Cloud Data Center Logical Router for Enterprise Network Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing networks do not seamlessly integrate with private enterprise networks, leading to challenges in resource allocation, security, and complexity when treating cloud resources as equivalent to internal resources.

Innovation Solution

A method involving the creation of a logical customer edge router in the Cloud Data Center, allocation of IP addresses, and encapsulation of packets to ensure seamless communication between private enterprise and cloud networks, using a directory server to map addresses and maintain security boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud resources are allocated separately from private enterprise network resources, then scalability and dynamic resource allocation are improved, but network complexity and security management deteriorate

Engineering Contradiction:
Improveresource allocation flexibilityVSAvoidnetwork management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges cloud network resources with private enterprise network resources by implementing a unified addressing scheme where cloud resources are assigned IP addresses from the enterprise's existing address space. This integration allows resources to be treated uniformly across both networks, eliminating the need for separate resource management while maintaining scalability through dynamic IP allocation from available subnets

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal network extension mechanism that enables the private enterprise network to function across both on-premises and cloud environments. By using a common routing protocol and addressing scheme, the network infrastructure can dynamically adapt to resources located anywhere, providing multi-functional capability that handles both fixed enterprise resources and dynamic cloud resources through the same management plane

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If cloud resources use different address spaces, then resource isolation and security are improved, but communication complexity and integration difficulty deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the addressing parameter by assigning cloud resources IP addresses from the enterprise's existing address space rather than using separate cloud address spaces. This parameter change enables seamless communication between enterprise and cloud resources while maintaining security through controlled IP allocation and routing policies that can filter and manage traffic based on the unified address space

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If cloud resources are integrated into the private network, then ease of operation and resource equivalence are improved, but security risks and attack surface deterioration

Engineering Contradiction:
Improveresource management simplicityVSAvoidsecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces routing protocols and network infrastructure components as intermediaries between enterprise resources and cloud resources. These intermediaries maintain security boundaries by controlling and filtering traffic flow, enabling simplified resource management through unified addressing while preventing direct exposure of enterprise resources to potential cloud-based threats through controlled communication paths

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8619779B2Scalable architecture for enterprise extension in a cloud topology
Publication Date: 2013.12.31 ALCATEL LUCENT SA
  • US8619779B2 patent drawing
  • US8619779B2 patent drawing
  • US8619779B2 patent drawing

AI summary

Various embodiments relate to a Cloud Data Center, a system comprising the Cloud Data Center, and a related method. The Cloud Data Center may include a logical customer edge router to send packets between addresses in a private enterprise network and addresses in a logical network within a cloud network. The logical network may have resources, known as virtual machines, allocated to the private enterprise network and may share a common IP address space with the private enterprise network. A directory at the Cloud Data Center may correlate the enterprise IP addresses of virtual machines with a cloud IP address and a location IP address within the logical network. The Cloud Data Center may double encapsulate packets with two specified headers, a cloudIP and locIP header, when sending a packet to a destination in the logical network.