Automated Cloud Network Connection via Policy Switch

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed cloud architectures, application managers face challenges in automatically establishing network connections between application components across different data centers, especially when private networks are involved, as they often lack access to necessary information and may not be granted wide access by private network owners.

Innovation Solution

An application manager with a processor and data storage, programmed to establish application components, select components, identify network characteristics from a network policy file, determine and associate necessary network connections, and establish connections between components, allowing for automatic interconnection without revealing sensitive network information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application providers manually manage network connections to private networks, then access control and security can be maintained, but the complexity and time required to establish and track network connections increases significantly

Engineering Contradiction:
Improvenetwork connection securityVSAvoidconnection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network switch as an intermediary device that automatically establishes network connections between application components and private networks. The switch receives connection requests from the application manager and autonomously configures network paths based on policy information, eliminating the need for application providers to manually manage complex network connections while maintaining security through controlled access policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service automation where the application manager automatically discovers private networks, retrieves policy information, and establishes network connections without human intervention. The network switch further autonomously manages connection lifecycle events including monitoring, failure detection, and reconnection attempts, freeing operators from manual tracking and management tasks.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If application providers are granted wide access to private networks, then network connection establishment becomes easier, but sensitive network information is exposed and security restrictions are violated

Engineering Contradiction:
Improveconnection establishment easeVSAvoidinformation exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network switch acts as a trusted intermediary that the application provider does not need to directly access. The switch receives policy information from private networks and uses this information to automatically establish appropriate connections. This allows connection establishment to proceed easily while the application provider never directly accesses or exposes sensitive private network information, as the switch handles all network configuration and policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network access by separating the application provider's role from direct network configuration. The application manager handles high-level connection requests while the network switch handles detailed network configuration and policy compliance. This segmentation allows ease of operation at the application level while maintaining security and information protection at the network level through automated policy enforcement.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated connection establishment is implemented without network policy files, then connection speed increases, but compliance with private network access restrictions cannot be ensured

Engineering Contradiction:
Improveconnection establishment speedVSAvoidpolicy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by having the network switch proactively discover private networks and retrieve policy information before connection requests are made. Policy files are pre-configured with network access restrictions and requirements. When connection requests arrive, the switch can immediately match them against pre-retrieved policy information, enabling fast automated connection establishment that is guaranteed to comply with private network restrictions.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If manual tracking of network changes is required, then connection accuracy can be maintained, but time and operational overhead increase significantly

Engineering Contradiction:
Improveconnection tracking accuracyVSAvoidtime to track network changes
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network switch implements continuous feedback mechanisms by monitoring network connection states, policy changes, and private network events in real-time. When changes are detected, the switch automatically updates its configuration and notifies the application manager. This automated feedback loop maintains precise tracking of network changes without requiring manual intervention, eliminating time loss while preserving connection accuracy through continuous state monitoring and automatic updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9065832B2Method and apparatus for automated network connectivity for managed application components within a cloud
Publication Date: 2015.06.23 ALCATEL LUCENT SA
  • US9065832B2 patent drawing
  • US9065832B2 patent drawing
  • US9065832B2 patent drawing

AI summary

Various exemplary embodiments relate to a method performed by an application manager for automatically establishing a network connection between components of an application within a distributed cloud, the method including: establishing application components in the distributed cloud; selecting a first application component; identifying network characteristics from the network policy file associated with the first application component; determining a network connection between the first application component and a second application component according to the network characteristics associated with the first application component; associating the network connection with the first application component; and establishing the network connection between the first and second application components.