Cloud Network Device Direct VM Public IP Assignment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud computing environments perform network address translation (NAT) on packets with public IP addresses, which can disrupt network protocols and hinder direct communication between virtual machines (VMs), leading to inefficiencies and security concerns.
Innovation Solution
A cloud network device is assigned a single public IP address and distributes separate public IP addresses to each VM, enabling direct communication between VMs without NAT, while ensuring security by isolating user access to subscribed VMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NAT is performed on packets with public IP addresses, then network address translation is achieved, but network protocols are disrupted and direct communication between VMs is hindered
Solution Approach 1:
The patent extracts the NAT function from the network communication path by assigning public IP addresses directly to VMs. This removes the packet transformation step that disrupted protocols, allowing VMs to communicate directly with public networks without NAT-induced protocol issues while maintaining security through controlled access paths.
Solution Approach 2:
The patent segments the network architecture by creating distinct network paths: one for public IP address assignment to individual VMs and another for private network communication. This segmentation allows public communication without NAT while preserving private network security boundaries, resolving the contradiction between adaptability and protocol integrity.
2Adaptability or versatility
If NAT is performed on packets, then address translation is enabled, but communication efficiency decreases due to packet transformation
Solution Approach 1:
By removing NAT from the communication path and assigning public IP addresses directly to VMs, the patent eliminates the packet transformation overhead. This extraction of the NAT function restores full communication efficiency while maintaining address translation capability through direct public IP assignment.
3Productivity
If VMs are assigned public IP addresses, then direct communication is enabled, but security isolation may be compromised
Solution Approach 1:
The patent applies local quality by assigning public IP addresses to specific VMs based on their security requirements and access needs. Not all VMs receive public IP addresses - only those that require direct public communication. This selective assignment maintains security isolation for VMs that don't need public access while enabling efficient communication for those that do.
Solution Approach 2:
The patent introduces a cloud network device as an intermediary that manages public IP address assignment and traffic routing. This mediator controls which VMs receive public IP addresses and how traffic is routed, maintaining security isolation while enabling efficient public communication when necessary.
4Device complexity
If a single public IP address is assigned to the cloud network device, then device complexity is reduced, but VM-specific public communication capability is limited
Solution Approach 1:
The patent applies universality by enabling the cloud network device to perform multiple functions: it can assign public IP addresses to individual VMs, route traffic between VMs with public IP addresses, and maintain a single public IP address for itself. This multi-functionality allows the device to support VM-specific public communication while maintaining simplified device configuration.
Data Source
AI summary
A network device, of a cloud computing environment, receives a packet destined for a virtual machine of the cloud computing environment. The packet is received from a user device and via public network. The network device is associated with a first public Internet protocol (IP) address, and the virtual machine is associated with a second public IP address that is different than the first public IP address. The network device determines, based on the packet, the second public IP address associated with the virtual machine, and provides the packet to the virtual machine based on the second public IP address associated with the virtual machine.


