Gateway Router WAN Optimization with Homomorphic Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for optimizing data transmission over wide area networks (WAN) are inflexible, costly, and inefficient, leading to data duplication and synchronization issues across multiple cloud regions.

Innovation Solution

A method for WAN optimization that involves a gateway router deployed in a public cloud, which aggregates multiple data streams from edge routers, performs traffic redundancy elimination (TRE), and compresses the data to produce a single, optimized outbound stream for forwarding to a centralized datacenter.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If multiple unoptimized data streams are sent individually from multiple routers to the centralized datacenter, then data transmission is performed, but bandwidth usage is excessive and operational costs increase

Engineering Contradiction:
Improvebandwidth usageVSAvoiddata transmission efficiency
Core Design Contradiction:
Loss of energyVSProductivity

Solution Approach 1:

The gateway router aggregates multiple data streams from different edge routers into a single optimized outbound stream. This merging process combines redundant data paths and eliminates duplicate transmissions, thereby reducing overall bandwidth consumption while improving transmission efficiency through centralized optimization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway router performs multiple functions including aggregation, redundancy elimination, compression, and encryption on a unified data stream. This multi-functional approach allows a single optimized stream to serve multiple original sources, reducing bandwidth usage while maintaining the productivity of data transmission to the centralized datacenter.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Stability of the object's composition

If data is moved to a central data-warehouse or few data-lakes with centralized compute, then data synchronization is achieved, but data duplication increases and synchronization becomes slow

Engineering Contradiction:
Improvedata synchronizationVSAvoiddata duplication
Core Design Contradiction:
Stability of the object's compositionVSQuantity of substance

Solution Approach 1:

The Traffic Redundancy Elimination (TRE) operation extracts and identifies duplicate data segments across multiple incoming streams. By detecting and removing redundant segments before forwarding to the centralized datacenter, the system achieves data synchronization without creating unnecessary duplications, thereby reducing the quantity of transmitted data while maintaining synchronization stability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway router performs aggregation, redundancy elimination, and compression operations before the data reaches the centralized datacenter. This preliminary optimization prevents data duplication from occurring in the first place, rather than having to manage and synchronize duplicates afterward, thereby reducing data duplication while maintaining synchronization.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption is applied to data streams for security, then data security is improved, but WAN optimization operations become more difficult to perform

Engineering Contradiction:
Improvedata securityVSAvoidoptimization operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway router acts as an intermediary that performs WAN optimization operations on encrypted data streams without requiring decryption. By operating directly on the ciphertext, the gateway maintains data security while performing aggregation, redundancy elimination, and compression, thereby avoiding the complexity of decrypting and re-encrypting data while still achieving optimization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the traditional mechanical approach of decrypting-optimizing-reencrypting with a cryptographic approach where optimization operations are performed directly on encrypted data. This substitution eliminates the need to break encryption for optimization purposes, maintaining security while reducing operational complexity through direct ciphertext manipulation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12328303B2Wan optimization for encrypted data traffic using fully homomorphic encryption
Publication Date: 2025.06.10 VMWARE INC
  • US12328303B2 patent drawing
  • US12328303B2 patent drawing
  • US12328303B2 patent drawing

AI summary

Some embodiments of the invention provide a method for WAN (wide area network) optimization for a WAN that connects multiple sites, each of which has at least one router. At a gateway router deployed to a public cloud, the method receives from at least two routers at least two sites, multiple data streams destined for a particular centralized datacenter. The method performs a WAN optimization operation to aggregate the multiple streams into one outbound stream that is WAN optimized for forwarding to the particular centralized datacenter. The method then forwards the WAN-optimized data stream to the particular centralized datacenter.