Hub-and-Spoke Cloud Network with BGP Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based computing platforms face challenges in managing scalable computing resources and ensuring secure, efficient routing for web platforms, particularly in hub-and-spoke connection configurations, which can lead to network performance issues and security vulnerabilities.

Innovation Solution

Implementing a hub-and-spoke connection configuration that connects a private cloud network to a public cloud network, with gateway devices at operator and client data centers, allowing for centralized control and dynamic resource allocation, and utilizing Border Gateway Protocol (BGP) messaging for routing configuration and payload data propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hub-and-spoke connection configuration is implemented to centralize control and improve security, then network security and resource allocation are improved, but network complexity and configuration management difficulty increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated BGP configuration propagation. When the hub device receives routing configuration information, it automatically propagates this configuration to all spoke devices without requiring manual intervention at each spoke location. This self-configuring mechanism resolves the contradiction by maintaining centralized security control while eliminating the complexity of manual configuration management across multiple devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The hub device acts as an intermediary between the central control point and multiple spoke devices. It receives routing configuration information and selectively propagates it to appropriate spokes, mediating the complexity by centralizing the configuration distribution function. This intermediary role allows the system to maintain simple spoke devices while achieving centralized security control through the hub's intelligent routing management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual routing configuration is used in distributed cloud networks, then device autonomy is maintained, but routing errors and security vulnerabilities increase

Engineering Contradiction:
Improverouting accuracyVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback through the BGP protocol, which automatically propagates routing configuration information from the hub to spoke devices and maintains synchronized routing tables. This automated feedback mechanism ensures routing accuracy by continuously updating all devices with the latest routing information, eliminating manual configuration errors while maintaining ease of operation through protocol-driven automation rather than manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Spoke devices perform self-service by automatically receiving and applying routing configuration information propagated from the hub via BGP messaging. This self-configuring behavior eliminates routing errors associated with manual configuration while maintaining operational simplicity, as each spoke device autonomously updates its routing table based on hub-provided information without requiring manual intervention.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If direct peer-to-peer connections are used between data centers, then network flexibility is improved, but security control and routing management become more difficult

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The hub device serves as an intermediary that enables flexible spoke-to-spoke communication while maintaining centralized security control. When payload data needs to be routed between spokes, the hub receives the data from one spoke, processes it according to centralized routing policies, and forwards it to the destination spoke. This intermediary approach preserves network flexibility for various communication patterns while ensuring all traffic passes through the security-controlled hub, preventing direct uncontrolled connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into hub and spoke components with distinct functional roles. The hub handles centralized control, security policy enforcement, and routing configuration, while spokes handle local data transmission. This segmentation allows flexible data flow between spokes through the hub while maintaining centralized security control at the hub, resolving the contradiction between flexibility and security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10084886B2Hub-and-spoke connection architecture
Publication Date: 2018.09.25 ACCENTURE GLOBAL SOLUTIONS LTD
  • US10084886B2 patent drawing
  • US10084886B2 patent drawing
  • US10084886B2 patent drawing

AI summary

A system, may include a private cloud network operated by an operator for a client. The private cloud network may be connected to a public cloud network that operates a web platform and a plurality of groups of gateway devices. A first group of gateway devices may be located at an operator data center associated with the operator, and may provide connectivity for the operator data center to connect to the public cloud network via the private cloud network. A second group of gateway devices may be located at a client data center associated with the client, and may provide connectivity for the client data center to connect to the public cloud network via the private cloud network. The private cloud network may be connected to the public cloud network, the operator data center, and the client data center in a hub-and-spoke connection configuration.