VLAN ID-Based VRF Indexing for Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN methods in campus networks are overly complex and cumbersome due to the need for multiple VLANs, sub-interfaces, and routing instances, leading to increased computational overhead and provisioning complexity.

Innovation Solution

The method encapsulates VPN traffic using a VLAN ID to identify the virtual route forwarding table, allowing for dynamic association of VLAN-IDs with VRFs, enabling simplified network segmentation and routing decisions across L3 routing entities with a common interface, while maintaining layer 2 segmentation through L2 switching entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple VLANs, sub-interfaces, and routing instances are used for VPN traffic isolation, then traffic segmentation and security are improved, but device complexity and provisioning complexity increase significantly

Engineering Contradiction:
Improvetraffic segmentationVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple routing instances and sub-interfaces into a single routing instance and shared interface by using VLAN ID-based virtualization. The single routing instance maintains multiple virtual routing tables indexed by VLAN ID, allowing multiple VPNs to share the same physical and logical interface while maintaining traffic isolation through VLAN tagging and virtual routing table selection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes a single interface and routing instance universal by enabling them to handle multiple VPNs simultaneously through VLAN ID-based identification. The shared interface can receive and forward traffic for multiple different VPNs by examining the VLAN ID in the Ethernet frame and selecting the appropriate virtual routing table, eliminating the need for dedicated interfaces per VPN.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple routing instances and sub-interfaces are deployed for each VPN, then VPN traffic isolation is achieved, but computational overhead increases substantially

Engineering Contradiction:
ImproveVPN traffic isolationVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines multiple routing instance operations into a single routing instance that maintains multiple virtual routing tables. Instead of running separate routing protocols and maintaining separate routing tables for each VPN, the system uses a single routing instance with VLAN ID-based table selection, reducing CPU overhead for routing protocol processing and route table lookups.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary organization of routing information by maintaining multiple virtual routing tables pre-indexed by VLAN ID. This allows the routing system to quickly select the appropriate routing table based on the VLAN ID in the incoming frame without having to process multiple routing instances sequentially, reducing computational overhead during packet forwarding.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional sub-interface assignment to VRF is used for routing, then VPN segmentation is maintained, but the system lacks scalability and requires substantial computing overhead

Engineering Contradiction:
ImproveVPN segmentationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the conventional approach by instead of assigning different interfaces to different VRFs, it assigns the same shared interface to multiple VRFs and uses VLAN ID-based identification to select the appropriate VRF. This inversion allows for better scalability as new VPNs can be added by creating new virtual routing tables indexed by new VLAN IDs without requiring new physical or logical interfaces.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces dynamic VLAN ID-based routing table selection that allows the system to adapt to different VPN requirements dynamically. The routing instance can switch between different virtual routing tables based on the VLAN ID in the incoming frame, providing flexible and scalable VPN segmentation that can accommodate changing network requirements without reconfiguring the underlying interface structure.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7688829B2System and methods for network segmentation
Publication Date: 2010.03.30 CISCO TECHNOLOGY INC
  • US7688829B2 patent drawing
  • US7688829B2 patent drawing
  • US7688829B2 patent drawing

AI summary

A routing mechanism provides network segmentation preservation by route distribution with segment identification, policy distribution for a given VPN segment, and encapsulation/decapsulation for each segment using an Ethernet VLAN_ID, indicative of the VPN segment (subnetwork). Encapsulated segmentation information in a message packet identifies which routing and forwarding table is employed for the next hop. A common routing instance receives the message packets from the common interface, and indexes a corresponding VRF table from the VLAN ID, or segment identifier, indicative of the subnetwork (e.g. segment). In this manner, the routing instance receives the incoming message packet, decapsulates the VLAN ID in the incoming message packet, and indexes the corresponding VRF and policy ID from the VLAN ID, therefore employing a common routing instance over a common subinterface for a plurality of segments (subnetworks) coupled to a particular forwarding device (e.g. VPN router).