US20060133265A1

Virtual private networking methods and systems

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Virtual private networking methods and systems are disclosed. A label switched path (LSP) is established between network elements which provide access to different autonomous systems (ASs). A record of resources which are used for the LSP is maintained, and a backup LSP is established between the network elements. The backup LSP excludes resources which were used for the LSP. Labeled routes associated with each AS are then redistributed to the network element within the other AS using the LSP or the backup LSP. In another embodiment, VPN labeled routes used by a first network element in a first AS and belonging to a VPN are aggregated into an aggregated inter-AS VPN labeled route, which is distributed to a second AS and redistributed to a second network element, in the second AS, which belongs to the VPN. A data structure for mapping VPN labeled routes to an aggregated inter-AS labeled route is also disclosed.

Term

Term ended

Projected expiry passed 22 December 2024, 1.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

20 claims: 5 independent, 15 dependent

  1. 1
    Broadest claimClaim Score 77, broad(NHIP)A method of providing a virtual private network (VPN) including network elements which provide access to respective autonomous systems (ASs), the method comprising:establishing a label switched path (LSP) between the network elements;maintaining a record of resources which are used for the LSP in at least one of the ASs;establishing a backup LSP between the network elements, the backup LSP excluding the resources which are used for the LSP;and redistributing labeled routes associated with each AS to the network element within the other AS using the LSP or the backup LSP.
  2. 6
    A system for providing a virtual private network (VPN) including network elements which provide access to respective autonomous systems (ASs), the system comprising:a transceiver configured for communication within one of the ASs and a communication link connecting the ASs;and a communications control module configured to establish a label switched path (LSP) between the network elements through the transceiver, to maintain a record of resources which are used for the LSP in at least one of the ASs, to establish a backup LSP between the network elements, the backup LSP excluding the resources which are used for the LSP, and to redistribute labeled routes associated with the one of the ASs to the network element within the other AS using the LSP or the backup LSP.
  3. 11
    A method of configuring an inter-domain virtual private network (VPN) between network elements which provide access to a plurality of autonomous systems (ASs), the method comprising:distributing within a first AS a plurality of VPN labeled routes used by a first network element in the first AS and belonging to a VPN;aggregating at least a subset of the plurality of VPN labeled routes into an aggregated inter-AS VPN labeled route;distributing the aggregated inter-AS VPN labeled route to a second AS;and redistributing the aggregated inter-AS VPN labeled route to a second network element in the second AS belonging to the VPN.
  4. 16
    A system for configuring an inter-domain virtual private network (VPN) between network elements which provide access to a plurality of autonomous systems (ASs), the system comprising:a transceiver adapted for communication both within a first AS and with a second AS;and a communications control module configured to receive through the transceiver from a first network element in the first AS and belonging to a VPN a plurality of VPN labeled routes used by the first network element, to aggregate at least a subset of the plurality of VPN labeled routes into an aggregated inter-AS VPN labeled route, and to distribute the aggregated inter-AS VPN labeled route through the transceiver to the second AS for redistribution by the second AS to a second network element in the second AS belonging to the VPN.
  5. 20
    A machine-readable medium storing a data structure comprising:a plurality of data fields storing identifiers associated with respective virtual private network (VPN) labeled routes used by a first network element in a first autonomous system (AS) and belonging to a VPN, the VPN labeled routes being distributed within the first AS by the first network element;and a data field storing an identifier of an aggregated inter-AS VPN labeled route into which the plurality of VPN labeled routes is aggregated, the aggregated inter-AS VPN labeled route being distributed to a second AS for redistribution to a second network element in the second AS belonging to the VPN.