Multi-Cloud Virtual Network Edge Node Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate networks face inefficiencies due to the reliance on expensive leased lines and the consumer Internet, which lacks reliability, quality of service guarantees, and security, especially with the rise of mobile access and public cloud usage, leading to costly and slow communication.

Innovation Solution

Establishing a virtual network over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and middlebox service machines, optimized for end-to-end performance, reliability, and security, while minimizing Internet traffic routing through these components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If corporate networks use expensive leased lines and traditional WAN infrastructure, then reliability and security are improved, but cost increases significantly

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidnetwork cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces expensive, long-term leased lines with temporary, on-demand VPN connections through public cloud datacenters. These VPN connections can be established quickly and terminated when no longer needed, providing a cost-effective alternative to permanent dedicated infrastructure while maintaining security through encrypted tunnels.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent introduces public cloud datacenters as intermediary nodes that facilitate secure communication between corporate networks. These intermediaries provide VPN endpoint functionality, enabling encrypted direct connections between corporations without requiring traditional leased line infrastructure, thus reducing cost while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If corporate networks route traffic through the consumer Internet, then cost decreases, but performance and reliability deteriorate

Engineering Contradiction:
Improvenetwork costVSAvoidnetwork performance
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent uses public cloud datacenters as intermediary nodes that provide VPN endpoint functionality. These intermediaries enable encrypted direct connections between corporations, bypassing the need to route traffic through the consumer Internet while maintaining cost-effectiveness. The cloud datacenters act as secure meeting points that establish direct tunnels rather than routing through public networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If corporations migrate to public cloud infrastructure, then cost and scalability are improved, but network security and control may be compromised

Engineering Contradiction:
ImprovescalabilityVSAvoidnetwork security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements temporary, on-demand VPN connections that can be quickly established and terminated. These short-lived connections reduce security risks by limiting the time window for potential attacks, while still providing the scalability benefits of cloud infrastructure. Connections are created only when needed and removed when no longer required.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent implements security measures at each VPN endpoint within the public cloud infrastructure. Each corporation's VPN endpoint is configured with specific security policies, encryption settings, and access controls tailored to its needs. This localized security approach allows each organization to maintain control over its own security parameters while utilizing shared cloud infrastructure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10959098B2Dynamically specifying multiple public cloud edge nodes to connect to an external multi-computer node
Publication Date: 2021.03.23 VMWARE INC
  • US10959098B2 patent drawing
  • US10959098B2 patent drawing
  • US10959098B2 patent drawing

AI summary

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.