Inter-network hub tunnel establishment for cross-network service communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring on-premises landscapes and virtual private clouds (VPCs) to communicate securely with each other for distributed processes is challenging due to complexities in establishing connections between distinct networks.
Innovation Solution
A method that involves registering a service at a computing device, assigning an IP address, and establishing tunnels between networks using an inter-network hub to create a logical connection, bypassing conventional security protocols and configuration steps.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security protocols and configuration steps are used to establish connections between distinct networks, then security is maintained, but the time required to establish connections increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring network services, assigning IP addresses in advance, and establishing tunnel endpoints before actual communication is needed. This allows the networking fabric to be pre-prepared so that when communication is required, connections can be established rapidly without going through lengthy conventional security protocols.
Solution Approach 2:
The patent introduces an intermediary networking fabric that mediates between distinct networks. This fabric includes components like the network service, DNS server, and tunnel endpoints that facilitate communication without requiring direct configuration between networks. The intermediary handles security and routing, allowing fast connection establishment while maintaining security through centralized control.
2Productivity
If direct communication between on-premises landscapes and VPCs is configured, then communication efficiency improves, but configuration complexity increases
Solution Approach 1:
The networking fabric acts as an intermediary layer between on-premises landscapes and VPCs, abstracting away the configuration complexity. Instead of directly configuring complex connections between networks, users simply register services with the networking fabric, which automatically handles IP assignment, DNS registration, and tunnel establishment, thereby maintaining communication efficiency while reducing configuration complexity.
Solution Approach 2:
The system implements self-service mechanisms where services automatically register themselves with the networking fabric, receive IP addresses automatically, and have their communication paths established without manual intervention. The DNS server automatically updates records, and tunnel endpoints are automatically configured, eliminating the need for complex manual configuration while maintaining efficient communication.
3Reliability
If manual IP address assignment and tunnel establishment is performed, then connection security is ensured, but the process becomes time-consuming
Solution Approach 1:
The networking fabric implements self-service automation where services automatically receive IP addresses from the network service, DNS records are automatically updated, and tunnel endpoints are automatically established. This automation maintains security through consistent application of security policies while dramatically increasing the speed of connection establishment by eliminating manual configuration steps.
Solution Approach 2:
The patent replaces manual mechanical configuration processes with automated electronic systems. Instead of manually assigning IP addresses and configuring tunnels, the system uses automated services including IP address management, DNS automatic updates, and programmable tunnel endpoints that can be established through software automation, thereby maintaining security while improving productivity.
Data Source
AI summary
Some embodiments provide a method for connecting a client of a first network to a service of a second network. The method includes registering the service of the second network. The method then receives, from a client of the first network, a request to communicate with the service, the client not having an address of the service. The method further assigns an IP address to the service and sends the IP address to the client. Additionally, the method sends, to an inter-network hub that connects the first network and the second network, a message in order for the inter-network hub to establish a first tunnel between the inter-network hub and a first gateway associated with the client and a second tunnel between the inter-network hub and a second gateway associated with the service.


