Shared VPN Route Targeting for VoIP Overhead Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches to providing Voice over Internet Protocol (VoIP) Virtual Private Network (VPN) services require separate trunks or IP security tunnels between each enterprise network and the provider network, leading to significant overhead and complexity.
Innovation Solution
The method involves tagging customer routes with specific route targets to form core network service VPNs and enterprise VPNs logically, allowing multiple customers to share core network services over a shared VPN infrastructure, using virtual routing and forwarding (VRF) technology and Multiprotocol Label Switching (MPLS) to manage route distribution and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate trunks or IP security tunnels are provisioned between each enterprise network and provider network, then data security is implemented, but overhead and complexity increase significantly
Solution Approach 1:
The patent merges multiple separate security tunnels into a single shared VPN infrastructure. Multiple customers share a common encryption tunnel between provider edge nodes, eliminating the need for individual dedicated tunnels for each customer while maintaining security through virtual routing and forwarding (VRF) isolation.
Solution Approach 2:
The shared VPN infrastructure serves multiple customers simultaneously through a single encryption tunnel. The provider edge nodes are configured to handle multiple customer routes through route targeting and VRF, allowing one tunnel to perform the security function for many customers rather than requiring separate tunnels for each.
2Reliability
If separate trunks are provisioned for each enterprise network, then data security is ensured, but the number of network links increases
Solution Approach 1:
Multiple individual network links are merged into a single shared physical or logical tunnel. The patent consolidates what would otherwise be numerous separate encrypted connections into one shared VPN tunnel that carries traffic from multiple customers, reducing the total quantity of network links required.
Solution Approach 2:
The patent creates virtual copies of the tunneling function through VRF and route targeting mechanisms. Instead of physical separate tunnels, virtual tunnel instances are created for each customer within the shared infrastructure, maintaining the appearance of dedicated connections while using shared physical resources.
3Productivity
If multiple customers share core network services over a single network link, then overhead is reduced, but VPN separation must be maintained
Solution Approach 1:
The shared VPN tunnel is segmented into separate virtual routing instances using VRF (Virtual Routing and Forwarding). Each customer's traffic is isolated in its own VRF instance, maintaining logical separation and security boundaries while physically sharing the same tunnel infrastructure. Route targets are used to control which routes are imported into which VRFs.
Solution Approach 2:
Provider edge nodes act as intermediaries that enforce VPN separation policies. These nodes use route targeting and VRF configuration to ensure that customer traffic is properly routed and isolated, mediating between the shared physical infrastructure and the requirement for logical separation.
Data Source
AI summary
A network architecture includes an edge network having provider edge nodes configured to form a core network service VPN logically between subscribing customer network sites and a core service network, the core service network providing a core network service, the core service network including a core network service node, and a plurality of customer network sites having customer edge nodes attached to associated provider edge nodes of the edge network, wherein each customer edge node is configured to import routes tagged with a core service specific route target, and wherein the core network service node is configured to import routes tagged with a core service specific customer route target.


