VCN Bridge Using Secondary VNICs for Multitenant Address Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in bridging multiple virtual cloud networks (VCNs) to enable secure and efficient communication between customer VCNs and a service provider's VCN, while addressing access mechanisms, connectivity issues, regional availability, service complexity, and customer isolation/security, particularly in scenarios like etcd-as-a-service where address space conflicts and security requirements are critical.
Innovation Solution
A system comprising a customer VCN, a service provider VCN, and a VCN bridge that utilizes secondary virtual network interface cards (VNICs) and multitenant-aware gateway software to establish secure connections, resolve address space conflicts, and ensure proper routing and identification of customer requests, leveraging virtual Ethernet pairs and network address translation to facilitate communication between customer and service provider VCNs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple customer VCNs are bridged to a service provider VCN to enable multitenant services, then service accessibility and connectivity are improved, but address space conflicts and security isolation challenges worsen
Solution Approach 1:
The patent introduces a gateway layer that operates at the network boundary between customer VCNs and service provider VCN. This gateway performs network address translation (NAT) and route manipulation, effectively adding a dimensional layer of address space management. Customer VCNs can use overlapping private IP ranges without conflicts because the gateway translates between customer addresses and service provider addresses, resolving the address space conflict while maintaining service accessibility.
Solution Approach 2:
The gateway acts as an intermediary component between customer VCNs and the service provider VCN. It mediates all traffic flows, performing authentication, address translation, and route control. This intermediary layer isolates customer address spaces from the service provider address space, preventing address conflicts while enabling secure multitenant service access.
2Speed
If direct connectivity is established between customer VCNs and service provider VCN, then communication efficiency is improved, but security isolation and access control complexity worsen
Solution Approach 1:
The gateway is designed as a universal access point that handles multiple functions: authentication, address translation, route manipulation, and security policy enforcement. All customer VCNs connect to services through this single gateway interface, which uniformly applies security controls and access policies. This multi-functional gateway reduces access control complexity by providing a standardized security boundary rather than requiring individual security configurations for each customer-service pair.
3Adaptability or versatility
If customer VCNs are allowed complete control over their network environment, then customer autonomy and configuration flexibility are improved, but service integration and connectivity management worsen
Solution Approach 1:
The system segments network control into two distinct layers: customer VCNs maintain full control over their internal network configuration, subnets, and resources, while the gateway layer manages service integration and connectivity to the service provider VCN. This segmentation allows customers to exercise complete autonomy over their network environment without compromising service integration, as the gateway handles the complexity of connecting multiple customer networks to services.
Data Source
AI summary
Described herein are systems and methods that can support bridging VCNs in a manner which addresses customer needs with respect to access mechanisms, connectivity, regional availability, service complexity, and customer isolation/security. The system and methods that can support bridging VCNs as described herein have particular utility with respect to providing etcd-as-a-Service. In particular embodiments virtual network interface (VNIC) features are used to implement a bridge between a subnet of an etcd VCN and a subnet of a customer VCN in order to bridge the subnets.


