub node can handle encryption/decryption for numerous spokes, and spokes can route through different hubs based on destination. This multi-functionality provides IP VPN-like performance and SLA guarantees while reducing costs by eliminating the need for dedicated private network infrastructure.
4Reliability
If IPSec VPN devices are deployed on per-customer basis, then security is improved, but scalability and cost-effectiveness deteriorate
Solution Approach 1:
The system merges multiple customer VPN networks by allowing spoke nodes from different customers to connect to the same hub node. The hub node maintains separate security contexts and encryption keys for each customer while providing centralized resource sharing. This merging enables scalability and cost-effectiveness while maintaining security through isolated encryption domains.
Data Source
AI summary
Systems and methods for communication. A network abstraction layer (NAL) is built on a public Internet; and a network virtualization layer (NVL) is built on the NAL.


