IP Library Granted Patent US 12,463,936
Granted Patent B2
US 12,463,936 · App. 18/059,693 · Granted Nov 4, 2025

Virtualized network functions through address space aggregation

Inventors: Syed Khalid Raza (Fremont, CA); Murtuza Attarwala (Davis, CA)
Assignee: Cisco Technology, Inc.
H04L61/2592H04L45/74H04L61/2514
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,936
App. No.
18/059,693
Granted
Nov 4, 2025
Kind
B2
Abstract

In some examples, an example method to provide a virtualized Carrier-grade Network Address Translation (CGN) at a first customer edge router may include establishing a tunnel between the first customer edge router and each aggregation router among one or more aggregation routers, performing a Network Address Translation (NAT) on a first data packet to create a NAT'ed first data packet, selecting a first aggregation router from amongst the one or more aggregation routers to send the NAT'ed first data packet to, encapsulating the NAT'ed first data packet with overlay information corresponding to a tunnel established between the first customer edge router and a first aggregation router, and sending the encapsulated NAT'ed first data packet through the tunnel to the first aggregation router.

Claims (62)

1 . A method to provide address translation at a customer edge router, the customer edge router being one of a plurality of customer edge routers, the method comprising:

establishing, using the customer edge router, a respective tunnel between the customer edge router in a network provider domain and each respective aggregation router among one or more aggregation routers in one or more function provider domains;

performing, using the customer edge router, a Network Address Translation (NAT) on a first data packet to create a NAT′ed first data packet, the NAT being a translation of a private IP address of the customer edge router to a public IP address of an aggregation router included in the one or more aggregation routers;

selecting, using the customer edge router, the aggregation router from amongst the one or more aggregation routers to send the NAT′ed first data packet to;

encapsulating, using the customer edge router, the NAT′ed first data packet with overlay information corresponding to the respective tunnel established between the customer edge router and the aggregation router to yield an encapsulated NAT′ed first data packet; and

sending, using the customer edge router, the encapsulated NAT′ed first data packet through the respective tunnel to the aggregation router.

2 . The method of claim 1 , wherein the public IP address is a device address associated with the customer edge router.

3 . The method of claim 2 , wherein the device address is an individual IP address of a functional IP address space associated with the aggregation router.

4 . The method of claim 1 , wherein:

the first data packet is received from a computing device associated with a Virtual Private Network (VPN); and

the method further comprises maintaining a Virtual Routing and Forwarding (VRF) record based on the NAT, the maintaining of the VRF record including entering an address associated with the computing device in the VRF record.

5 . The method of claim 1 , further comprising maintaining a NAT record based on the NAT, the maintaining including creating an entry in a NAT table indicative of a Virtual Private Network (VPN) associated with the first data packet.

6 . The method of claim 5 , wherein the NAT record is associated with the private IP address of the customer edge router and the public IP address of the aggregation router.

7 . The method of claim 1 , wherein:

the overlay information includes an overlay header; and

the overlay header includes a port address associated with the customer edge router and a port address associated with the aggregation router used to establish the respective tunnel between the customer edge router and the aggregation router.

8 . The method of claim 1 , further comprising:

receiving, using the customer edge router, a second data packet through the respective tunnel established between the customer edge router and the aggregation router;

removing, using the customer edge router, overlay information from the second data packet to create a de-encapsulated second data packet;

performing, using the customer edge router, a reverse NAT on the de-encapsulated second data packet to yield a reverse NAT′ed de-encapsulated second data packet; and

forwarding the reverse NAT′ed de-encapsulated second data packet for delivery to a destination address specified in the reverse NAT′ed de-encapsulated second data packet.

9 . The method of claim 1 , further comprising terminating one or more tunnels from an endpoint layer to form a gateway.

10 . The method of claim 9 , further comprising advertising an aggregated IP space.

11 . The method of claim 1 , further comprising:

receiving, using the aggregation router, the encapsulated NAT′ed first data packet through the respective tunnel;

removing, using the aggregation router, the overlay information to yield a de-encapsulated NAT′ed packet; and

maintaining, using the aggregation router, a record of the respective tunnel through which the encapsulated NAT′ed first data packet was received without maintaining any NAT state information.

12 . A customer edge router, the customer edge router included in a plurality of customer edge routers, the customer edge router comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions, wherein execution of the instructions causes the processor to:

establish a respective tunnel between the customer edge router in a network provider domain and each respective aggregation router among one or more aggregation routers in one or more function provider domains;

perform a Network Address Translation (NAT) on a first data packet to create a NAT′ed first data packet, the NAT being a translation of a private IP address of the customer edge router to a public IP address of an aggregation router included in the one or more aggregation routers;

select the aggregation router from amongst the one or more aggregation routers to send the NAT′ed first data packet to;

encapsulate the NAT′ed first data packet with overlay information corresponding to the respective tunnel established between the customer edge router and the aggregation router to yield an encapsulated NAT′ed first data packet; and

send the encapsulated NAT′ed first data packet through the respective tunnel to the aggregation router.

13 . The customer edge router of claim 12 , wherein the public IP address is a device address associated with the customer edge router.

14 . The customer edge router of claim 13 , wherein the device address is an individual IP address of a functional IP address space associated with the first aggregation router.

15 . The customer edge router of claim 12 , wherein:

the overlay information includes an overlay header, and

the overlay header includes a port address associated with the customer edge router and a port address associated with the aggregation router used to establish the respective tunnel between the customer edge router and the aggregation router.

