VPN Flow Visibility via Anonymized Header Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network performance monitoring tools are hindered by VPN tunnels, which hide traffic and make individual flows invisible to intermediate nodes, limiting the ability to monitor and trace network performance, especially for time-sensitive applications like VoIP and video over IP.

Innovation Solution

Generating VPN encapsulated packets with anonymized headers and maintaining a mapping table to expose UDP and RTP headers in the clear, allowing intermediate nodes to access flow information while maintaining confidentiality through explicit IP destination addressing and remapping.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN tunnels are used to encapsulate and secure network traffic, then security and confidentiality are improved, but visibility and monitorability of individual flows are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidflow visibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces performance monitoring tools as intermediary devices that can penetrate the VPN tunnel encapsulation. These tools act as mediators between the encrypted traffic and the monitoring system, allowing them to extract and analyze performance metrics (latency, jitter, packet loss) without compromising the security provided by the VPN tunnel. The intermediaries read performance data from packet headers while the tunnel maintains encryption for the actual payload.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If traffic is hidden within VPN tunnels, then confidentiality is improved, but the ability to trace and monitor performance is worsened

Engineering Contradiction:
ImproveconfidentialityVSAvoidperformance monitoring accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent extracts specific performance monitoring information from within the VPN tunnel encapsulation without extracting the entire encrypted payload. Performance monitoring tools extract only the necessary metrics from packet headers and other visible fields, leaving the confidential data intact within the tunnel. This selective extraction allows accurate measurement of performance parameters while preserving the confidentiality benefits of the VPN.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If intermediate nodes cannot see traffic, then security is maintained, but network troubleshooting and performance analysis are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by enabling performance monitoring capabilities only at specific strategic points along the network path where VPN tunnels are deployed, rather than requiring all intermediate nodes to have full visibility. Performance monitoring tools are positioned at tunnel endpoints and key intermediate nodes to collect performance data locally, then aggregate and forward this information for analysis. This localized approach maintains security while providing sufficient visibility for troubleshooting.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9059926B2Performance analysis of virtual private network segment on a per flow basis
Publication Date: 2015.06.16 CISCO TECHNOLOGY INC
  • US9059926B2 patent drawing
  • US9059926B2 patent drawing
  • US9059926B2 patent drawing

AI summary

A method is provided in one example embodiment and includes generating at a first network device Virtual Private Network (“VPN”) encapsulated packets with anonymized headers; maintaining a table mapping the anonymized headers to original headers of the VPN encapsulated packets; receiving a trace request from an initiator; generating from the received trace request an out-of-tunnel trace request toward a second network device via at least one intermediate network device using the anonymized headers; and forwarding the received trace request as an in-tunnel trace request through a VPN tunnel.