Secure Bi-directional Network Connectivity System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing secure and efficient private network connectivity between on-premise and cloud environments is complex and time-consuming, requiring manual configuration of site-to-site connections and route management, which can be error-prone and labor-intensive for enterprises migrating applications and data to the cloud.
Innovation Solution
A secure network connectivity system within a cloud service provider infrastructure that creates a virtual overlay network, registering external resources as endpoints with virtual network interface cards (VNICs) and establishing secure VPN connections using agents to enable bi-directional connectivity without explicit user configuration of external resources or routes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of site-to-site network connections is implemented, then secure connectivity between on-premise and cloud environments is achieved, but the complexity and time required for setup and management increases significantly
Solution Approach 1:
The patent introduces a network connectivity system with computing nodes that act as intermediaries between on-premise networks and cloud environments. These computing nodes automatically establish and manage network connections, routing traffic and maintaining security without requiring manual configuration by users. The system mediates the connection process, handling route management and connectivity establishment automatically.
Solution Approach 2:
The network connectivity system performs self-configuration and automatic route management without human intervention. The computing nodes autonomously establish connections, manage routing tables, and maintain network pathways between on-premise and cloud resources. This self-service capability eliminates the need for manual configuration while maintaining secure connectivity.
2Productivity
If manual route management is performed, then network traffic between different networks can be controlled, but the time and labor required for setup and maintenance increases
Solution Approach 1:
The system pre-establishes network routes and connectivity pathways before traffic needs to flow. Computing nodes proactively configure routing tables and network pathways in advance, so that when applications need to communicate between on-premise and cloud environments, the routes are already in place and traffic can flow immediately without manual setup delays.
Solution Approach 2:
The network connectivity system automatically manages route configuration and traffic control without human intervention. Computing nodes monitor network conditions, dynamically adjust routing paths, and maintain optimal traffic flow between networks autonomously, eliminating the time and labor required for manual route management.
3Adaptability or versatility
If site-to-site network connections are configured for multiple networks, then scalability is improved, but the error-prone nature of manual configuration increases
Solution Approach 1:
The system automatically discovers and configures network connections when new networks or resources are added. Computing nodes autonomously detect new network segments, generate appropriate routing rules, and establish connectivity pathways without human intervention. This eliminates configuration errors that typically occur during manual setup while maintaining full scalability to support multiple networks.
Solution Approach 2:
The network connectivity system continuously monitors network topology and traffic patterns, using feedback loops to automatically adjust and optimize connections. When changes are detected in the network environment, the system responds by automatically reconfiguring routes and pathways, ensuring accurate and reliable connectivity across all networks without manual intervention.
Data Source
AI summary
A secure private network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) is described that provides secure private network connectivity between external resources residing in a customer's on-premise environment and the customer's resources residing in the cloud. The SNCS provides secure private bi-directional network connectivity between external resources residing in a customer's external site representation and resources and services residing in the customer's VCN in the cloud without a user (e.g., an administrator) of the enterprise having to explicitly configure the external resources, advertise routes or set up site-to-site network connectivity. The SNCS provides a high performant, scalable, and highly available site-to-site network connection for processing network traffic between a customer's on-premise environment and the CSPI by implementing a robust infrastructure of network elements and computing nodes that are used to provide the secure site to site network connectivity.


