Virtual Layer-3 Router for Hybrid Cloud Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hybrid cloud networks face challenges in networking, particularly in connecting virtual machines across different locations, as existing VPN solutions introduce performance bottlenecks and require manual configuration, limiting flexibility and scalability.

Innovation Solution

Implementing a virtual layer-3 router to connect multiple virtual layer-2 networks, allowing for user-configurable virtual networking that enables seamless communication between isolated virtual networks without the need for manual VPN tunnel setup, thereby improving scalability and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual VPN tunnel setup is used to connect virtual machines across different locations, then network isolation and security are maintained, but configuration complexity and administrative burden increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service network configuration where virtual machines automatically discover and establish connections through the virtual router without manual VPN tunnel setup. The virtual router autonomously manages routing tables and connection establishment, eliminating the need for administrators to manually configure VPN tunnels while maintaining network isolation and security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtual router acts as an intermediary device between isolated virtual networks, providing automated routing and connection management. Instead of requiring direct manual configuration between remote virtual machines, the virtual router mediates communications by automatically establishing routes and managing connectivity, thereby reducing configuration complexity while maintaining network isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional VPN solutions are used to connect hybrid cloud networks, then network security is maintained, but performance bottlenecks and latency increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transfer speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces the traditional mechanical VPN tunnel establishment process with a software-based virtual routing system. Instead of relying on heavy VPN protocols that create performance bottlenecks, the system uses virtual routers with automated routing tables to manage connections, achieving better performance while maintaining security through virtual network isolation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The virtual routing system dynamically adjusts routes and connections based on real-time network conditions rather than relying on static VPN configurations. The virtual router automatically updates routing tables and optimizes data paths, enabling adaptive performance management that reduces latency and avoids the rigid performance constraints of traditional VPN solutions.

Inventive Principle:
Principle #15Dynamics

3Stability of the object's composition

If fixed network infrastructure is used in hybrid cloud environments, then stability is maintained, but adaptability to dynamic resource allocation decreases

Engineering Contradiction:
Improvenetwork stabilityVSAvoidnetwork adaptability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The virtual routing system provides dynamic adaptability by automatically adjusting routing configurations in response to changing resource allocation in hybrid cloud environments. When virtual machines are provisioned, migrated, or terminated, the virtual router dynamically updates routing tables to reflect current network topology, maintaining both stability through consistent routing policies and adaptability through automated reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the virtual router continuously monitors network conditions and resource allocation changes. This feedback enables the routing system to automatically adapt to dynamic cloud resource provisioning while maintaining stable network operations, as the router uses real-time information to adjust routes and connections without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

4Reliability

If centralized network management is used in cloud environments, then control and security are improved, but system scalability and flexibility decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments network management into distributed virtual routers that operate autonomously while maintaining overall security control. Each virtual router independently manages its own routing decisions and connections, enabling local scalability and flexibility. The segmentation allows the system to scale horizontally by adding more virtual routers without requiring centralized management intervention, while security control is maintained through virtual network isolation policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual routers perform self-service management by automatically discovering networks, establishing connections, and updating routing tables without requiring centralized administration. This self-service capability enables rapid system scalability and flexibility as virtual machines are provisioned or migrated, while security is maintained through automated enforcement of virtual network isolation policies that each router executes independently.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9197543B2Fully distributed routing over a user-configured on-demand virtual network for infrastructure-as-a-service (IaaS) on hybrid cloud networks
Publication Date: 2015.11.24 CISCO TECHNOLOGY INC
  • US9197543B2 patent drawing
  • US9197543B2 patent drawing
  • US9197543B2 patent drawing

AI summary

A layer-3 virtual router connects two or more virtual networks. Virtual networks are overlaid upon physical networks. Each virtual network (VN) is a layer-2 network that appears to expand an organization's LAN using virtual MAC addresses. The network stack forms a virtual-network packet with a virtual gateway MAC address of the virtual router to reach a remote virtual network. A VN device driver shim intercepts packets and their virtual MAC and IP addresses and encapsulates them with physical packets sent over the Internet. A VN switch table is expanded to include entries for nodes on the remote virtual network so that all nodes on both virtual networks are accessible. A copy of the VN switch table is stored on each node by a virtual network management daemon on the node. A Time-To-Live field in the virtual-network packet is decremented for each virtual hop and a checksum recalculated.