Pre-configured Virtual Gateways for Isolated Network Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data center networks face challenges in providing reliable, secure, and high-performance connectivity for business-critical services due to unpredictable performance and security characteristics of public Internet paths, and the costs and complexities associated with direct physical connections.
Innovation Solution
The implementation of partitioned private physical interconnects (PPIs) allows for the subdivision of bandwidth capacity among multiple customers, enabling dedicated interconnect partitions (ICPs) with shared ownership, managed through a connectivity intermediary and provider network, using virtual interfaces and gateways for isolated and secure connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct isolated physical links are offered to customers, then network reliability and security are improved, but device complexity and administrative overhead increase
Solution Approach 1:
A connectivity intermediary is introduced as a mediator between customers and the provider network. The intermediary manages the complex tasks of establishing, configuring, and maintaining direct physical links to the provider network on behalf of customers. This resolves the contradiction by maintaining high reliability through direct physical links while reducing customer-side complexity through intermediary management.
Solution Approach 2:
The system enables self-service capability where customers can programmatically select from pre-configured virtual gateways without manual intervention in the complex physical connection setup. The intermediary automatically provisions and configures the necessary network infrastructure based on customer selections, maintaining reliability while simplifying the customer experience.
2Reliability
If direct isolated physical links are offered to customers, then network security is improved, but ease of operation deteriorates
Solution Approach 1:
The connectivity intermediary acts as a security gatekeeper and setup simplifier. It provides secure direct physical links to the provider network while handling all the complex configuration, authentication, and provisioning tasks automatically. Customers simply select from pre-configured options rather than performing manual setup, maintaining security without sacrificing ease of operation.
Solution Approach 2:
Virtual gateways and physical links are pre-configured and prepared in advance by the intermediary. When customers need connectivity, they can immediately select from ready-to-use pre-configured options rather than undergoing complex real-time setup procedures. This preliminary preparation maintains high security standards while dramatically improving ease of operation.
3Speed
If bandwidth capacity is allocated to customers, then network performance is improved, but loss of energy increases
Solution Approach 1:
The physical interconnect bandwidth is segmented into multiple virtual channels or partitions that can be independently allocated to different customers and services. This segmentation allows for efficient bandwidth utilization where each customer receives only the amount needed for their specific traffic patterns, preventing waste while maintaining high performance for active users.
Solution Approach 2:
The system implements dynamic bandwidth allocation where customers can adjust their allocated bandwidth capacity based on actual traffic demands. The intermediary can reallocate unused bandwidth capacity to other customers or services, optimizing overall utilization. This dynamic adjustment maintains high performance for active connections while minimizing energy waste from over-provisioned static allocations.
Data Source
AI summary
Methods and apparatus for pre-configured virtual gateways for isolated virtual networks are described. An isolated virtual network (IVN) is configured at a provider network on behalf of a customer. The IVN includes one or more devices whose network addresses are not accessible from the public Internet. In response to a request from a connectivity intermediary, a virtual private gateway (VPG) is established, configurable to enable connectivity between IVNs of the provider network and devices outside the provider network. The VPG is included within a set of candidate VPGs indicated programmatically to the customer. Connectivity is established between the customer's IVN and an external device via the VPG.


