Cloud Bridge Extending Private Cloud Endpoint Groups to Public Cloud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in extending a private cloud to a public cloud while maintaining security and scalability, as existing solutions require significant administrative effort due to differing cloud management structures and security rules between private and public clouds.
Innovation Solution
Establishing a virtual private network between the private and public clouds, with an orchestrator determining access control lists to enable bi-directional communication and creating a layer three connection bridge for secure communication, allowing seamless extension of end point groups or tiers from the private cloud to the public cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a private cloud connects to a public cloud to utilize public cloud resources, then scalability and capacity are improved, but security control and management complexity worsen
Solution Approach 1:
The patent introduces a cloud bridge as an intermediary device that mediates between the private cloud and public cloud networks. This cloud bridge establishes a secure tunnel connection, allowing the private cloud to access public cloud resources while maintaining security policies and reducing direct management complexity between the two cloud environments.
2Reliability
If security rules are enforced between private and public clouds, then data security is improved, but administrative effort and configuration complexity worsen
Solution Approach 1:
The cloud bridge acts as a security intermediary that enforces security policies between private and public clouds. It manages access control lists and security rules centrally, reducing the administrative burden of configuring and maintaining security policies across multiple cloud environments while maintaining strong security controls.
Solution Approach 2:
The cloud bridge provides multiple functions including security enforcement, network routing, and access control in a single device. This multi-functionality reduces the number of separate security appliances and configurations needed, thereby reducing administrative effort while maintaining comprehensive security.
3Ease of operation
If end point groups are extended across clouds, then connectivity and communication are improved, but network complexity and security configuration worsen
Solution Approach 1:
The cloud bridge serves as a network intermediary that extends end point groups across private and public clouds through a tunnelled connection. It abstracts the underlying network complexity by providing a unified network interface, allowing end points to communicate across clouds as if they were on the same local network without requiring complex routing or networking configurations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are systems, methods and computer-readable storage medium for extending a private cloud to a public cloud. The private cloud can be extended to the public cloud by establishing a virtual private network between a private cloud and a public cloud, receiving one or more access control lists provisioned by the private cloud, determining contracts between an end point group of the private cloud and an end point group of the public cloud based on the one or more access control lists, and extending the end point group of the private cloud to the end point group of the public cloud across the virtual private network.