Appliance Backnet for Vendor Traffic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, customers face challenges in managing dedicated network spaces, where appliance services require specific communication with vendors or other instances, leading to issues like unintended billing and operational decoupling, as existing technologies lack efficient mechanisms for isolating and managing traffic within dedicated customer clouds.
Innovation Solution
The implementation of a 'backnet' – a dedicated, vendor-owned sub-network within the customer cloud, utilizing separate virtual network interfaces for customer and vendor communication, allowing for explicit control and separation of traffic types, enabling appliance vendors to manage and bill for their own bandwidth usage while maintaining customer isolation and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a customer uses a dedicated customer network space to isolate from other users, then network isolation and security are improved, but appliance services cannot communicate with vendors outside the dedicated space and billing control becomes difficult
Solution Approach 1:
The patent divides the network communication into two distinct segments: a customer-facing network interface for customer traffic and a vendor-facing network interface for appliance-vendor communication. This segmentation allows the customer network space to remain isolated and secure while enabling appliances to communicate with vendors through a separate, dedicated channel that bypasses customer network restrictions.
Solution Approach 2:
The patent introduces a network appliance as an intermediary component that resides within the customer network space but maintains separate communication paths. The appliance acts as a mediator between customer traffic and vendor traffic, allowing vendor communication to occur through controlled interfaces without compromising the isolation of the customer network space.
2Productivity
If appliance services communicate with vendors outside the customer cloud, then operational functionality is maintained, but customers are incorrectly billed for vendor-related bandwidth usage
Solution Approach 1:
The patent segments network traffic into customer-initiated traffic and vendor-initiated traffic through separate network interfaces and communication paths. Vendor-related bandwidth usage is isolated in a distinct communication channel that is excluded from customer billing metrics, allowing accurate differentiation between billable and non-billable traffic.
Solution Approach 2:
The patent implements monitoring and control mechanisms that track bandwidth usage by source and destination. The system provides feedback to the billing system to identify and exclude vendor-related traffic from customer billing calculations, ensuring that customers are only charged for their own network consumption.
3Adaptability or versatility
If customers control all traffic in their dedicated network space, then network autonomy is improved, but appliance operations are restricted by customer traffic restrictions
Solution Approach 1:
The patent creates separate network control domains: one where the customer has full control over customer-facing traffic, and another where the vendor has control over appliance-vendor communication. This segmentation allows both customer autonomy and appliance functionality to coexist without conflict.
Solution Approach 2:
The patent applies different control characteristics to different parts of the network infrastructure. Customer network space maintains strict customer control for customer traffic, while appliance network spaces have configured access to vendor interfaces. Each network segment has tailored control properties appropriate to its function.
Data Source
AI summary
A backnet can be created within a dedicated private network of a customer that enables a distinct party to access and/or control a portion of the resources within the private network. In one example, a backnet includes a separate virtual interface for an appliance or other such resource that is not visible or accessible to the customer owning the customer cloud, but can be accessed by another appliance or component in the customer cloud, or an appliance vendor external to the customer cloud. While the customer can control the permission for the backnet, the vendor can control or implement the resources within the backnet in a way that is isolated from the customer. Usage of the backnet can be separately monitored and billed to the vendor, even though the resources are part of the dedicated customer cloud.


