Apparatus and methods for establishing virtual private networks in a broadband network
Abstract
A method for establishing private virtual networks in a communications network, comprising: the creation of a plurality of label switching routes between the corresponding service locations (402, 404, 406, 602,604, 606), each of the switching routes of labels providing a class of services; the assignment of a label to each of the label switching link paths, each tag identifying a service class for a corresponding tag switching path; and the configuration of a series of service logical networks to transport private virtual network routes (206, 502, 504, 506, 608,610, 612) using the label switching paths.

Term
Term ended
Projected expiry passed 8 March 2022, 4.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
24 claims: 2 independent, 22 dependent
- 1ES 2 393 098 T3 REIVINDICACIONES 1. Un método para establecer redes virtuales privadas en una red de comunicaciones, comprendiendo:la creación de una pluralidad de rutas de conmutación de etiquetas entre las ubicaciones de servicio correspondientes (402, 404, 406, 602, 604, 606), cada una de las rutas de conmutación de etiquetas proporcionando una clase de servicios;la asignación de una etiqueta a cada una de las rutas de enlace de conmutación de etiquetas, cada etiqueta identificando una clase de servicios para una ruta de conmutación de etiquetas correspondiente;y la configuración de una serie de redes lógicas de servicio para transportar rutas de redes virtuales privadas (206, 502, 504, 506, 608, 610, 612) utilizando las rutas de conmutación de etiquetas.
- 2El método de la reivindicación 1, comprendiendo además el servicio a diferentes especificaciones de tráfico en diferentes redes lógicas de servicio.
- 3El método de la reivindicación 1, en el que las ubicaciones de servicio correspondientes (402, 406, 602, 604, 606) no están conectadas directamente.
- 4El método de la reivindicación 1, comprendiendo también la asignación de un identificador único a cada instalación de cliente para un cliente.
- 5El método de la reivindicación 4, comprendiendo también el establecimiento de al menos una ruta de red privada virtual entre las instalaciones de cliente.
- 6El método de la reivindicación 5, comprendiendo también la enrutación de tráfico entre las instalaciones de cliente a través de la establecida al menos una ruta de red privada virtual basada en la etiqueta asignada y el identificador único asignado.
- 7El método de la reivindicación 1, en el que la configuración de la serie de redes lógicas de servicio se realiza mediante etiquetas multiprotocolo.
- 8El método de la reivindicación 1, comprendiendo también el establecimiento de la etiqueta en una memoria de conmutación de etiquetas multiprotocolo. ES 2 393 098 T3
- 9El método de la reivindicación 1, comprendiendo también:la asignación de un identificador único a una instalación de cliente;y el establecimiento de dicho identificador único en etiquetas asociadas con la instalación de cliente.
- 10El método de la reivindicación 1, comprendiendo también la caracterización de cada una de las mencionadas redes lógicas de servicio con parámetros seleccionados de un grupo incluyendo:tipo de tráfico, amplitud de banda, demora, cuenta de saltos, flujo de información asegurada y/o prioridades de restauración.
- 11El método de la reivindicación 1, comprendiendo también la creación de al menos una ruta de etiquetas de conmutación para una ubicación de servicio en particular para configurar la ubicación del servicio en particular con un número correspondiente de rutas virtuales hacia otras ubicaciones de servicio.
- 12El método de la reivindicación 11, en el que cada ruta virtual abarca al menos una ruta física.
- 13Una red de comunicaciones comprendiendo:una pluralidad de rutas de conmutación de etiquetas entre las ubicaciones de servicio correspondientes, cada una de las rutas de conmutación proporcionando una clase de servicios;una etiqueta asignada a cada una de las rutas de conmutación de etiquetas, cada etiqueta identificando una clase de servicios para una ruta de conmutación de etiquetas correspondiente;y una serie de redes lógicas de servicio configuradas para transportar múltiples rutas virtuales de red privadas utilizando las rutas de conmutación de etiquetas.
- 14La red de comunicación de la reivindicación 13, en la que diferentes redes lógicas de servicio se configuran para dar servicio a diferentes especificaciones de tráfico.
- 15La red de comunicación de la reivindicación 13, en la que las ubicaciones de servicio correspondientes no están conectadas directamente. ES 2 393 098 T3
- 16La red de comunicación de la reivindicación 13, comprendiendo también un identificador único asignado a cada instalación de cliente para un cliente.
