Multi-region Cloud Architecture with Edge Proxy Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying multi-region cloud services poses challenges in maintaining data privacy, as existing solutions struggle to prevent the exportation of private data outside its designated geographical region, compromising security and compliance with regulatory directives.

Innovation Solution

A multi-region cloud service architecture utilizing a distributed container execution system with edge proxy servers and application servers deployed across geographical regions, where requests are routed based on geographical routing information to ensure that private data remains within its region of origin, using regional storage and secret management to isolate sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud services are distributed across multiple geographical regions to enable global access, then service availability and accessibility are improved, but data privacy and security are compromised due to potential data exportation outside designated regions

Engineering Contradiction:
Improveglobal accessVSAvoiddata privacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments cloud services into region-specific deployments with dedicated infrastructure in each geographical region. Each region operates as an isolated environment with its own compute, storage, and networking resources, preventing cross-region data access while maintaining global service availability through local processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces regional edge proxy servers as intermediary components that receive and process requests locally within each region. These proxies act as mediators between user requests and region-specific application servers, ensuring that data processing remains within the designated geographical boundary while enabling seamless user access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is kept isolated within each geographical region to maintain data privacy, then security and compliance are improved, but service scalability and performance are worsened due to limited resource sharing

Engineering Contradiction:
Improvedata securityVSAvoidservice scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides cloud infrastructure into independent region-specific segments with dedicated resources for compute, storage, and networking. Each segment operates autonomously with its own resource pool, ensuring data isolation while maintaining service scalability through local resource availability and independent provisioning.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic resource allocation within each region by changing operational parameters such as compute capacity, storage allocation, and network bandwidth based on demand. This allows each isolated region to scale its resources independently without affecting other regions, maintaining both security and scalability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If region-specific infrastructure is deployed in each geographical region to prevent data exportation, then data privacy is improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improvedata privacyVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the overall cloud infrastructure into standardized region-specific units, each containing application servers, edge proxy servers, and storage resources. This modular segmentation simplifies deployment by allowing identical architectural patterns to be replicated across regions, reducing overall system complexity despite the multi-region configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal regional architecture template that can be deployed in any geographical region with the same functional components and configurations. This multi-functional design allows the same system blueprint to serve multiple regions, reducing deployment complexity through standardization while maintaining data privacy through regional isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11470182B1Multi-region cloud architecture
Publication Date: 2022.10.11 MONDAY COM LTD
  • US11470182B1 patent drawing
  • US11470182B1 patent drawing
  • US11470182B1 patent drawing

AI summary

A multi-region cloud service facilitated by a distributed container execution system comprising a plurality of edge proxy servers deployed in a plurality of geographical regions to receive from a plurality of client devices a plurality of requests to access the distributed container execution system and a plurality of application servers deployed in the plurality of geographical regions to provide the cloud service. Each edge proxy server is configured to analyze each request it receives to identify a target geographical region of the respective request, transmit the respective request to the application server(s) deployed in a same geographical region in case the target geographical region is the geographical region of the edge proxy server, and transmit the respective request to other edge proxy server(s) deployed in the target geographical region in case the target geographical region is not the geographical region of the respective edge proxy server.