IP Library Granted Patent US 10,091,102
Granted Patent B2
US 10,091,102 · App. 13/737,641 · Granted Oct 2, 2018

Tunnel sub-interface using IP header field

Inventors: Pascal Thubert (Mougins, FR); Michael Behringer (Mougins, FR); Aswini Kumar Sattaluri (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04L45/74H04L12/4633H04L45/64H04L45/68H04L63/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,091,102
App. No.
13/737,641
Granted
Oct 2, 2018
Kind
B2
Abstract

In one implementation, sub-interfaces are defined in Layer three (L3) tunnels, such as generic routing encapsulization (GRE) or Internet protocol security (IPsec) tunnels. Sub-interfaces inside a L3 tunnel may be preferred to using several L3 tunnels. The flow label of the tunnel header is used to define sub-interfaces of a tunnel interface. The flow label is populated with a routing instance identifier to index the sub-interfaces.

Claims (38)

1. A method comprising:

creating layer three tunnels between devices in a network, wherein each layer three tunnel has a tunnel header;

operating multiple routing instances for the network;

inserting identifiers of the routing instances for packets of data traffic into flow label fields of the tunnel headers, different identifiers for each of the created tunnels representing parallel virtual point-to-point routes between the same devices;

communicating the packets of the data traffic between the devices using the created tunnels based on the tunnel headers of the packets of the data traffic;

separating the packets of the data traffic based on the identifiers of the routing instances from the flow label fields of the tunnel headers; and

routing the separated packets according to the respective routing instances from the flow label fields of the tunnel headers,

wherein operating the multiple routing instances for the network comprises operating multiple routing instances of a routing protocol for low power and lossy networks (RPL), and wherein inserting comprises inserting RPL instance identifiers.

2. The method of claim 1 wherein creating the tunnels comprises creating secure tunnels.

3. The method of claim 1 wherein creating the tunnels comprises creating the tunnels as IPsec tunnels.

4. The method of claim 1 wherein operating the multiple routing instances comprises operating a control plane with different ones of the instances corresponding to network evolution over time in an autonomic network.

5. The method of claim 1 wherein operating the multiple routing instances comprises operating the multiple routing instances pursuant to a common virtual routing and forwarding.

6. The method of claim 1 wherein inserting the identifiers comprises inserting the identifiers of the routing instances into differentiated services code point fields of the tunnel headers.

7. The method of claim 1 wherein inserting the identifiers comprises inserting the identifiers into an unused field in the tunnel header.

8. The method of claim 1 wherein separating comprises extracting the identifiers from the flow label fields of tunnel headers, and wherein routing comprises removing the tunnel headers and transmitting the packets based on destinations in the packets.

9. The method of claim 1 further comprising including the flow label fields in message integrity checks.

10. The method of claim 1 , further comprising swapping a flow label field of the packets with the flow label fields of the tunnel headers for the communicating, wherein the communicating comprises encrypting the packets.

11. The method of claim 1 wherein the different identifiers for each created tunnel are for different types of information.

12. A system comprising:

a plurality of devices in a network, each device configured to:

create layer three tunnels between devices in a network, wherein each layer three tunnel has a tunnel header; and

operate multiple routing instances for the network by operating multiple routing instances of a routing protocol for low power and lossy networks (RPL);

an ingress device among the plurality of devices configured to:

insert identifiers of the routing instances for packets of data traffic into flow label fields of the tunnel headers, different identifiers for each of the created tunnels representing parallel virtual point-to-point routes between the same devices, wherein inserting comprises inserting RPL instance identifiers; and

communicate the packets of the data traffic between the devices using the created tunnels based on the tunnel headers of the packets of the data traffic; and an egress device among the plurality of devices configured to:

separate the packets of the data traffic based on the identifiers of the routing instances from the flow label fields of the tunnel headers; and

route the separated packets according to the respective routing instances from the flow label fields of the tunnel headers.

13. The system of claim 12 , wherein each device in the network is configured to create the tunnels by creating secure tunnels.

14. The system of claim 12 , wherein at least some of the devices in the network are configured to create the tunnels by creating the tunnels as IPsec tunnels.

15. The system of claim 12 , wherein each device in the network is configured to operate the multiple routing instances by operating a control plane with different ones of the instances corresponding to network evolution over time in an autonomic network.

16. The system of claim 12 , wherein each device in the network is configured to operate the multiple routing instances by operating the multiple routing instances pursuant to a common virtual routing and forwarding.

17. The system of claim 12 , wherein the ingress device is configured to insert the identifiers by inserting the identifiers of the routing instances into differentiated services code point fields of the tunnel headers.

18. The system of claim 12 , wherein the egress device is configured to:

separate the packets of data traffic by extracting the identifiers from the flow label fields of tunnel headers; and

route the separated packets by removing the tunnel headers and transmitting the packets based on destinations in the packets.

19. The system of claim 12 , wherein the ingress device is further configured to include the flow label fields in message integrity checks.

20. The system of claim 12 , wherein the ingress device is further configured to:

swap a flow label field of the packets with the flow label fields of the tunnel headers to communicate the packets by encrypting the packets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2013
From: THUBERT, PASCAL; BEHRINGER, MICHAEL; SATTALURI, ASWINI KUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 029672/0340 →
Continuity (1)
Related Publication 20140192808A1 · Jul 10, 2014
Cited By (2)
US 12,401,602 US 12,500,843