- 17La red de comunicación de la reivindicación 16, comprendiendo también al menos una ruta de red privada virtual entre las instalaciones de cliente.
- 18La red de comunicación de la reivindicación 17, en la que las instalaciones de los clientes están configuradas para dirigir el tráfico entre ellas a través de la establecida al menos una ruta de red privada virtual basada en la etiqueta asignada y en el identificador único asignado.
- 19La red de comunicación de la reivindicación 13, comprendiendo también etiquetas multiprotocolo asociadas con la serie de redes lógicas de servicio.
- 20La red de comunicación de la reivindicación 13, comprendiendo también una memoria de conmutación de etiquetas multiprotocolo configurada para contener las etiquetas registradas.
- 21La red de comunicación de la reivindicación 13, comprendiendo también una instalación de cliente con un identificador único asignado a ella;y en el que la etiqueta se configura para tener el identificador único registrado a continuación.
- 22La red de comunicación de la reivindicación 13, en la que cada una de las redes lógicas de servicio se caracteriza por unos parámetros seleccionados de un grupo incluyendo:tipo de tráfico, amplitud de banda, demora, cuenta de saltos, flujo de información asegurada y/o prioridades de restauración.
- 23La red de comunicación de la reivindicación 13, comprendiendo también al menos una ruta de conmutación de etiquetas para una ubicación de servicio en particular y configurada para la ubicación de servicio en particular con un número correspondiente de rutas virtuales a otras ubicaciones de servicio.
- 24La red de comunicación de la reivindicación 23, en la que cada ruta virtual abarca al menos una ruta física.
Independent claims24
35 paragraphs in 11 sections, as filed
ES 2 393 098 T3
DESCRIPTION
Equipment and methods for establishing virtual private networks in a broadband network.
RELATED REQUESTS
[0001] This application refers to an application called "Apparatus and Methods for Managing Packets in a Broadband Data Stream" filed on December 15, 2000, with the serial number 09 / 737,916 (published as US2004 / 0196789 and issued as US6741562), an application called "Apparatus and Methods for Scheduling Packets in a Broadband Data Stream" filed December 15, 2000, serial number 09 / 737,917 (published as US2002 / 0110134 and US2009 / 0086628 and issued as US6987732 and US7697430), and an application called "Apparatus and Methods for Processing Packets in a Broadband Data Stream" filed on September 13, 2000.
SCOPE OF THE INVENTION
[0002] The present invention relates to the equipment and methods necessary to establish virtual private networks. In particular, this invention relates to the equipment and methods necessary to establish virtual private networks in a broadband network.
BACKGROUND OF THE INVENTION
[0003] As the Internet becomes a global commercial data network for electronic commerce and the management of public data services, increasingly, consumer demands have focused on the need for consumer services. More advanced Internet Protocol (IP) to improve the content of the accommodation, the dissemination of videos and the application of "outsourcing" (purchase of manufactured products in a foreign company to save costs). In order to remain competitive, network operators and internet service providers (/ SPs) must resolve two main issues: continually meet the demands of growing backbone traffic and provide appropriate Quality of Service (QoS) for that traffic. Today, many vendors / SPs have implemented various virtual path techniques
ES 2 393 098 T3 to overcome these new challenges. In general, existing virtual path techniques require a build of overlapping networks and physical equipment. The best known existing virtual path techniques are: the optical transport network, the asynchronous transfer mode (ATM) I frame relay (FR) or connection technique by means of switching frame relay, and the private virtual networks of the internet protocol. (IP VPN). Figure 1 schematically illustrates the existing common virtual paths for switching layers.
[0004] Optical transport technique 102 is the most commonly used virtual path technique. According to this technique, an ISP provider uses broadband bit pipes to tailor a point-to-point circuit or network for each consumer. Therefore, this technique forces the ISP provider to create a new circuit or network each time a consumer is added. Once the circuit or network is created for a consumer, the bandwidth available to that circuit or network remains static.
[0005] The ATM / FR 104 layer-switching technique provides Quality of Service (QoS) and traffic engineering through point-to-point virtual circuits. Thus, this technique does not require the physical creation of specific circuits or networks, as is the case with the optical transport technique 102. Although this technique 104 is an improvement of the optical transport technique 102, this technique 104 has various drawbacks. One of the major drawbacks of the ATM / FR 104 technique is that this type of technique is not scalable. Furthermore, the ATM / FR 104 technique also requires that a virtual circuit be established each time a request to send data is received from a consumer.
