Secure Virtual Network Platform for Hybrid Cloud Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise IT faces challenges in establishing a hybrid cloud infrastructure that securely connects applications and computing resources across public and private environments without compromising security and compliance, particularly due to the distributed and segregated nature of network and infrastructure security in hybrid cloud environments.
Innovation Solution
A secure virtual network platform that connects two or more network domains by determining whether data packets should be forwarded outside the platform or transmitted via a virtual network, using a controller to manage connections and ensure security through virtual network switches and proxies, allowing only authorized applications to use the virtual network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a unified network and infrastructure security approach is used within a single datacenter, then management complexity is reduced and services are simplified, but this approach cannot be applied in hybrid cloud environments where network and infrastructure security are distributed and belong to multiple authorities
Solution Approach 1:
The patent segments the hybrid cloud environment into multiple network domains (public cloud domain, private cloud domain, on-premises domain) with dedicated security boundaries. Each domain maintains its own security policies and controls, allowing the unified management approach to be applied within each segment while adapting to the distributed nature of hybrid cloud infrastructure through the virtual network platform that connects these segmented domains.
2Reliability
If corporate firewalls and security infrastructure are deployed to protect critical business data and operations, then security and compliance are improved, but legitimate access from external locations becomes extremely difficult and requires tremendous IT efforts to re-provision
Solution Approach 1:
The patent introduces a virtual network platform as an intermediary layer between external locations and the protected corporate network. This virtual network acts as a mediator that enables legitimate access requests to traverse through the firewall infrastructure without requiring re-provisioning. The platform establishes virtual connections that are approved by the controller, allowing external access while maintaining the integrity of the security boundary and without compromising the firewall's protective function.
3Reliability
If valuable IP and development resources are placed behind layers of firewalls for protection, then security is improved, but collaboration with ecosystem partners and vendors suffers with poor productivity and long resolution times
Solution Approach 1:
The patent implements dynamic access control where the virtual network connection status changes based on real-time security approval. When collaboration is needed, the controller dynamically approves connection requests, establishing temporary virtual network paths that enable partners and vendors to access protected resources. This dynamic approach maintains security protection while enabling productive collaboration when required, resolving the contradiction between security and productivity.
4Stability of the object's composition
If conventional IT network security technology is used in hybrid environments, then existing security policies are maintained, but enterprise IT faces tremendous operating risks and efforts to accomplish their mission
Solution Approach 1:
The patent creates a universal virtual network platform that can operate across multiple cloud domains and on-premises infrastructure. This single platform provides multi-functional capabilities including secure connection establishment, security policy enforcement, and access control across diverse hybrid cloud environments. By providing a unified solution that works across different domains, it reduces the operating time and effort required compared to managing separate security technologies for each environment.
Data Source
AI summary
Clusters of virtual network switches (VNS) and controllers are provided. The controller cluster is connected to the VNS cluster which is between first and second network domains. A request is received at a first end point in the first network domain to connect to a second end point in the second network domain. If the connection should be through a virtual network connecting the network domains, a virtual network connection is established as allowed by a controller of the controller cluster. The establishment includes initiating first outbound traffic from the first end point to a VNS of the VNS cluster and initiating second outbound traffic from the second end point to the VNS. The VNS places a payload from the first outbound traffic into a reply to the second outbound traffic.


