VPN Traffic Segmentation via Control and Data Plane Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems for virtual private networks (VPNs) face challenges in efficiently routing and forwarding control and data packets between autonomous systems, particularly when different VPNs use incompatible data switching techniques, leading to potential traffic overlap and compatibility issues.
Innovation Solution
The system employs control and data plane tunnels with route distinguishers to identify and route control and data packets separately, using tags to distinguish traffic from different VPNs, allowing for the use of multiple VPNs over a single link without impacting transit autonomous systems, and utilizing techniques like MPLS, VRF, and OTV for node routing isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple VPNs use a single shared link between autonomous systems, then link utilization and efficiency are improved, but traffic overlap and compatibility issues occur when VPNs use different data switching techniques
Solution Approach 1:
The patent segments traffic by introducing routing instances and forwarding instances that separately handle control packets and data packets for different VPNs. Each VPN's traffic is divided into distinct routing instances with unique route distinguishers, preventing traffic overlap while sharing the same physical link. This segmentation allows multiple VPNs to coexist on a single link without interference.
Solution Approach 2:
The patent adds a new dimension of abstraction by introducing routing instances and forwarding instances as intermediate layers between the physical link and VPN traffic. This dimensional addition allows traffic from different VPNs to be distinguished and handled separately through control tags and data tags, enabling multiple VPNs to share a single link without compatibility issues.
2Device complexity
If control packets and data packets are routed using the same routing instance, then system complexity is reduced, but traffic from different VPNs cannot be properly distinguished and routed
Solution Approach 1:
The patent segments the routing system into separate routing instances for different VPNs. Each routing instance is assigned a unique route distinguisher that enables identification and separate handling of control packets for specific VPNs. This segmentation allows the system to maintain simplicity within each routing instance while achieving versatility across multiple VPNs through the use of multiple distinct routing instances.
Solution Approach 2:
The patent creates a universal routing framework where routing instances can handle multiple VPNs through the use of route distinguishers and control tags. The same routing infrastructure is made multi-functional by enabling it to distinguish and route traffic from different VPNs using tagging mechanisms, thus achieving both simplicity and versatility.
3Adaptability or versatility
If VPNs use incompatible data switching techniques, then each VPN can optimize for its specific requirements, but compatibility issues and traffic overlap occur when communicating over shared links
Solution Approach 1:
The patent introduces routing instances and forwarding instances as intermediary layers between VPNs with incompatible switching techniques. These intermediaries use route distinguishers and tags to translate and distinguish traffic from different VPNs, allowing VPNs to maintain their own switching techniques while preventing traffic overlap through the mediating routing and forwarding instances.
Data Source
AI summary
According to certain embodiments, control packets are received through a control plane tunnel that communicates control traffic for virtual private networks (VPNs) among autonomous systems. A routing instance of each control packet is identified according to a control tag of the control packet. At least two routing instances are distinct from each other. The control packets are routed according to the routing instances. According to certain embodiments, data packets are received through a data plane tunnel that communicates data traffic for the VPNs among the autonomous systems. A forwarding instance of the control packet is identified for each data packet according to a data tag of the data packet. At least two forwarding instances are distinct from each other. The data packets are forwarded according to the forwarding instances.


