Tenant-Specific Overlay Networks for Bi-Directional Cloud Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing secure, high-performance, and scalable site-to-site network connectivity between on-premise and cloud environments is complex and time-consuming, requiring manual configuration and increasing the risk of errors, especially when managing multiple networks and resources.

Innovation Solution

A secure network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) enables secure bi-directional network connectivity between on-premise and cloud resources without explicit user configuration, using a robust infrastructure of network elements and computing nodes to establish a tenant-specific overlay network, allowing resources to access each other as if they were native within the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration is used to establish site-to-site network connectivity, then security and performance can be controlled, but the process becomes complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated network connectivity establishment where the network elements and computing nodes automatically configure and establish tenant-specific overlay networks without requiring explicit manual user configuration, while maintaining security through automated authentication and encryption protocols

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces intermediate network elements and computing nodes that act as mediators between on-premise and cloud resources, automatically managing the complex configuration tasks including tunnel establishment, encryption key management, and routing while presenting a simplified interface to users

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration is used for network connectivity, then security can be maintained, but errors increase due to the time-consuming process

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The automated system performs self-configuration with built-in validation mechanisms that eliminate human error in configuration tasks, while maintaining security through pre-defined security policies and automated authentication protocols

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates automated feedback loops that validate configuration accuracy in real-time, detecting and correcting errors before they affect network operation, while continuously monitoring security parameters to ensure compliance

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional network connectivity methods are used, then security can be ensured, but scalability is limited when managing multiple networks

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal platform that can simultaneously manage multiple tenant-specific overlay networks with different security requirements and configurations, allowing the system to scale by simply adding new tenants without reconfiguring existing secure connections

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments network connectivity into independent tenant-specific overlay networks, where each segment maintains its own security context and configuration, allowing scalable expansion by creating isolated segments that don't interfere with existing networks

Inventive Principle:
Principle #1Segmentation

4Device complexity

If automated network establishment is implemented, then complexity is reduced, but infrastructure requirements increase

Engineering Contradiction:
Improveconfiguration complexityVSAvoidinfrastructure resources
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent combines multiple network elements and computing nodes into an integrated automated system that shares common infrastructure resources such as encryption modules, authentication services, and routing tables, reducing the total infrastructure required compared to separate manual configurations

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12413469B2Secure bi-directional network connectivity system between private networks
Publication Date: 2025.09.09 ORACLE INT CORP
  • US12413469B2 patent drawing
  • US12413469B2 patent drawing
  • US12413469B2 patent drawing

AI summary

A secure private network connectivity system (SNCS) within a cloud service provider infrastructure (CSPI) is described that provides secure private network connectivity between external resources residing in a customer's on-premise environment and the customer's resources residing in the cloud. The SNCS provides secure private bi-directional network connectivity between external resources residing in a customer's external site representation and resources and services residing in the customer's VCN in the cloud without a user (e.g., an administrator) of the enterprise having to explicitly configure the external resources, advertise routes or set up site-to-site network connectivity. The SNCS provides a high performant, scalable, and highly available site-to-site network connection for processing network traffic between a customer's on-premise environment and the CSPI by implementing a robust infrastructure of network elements and computing nodes that are used to provide the secure site to site network connectivity.