Private Communication Setup in Public Cloud via Metadata Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public cloud environments face challenges with security, scalability, and reliability due to limited scalability and reliability of private communication links, as well as susceptibility to DDoS attacks and network address translation latency, especially when using public IP addresses for communication between entities.

Innovation Solution

A private communication set-up system that monitors metadata tags in a public cloud environment to configure producer-side and consumer-side private link services, using metadata to create private DNS records and network load balancers, thereby establishing secure and scalable private communication links without the need for a three-way handshake protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If public IP addresses are used for communication in public cloud environment, then network accessibility is improved, but security is worsened due to susceptibility to DDoS attacks and gateway exposure

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway service as an intermediary component that sits between external networks and internal cloud resources. This gateway acts as a mediator that handles all incoming and outgoing traffic, preventing direct exposure of internal services to the internet while maintaining network accessibility. The gateway service can implement security policies, authentication, and traffic filtering without blocking legitimate communication needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If private communication pathways are implemented using virtual private clouds, then security is improved, but scalability is worsened due to limited scalability of conventional protocols

Engineering Contradiction:
Improvesecurity protectionVSAvoidscalability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The gateway service is designed as a universal, multi-functional component that can serve multiple purposes: providing security, enabling private communication, supporting scalability, and facilitating various communication protocols. This single gateway infrastructure can dynamically adapt to serve different communication needs without requiring separate dedicated infrastructure for each function, thus achieving both security and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway service implements dynamic configuration and scaling capabilities, allowing it to adapt to changing communication demands. The service can dynamically adjust its resources, configure new communication pathways, and scale horizontally to handle increased traffic loads, making the private communication infrastructure both secure and scalable.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If network address translation is used for public cloud communication, then network connectivity is improved, but latency is worsened due to additional translation overhead

Engineering Contradiction:
Improvenetwork connectivityVSAvoidcommunication latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary network configuration and address mapping through the gateway service before actual communication occurs. The gateway pre-establishes communication pathways, configures routing rules, and sets up address mappings in advance, so that when actual data transmission occurs, the traffic flows through pre-configured optimized paths without requiring real-time address translation, thus reducing latency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11757845B2Private communication service in a public cloud environment
Publication Date: 2023.09.12 SALESFORCE INC
  • US11757845B2 patent drawing
  • US11757845B2 patent drawing
  • US11757845B2 patent drawing

AI summary

A private communication set-up service enables scalable private connectivity between producers and consumers residing within a public cloud environment. A producer exposes metadata information about a new or updated resource within the public cloud environment using a tag. The system monitors the public cloud environment for tagged metadata about new resources and configures a producer-side service to a private link. Subsequently, the system exposes metadata information about the private link. The system monitors for tagged metadata about private links and configures the consumer-side private link endpoint to the private link. The producer and the consumer communicate using the configured private link.