Layer 4 Optimization for Virtual Network Over Public Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate WANs become costly detours due to the need for all traffic to go through secure WAN gateways, especially with the rise of mobile access and applications migrating to SaaS and public clouds, leading to poor and unreliable performance, and existing SD-WAN solutions do not adequately address mid-mile connectivity issues or mobile/IoT devices.

Innovation Solution

A virtual network is established over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and layer-4 connection proxies, optimized for end-to-end performance, reliability, and security, minimizing Internet routing and leveraging public cloud infrastructure for scalable and cost-effective connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all corporate traffic is routed through secure WAN gateways to maintain security and reliability, then network security is improved, but network performance and speed deteriorate due to the detour through corporate WAN

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent introduces cloud-based SD-WAN appliances as intermediary devices that establish direct encrypted tunnels between branch offices and cloud data centers. These intermediaries bypass the traditional corporate WAN gateway while maintaining security through encrypted direct connections, thus improving speed without sacrificing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network traffic into different paths: critical business traffic flows directly through encrypted SD-WAN tunnels to cloud data centers, while non-critical traffic can use traditional WAN routes. This segmentation allows performance optimization for time-sensitive traffic without compromising the security architecture for all traffic.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional on-premise applications and datacenters are used to maintain control and security, then security management is improved, but infrastructure cost and complexity increase

Engineering Contradiction:
Improvesecurity managementVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts application hosting and data storage functions from on-premise data centers and relocates them to cloud-based data centers. The SD-WAN appliances at branch offices maintain security control by establishing encrypted connections to these cloud services, thus reducing infrastructure complexity while preserving security management capabilities through centralized cloud control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs universal cloud-based services that can host multiple applications and data services across different branch offices. The SD-WAN platform provides multi-functional capabilities including secure connectivity, application delivery, and centralized management, replacing multiple separate on-premise systems with a unified cloud-based infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If SD-WAN appliances are deployed at branch offices to optimize local traffic, then local network performance is improved, but mobile devices and IoT devices are not adequately addressed

Engineering Contradiction:
Improvelocal network performanceVSAvoidmobile and IoT device support
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent introduces cloud-based SD-WAN appliances as intermediaries that provide centralized service delivery for mobile and IoT devices. Instead of requiring appliances at every endpoint, the cloud-based intermediaries manage secure connectivity and optimization for diverse devices including mobile phones and IoT devices, thus extending adaptability while maintaining performance benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If expensive leased lines and MPLS networks are used to ensure reliable mid-mile connectivity, then network reliability is improved, but network cost increases significantly

Engineering Contradiction:
Improvemid-mile connectivityVSAvoidnetwork cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent replaces expensive, long-term leased line contracts with more flexible, cost-effective cloud connectivity options. The SD-WAN architecture enables the use of commercial broadband and other lower-cost connections for mid-mile connectivity, maintaining reliability through software-defined optimization and encryption rather than relying on expensive dedicated physical infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11089111B2Layer four optimization for a virtual network defined over public cloud
Publication Date: 2021.08.10 VMWARE INC
  • US11089111B2 patent drawing
  • US11089111B2 patent drawing
  • US11089111B2 patent drawing

AI summary

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.