Cloud Traffic Redirector for VPN Host Routing Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy routers used in cloud data centers for facilitating communication between on-premises data centers and virtual cloud networks have limitations such as reduced support for evolving cryptographic algorithms, lack of VPN priority, high costs, scalability issues, and slow problem resolution, leading to inefficient and expensive communication setups.

Innovation Solution

Implementing a VPN-as-a-Service (VPNaas) in an overlay network within the cloud infrastructure, using host machines to terminate and route VPN connections, eliminating dependence on legacy routers and enabling scalable, secure, and cost-effective communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If legacy routers are used to facilitate communication between on-premises data centers and virtual cloud networks, then communication channels can be established, but the system suffers from reduced support for evolving cryptographic algorithms, high costs, and scalability issues

Engineering Contradiction:
Improvesupport for cryptographic algorithmsVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the routing function from legacy hardware routers and relocates it to virtual network components (virtual gateways and network virtualization layer). This allows the system to use software-based routing that can be easily updated to support evolving cryptographic algorithms while maintaining communication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual copy of the routing functionality through virtual gateways that emulate router behavior. These virtual gateways can be programmed with latest cryptographic standards without replacing physical hardware, thus improving adaptability while maintaining reliable communication.

Inventive Principle:
Principle #26Copying

2Ease of operation

If legacy routers are deployed in cloud data centers, then communication facilitation is achieved, but the system incurs high procurement costs and scalability issues

Engineering Contradiction:
Improvecommunication facilitationVSAvoidinfrastructure cost
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical router system with a software-based virtual networking layer. Virtual gateways and network virtualization components substitute for physical routers, eliminating the need for expensive hardware procurement while maintaining communication facilitation capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The virtual network gateway performs multiple functions including routing, NAT, firewall, and cryptographic operations that were previously handled by separate legacy router devices. This consolidation reduces infrastructure complexity and cost while improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If legacy routers are used for VPN connections, then basic connectivity is provided, but VPN support is not a priority and problem resolution is slow

Engineering Contradiction:
ImproveVPN connection stabilityVSAvoidproblem resolution speed
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent introduces a network virtualization layer as an intermediary between physical networks and virtual cloud networks. This layer provides specialized VPN capabilities with dedicated support for encryption, tunneling, and secure connectivity, improving VPN reliability while enabling centralized management for faster problem resolution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual networking architecture implements centralized control and monitoring capabilities that provide real-time feedback on connection status and performance. This enables faster detection and resolution of VPN issues compared to distributed legacy router systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12506688B2Selective handling of traffic received from on-premises data centers
Publication Date: 2025.12.23 ORACLE INT CORP
  • US12506688B2 patent drawing
  • US12506688B2 patent drawing
  • US12506688B2 patent drawing

AI summary

A redirector (RD) in a cloud hosted data center receives a packet originating from a source device in an on-premises data center. The packet is directed to a destination IP address associated with a router located in the cloud hosted data center. A destination address field in a header of the packet is set to the destination IP address. The RD determines whether the packet is to be forwarded to the router or to a host machine implementing a service host that implements a tunnel end-point in a VCN. Responsive to determining that the packet is to be forwarded to the host machine: the RD sets the destination address field to an address associated with the service host, and forwards the packet to the host machine. Responsive to determining that the packet is to be forwarded to the router, the RD forwards the packet to the router.