Service Access Gateway for Container Network Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web application development requires frequent changes to access codes and exposes business information due to the need for new IP addresses and port numbers when requesting functions from application service providers, complicating the development process and security.

Innovation Solution

A service access method and device that acquire and forward network data packets using a routing table established from virtual network interface card IP-segment information, securing the physical address of the application service and automating router selection and load balancing, thereby simplifying the development process and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the application developer directly accesses the application service provider through IP addresses and port numbers, then the access is direct and efficient, but the physical address of the application service is exposed and security is compromised

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway component as an intermediary between the application developer and the application service provider. The gateway acquires the physical address of the application service and establishes a routing table, allowing the developer to access services through the gateway without exposing the physical address. This mediator approach resolves the contradiction by maintaining access efficiency while preventing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the application developer requests new functions from new application service providers, then new functions can be accessed, but new API protocols need to be learned and access codes need to be changed, complicating the development process

Engineering Contradiction:
ImprovefunctionalityVSAvoiddevelopment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network communication into two parts: the application layer (where developers interact with service names through simplified APIs) and the network layer (where the gateway handles IP address mapping and routing). This segmentation allows developers to access new functions by simply adding service names to their application code without needing to learn new API protocols or modify access codes, as the gateway manages the complexity of IP address translation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the application developer manually configures routing tables and handles router selection, then precise control over network data packets is achieved, but the development process becomes more complex and time-consuming

Engineering Contradiction:
Improvenetwork controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway component automatically acquires physical addresses of application services and builds routing tables without requiring manual configuration from the application developer. The gateway self-manages the network routing processes, including router selection and packet forwarding, providing reliable network control while eliminating the complexity of manual configuration. This self-service approach allows developers to focus on application logic rather than network infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9407600B2Service access method and device for conducting the same
Publication Date: 2016.08.02 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9407600B2 patent drawing
  • US9407600B2 patent drawing
  • US9407600B2 patent drawing

AI summary

For service access, a physical address of a specified application service corresponding to a specified IP segment is acquired by a user mode component in accordance with an IP-segment information of the specified IP segment, which is included in a virtual network interface card configured in a system container, and an address information including the physical address is transmitted to a router module of a machine kernel. A routing table is established by the router module in accordance with the address information. Then a network data packet is acquired and forwarded to a destination service site by the router module in accordance with the routing table.