Logical Customer Edge Router for Layer 2 Cloud Enterprise Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing networks do not seamlessly integrate cloud resources with private enterprise networks, leading to complexities in addressing and security issues when communicating between internal and cloud resources, as they are treated as distinct entities rather than equivalent resources.

Innovation Solution

A method involving a logical customer edge router in the cloud data center that encapsulates and forwards Layer 2 packets with MAC and location IP headers to ensure seamless communication between private enterprise and cloud networks, maintaining a shared IP address space and VLAN, thereby integrating cloud resources into the enterprise's existing topology and ensuring security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud resources are treated as distinct entities from private enterprise network resources, then security isolation is improved, but network integration and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetwork integration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a network address translation (NAT) gateway as an intermediary component that sits between the private enterprise network and the cloud resources. This NAT gateway performs address translation and protocol conversion, allowing resources to communicate while maintaining security boundaries. The intermediary handles the complexity of integration, enabling seamless operation without compromising security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud resources are treated as distinct entities with separate addressing schemes, then security boundaries are maintained, but device complexity and addressing complexity increase

Engineering Contradiction:
Improvesecurity boundariesVSAvoidaddressing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the addressing parameter by introducing a unified addressing scheme where cloud resources are assigned addresses from the same address space as private enterprise resources. This parameter change eliminates the need for complex address translation and routing rules, reducing addressing complexity while maintaining security boundaries through logical isolation rather than physical separation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If separate infrastructure is used for cloud and private network resources, then resource allocation flexibility is improved, but workload distribution and productivity deteriorate

Engineering Contradiction:
Improveresource allocation flexibilityVSAvoidworkload distribution
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges the cloud resources and private enterprise resources into a single unified network fabric, allowing workloads to be distributed seamlessly across both environments. Resources from both locations appear equivalent to applications, enabling automatic workload placement and distribution based on availability, performance, and cost considerations, thereby improving productivity while maintaining allocation flexibility.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2484059B1Layer 2 seamless site extension of enterprises in cloud computing
Publication Date: 2014.11.05 ALCATEL LUCENT SA
  • EP2484059B1 patent drawingFigure 1
  • EP2484059B1 patent drawingFigure 2
  • EP2484059B1 patent drawingFigure 3

AI summary

Various embodiments relate to a Cloud Data Center, a system comprising the Cloud Data Center, and a related method. The Cloud Data Center may include a logical customer edge router to send packets between addresses in a private enterprise network and addresses in a logical network within a cloud network using Layer 2 protocol and MAC addressing. The logical network may have resources, known as virtual machines, allocated to the private enterprise network and may share a common IP address space with the private enterprise network. A directory at the Cloud Data Center may correlate the enterprise IP addresses of virtual machines with a MAC address, cloud IP address, and a location IP address within the logical network. The Cloud Data Center may double encapsulate packets with MAC, cloudIP, and locIP headers, when sending a packet to a destination in the logical network.