VNET-Shim for Scalable Virtual LAN Interconnection Over WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for interconnecting virtual LAN segments across a wide area network are not scalable and require separate point-to-point connections or overlay routing protocols, limiting the deployment of virtual LANs.
Innovation Solution
The solution involves embedding a 'VNET-shim' between the IPSec header and the outer IP header of a data packet, using a new IP protocol value to signal the presence of the VNET-shim, and encoding the VNET-id within the shim to enable secure and scalable interconnection of virtual LAN segments without the need for site-to-site GRE tunnels or overlay routing protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If GRE tunnels or overlay routing protocols are used to create point-to-point connections among hosts, then VNET segments can exist across an IP WAN, but the network architecture becomes non-scalable and complex
Solution Approach 1:
The patent merges multiple VNET segments onto a single IP WAN connection by embedding VNET identification information directly into the IP packet header. This eliminates the need for separate GRE tunnels or overlay routing protocols for each host pair, allowing multiple virtual networks to share the same physical infrastructure while maintaining logical separation.
Solution Approach 2:
The patent introduces an intermediary mechanism by embedding VNET-ID information within the IP packet header itself, acting as a mediator between the physical WAN infrastructure and the virtual network segments. This intermediary approach allows the network to distinguish between different VNETs without requiring complex tunneling protocols.
2Reliability
If separate point-to-point connections are created for each host pair, then VNET segments can communicate over WAN, but the number of connections required becomes unmanageable
Solution Approach 1:
The patent applies universality by enabling a single IP WAN connection to serve multiple VNET segments simultaneously. The IP packet header is modified to include VNET identification information, allowing the same physical connection to carry traffic for different virtual networks without requiring separate dedicated connections for each host pair.
Solution Approach 2:
The patent segments the IP packet header into distinct fields, embedding VNET-ID information within the existing IP header structure. This segmentation allows the network to maintain logical separation between different VNETs while using the same physical infrastructure, reducing the number of required connections from O(n²) to O(n).
3Adaptability or versatility
If overlay routing protocols are used, then VNET segments can be interconnected, but the routing complexity and protocol overhead increase
Solution Approach 1:
The patent extracts the VNET identification function from complex overlay routing protocols and embeds it directly into the IP packet header. This extraction eliminates the need for separate routing protocols to manage VNET segments, as the VNET-ID is carried within the standard IP header, simplifying the routing infrastructure while maintaining interconnection capability.
Data Source
AI summary
One embodiment provides a method to interconnect virtual network segments (VNETs) defined for a local-area network (LAN) infrastructure separated by a wide-area network infrastructure. The technique involves the routing device at the LAN-WAN interconnection points to impose or dispose the VNET-shim, which encodes the VNET-id information in a Layer 4 portion of the packet. In a data plane, a new IP protocol value may be used to signify the presence of the VNET-shim followed by cryptography specific information in an IP packet. In a control plane, the routing protocol is expanded to exchange the routing information along with the VNET information.


