Inter-network hub tunnel establishment for cross-network service communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring on-premises landscapes and virtual private clouds (VPCs) to communicate securely with each other for distributed processes is challenging due to complexities in establishing connections between distinct networks.

Innovation Solution

A method that involves registering a service at a computing device, assigning an IP address, and establishing tunnels between networks using an inter-network hub to create a logical connection, bypassing conventional security protocols and configuration steps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security protocols and configuration steps are used to establish connections between distinct networks, then security is maintained, but the time required to establish connections increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime required to establish connections
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring network services, assigning IP addresses in advance, and establishing tunnel endpoints before actual communication is needed. This allows the networking fabric to be pre-prepared so that when communication is required, connections can be established rapidly without going through lengthy conventional security protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary networking fabric that mediates between distinct networks. This fabric includes components like the network service, DNS server, and tunnel endpoints that facilitate communication without requiring direct configuration between networks. The intermediary handles security and routing, allowing fast connection establishment while maintaining security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct communication between on-premises landscapes and VPCs is configured, then communication efficiency improves, but configuration complexity increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The networking fabric acts as an intermediary layer between on-premises landscapes and VPCs, abstracting away the configuration complexity. Instead of directly configuring complex connections between networks, users simply register services with the networking fabric, which automatically handles IP assignment, DNS registration, and tunnel establishment, thereby maintaining communication efficiency while reducing configuration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service mechanisms where services automatically register themselves with the networking fabric, receive IP addresses automatically, and have their communication paths established without manual intervention. The DNS server automatically updates records, and tunnel endpoints are automatically configured, eliminating the need for complex manual configuration while maintaining efficient communication.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual IP address assignment and tunnel establishment is performed, then connection security is ensured, but the process becomes time-consuming

Engineering Contradiction:
Improveconnection securityVSAvoidspeed of connection establishment
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The networking fabric implements self-service automation where services automatically receive IP addresses from the network service, DNS records are automatically updated, and tunnel endpoints are automatically established. This automation maintains security through consistent application of security policies while dramatically increasing the speed of connection establishment by eliminating manual configuration steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated electronic systems. Instead of manually assigning IP addresses and configuring tunnels, the system uses automated services including IP address management, DNS automatic updates, and programmable tunnel endpoints that can be established through software automation, thereby maintaining security while improving productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11509622B2Facilitating communication between resources in different network environments
Publication Date: 2022.11.22 SAP SE
  • US11509622B2 patent drawing
  • US11509622B2 patent drawing
  • US11509622B2 patent drawing

AI summary

Some embodiments provide a method for connecting a client of a first network to a service of a second network. The method includes registering the service of the second network. The method then receives, from a client of the first network, a request to communicate with the service, the client not having an address of the service. The method further assigns an IP address to the service and sends the IP address to the client. Additionally, the method sends, to an inter-network hub that connects the first network and the second network, a message in order for the inter-network hub to establish a first tunnel between the inter-network hub and a first gateway associated with the client and a second tunnel between the inter-network hub and a second gateway associated with the service.