Identity-Based Private Traffic Exchange Through Cross-Customer GRE Tunnels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networking solutions for connecting private networks across geographies require complex routing, physical devices, and security measures, making it difficult to maintain control over security and access policies across different networks.
Innovation Solution
A distributed cloud computing network handles traffic between customer networks using virtual tunnels and identity-based policies, enabling secure and unified traffic exchange across disparate private networks and client devices, with services like routing, security, and performance provided by the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical devices and complex routing are used to connect private networks across geographies, then network connectivity and security control are achieved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent replaces physical networking devices (routers, firewalls, DDoS appliances) and manual routing configurations with a virtualized network service running on distributed compute servers. The networking stack is virtualized and managed through software, eliminating the need for physical hardware deployment and complex manual routing setup while maintaining security and connectivity functions.
Solution Approach 2:
The unified network service consolidates multiple networking functions (routing, security, DDoS protection, traffic exchange) into a single virtualized platform that can serve multiple customers and networks simultaneously. This multi-functional service replaces the need for separate physical devices for each function, reducing overall device complexity while maintaining comprehensive network control.
2Reliability
If physical colocation or direct point-to-point tunnels are used to connect networks, then security and access policy control are maintained, but scalability and ease of deployment are reduced
Solution Approach 1:
The system enables automated self-provisioning of network connections through virtual tunnels and policy-based routing. Customers can define their security and access policies through configuration files or APIs, and the system automatically establishes the appropriate virtual network paths without requiring manual physical colocation or complex tunnel setup, thereby improving deployment ease and scalability while maintaining security control.
3Reliability
If gateway boxes are installed to provide internet access, then network security is maintained, but device complexity and management overhead increase
Solution Approach 1:
The patent merges the functions of gateway boxes, firewalls, and internet access points into a unified virtual network service that runs on distributed compute servers. This consolidation eliminates the need for separate physical gateway devices at each network location, reducing device complexity and management overhead while maintaining security functions through virtualized network stacks and centralized policy enforcement.
Data Source
AI summary
Traffic is received at an interface of a compute server. Identity information associated with the traffic is determined including an identifier of a customer to which the traffic is attributable. An egress policy configured for the first customer is used to determine whether the traffic is allowed to be transmitted to a destination where that destination is a resource of a second customer. If the traffic is allowed to be transmitted, the traffic and identity information is transmitted over a cross-customer GRE tunnel to a namespace of the second costumer on the compute server. An ingress policy configured for the second customer is used to determine whether the traffic is allowed to be transmitted to the destination, and if it is, then the traffic is transmitted.