[0006] The IP VPN narrowband network technique 106 uses "best effort" type forwarding and encrypted conduits to provide secure routes to consumers. One of the biggest disadvantages of "best effort" shipping is the lack of guarantees that the package will even be shipped. Therefore, this type of forwarding is not a good option for transmitting critical data.
[0007] An example label switching network is described in EP1065858, which addresses the problems of providing acceptable quality of service and data security. This document publishes that the use of encryption to provide security was already known and acknowledges that encryption is an expensive process. To address this, the system exclusively reserves some multiprotocol label switching (MPLS) pipes for inter-outbound traffic. In this sense, those MPLS conduits can provide security from third-party access without the use of encryption. Since call servers are capable of forcing traffic into MPLS conduits with contracts
ES 2 393 098 T3 of guaranteed traffic, the servers are capable of carrying out an explicit count of the bandwidth from the bandwidth information received from an InterCall signaling server system for each of the streams they manage. Therefore, the system is able to determine if there is sufficient bandwidth available for traffic in one MPLS conduit, and if not, be able to use a different MPLS conduit. MPLS conduits have the same characteristics and are of uncertain traffic. In this system, two labels are attached to each IP packet, the first label identifying the conduit to use and the second label identifying the destination output for the packet.
[0008] EP 1069742 describes a telecommunications network architecture that provides transport and switching of user services.
[0009] Therefore, it is desirable to provide equipment and methods that reduce operating costs for service providers by joining multiple overlapping networks on a multi-service IP trunk. In particular, it is desirable to provide equipment and methods that allow an ISP to build the network once and sell the network multiple times to multiple consumers.
SUMMARY OF THE INVENTION
The invention includes a method for establishing virtual private networks in a communication network. The method comprises the steps of creating a series of label switched link paths, assigning a link label to each of the label switched link paths, and configuring a series of logical service networks through multiprotocol labels. to transport the multiple private virtual network paths using the label switched link paths. According to an exemplary embodiment, each label switched link route provides a class of services and a link label associated with each label switched link route identifies the class of services that route provides. According to an exemplary embodiment, each label switched link path provides a class of services and a link label associated with each label switched link path identifies the class of services provided by that link. According to one embodiment, the creation step includes the step of creating a series of label switched link routes at each service location. A service provider may want to provide services at multiple service locations. According to an exemplary embodiment, the logical service networks are statically configured through the introduction of a service provider. According to another
ES 2 393 098 T3 exemplary embodiment, the service logical networks are configured automatically by means of the software.
In one embodiment, the method also comprises the steps of registering link labels in a multiprotocol label switching memory, assigning a unique identifier to a customer facility and registering that unique identifier on a link label. In another embodiment, the method also comprises the steps of assigning a unique group identifier to customer facilities for a customer and establishing at least one virtual route between customer facilities.
The invention includes a private virtual network with a series of label switched link paths. A label switched link path is defined for a class of services. A link label identifies the class of services for the label switched link path. A number of service logical networks are configured by multiprotocol labels to carry the multiple virtual private paths using the label switched link paths.
[0013] A number of label switched link paths may be defined at each serving location. The rede series logical service networks can be configured statically or automatically. In one embodiment, the link label is registered in a multiprotocol label switch memory. A unique identifier can be assigned to a customer installation by registering it on a binding tag. A unique group identifier can be associated with customer facilities for a particular customer. The virtual private network uses the unique group identifier to form at least one virtual path between customer facilities.
The invention enables service providers to reduce multiple overlapping networks by creating multiple logical service networks (LSNs) over a physical or fiber optic network. LSNs are established by a service provider and can be characterized by type of traffic, bandwidth, delay, hop count, assured information flow, and / or restoration priorities. Once established, LSN networks allow the service provider to provide a variety of services to multiple consumers depending on the traffic specifications of each customer. For example, different LSN networks handle different specification traffic, depending on the characteristics of each LSN network. Furthermore, such LSN networks, once built within a broadband network, can be adapted and sold to multiple customers.
ES 2 393 098 T3
BRIEF DESCRIPTION OF THE DRAWINGS
[0015]
FIG.1 schematically illustrates a prior art for implementing virtual routes.
FIG.2 schematically illustrates an example of implementation of a virtual route according to an embodiment of the invention.
FIG. 3 schematically illustrates exemplary LSN networks in accordance with one embodiment of the invention.
