Tenant-Specific Overlay Networks for Bi-Directional Cloud Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing secure, high-performance, and scalable site-to-site network connectivity between on-premise and cloud environments is complex and time-consuming, requiring manual configuration and increasing the risk of errors, especially when managing multiple networks and resources.
Innovation Solution
A secure network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) enables secure bi-directional network connectivity between on-premise and cloud resources without explicit user configuration, using a robust infrastructure of network elements and computing nodes to establish a tenant-specific overlay network, allowing resources to access each other as if they were native within the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration is used to establish site-to-site network connectivity, then security and performance can be controlled, but the process becomes complex and time-consuming
Solution Approach 1:
The system enables automated network connectivity establishment where the network elements and computing nodes automatically configure and establish tenant-specific overlay networks without requiring explicit manual user configuration, while maintaining security through automated authentication and encryption protocols
Solution Approach 2:
The patent introduces intermediate network elements and computing nodes that act as mediators between on-premise and cloud resources, automatically managing the complex configuration tasks including tunnel establishment, encryption key management, and routing while presenting a simplified interface to users
2Reliability
If manual configuration is used for network connectivity, then security can be maintained, but errors increase due to the time-consuming process
Solution Approach 1:
The automated system performs self-configuration with built-in validation mechanisms that eliminate human error in configuration tasks, while maintaining security through pre-defined security policies and automated authentication protocols
Solution Approach 2:
The system incorporates automated feedback loops that validate configuration accuracy in real-time, detecting and correcting errors before they affect network operation, while continuously monitoring security parameters to ensure compliance
3Reliability
If traditional network connectivity methods are used, then security can be ensured, but scalability is limited when managing multiple networks
Solution Approach 1:
The patent creates a universal platform that can simultaneously manage multiple tenant-specific overlay networks with different security requirements and configurations, allowing the system to scale by simply adding new tenants without reconfiguring existing secure connections
Solution Approach 2:
The system segments network connectivity into independent tenant-specific overlay networks, where each segment maintains its own security context and configuration, allowing scalable expansion by creating isolated segments that don't interfere with existing networks
4Device complexity
If automated network establishment is implemented, then complexity is reduced, but infrastructure requirements increase
Solution Approach 1:
The patent combines multiple network elements and computing nodes into an integrated automated system that shares common infrastructure resources such as encryption modules, authentication services, and routing tables, reducing the total infrastructure required compared to separate manual configurations
Data Source
AI summary
A secure private network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) is described that provides secure private network connectivity between external resources residing in a customer's on-premise environment and the customer's resources residing in the cloud. The SNCS provides secure private bi-directional network connectivity between external resources residing in a customer's external site representation and resources and services residing in the customer's VCN in the cloud without a user (e.g., an administrator) of the enterprise having to explicitly configure the external resources, advertise routes or set up site-to-site network connectivity. The SNCS provides a high performant, scalable, and highly available site-to-site network connection for processing network traffic between a customer's on-premise environment and the CSPI by implementing a robust infrastructure of network elements and computing nodes that are used to provide the secure site to site network connectivity.


