Cross-Regional Virtual Network Peering Bypassing Gateway Bottlenecks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale networked systems face bandwidth constraints and latency issues due to gateway bottlenecks, limiting data transfer and real-time application performance in cloud services.

Innovation Solution

Global virtual network peering enables direct communication between virtual networks across different geographical regions without additional bandwidth restrictions, using IPv6 for enhanced security and efficient routing, thereby bypassing the need for gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a gateway is used to provide secure connections between virtualized networks, then security is improved, but bandwidth constraints and latency increase

Engineering Contradiction:
Improveconnection securityVSAvoiddata transfer bandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security function from the gateway bottleneck by implementing security controls at the network edge and within the virtual network fabric itself. Virtual network functions and security policies are distributed to multiple points in the network, removing the single gateway as the sole security enforcement point and eliminating it as a bandwidth bottleneck.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network architecture is segmented into multiple virtual network functions distributed across different locations. Instead of a single centralized gateway, security and networking functions are divided and distributed throughout the network fabric, allowing parallel data paths that bypass gateway bottlenecks while maintaining security through distributed policy enforcement.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a gateway is used to connect virtualized networks, then secure communication is achieved, but real-time application performance deteriorates due to latency

Engineering Contradiction:
Improvesecure communicationVSAvoidapplication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security policies, authentication mechanisms, and network routing rules are pre-configured and distributed throughout the network fabric before data transmission occurs. This preliminary setup eliminates the need for real-time gateway processing, allowing data to flow directly through pre-authenticated paths with minimal latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces virtual network functions and distributed routing intermediaries that handle security and routing decisions locally within the network fabric. These intermediaries process security requirements in advance and establish direct encrypted tunnels between source and destination, bypassing the need for gateway-mediated communication and reducing latency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If gateway bandwidth constraints are imposed, then network security is maintained, but data replication and disaster recovery capabilities are limited

Engineering Contradiction:
Improvenetwork securityVSAvoiddata replication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent adds dimensional diversity to data replication by establishing multiple parallel network paths through the virtual network fabric. Data can be replicated simultaneously through different routing dimensions (multiple virtual networks, different geographic regions, various transport paths), bypassing the single gateway bottleneck while maintaining security through distributed encryption and authentication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Multiple security functions (encryption, authentication, authorization, integrity checking) are merged and distributed across the network fabric rather than concentrated at a single gateway. This distributed merging of security capabilities allows parallel data flows to maintain security independently, enabling high-speed data replication and disaster recovery without gateway constraints.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11102079B2Cross-regional virtual network peering
Publication Date: 2021.08.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11102079B2 patent drawing
  • US11102079B2 patent drawing
  • US11102079B2 patent drawing

AI summary

Virtual networks located in different regions of cloud provider are peered using unique regional identifiers for the virtual networks. The regional identifiers and other information are pushed down a network management stack to implement the peering.