Secure Exchange Network for Autonomous Service Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for secure service delivery between business networks often require significant modifications to existing IT infrastructure, migration to cloud-based topologies, or deployment of proprietary integration solutions, which can be costly and disruptive.

Innovation Solution

A secure exchange network with exchange edge devices that enable on-demand delivery of network-based services between autonomous networks without modifying existing IT infrastructure, using secure peer-to-peer connections over a distinct data network, allowing service providers and consumers to establish secure channels for service delivery and consumption within their administrative control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If proprietary B2B integration solutions or cloud migration are implemented to improve service delivery, then service delivery capability is improved, but infrastructure complexity and cost increase

Engineering Contradiction:
Improveservice delivery capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a service exchange network as an intermediary between service provider networks and service consumer networks. This intermediary enables service delivery without requiring direct integration between participating networks, thus improving service delivery capability while avoiding the complexity of proprietary B2B integration solutions. The exchange network handles service matching, authorization, and connection establishment, allowing organizations to maintain their existing infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN gateways and DMZ are deployed to protect private networks, then network security is improved, but network architecture complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the core service exchange network, implementing it through authorized representative devices deployed within participant networks. These representatives handle authorization and authentication locally, while the main exchange network focuses on service matching and connection management. This separation allows security to be maintained without adding complexity to the overall network architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If cloud infrastructure migration is performed to improve service delivery, then service accessibility is improved, but implementation cost and disruption increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidimplementation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent enables networks to independently publish their service capabilities and consume services from other networks through the exchange network, without requiring migration to a centralized cloud infrastructure. Each participant maintains control of its own resources and can quickly join or leave the service exchange, enabling rapid deployment without the time-consuming process of cloud migration while still achieving improved service accessibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3202107B1Virtualized on-demand service delivery between data networks via secure exchange network
Publication Date: 2021.03.31 CISCO TECHNOLOGY INC
  • EP3202107B1 patent drawingFigure 1
  • EP3202107B1 patent drawingFigure 2
  • EP3202107B1 patent drawingFigure 3

AI summary

In one embodiment, a method comprises determining, by a network edge device in a first autonomous network, whether a second network edge device in a second autonomous network is authorized to submit a service request to the first autonomous network, the service request associated with one of providing or consuming an identified network-based service; identifying, by the network edge device within the first autonomous network, a third network edge device in a third autonomous network and identified as responsive to the service request for the identified network-based service; and sending instructions for establishing a secure communications between the second network edge device and the third network edge device via a data network distinct from the first, second, or third autonomous networks, for establishment of the identified network service between the second autonomous network and the third autonomous network via the data network.