FIG. 4 schematically illustrates an example of a VPN virtual private network according to an embodiment of the invention.
FIG. 5 schematically illustrates an example of a virtual route for a client according to an embodiment of the invention.
FIG. 6 schematically illustrates an example virtual route for multiple clients according to an embodiment of the invention.
DETAILED DESCRIPTION OF THE INVENTION
[0016] FIG. 2 schematically illustrates the switch layer virtual path 200 according to one embodiment of the invention. The switch layer virtual path 200 combines switching and routing to provide virtual services. In particular, the switching layer virtual path 200 combines the advantages of layer 106 (eg scalability and flexibility) and layer 202 (eg security and quality of service). According to FIG. 2, a multiprotocol label switching (MPLS) layer 202 replaces the ATM / FR switching layer 104 of FIG. 1. Multiple label switched link paths (LSP links) are established as link groups at the optical transport layer 102 to carry multiple virtual routing service (VRS) paths 206. LSP link paths allow providers service control traffic. According to an exemplary embodiment, the virtual routing networks 204 are located at the end of the MPLS switching layer 202. The VRS routes 206 are connected to virtual routing networks 204 through the MPLS switching layer 202. According to a mode of embodiment, the VRS routing networks 204 are uniquely identified; therefore, safety is guaranteed. In one exemplary embodiment, non-VRS traffic is directed to an Internet router through the IP Internet routing layer 106. In one embodiment, the switch layer virtual path 200 does not maintain the connections. internet routing tables known for this technique.
ES 2 393 098 T3
[0017] FIG. 3 schematically illustrates an example of an LSN network according to an embodiment of the invention. A service provider creates LSP links at each service location. For example, multiple LSP links are created in San Francisco (SFO), Saint Louis (STL), Chicago, and New York (NYC). In an exemplary embodiment, one LSP link is established for each class of service. Each LSP link can be implemented using the technology described in the commonly named co-pending patent applications: “Apparatus and Methods for Managing Packets in a Broadband Data Stream” filed December 15, 2000, serial number 09 / 737,916 (published as US2004 / 0196789 and issued as US6741562), an application called "Apparatus and Methods for Scheduling Packets in a Broadband Data Stream" filed December 15, 2000, serial number 09 / 737,917 (published as US2002 / 0110134 and US2009 / 0086628 and issued as US6987732 and US7697430), and "Apparatus and Methods for Processing Packets in a Broadband Data Stream" filed September 13, 2000, which is expressly incorporated by reference.
[0018] According to an exemplary embodiment, each LSP link is identified with a link label. In one embodiment, said link label also identifies the class of services assigned to the associated LSP link. According to one embodiment, the LSP link labels (302, 304, 306 and 308) are recorded in an MPLS memory. LNS networks are established based on the LSP links created. In one embodiment, the LNS networks are statically established by introducing a service provider. In another embodiment, the LSNs are established automatically through software. After LSNs are established or built, customer and customer traffic can be custom added to those networks.
[0019] FIG. 4 schematically illustrates an example VPN network for a client according to an embodiment of the invention. In FIG. 4, Customer A signs up for services at multiple locations (customer premises). In one embodiment, each customer facility is assigned a unique identifier (eg a VPN label). In an exemplary embodiment, said unique identifier is recorded at the top of the link tag in MPLS memory. For example, in FIG. 4, Customer A at location 1 is assigned the tag 402 registered at the top of the LSP 302 link network, Customer A at location 2 is assigned the tag 404 registered at the
ES 2 393 098 T3 superior of the link network LSP 304, and customer A at location 3 is assigned the label 406 registered in the upper part of the link network LSP 308. In an example of an embodiment, the facilities Client numbers for a client are grouped together and assigned a single group of network VPN labels called "A". The single group of VPN network labels "A" associates the client premises of the client "A" with a private network.
[0020] FIG. 5 schematically illustrates examples of virtual routes for a client according to an embodiment of the invention. A private IP route is established to guide traffic between customer facilities. For example, a private IP route 502 is established between location 1 and location 2, a private IP route 504 is established between location 2 and location 3, and a private IP route 506 is established between location 1 and location 3. In an exemplary embodiment, a private IP route is a logical route. Private IP routes 502, 504, and 506 are unique to customer A and can be monitored.
According to one embodiment, the private IP routes for each client are associated with each other by a unique group of VPN labels. In an exemplary embodiment, the private IP routes established for each client and the associated unique group of VPN labels provide security assurance. In addition, the LSP links (302, 304 and 308) at each customer facility associate data with a known quality and / or class of service.
