Virtual Cloud-Connector Nodes for Cross-Facility Secure Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face challenges in seamlessly migrating virtual machines and applications across multiple cloud-computing facilities, particularly in creating secure and efficient virtual private networks that allow access to protected resources across public and private clouds.

Innovation Solution

The implementation of a virtual cloud-connector server and virtual cloud-connector nodes within a distributed hybrid cloud infrastructure enables the setup, configuration, and management of virtual private networks, allowing secure communication between corporate resources in public clouds and corporate data centers through a secure tunnel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual machines are migrated across multiple cloud-computing facilities, then load balancing and fault tolerance are improved, but network security and resource protection become more difficult to maintain

Engineering Contradiction:
Improvefault toleranceVSAvoidnetwork security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces virtual cloud-connector nodes as intermediary components that establish secure tunnel connections between virtual machines across different cloud facilities. These connectors act as mediators that maintain security boundaries while enabling migration and communication, resolving the contradiction between improved fault tolerance and maintained network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network infrastructure is segmented into multiple virtual cloud-connector nodes distributed across different cloud-computing facilities. Each node manages local virtual machines and establishes secure connections to remote nodes, allowing the system to maintain security at each segment while enabling cross-facility migration for load balancing and fault tolerance.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If virtual private networks are established across multiple cloud facilities, then resource accessibility is improved, but system complexity increases

Engineering Contradiction:
Improveresource accessibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The virtual cloud-connector nodes are designed as universal components that perform multiple functions: establishing secure tunnels, managing virtual machine migrations, enabling resource access across clouds, and maintaining network security. This multi-functionality reduces overall system complexity by consolidating diverse operations into standardized nodes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual cloud-connector nodes automatically manage their own configuration and establishment of secure connections without requiring complex manual setup. The system enables self-service provisioning of virtual private networks across multiple cloud facilities, reducing operational complexity while maintaining high resource accessibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9391801B2Virtual private networks distributed across multiple cloud-computing facilities
Publication Date: 2016.07.12 VMWARE INC
  • US9391801B2 patent drawing
  • US9391801B2 patent drawing
  • US9391801B2 patent drawing

AI summary

The current document discloses methods and systems for extending an internal network within a first cloud-computing facility to a second cloud-computing facility and using the extended internal network as a basis for creating virtual private clouds distributed across multiple cloud-computing facilities. In one implementation, a pool of IP addresses is allocated and distributed to end appliances of the first and second cloud-computing facilities. In this implementation, the internal network is extended via a secure tunnel between end appliances in the first and second cloud-computing facilities and the end appliances of the extended internal network are configured to route messages transmitted by a first member of the virtual private cloud executing on a first cloud-computing facility to a second member of the virtual private cloud executing on a second cloud-computing facility through the secure tunnel.