Multi-Cloud Virtual Network for Enterprise Traffic Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate networks face inefficiencies due to the reliance on expensive leased lines and the consumer Internet, which lacks reliability, quality of service guarantees, and security, especially with the rise of mobile access and cloud migrations, leading to costly and slow communications.

Innovation Solution

Establishing a virtual network over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and middlebox service machines, optimized for end-to-end performance, reliability, and security, while minimizing Internet traffic routing through a logically centralized controller cluster.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If corporate networks use consumer Internet for traffic transmission, then cost is reduced, but reliability and quality of service deteriorate

Engineering Contradiction:
ImprovecostVSAvoidreliability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent segments network traffic into two categories: consumer traffic routed through the public Internet and corporate traffic routed through dedicated private networks. This segmentation allows each type of traffic to use the most appropriate transmission path, with corporate applications getting reliable private connectivity while consumer traffic uses cost-effective public infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (SDN controller and network gateway) that mediates between corporate applications and network infrastructure. This intermediary intelligently routes traffic based on application type, ensuring that time-sensitive corporate traffic receives priority handling while maintaining cost efficiency for non-critical communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If corporate networks use leased lines for secure communication, then reliability and security are improved, but cost increases

Engineering Contradiction:
ImprovereliabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by providing different network service qualities to different applications and locations. Critical corporate applications receive high-reliability private network connectivity, while less critical traffic uses public Internet. This localized quality differentiation optimizes cost by avoiding expensive leased lines for all traffic while maintaining reliability where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically changes network parameters (routing paths, QoS policies, bandwidth allocation) based on real-time traffic conditions and application requirements. This allows the system to adaptively optimize the balance between cost and reliability, switching between public and private network paths as needed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all corporate traffic is routed through secure WAN gateways, then security is improved, but communication speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent extracts the security function from the general-purpose WAN gateway and implements it as a distributed security policy enforcement point across multiple network locations. This allows security checks to be performed locally at the edge of the private network rather than forcing all traffic through a central gateway, thereby maintaining security while reducing latency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary security authentication and policy enforcement before traffic enters the core network infrastructure. By pre-establishing security contexts and authorizing traffic flows in advance, the system avoids real-time security processing delays for established connections while maintaining rigorous security controls.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If corporations migrate to public cloud infrastructure, then adaptability and scalability are improved, but control over network quality deteriorates

Engineering Contradiction:
ImproveadaptabilityVSAvoidcontrol over network quality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the SDN controller continuously monitors network performance metrics from public cloud infrastructure and dynamically adjusts routing policies and resource allocation. This closed-loop control allows corporations to maintain quality standards even when using external cloud providers, as the system automatically compensates for performance variations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal network orchestration layer that can manage both on-premises infrastructure and public cloud resources through a single control plane. This multi-functional approach allows corporations to maintain consistent network quality policies across hybrid environments while leveraging the adaptability of public cloud infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10999165B2Three tiers of SaaS providers for deploying compute and network infrastructure in the public cloud
Publication Date: 2021.05.04 VMWARE INC
  • US10999165B2 patent drawing
  • US10999165B2 patent drawing
  • US10999165B2 patent drawing

AI summary

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.