Cloud Traffic Redirector for VPN Host Routing Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy routers used in cloud data centers for facilitating communication between on-premises data centers and virtual cloud networks have limitations such as reduced support for evolving cryptographic algorithms, lack of VPN priority, high costs, scalability issues, and slow problem resolution, leading to inefficient and expensive communication setups.
Innovation Solution
Implementing a VPN-as-a-Service (VPNaas) in an overlay network within the cloud infrastructure, using host machines to terminate and route VPN connections, eliminating dependence on legacy routers and enabling scalable, secure, and cost-effective communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If legacy routers are used to facilitate communication between on-premises data centers and virtual cloud networks, then communication channels can be established, but the system suffers from reduced support for evolving cryptographic algorithms, high costs, and scalability issues
Solution Approach 1:
The patent extracts the routing function from legacy hardware routers and relocates it to virtual network components (virtual gateways and network virtualization layer). This allows the system to use software-based routing that can be easily updated to support evolving cryptographic algorithms while maintaining communication functionality.
Solution Approach 2:
The patent creates a virtual copy of the routing functionality through virtual gateways that emulate router behavior. These virtual gateways can be programmed with latest cryptographic standards without replacing physical hardware, thus improving adaptability while maintaining reliable communication.
2Ease of operation
If legacy routers are deployed in cloud data centers, then communication facilitation is achieved, but the system incurs high procurement costs and scalability issues
Solution Approach 1:
The patent replaces the mechanical/physical router system with a software-based virtual networking layer. Virtual gateways and network virtualization components substitute for physical routers, eliminating the need for expensive hardware procurement while maintaining communication facilitation capabilities.
Solution Approach 2:
The virtual network gateway performs multiple functions including routing, NAT, firewall, and cryptographic operations that were previously handled by separate legacy router devices. This consolidation reduces infrastructure complexity and cost while improving ease of operation.
3Reliability
If legacy routers are used for VPN connections, then basic connectivity is provided, but VPN support is not a priority and problem resolution is slow
Solution Approach 1:
The patent introduces a network virtualization layer as an intermediary between physical networks and virtual cloud networks. This layer provides specialized VPN capabilities with dedicated support for encryption, tunneling, and secure connectivity, improving VPN reliability while enabling centralized management for faster problem resolution.
Solution Approach 2:
The virtual networking architecture implements centralized control and monitoring capabilities that provide real-time feedback on connection status and performance. This enables faster detection and resolution of VPN issues compared to distributed legacy router systems.
Data Source
AI summary
A redirector (RD) in a cloud hosted data center receives a packet originating from a source device in an on-premises data center. The packet is directed to a destination IP address associated with a router located in the cloud hosted data center. A destination address field in a header of the packet is set to the destination IP address. The RD determines whether the packet is to be forwarded to the router or to a host machine implementing a service host that implements a tunnel end-point in a VCN. Responsive to determining that the packet is to be forwarded to the host machine: the RD sets the destination address field to an address associated with the service host, and forwards the packet to the host machine. Responsive to determining that the packet is to be forwarded to the router, the RD forwards the packet to the router.


