VPN Tunnel Header Rewrite Sharing With Hierarchical FECs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face inefficiencies and increased hardware resource usage due to the duplication of egress tunnel header rewrite table entries for each tunnel, leading to higher costs and memory constraints in network devices.

Innovation Solution

Implementing a hierarchy of forwarding equivalence classes (FECs) to reorder and share common egress tunnel header rewrite table entries across virtual private network (VPN) tunnels, reducing duplication and optimizing hardware resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If egress tunnel header rewrite table entries are duplicated for each tunnel, then routing functionality is maintained for each VPN tunnel, but hardware resource consumption increases and memory constraints are exceeded

Engineering Contradiction:
Improverouting functionalityVSAvoidhardware resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges common egress tunnel header rewrite table entries across multiple VPN tunnels by introducing a shared table structure. Instead of maintaining separate duplicated entries for each tunnel, the system combines common entries into a single shared table that can be referenced by multiple tunnels through FEC (Forwarding Equivalence Class) mechanisms, thereby reducing hardware resource consumption while preserving routing functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared egress tunnel header rewrite table entries are designed to serve multiple VPN tunnels simultaneously. The table structure enables universal usage where a single entry can be referenced by different tunnels through FEC pointers, allowing the same hardware resources to support multiple routing functions without requiring separate dedicated entries for each tunnel.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If egress tunnel header rewrite table entries are duplicated for each tunnel, then each tunnel has dedicated routing information, but memory size constraints in network devices are exceeded

Engineering Contradiction:
Improvetunnel routing informationVSAvoidmemory size
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent merges redundant memory entries by implementing a shared table structure for egress tunnel header rewrite information. Common entries are consolidated into a single memory location that can be referenced by multiple tunnels, significantly reducing the total memory footprint compared to maintaining separate duplicated entries for each tunnel while preserving complete routing information.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces FEC (Forwarding Equivalence Class) pointers as intermediaries between tunnels and the shared table entries. These FEC mechanisms act as mediators that allow multiple tunnels to reference common table entries without requiring actual duplication in memory, thereby reducing memory size constraints while maintaining tunnel-specific routing information through the intermediary mapping structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If conventional routing tables are used without sharing, then routing simplicity is maintained, but hardware resources are wasted through duplication

Engineering Contradiction:
Improverouting simplicityVSAvoidhardware resource usage
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent segments the routing table structure into two parts: a shared common entries section and tunnel-specific FEC pointer sections. This segmentation allows the bulk of common egress tunnel header rewrite entries to be stored once and shared, while maintaining tunnel-specific information through lightweight FEC references, thereby reducing hardware resource usage while preserving routing functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a flat duplicated table structure to a hierarchical dimensionality where common entries exist at one level and tunnel-specific FEC pointers exist at another level. This dimensional reorganization allows efficient sharing of common resources while maintaining tunnel-specific routing information, reducing hardware resource consumption without complicating the routing operation process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12592884B2Sharing egress tunnel header rewrite table entries across virtual private network (VPN) tunnels
Publication Date: 2026.03.31 ARISTA NETWORKS INC
  • US12592884B2 patent drawing
  • US12592884B2 patent drawing
  • US12592884B2 patent drawing

AI summary

A method of forwarding a data packet includes, in part, receiving the data packet at an ingress interface, reordering entries of the data packet such that a first forwarding equivalence class (FEC), indexed by a first forwarding lookup table, is caused to point to a virtual private network (VPN) identifier associated with a tunnel through which the data packet is to be forwarded. The reordering of the entries causes a second FEC to point to a multitude of common tunnel header entries. The second FEC is indexed by the first FEC and has a lower level than the first FEC. The data packet with the reordered entries is forwarded through the tunnel. The egress tunnel header rewrite table entries are also reordered in accordance with which the data packet is forwarded.