VNET-Shim for Scalable Virtual LAN Interconnection Over WAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for interconnecting virtual LAN segments across a wide area network are not scalable and require separate point-to-point connections or overlay routing protocols, limiting the deployment of virtual LANs.

Innovation Solution

The solution involves embedding a 'VNET-shim' between the IPSec header and the outer IP header of a data packet, using a new IP protocol value to signal the presence of the VNET-shim, and encoding the VNET-id within the shim to enable secure and scalable interconnection of virtual LAN segments without the need for site-to-site GRE tunnels or overlay routing protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If GRE tunnels or overlay routing protocols are used to create point-to-point connections among hosts, then VNET segments can exist across an IP WAN, but the network architecture becomes non-scalable and complex

Engineering Contradiction:
ImprovescalabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple VNET segments onto a single IP WAN connection by embedding VNET identification information directly into the IP packet header. This eliminates the need for separate GRE tunnels or overlay routing protocols for each host pair, allowing multiple virtual networks to share the same physical infrastructure while maintaining logical separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary mechanism by embedding VNET-ID information within the IP packet header itself, acting as a mediator between the physical WAN infrastructure and the virtual network segments. This intermediary approach allows the network to distinguish between different VNETs without requiring complex tunneling protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate point-to-point connections are created for each host pair, then VNET segments can communicate over WAN, but the number of connections required becomes unmanageable

Engineering Contradiction:
ImproveVNET communication reliabilityVSAvoidnumber of connections
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies universality by enabling a single IP WAN connection to serve multiple VNET segments simultaneously. The IP packet header is modified to include VNET identification information, allowing the same physical connection to carry traffic for different virtual networks without requiring separate dedicated connections for each host pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the IP packet header into distinct fields, embedding VNET-ID information within the existing IP header structure. This segmentation allows the network to maintain logical separation between different VNETs while using the same physical infrastructure, reducing the number of required connections from O(n²) to O(n).

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If overlay routing protocols are used, then VNET segments can be interconnected, but the routing complexity and protocol overhead increase

Engineering Contradiction:
ImproveVNET interconnection capabilityVSAvoidrouting protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the VNET identification function from complex overlay routing protocols and embeds it directly into the IP packet header. This extraction eliminates the need for separate routing protocols to manage VNET segments, as the VNET-ID is carried within the standard IP header, simplifying the routing infrastructure while maintaining interconnection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8165023B2Methods for the secured interconnection of VNET sites over WAN
Publication Date: 2012.04.24 CISCO TECHNOLOGY INC
  • US8165023B2 patent drawing
  • US8165023B2 patent drawing
  • US8165023B2 patent drawing

AI summary

One embodiment provides a method to interconnect virtual network segments (VNETs) defined for a local-area network (LAN) infrastructure separated by a wide-area network infrastructure. The technique involves the routing device at the LAN-WAN interconnection points to impose or dispose the VNET-shim, which encodes the VNET-id information in a Layer 4 portion of the packet. In a data plane, a new IP protocol value may be used to signify the presence of the VNET-shim followed by cryptography specific information in an IP packet. In a control plane, the routing protocol is expanded to exchange the routing information along with the VNET information.