Identity-Based Private Traffic Exchange Through Cross-Customer GRE Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking solutions for connecting private networks across geographies require complex routing, physical devices, and security measures, making it difficult to maintain control over security and access policies across different networks.

Innovation Solution

A distributed cloud computing network handles traffic between customer networks using virtual tunnels and identity-based policies, enabling secure and unified traffic exchange across disparate private networks and client devices, with services like routing, security, and performance provided by the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical devices and complex routing are used to connect private networks across geographies, then network connectivity and security control are achieved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvenetwork security controlVSAvoidphysical devices and routing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical networking devices (routers, firewalls, DDoS appliances) and manual routing configurations with a virtualized network service running on distributed compute servers. The networking stack is virtualized and managed through software, eliminating the need for physical hardware deployment and complex manual routing setup while maintaining security and connectivity functions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The unified network service consolidates multiple networking functions (routing, security, DDoS protection, traffic exchange) into a single virtualized platform that can serve multiple customers and networks simultaneously. This multi-functional service replaces the need for separate physical devices for each function, reducing overall device complexity while maintaining comprehensive network control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If physical colocation or direct point-to-point tunnels are used to connect networks, then security and access policy control are maintained, but scalability and ease of deployment are reduced

Engineering Contradiction:
Improvesecurity and access policy controlVSAvoiddeployment ease and scalability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system enables automated self-provisioning of network connections through virtual tunnels and policy-based routing. Customers can define their security and access policies through configuration files or APIs, and the system automatically establishes the appropriate virtual network paths without requiring manual physical colocation or complex tunnel setup, thereby improving deployment ease and scalability while maintaining security control.

Inventive Principle:
Principle #25Self-service

3Reliability

If gateway boxes are installed to provide internet access, then network security is maintained, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidgateway box deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of gateway boxes, firewalls, and internet access points into a unified virtual network service that runs on distributed compute servers. This consolidation eliminates the need for separate physical gateway devices at each network location, reducing device complexity and management overhead while maintaining security functions through virtualized network stacks and centralized policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12457196B2Secure private traffic exchange in a unified network service
Publication Date: 2025.10.28 CLOUDFLARE INC
  • US12457196B2 patent drawing
  • US12457196B2 patent drawing
  • US12457196B2 patent drawing

AI summary

Traffic is received at an interface of a compute server. Identity information associated with the traffic is determined including an identifier of a customer to which the traffic is attributable. An egress policy configured for the first customer is used to determine whether the traffic is allowed to be transmitted to a destination where that destination is a resource of a second customer. If the traffic is allowed to be transmitted, the traffic and identity information is transmitted over a cross-customer GRE tunnel to a namespace of the second costumer on the compute server. An ingress policy configured for the second customer is used to determine whether the traffic is allowed to be transmitted to the destination, and if it is, then the traffic is transmitted.