Secure Cloud Fabric for Hybrid Network Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise IT faces challenges in establishing a hybrid cloud infrastructure that securely connects applications and computing resources across public and private environments without compromising security and compliance, particularly due to the distributed and segregated nature of network and infrastructure security in hybrid cloud environments.

Innovation Solution

A secure virtual network platform that connects subnets in different network domains using a WAN virtual network platform, allowing connections between server groups, server groups and physical networks, and physical networks without altering existing firewalls or network topology, utilizing virtual gateways and routing tables to manage and secure communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a hybrid cloud infrastructure is established to connect public and private computing environments, then connectivity and flexibility are improved, but security and compliance are compromised

Engineering Contradiction:
Improvehybrid cloud connectivityVSAvoidsecurity and compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cloud fabric as an intermediary layer that sits between public and private network domains. This cloud fabric includes virtual network functions and security policies that mediate communications, allowing hybrid cloud connectivity while maintaining security through centralized policy enforcement and virtualized network functions that act as trusted intermediaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network infrastructure into distinct virtual network domains and subnets, each with its own security policies and access controls. This segmentation allows different security levels to coexist, enabling hybrid cloud connectivity while maintaining compliance through isolated security zones and controlled access paths.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional IT network security technology is used to protect critical business data behind firewalls, then security is improved, but ease of operation deteriorates when new business initiatives require external access

Engineering Contradiction:
Improvesecurity protectionVSAvoidaccess provisioning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access provisioning through the cloud fabric, where security policies and network paths can be dynamically created, modified, and removed based on business needs. This allows secure access to be rapidly provisioned for new initiatives without manual firewall reconfiguration, maintaining both security protection and ease of operation through automated policy-driven access management.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If a flat cloud computing infrastructure is deployed within a single datacenter, then ease of management is improved, but adaptability to hybrid environments deteriorates

Engineering Contradiction:
Improvemanagement simplicityVSAvoidhybrid environment support
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal cloud fabric architecture that can operate across single datacenter, multi-datacenter, public cloud, and hybrid environments. The virtual network functions and security policies are designed to be environment-agnostic, providing consistent management simplicity while adapting to various deployment scenarios including hybrid cloud configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10523514B2Secure cloud fabric to connect subnets in different network domains
Publication Date: 2019.12.31 ZENTERA SYST
  • US10523514B2 patent drawing
  • US10523514B2 patent drawing
  • US10523514B2 patent drawing

AI summary

A secure virtual network platform connects two or more subnets in different or separate network domains. The secure virtual network can use the under layer physical networks in various domains as an IP forwarding fabric without changing any existing firewalls, security settings, or network topology. A first type of connection across the virtual network involves connecting server groups. A second type of connection across the virtual network involves connecting a server group to a physical network. A third type of connection across the virtual network involves connecting a physical network to another physical network.