Multi-Tenant VPN Route Labeling for Flow-Aware BGP Steering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multitenant virtual private networks (VPNs), the active route for a given flow may not be identifiable as an active route for the flow, leading to challenges in routing decisions based on paths and network policies using Border Gateway Protocol (BGP).
Innovation Solution
Implementing a system with a multitenant VPN gateway protocol labeling and routing engine that tags packets for flows, maintains consistent hashing for flow identity, and uses a consistent hashing engine to ensure forward and reverse flows are steered to the same service node, enabling efficient autoscaling and stateful service provisioning without disrupting existing connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If BGP routing decisions are based on standard next-hop reachability, then routing simplicity is maintained, but flow-specific active route identification fails in multitenant VPNs
Solution Approach 1:
The patent introduces BGP labels as intermediary elements that mediate between standard BGP routing and flow-specific route identification. These labels are attached to NLRI and enable precise flow identification without complicating the underlying BGP routing mechanism. The labels act as a bridge that carries flow-specific information through the routing system while maintaining compatibility with standard BGP operations.
Solution Approach 2:
The patent extends BGP routing by adding label parameters to NLRI. This parameter change allows the routing system to carry additional flow-specific information without fundamentally altering the BGP protocol structure. The label parameters enable the routing decision process to distinguish between different flows while maintaining the existing BGP decision-making framework.
2Productivity
If network infrastructure scales rapidly by adding nodes, then service provisioning speed improves, but flow consistency across nodes becomes challenging
Solution Approach 1:
The patent implements feedback mechanisms where BGP labels are propagated through the routing system and used to steer traffic consistently across all nodes. When a flow is labeled at one node, the label information feedbacks through BGP routing to ensure the same flow receives identical treatment at all participating nodes, maintaining flow consistency during rapid scaling operations.
Solution Approach 2:
The BGP label mechanism serves multiple functions simultaneously: it identifies flows, steers traffic, maintains state information, and enables consistent routing across dynamically added nodes. This universal approach allows the same labeling system to handle both flow identification and traffic steering, simplifying the scaling process while maintaining flow consistency.
3Adaptability or versatility
If stateful service provisioning is implemented, then flow-specific routing control improves, but system complexity increases
Solution Approach 1:
The patent enables flows to carry their own identification information through BGP labels embedded in NLRI. This self-service approach allows flows to be automatically identified and routed based on their inherent label information without requiring complex external state management systems. The routing decisions are made autonomously based on the label parameters present in the routing information itself.
Data Source
AI summary
A cloud exchange platform includes policy-based routing. Labeling (or tagging) on a multi-tenant virtual private network (VPN) facilitates recognition of active routes for a flow. The tags can be implemented such that flows are treated as having active routes across a multi-tenant VPN to enable a customer to treat flows as having an identifiable active route through the multi-tenant VPN. Thus, for example, BGP can be used as a generalized signaling protocol to carry information about flows through a multi-tenant VPN.


