Cloud Gateway Service Insertion in Public Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring and providing services in public cloud environments is challenging due to limited control over underlying hypervisors and hardware, leading to performance and scalability issues with service insertion for virtual machines (VMs) and service virtualized computing instances (SVMs).

Innovation Solution

Deploying a network device, such as a cloud gateway, within the same virtual network as the service virtualized computing instance allows native communication, eliminating the need for tunnels and resource-intensive IPSec operations, thereby improving throughput by enabling service insertion for east-west and north-south traffic without requiring direct access to underlying hypervisors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If service insertion is implemented in public cloud environments using traditional methods, then services can be provided for virtual machines, but throughput is reduced due to the need for tunnels and IPSec operations

Engineering Contradiction:
Improveservice insertion throughputVSAvoidencapsulation and decapsulation operations
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the service insertion function from the traditional hypervisor-level implementation and relocates it to a network device at the network layer. This separation allows service insertion to occur without requiring direct access to hypervisors or complex tunneling mechanisms, thereby improving throughput by eliminating resource-intensive IPSec operations while maintaining service functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If direct access to underlying hypervisors is required for service insertion, then service control is improved, but device complexity and operational difficulty increase in public cloud environments

Engineering Contradiction:
Improveservice configuration easeVSAvoidhypervisor access requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a network device as an intermediary between the service virtualized computing instance and the underlying hypervisor infrastructure. This network device performs service insertion at the network layer without requiring direct access to hypervisors, thereby simplifying operations and reducing complexity while maintaining effective service control through standard network protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If service virtualized computing instances are deployed in public cloud environments, then cloud scalability is improved, but service insertion performance deteriorates due to limited control over infrastructure

Engineering Contradiction:
Improvecloud environment adaptabilityVSAvoidservice insertion performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent shifts the service insertion operation from the virtualization layer (hypervisor level) to the network layer. This dimensional change allows service insertion to occur independently of hypervisor control, enabling high-performance service processing in public cloud environments where full infrastructure control is limited, thus maintaining both cloud scalability and service insertion performance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3903456B1Service insertion in public cloud environments
Publication Date: 2024.08.21 VMWARE INC
  • EP3903456B1 patent drawingFigure 1
  • EP3903456B1 patent drawingFigure 2
  • EP3903456B1 patent drawingFigure 3

AI summary

Example methods are provided a network device to perform service insertion in a public cloud environment that includes a first virtual network and a second virtual network. In one example method, in response to receiving a first encapsulated packet from a first virtualized computing instance located in the first virtual network, the network device may generate a decapsulated packet by performing decapsulation to remove, from the first encapsulated packet. The method may also comprise identifying a service path specified by a service insertion rule, and sending the decapsulated packet to the service path to cause the service path to process the decapsulated packet according to one or more services. The method may further comprise: in response to the network device receiving the decapsulated packet processed by the service path, sending the decapsulated packet, or generating and sending a second encapsulated packet, towards a destination address.