16 . The customer edge router of claim 12 , wherein execution of the instructions causes the processor to:

receive a second data packet using the respective tunnel;

remove overlay information from the second data packet to create a de-encapsulated second data packet;

perform a reverse NAT on the de-encapsulated second data packet to yield a reverse NAT′ed de-encapsulated second data packet; and

forward the reverse NAT′ed de-encapsulated second data packet for delivery to a destination address specified in the reverse NAT′ed de-encapsulated second data packet.

17 . A non-transitory computer-readable storage media storing thereon instructions that, in response to execution by a processor of a customer edge router, causes the processor to:

establish a respective tunnel between the customer edge router in a network provider domain and each respective aggregation router among one or more aggregation routers in one or more function provider domains;

perform a Network Address Translation (NAT) on a first data packet to create a NAT′ed first data packet, the NAT being a translation of a private IP address of the customer edge router to a public IP address of an aggregation router included in the one or more aggregation routers;

select the aggregation router from amongst the one or more aggregation routers to send the NAT′ed first data packet to;

encapsulate the NAT′ed first data packet with overlay information corresponding to the respective tunnel established between the customer edge router and the aggregation router to yield an encapsulated NAT′ed first data packet; and

send the encapsulated NAT′ed first data packet through the respective tunnel to the aggregation router.

18 . The non-transitory computer-readable storage media of claim 17 , wherein:

the public IP address is a device address associated with the customer edge router; and

the device address is an individual IP address of a functional IP address space associated with the aggregation router.

19 . The non-transitory computer-readable storage media of claim 17 , further storing thereon instructions that, in response to execution by the processor, causes the processor to:

receive a second data packet through the respective tunnel;

remove overlay information from the second data packet to create a de-encapsulated second data packet;

perform a reverse NAT on the de-encapsulated second data packet to yield a reverse NAT′ed de-encapsulated second data packet; and

forward the reverse NAT′ed de-encapsulated second data packet for delivery to a destination address specified in the reverse NAT′ed de-encapsulated second data packet.

20 . The non-transitory computer-readable storage media of claim 17 , wherein:

the overlay information includes an overlay header, and

the overlay header includes a port address associated with the customer edge router and a port address associated with the aggregation router used to establish the respective tunnel between the customer edge router and the aggregation router.

Continuity (2)
Continuation 15664869 · Jul 31, 2017
Related Publication 20230090829A1 · Mar 23, 2023
References Cited (43)
US 7411975B1 · Mohaban · 2008 [cited by examiner]
US 8316435B1 · Varadhan · 2012 [cited by examiner]
US 8725898B1 · Vincent · 2014 [cited by examiner]
US 9641434B1 · Laurence · 2017 [cited by examiner]
US 9948552B2 · Teng · 2018 [cited by examiner]
US 11522828B2 · Raza · 2022 [cited by examiner]
US 20010043571A1 · Jang · 2001 [cited by examiner]
US 20020023174A1 · Garrett · 2002 [cited by examiner]
US 20040044789A1 · Angel · 2004 [cited by examiner]
US 20050041675A1 · Trostle · 2005 [cited by examiner]
US 20060013209A1 · Somasundaram · 2006 [cited by applicant]
US 20060062206A1 · Krishnaswamy · 2006 [cited by examiner]
US 20070064661A1 · Sood · 2007 [cited by applicant]
US 20080069111A1 · Sutton · 2008 [cited by examiner]
US 20090034557A1 · Fluhrer · 2009 [cited by examiner]
US 20110145434A1 · Ringen · 2011 [cited by examiner]
US 20120027013A1 · Napierala · 2012 [cited by examiner]
US 20120151057A1 · Paredes et al. · 2012 [cited by applicant]
US 20120204251A1 · Kopti · 2012 [cited by examiner]
US 20130294461A1 · Zhou et al. · 2013 [cited by applicant]
US 20140237140A1 · Sarawat · 2014 [cited by examiner]
US 20140280884A1 · Searle et al. · 2014 [cited by applicant]
US 20140313905A1 · Zampiello · 2014 [cited by examiner]
US 20150124622A1 · Kovvali · 2015 [cited by examiner]
US 20150222734A1 · Inada · 2015 [cited by examiner]
US 20160308762A1 · Teng · 2016 [cited by examiner]
US 20170085529A1 · Finkelstein · 2017 [cited by examiner]
US 20170093702A1 · Teng · 2017 [cited by examiner]
US 20170118127A1 · Finkelstein · 2017 [cited by examiner]
US 20170222833A1 · Brandwine · 2017 [cited by examiner]
US 20180054421A1 · Deb · 2018 [cited by examiner]
US 20180324247A1 · Hood · 2018 [cited by examiner]
US 20180336059A1 · Thomas · 2018 [cited by examiner]
US 20190007366A1 · Voegele · 2019 [cited by examiner]
US 20190036876A1 · Raza · 2019 [cited by examiner]
US 20230188492A1 · Shen · 2023 [cited by examiner]
CN 102546407 · 2012 [cited by applicant]
EP 2635002 · 2013 [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2018/043618, mailed Feb. 13, 2020, 8 Pages. [cited by applicant]
International Search Report and Written Opinion from the International Searching Authority, mailed Oct. 24, 2018, 2018, 10 pages, for corresponding International Patent Application No. PCT/US2018/043618. [cited by applicant]
Borella, M., et al., “Realm Specific IP: Protocol Specification,” Oct. 2001, pp. 1-54. [cited by applicant]
Cui, Y., et al., “Lightweight 4over6: An Extension to the Dual-Stack Lite Architecture,” Jul. 2015, pp. 1-22. [cited by applicant]
Durand, A., et al., “Dual-Stack Lite Broadband Deployments Following IPv4 Exhaustion,” Aug. 2011, pp. 1-32. [cited by applicant]