Reverse Connection Endpoint for Cloud Network Redirect Trapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to managing network connectivity between private and public clouds face challenges due to network isolation and access controls, particularly when load balancing operations redirect connections to different targets within the private network, leading to network connection failures as the public cloud lacks necessary routing information.

Innovation Solution

The method involves leveraging a reverse connection endpoint and IP address mapping controller to capture redirection messages and manage network address translation, enabling the public cloud to initiate connections to dynamically determined IP addresses within the private cloud, thus overcoming routing infrastructure limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network isolation and access controls are implemented between private and public clouds, then network security is maintained, but public cloud cannot initiate connections to private cloud

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection initiation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a reverse connection endpoint (RCE) as an intermediary component deployed in the private cloud network. This RCE acts as a mediator that receives connection requests from the public cloud and forwards them to the intended private cloud resources, thereby enabling public cloud initiation while maintaining private cloud security boundaries. The RCE serves as a controlled access point that reconciles the security requirements with the need for bidirectional communication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If reverse connection endpoint is used for public cloud to connect to private cloud, then connection capability is improved, but redirect trapping to different targets fails

Engineering Contradiction:
Improveconnection initiation capabilityVSAvoidrouting management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a redirect trapping mechanism that captures redirect messages from load balancers and other networking equipment within the private cloud. The system monitors outgoing traffic patterns, detects redirect attempts to different targets, and dynamically updates the RCE routing table accordingly. This feedback loop enables the system to adapt to dynamic target changes without requiring manual reconfiguration, thereby managing routing complexity automatically while maintaining connection capability.

Inventive Principle:
Principle #23Feedback

3Productivity

If load balancing operation redirects connection to different target, then service distribution is improved, but network connection fails due to missing RCE

Engineering Contradiction:
Improveservice distribution efficiencyVSAvoidconnection reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent makes the reverse connection endpoint routing table dynamic by implementing automatic update mechanisms. When load balancers or networking equipment redirect connections to different targets, the system detects these changes and dynamically updates the RCE routing information. This dynamic adaptation ensures that the RCE always has current routing information for active targets, maintaining connection reliability while supporting flexible load balancing operations without requiring static pre-configuration for all possible targets.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12170643B2Application routing infrastructure for private-level redirect trapping and creation of NAT mapping to work with connectivity in cloud and customer networks
Publication Date: 2024.12.17 ORACLE INT CORP
  • US12170643B2 patent drawing
  • US12170643B2 patent drawing
  • US12170643B2 patent drawing

AI summary

A computer program product, system, and computer implemented method for application-level redirect trapping and creation of NAT mapping to work with routing infrastructure for private connectivity in cloud and customer networks. The approach disclosed herein generally comprises a method of leveraging a reverse connection endpoint and IP address mapping controller to capture redirection messages from a private cloud or network (e.g., a service consumer network or a service consumer hybrid cloud). This allows at least the IP address mapping controller to manage a cloud networking infrastructure to provide for a service provider network (e.g., a public cloud) to support applications that overcome the isolation requirements of a private cloud or network to perform useful work. For example, without saddling the private cloud or network user with a heavy pre-configuration burden, the approach disclosed herein supports redirection to dynamically determined IP addresses at the private cloud or network.