Cloud Bridge Extending Private Cloud Endpoint Groups to Public Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in extending a private cloud to a public cloud while maintaining security and scalability, as existing solutions require significant administrative effort due to differing cloud management structures and security rules between private and public clouds.

Innovation Solution

Establishing a virtual private network between the private and public clouds, with an orchestrator determining access control lists to enable bi-directional communication and creating a layer three connection bridge for secure communication, allowing seamless extension of end point groups or tiers from the private cloud to the public cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a private cloud connects to a public cloud to utilize public cloud resources, then scalability and capacity are improved, but security control and management complexity worsen

Engineering Contradiction:
ImprovescalabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud bridge as an intermediary device that mediates between the private cloud and public cloud networks. This cloud bridge establishes a secure tunnel connection, allowing the private cloud to access public cloud resources while maintaining security policies and reducing direct management complexity between the two cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security rules are enforced between private and public clouds, then data security is improved, but administrative effort and configuration complexity worsen

Engineering Contradiction:
Improvedata securityVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud bridge acts as a security intermediary that enforces security policies between private and public clouds. It manages access control lists and security rules centrally, reducing the administrative burden of configuring and maintaining security policies across multiple cloud environments while maintaining strong security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud bridge provides multiple functions including security enforcement, network routing, and access control in a single device. This multi-functionality reduces the number of separate security appliances and configurations needed, thereby reducing administrative effort while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If end point groups are extended across clouds, then connectivity and communication are improved, but network complexity and security configuration worsen

Engineering Contradiction:
ImproveconnectivityVSAvoidnetwork complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The cloud bridge serves as a network intermediary that extends end point groups across private and public clouds through a tunnelled connection. It abstracts the underlying network complexity by providing a unified network interface, allowing end points to communicate across clouds as if they were on the same local network without requiring complex routing or networking configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3276490B1Extension of a private cloud end-point group to a public cloud
Publication Date: 2020.02.12 CISCO TECHNOLOGY INC
  • EP3276490B1 patent drawingFigure 1
  • EP3276490B1 patent drawingFigure 2
  • EP3276490B1 patent drawingFigure 3

AI summary

Disclosed are systems, methods and computer-readable storage medium for extending a private cloud to a public cloud. The private cloud can be extended to the public cloud by establishing a virtual private network between a private cloud and a public cloud, receiving one or more access control lists provisioned by the private cloud, determining contracts between an end point group of the private cloud and an end point group of the public cloud based on the one or more access control lists, and extending the end point group of the private cloud to the end point group of the public cloud across the virtual private network.