VCN Bridge Using Secondary VNICs for Multitenant Address Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in bridging multiple virtual cloud networks (VCNs) to enable secure and efficient communication between customer VCNs and a service provider's VCN, while addressing access mechanisms, connectivity issues, regional availability, service complexity, and customer isolation/security, particularly in scenarios like etcd-as-a-service where address space conflicts and security requirements are critical.

Innovation Solution

A system comprising a customer VCN, a service provider VCN, and a VCN bridge that utilizes secondary virtual network interface cards (VNICs) and multitenant-aware gateway software to establish secure connections, resolve address space conflicts, and ensure proper routing and identification of customer requests, leveraging virtual Ethernet pairs and network address translation to facilitate communication between customer and service provider VCNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple customer VCNs are bridged to a service provider VCN to enable multitenant services, then service accessibility and connectivity are improved, but address space conflicts and security isolation challenges worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidaddress space conflicts
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway layer that operates at the network boundary between customer VCNs and service provider VCN. This gateway performs network address translation (NAT) and route manipulation, effectively adding a dimensional layer of address space management. Customer VCNs can use overlapping private IP ranges without conflicts because the gateway translates between customer addresses and service provider addresses, resolving the address space conflict while maintaining service accessibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The gateway acts as an intermediary component between customer VCNs and the service provider VCN. It mediates all traffic flows, performing authentication, address translation, and route control. This intermediary layer isolates customer address spaces from the service provider address space, preventing address conflicts while enabling secure multitenant service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If direct connectivity is established between customer VCNs and service provider VCN, then communication efficiency is improved, but security isolation and access control complexity worsen

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidaccess control complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The gateway is designed as a universal access point that handles multiple functions: authentication, address translation, route manipulation, and security policy enforcement. All customer VCNs connect to services through this single gateway interface, which uniformly applies security controls and access policies. This multi-functional gateway reduces access control complexity by providing a standardized security boundary rather than requiring individual security configurations for each customer-service pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If customer VCNs are allowed complete control over their network environment, then customer autonomy and configuration flexibility are improved, but service integration and connectivity management worsen

Engineering Contradiction:
Improvecustomer configuration flexibilityVSAvoidservice integration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system segments network control into two distinct layers: customer VCNs maintain full control over their internal network configuration, subnets, and resources, while the gateway layer manages service integration and connectivity to the service provider VCN. This segmentation allows customers to exercise complete autonomy over their network environment without compromising service integration, as the gateway handles the complexity of connecting multiple customer networks to services.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10721095B2Virtual interface system and method for multi-tenant cloud networking
Publication Date: 2020.07.21 ORACLE INT CORP
  • US10721095B2 patent drawing
  • US10721095B2 patent drawing
  • US10721095B2 patent drawing

AI summary

Described herein are systems and methods that can support bridging VCNs in a manner which addresses customer needs with respect to access mechanisms, connectivity, regional availability, service complexity, and customer isolation/security. The system and methods that can support bridging VCNs as described herein have particular utility with respect to providing etcd-as-a-Service. In particular embodiments virtual network interface (VNIC) features are used to implement a bridge between a subnet of an etcd VCN and a subnet of a customer VCN in order to bridge the subnets.