[0022] FIG. 6 schematically illustrates multiple VPN networks established for multiple clients in accordance with one embodiment of the invention. In FIG. 6, Customer B signs up for services from multiple locations (customer premises). A single VPN label is assigned to each client installation (location) for client B. As shown, customer B at location 1 is assigned a tag 602 registered at the top of the LSP link path 302, customer B at location 2 is assigned a tag 604 registered at the top of the link path 306, and customer B at location 3 is assigned a tag 606 registered at the top of the LSP link path 308. In an exemplary embodiment, the customer premises for customer B are grouped together and assigned a VPN tag group named "B". The unique VPN tag group named "B" associates customer B's facilities on a private network. Next, a VPN network is established for client B. For example, an IP 608 private route is established between location 1 and location 2, an IP 610 private route is established between location 2 and location 3, and an IP 612 private route is established between location 1 and location 3. IP private routes 608, 610, and 612 are unique to customer B and can be monitored.
ES 2 393 098 T3
[0023] Generally, the separation of the service plane from the network provides significant scalability advantages, in the sense that the network does not need to know the final services offered after providing the adequate quality of the transport service. (QoS). For example, a company can set QoS quality parameters and design a network using a combination of LSP link paths. LSP link path signalings are propagated and passed from node to node using, for example, common signaling techniques such as Resource Reservation Protocol (RSVP) or Limited Routing Label Distribution Protocol (CR-LDP) . The network and link redundancy parameter is set in advance. After establishing the network, the company can add clients to the end of the network. End-to-end services are signaled end-to-end regardless of whether the network or LSP link knows that signaling is taking place. In a sense, the creation of the service only affects the end node where the service is actually created. Therefore, the creation of the service is scalable because it is signaled from start to finish. Any failure in the network is solved at the network level, for example, by reestablishing the LSP link routes that are normally of a smaller magnitude than the number of services that circulate on those links.
[0024] The above examples illustrate certain examples of embodiments of the invention from which other embodiments, or variations and modifications will be apparent to those skilled in the art. The invention should not, therefore, be limited to the embodiments discussed above, but is better defined by the claims.
Contents11
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
22 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 803090 | United States of America | – | |
| 80309001 | United States of America | A | |
| 80309001 | United States of America | A | |
| 803090 | – | – | – |
| US20010803090 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| US2002126681A1 | United States of America | A1 | |
| CA2440241A1 | Canada | A1 | |
| WO02073909A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1366606A1 | European Patent Office (EPO) | A1 | |
| EP1366606A4 | European Patent Office (EPO) | A4 | |
| US6847641B2 | United States of America | B2 | |
| US2005099947A1 | United States of America | A1 | |
| US2007081542A1 | United States of America | A1 | |
| US7835353B2 | United States of America | B2 | |
| EP2296319A1 | European Patent Office (EPO) | A1 | |
| US8014411B2 | United States of America | B2 | |
| US2011286364A1 | United States of America | A1 | |
| EP1366606B1 | European Patent Office (EPO) | B1 | |
| AT557500T | Austria | T | |
| ATE557500T1 | Austria | T1 | |
| EP2296319B1 | European Patent Office (EPO) | B1 | |
| ES2386630T3 | Spain | T3 | |
| ES2393098T3This record | Spain | T3 | |
| US8553705B2 | United States of America | B2 | |
| US2014003292A1 | United States of America | A1 | |
| CA2440241C | Canada | C | |
| US9025615B2 | United States of America | B2 |
Numbers
- Publication
- 2393098
- Publication, DOCDB
- 2393098
- Publication, EPODOC
- ES2393098T
- Application
- 10012763
- Application, DOCDB
- 10012763
- Application, EPODOC
- ES20100012763T
Titles2
- Spanish
- Equipo y métodos para establecer redes virtuales privadas en una red de banda ancha
- English
- Equipment and methods to establish private virtual networks in a broadband network
Classification
- CPC, 10
- H04L12/4604
- H04L41/0893
- H04L12/66
- H04L45/50
- H04Q11/0062
- H04Q2011/0084
- H04Q2011/0086
- H04Q2011/009
- H04L41/0894
- H04L41/32
- IPC, 5
- H04L12 46
- H04Q11 04
- H04L45 50
- H04L12 56
- H04Q11 00