VPN Tunnel Header Rewrite Sharing With Hierarchical FECs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face inefficiencies and increased hardware resource usage due to the duplication of egress tunnel header rewrite table entries for each tunnel, leading to higher costs and memory constraints in network devices.
Innovation Solution
Implementing a hierarchy of forwarding equivalence classes (FECs) to reorder and share common egress tunnel header rewrite table entries across virtual private network (VPN) tunnels, reducing duplication and optimizing hardware resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If egress tunnel header rewrite table entries are duplicated for each tunnel, then routing functionality is maintained for each VPN tunnel, but hardware resource consumption increases and memory constraints are exceeded
Solution Approach 1:
The patent merges common egress tunnel header rewrite table entries across multiple VPN tunnels by introducing a shared table structure. Instead of maintaining separate duplicated entries for each tunnel, the system combines common entries into a single shared table that can be referenced by multiple tunnels through FEC (Forwarding Equivalence Class) mechanisms, thereby reducing hardware resource consumption while preserving routing functionality.
Solution Approach 2:
The shared egress tunnel header rewrite table entries are designed to serve multiple VPN tunnels simultaneously. The table structure enables universal usage where a single entry can be referenced by different tunnels through FEC pointers, allowing the same hardware resources to support multiple routing functions without requiring separate dedicated entries for each tunnel.
2Reliability
If egress tunnel header rewrite table entries are duplicated for each tunnel, then each tunnel has dedicated routing information, but memory size constraints in network devices are exceeded
Solution Approach 1:
The patent merges redundant memory entries by implementing a shared table structure for egress tunnel header rewrite information. Common entries are consolidated into a single memory location that can be referenced by multiple tunnels, significantly reducing the total memory footprint compared to maintaining separate duplicated entries for each tunnel while preserving complete routing information.
Solution Approach 2:
The patent introduces FEC (Forwarding Equivalence Class) pointers as intermediaries between tunnels and the shared table entries. These FEC mechanisms act as mediators that allow multiple tunnels to reference common table entries without requiring actual duplication in memory, thereby reducing memory size constraints while maintaining tunnel-specific routing information through the intermediary mapping structure.
3Ease of operation
If conventional routing tables are used without sharing, then routing simplicity is maintained, but hardware resources are wasted through duplication
Solution Approach 1:
The patent segments the routing table structure into two parts: a shared common entries section and tunnel-specific FEC pointer sections. This segmentation allows the bulk of common egress tunnel header rewrite entries to be stored once and shared, while maintaining tunnel-specific information through lightweight FEC references, thereby reducing hardware resource usage while preserving routing functionality.
Solution Approach 2:
The patent transitions from a flat duplicated table structure to a hierarchical dimensionality where common entries exist at one level and tunnel-specific FEC pointers exist at another level. This dimensional reorganization allows efficient sharing of common resources while maintaining tunnel-specific routing information, reducing hardware resource consumption without complicating the routing operation process.
Data Source
AI summary
A method of forwarding a data packet includes, in part, receiving the data packet at an ingress interface, reordering entries of the data packet such that a first forwarding equivalence class (FEC), indexed by a first forwarding lookup table, is caused to point to a virtual private network (VPN) identifier associated with a tunnel through which the data packet is to be forwarded. The reordering of the entries causes a second FEC to point to a multitude of common tunnel header entries. The second FEC is indexed by the first FEC and has a lower level than the first FEC. The data packet with the reordered entries is forwarded through the tunnel. The egress tunnel header rewrite table entries are also reordered in accordance with which the data packet is forwarded.


