Multi-Cloud Network Link Using Encapsulated Virtual Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud environments provided by different cloud service providers operate as closed ecosystems, limiting customers' ability to easily access services from other cloud environments, hindering seamless integration and utilization of services across multiple cloud platforms.
Innovation Solution
A multi-cloud control plane (MCCP) framework enables communication channels between cloud environments, allowing users to access services from different cloud providers with a native-like experience by encapsulating and decapsulating traffic between virtual networks, thereby facilitating the use of services from one cloud environment within another.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud environments operate as closed ecosystems, then each cloud provider maintains control and security over their services, but customers cannot easily access services from other cloud environments
Solution Approach 1:
The patent introduces a network link as an intermediary component that connects virtual networks from different cloud environments. This network link acts as a mediator that enables communication between AWS virtual networks and OCI virtual networks without requiring direct integration between the cloud providers' systems, thus maintaining their closed ecosystem structure while enabling cross-cloud service access.
Solution Approach 2:
The solution segments the cross-cloud connectivity problem into separate virtual network components that can be independently configured and managed. Each cloud environment maintains its own virtual network segment, and the network link connects these segmented networks at the network layer, allowing selective interconnection without merging the entire cloud ecosystems.
2Speed
If network traffic is routed directly between cloud environments, then communication efficiency is improved, but security and network management control are reduced
Solution Approach 1:
The network link implements nested networking where one virtual network is embedded within another through encapsulation. The first virtual network's traffic is encapsulated within the second virtual network's protocol structure, allowing nested communication that maintains security boundaries while enabling direct routed communication between the nested networks at optimized speeds.
Solution Approach 2:
The network link serves as a controlled intermediary that all cross-cloud traffic must pass through. This intermediary enforces security policies, routing rules, and access controls while maintaining efficient direct communication paths between the connected virtual networks, balancing speed and security requirements.
Data Source
AI summary
Techniques are described for creating a network-link between a first virtual network in a first cloud environment and a second virtual network in a second cloud environment. The first virtual network in the first cloud environment is created to enable a user associated with a customer tenancy in the second cloud environment to access one or more services provided in the first cloud environment. The network-link is created based on network resources and one or more link-enabling virtual networks being deployed in the first cloud environment and the second cloud environment.


