Layer 4 Optimization for Virtual Network Over Public Cloud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate WANs become costly detours due to the need for all traffic to go through secure WAN gateways, especially with the rise of mobile access and applications migrating to SaaS and public clouds, leading to poor and unreliable performance, and existing SD-WAN solutions do not adequately address mid-mile connectivity issues or mobile/IoT devices.
Innovation Solution
A virtual network is established over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and layer-4 connection proxies, optimized for end-to-end performance, reliability, and security, minimizing Internet routing and leveraging public cloud infrastructure for scalable and cost-effective connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all corporate traffic is routed through secure WAN gateways to maintain security and reliability, then network security is improved, but network performance and speed deteriorate due to the detour through corporate WAN
Solution Approach 1:
The patent introduces cloud-based SD-WAN appliances as intermediary devices that establish direct encrypted tunnels between branch offices and cloud data centers. These intermediaries bypass the traditional corporate WAN gateway while maintaining security through encrypted direct connections, thus improving speed without sacrificing security.
Solution Approach 2:
The patent segments the network traffic into different paths: critical business traffic flows directly through encrypted SD-WAN tunnels to cloud data centers, while non-critical traffic can use traditional WAN routes. This segmentation allows performance optimization for time-sensitive traffic without compromising the security architecture for all traffic.
2Reliability
If traditional on-premise applications and datacenters are used to maintain control and security, then security management is improved, but infrastructure cost and complexity increase
Solution Approach 1:
The patent extracts application hosting and data storage functions from on-premise data centers and relocates them to cloud-based data centers. The SD-WAN appliances at branch offices maintain security control by establishing encrypted connections to these cloud services, thus reducing infrastructure complexity while preserving security management capabilities through centralized cloud control.
Solution Approach 2:
The patent employs universal cloud-based services that can host multiple applications and data services across different branch offices. The SD-WAN platform provides multi-functional capabilities including secure connectivity, application delivery, and centralized management, replacing multiple separate on-premise systems with a unified cloud-based infrastructure.
3Speed
If SD-WAN appliances are deployed at branch offices to optimize local traffic, then local network performance is improved, but mobile devices and IoT devices are not adequately addressed
Solution Approach 1:
The patent introduces cloud-based SD-WAN appliances as intermediaries that provide centralized service delivery for mobile and IoT devices. Instead of requiring appliances at every endpoint, the cloud-based intermediaries manage secure connectivity and optimization for diverse devices including mobile phones and IoT devices, thus extending adaptability while maintaining performance benefits.
4Reliability
If expensive leased lines and MPLS networks are used to ensure reliable mid-mile connectivity, then network reliability is improved, but network cost increases significantly
Solution Approach 1:
The patent replaces expensive, long-term leased line contracts with more flexible, cost-effective cloud connectivity options. The SD-WAN architecture enables the use of commercial broadband and other lower-cost connections for mid-mile connectivity, maintaining reliability through software-defined optimization and encryption rather than relying on expensive dedicated physical infrastructure.
Data Source
AI summary
Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.


