VPN Traffic Segmentation via Control and Data Plane Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems for virtual private networks (VPNs) face challenges in efficiently routing and forwarding control and data packets between autonomous systems, particularly when different VPNs use incompatible data switching techniques, leading to potential traffic overlap and compatibility issues.

Innovation Solution

The system employs control and data plane tunnels with route distinguishers to identify and route control and data packets separately, using tags to distinguish traffic from different VPNs, allowing for the use of multiple VPNs over a single link without impacting transit autonomous systems, and utilizing techniques like MPLS, VRF, and OTV for node routing isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple VPNs use a single shared link between autonomous systems, then link utilization and efficiency are improved, but traffic overlap and compatibility issues occur when VPNs use different data switching techniques

Engineering Contradiction:
Improvelink utilizationVSAvoidtraffic isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments traffic by introducing routing instances and forwarding instances that separately handle control packets and data packets for different VPNs. Each VPN's traffic is divided into distinct routing instances with unique route distinguishers, preventing traffic overlap while sharing the same physical link. This segmentation allows multiple VPNs to coexist on a single link without interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of abstraction by introducing routing instances and forwarding instances as intermediate layers between the physical link and VPN traffic. This dimensional addition allows traffic from different VPNs to be distinguished and handled separately through control tags and data tags, enabling multiple VPNs to share a single link without compatibility issues.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If control packets and data packets are routed using the same routing instance, then system complexity is reduced, but traffic from different VPNs cannot be properly distinguished and routed

Engineering Contradiction:
Improverouting system complexityVSAvoidVPN traffic distinction capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the routing system into separate routing instances for different VPNs. Each routing instance is assigned a unique route distinguisher that enables identification and separate handling of control packets for specific VPNs. This segmentation allows the system to maintain simplicity within each routing instance while achieving versatility across multiple VPNs through the use of multiple distinct routing instances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal routing framework where routing instances can handle multiple VPNs through the use of route distinguishers and control tags. The same routing infrastructure is made multi-functional by enabling it to distinguish and route traffic from different VPNs using tagging mechanisms, thus achieving both simplicity and versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If VPNs use incompatible data switching techniques, then each VPN can optimize for its specific requirements, but compatibility issues and traffic overlap occur when communicating over shared links

Engineering Contradiction:
ImproveVPN switching technique flexibilityVSAvoidtraffic isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces routing instances and forwarding instances as intermediary layers between VPNs with incompatible switching techniques. These intermediaries use route distinguishers and tags to translate and distinguish traffic from different VPNs, allowing VPNs to maintain their own switching techniques while preventing traffic overlap through the mediating routing and forwarding instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8711859B2Interconnecting virtual domains
Publication Date: 2014.04.29 CISCO TECHNOLOGY INC
  • US8711859B2 patent drawing
  • US8711859B2 patent drawing
  • US8711859B2 patent drawing

AI summary

According to certain embodiments, control packets are received through a control plane tunnel that communicates control traffic for virtual private networks (VPNs) among autonomous systems. A routing instance of each control packet is identified according to a control tag of the control packet. At least two routing instances are distinct from each other. The control packets are routed according to the routing instances. According to certain embodiments, data packets are received through a data plane tunnel that communicates data traffic for the VPNs among the autonomous systems. A forwarding instance of the control packet is identified for each data packet according to a data tag of the data packet. At least two forwarding instances are distinct from each other. The data packets are forwarded according to the forwarding instances.