Identity Location Separation VPN Mapping Table
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IP-based network architecture faces challenges with routing scalability, mobility, multiple homes, and security due to the dual attributes of IP addresses, which hinder the development of next-generation networks, especially in regions with limited IP address space like China.
Innovation Solution
Implementing a virtual private network (VPN) based on an identity and location separation network, using a VPN dedicated mapping table and a general mapping table to manage identity and location identifiers, ensuring secure and scalable communication by separating identity and location attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IPv4 address space is used to support growing network users, then network coverage and user access are improved, but IP address exhaustion occurs and routing scalability deteriorates
Solution Approach 1:
The patent segments the traditional flat IP address space into hierarchical regions using route aggregates. By dividing the network into regional routing domains and applying aggregation at multiple levels, the system can support exponentially more users without proportionally increasing the address space requirement. This segmentation allows efficient address utilization while maintaining routing scalability.
Solution Approach 2:
The patent introduces a new dimensional structure to IP address organization by implementing multi-level route aggregation. Instead of relying solely on the traditional single-level hierarchical addressing, the system adds temporal and regional dimensions to address allocation, enabling more efficient use of the existing IPv4 address space through sophisticated aggregation patterns across multiple routing tiers.
2Device complexity
If traditional IP-based network architecture is used, then network simplicity is maintained, but routing scalability and mobility support are limited
Solution Approach 1:
The patent segments the routing function into multiple independent components: regional routing domains, aggregate routing tables, and host-specific routing. This segmentation allows each component to operate independently and scale separately, improving overall routing scalability without significantly increasing the complexity of individual components. The segmented architecture enables parallel processing of routing decisions across different regions.
Solution Approach 2:
The patent introduces dynamic routing aggregation that can adapt to changing network conditions. Route aggregates are dynamically created, modified, and removed based on traffic patterns and network topology changes. This dynamic behavior allows the routing system to scale efficiently by activating or deactivating aggregation levels as needed, without requiring fundamental architectural changes.
3Ease of operation
If IP addresses are allocated for each user, then individual user access is ensured, but address space exhaustion occurs in regions with limited IPv4 allocation
Solution Approach 1:
The patent makes IP address blocks serve multiple functions simultaneously. A single IP address block can represent both a regional aggregate for routing efficiency and individual user addresses for access. Through the use of route aggregates and hierarchical decomposition, the same address space supports both bulk routing operations and individual user connectivity, maximizing the utility of limited IPv4 allocations.
Solution Approach 2:
The patent segments the address allocation process into hierarchical levels where larger blocks are allocated to regions for aggregate routing, while smaller sub-blocks are allocated to individual users or organizations. This segmentation allows efficient management of limited address space by matching allocation granularity to actual usage patterns, ensuring both individual access and overall scalability.
Data Source
AI summary
An implementation method and system of a virtual private network (VPN) are provided in the invention, wherein, the VPN dedicated mapping table of the VPN is stored in the mapping plane in the identity and location separation network, and it is determined whether to achieve the communication between the VPN end host users in the VPN or not according to the VPN dedicated mapping table, thereby the VPN is efficiently achieved in the identity and location separation network, meeting the user requirements for the VPN, eliminating the influence of the identity and location separation technical solution on the traditional VPN service, and reducing the changes on the existing devices and software tools due to the implementation of VPN.


