Cloud Network Device Direct VM Public IP Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing environments perform network address translation (NAT) on packets with public IP addresses, which can disrupt network protocols and hinder direct communication between virtual machines (VMs), leading to inefficiencies and security concerns.

Innovation Solution

A cloud network device is assigned a single public IP address and distributes separate public IP addresses to each VM, enabling direct communication between VMs without NAT, while ensuring security by isolating user access to subscribed VMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NAT is performed on packets with public IP addresses, then network address translation is achieved, but network protocols are disrupted and direct communication between VMs is hindered

Engineering Contradiction:
Improvenetwork address translation capabilityVSAvoidnetwork protocol integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the NAT function from the network communication path by assigning public IP addresses directly to VMs. This removes the packet transformation step that disrupted protocols, allowing VMs to communicate directly with public networks without NAT-induced protocol issues while maintaining security through controlled access paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the network architecture by creating distinct network paths: one for public IP address assignment to individual VMs and another for private network communication. This segmentation allows public communication without NAT while preserving private network security boundaries, resolving the contradiction between adaptability and protocol integrity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If NAT is performed on packets, then address translation is enabled, but communication efficiency decreases due to packet transformation

Engineering Contradiction:
Improveaddress translation capabilityVSAvoidcommunication efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

By removing NAT from the communication path and assigning public IP addresses directly to VMs, the patent eliminates the packet transformation overhead. This extraction of the NAT function restores full communication efficiency while maintaining address translation capability through direct public IP assignment.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If VMs are assigned public IP addresses, then direct communication is enabled, but security isolation may be compromised

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning public IP addresses to specific VMs based on their security requirements and access needs. Not all VMs receive public IP addresses - only those that require direct public communication. This selective assignment maintains security isolation for VMs that don't need public access while enabling efficient communication for those that do.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a cloud network device as an intermediary that manages public IP address assignment and traffic routing. This mediator controls which VMs receive public IP addresses and how traffic is routed, maintaining security isolation while enabling efficient public communication when necessary.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If a single public IP address is assigned to the cloud network device, then device complexity is reduced, but VM-specific public communication capability is limited

Engineering Contradiction:
Improvenetwork device configurationVSAvoidVM public communication capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by enabling the cloud network device to perform multiple functions: it can assign public IP addresses to individual VMs, route traffic between VMs with public IP addresses, and maintain a single public IP address for itself. This multi-functionality allows the device to support VM-specific public communication while maintaining simplified device configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11038954B2Secure public connectivity to virtual machines of a cloud computing environment
Publication Date: 2021.06.15 VERIZON PATENT & LICENSING INC
  • US11038954B2 patent drawing
  • US11038954B2 patent drawing
  • US11038954B2 patent drawing

AI summary

A network device, of a cloud computing environment, receives a packet destined for a virtual machine of the cloud computing environment. The packet is received from a user device and via public network. The network device is associated with a first public Internet protocol (IP) address, and the virtual machine is associated with a second public IP address that is different than the first public IP address. The network device determines, based on the packet, the second public IP address associated with the virtual machine, and provides the packet to the virtual machine based on the second public IP address associated with the virtual machine.