Virtual Network Layer-4 Optimization for Cloud WAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate WANs become costly detours due to the need for all corporate traffic to go through secure WAN gateways, especially with the rise of mobile access and public cloud usage, as they lack the reliability and quality of service expected by business applications, and existing SD-WAN solutions do not adequately address mid-mile connectivity issues or mobile/IoT devices.

Innovation Solution

A virtual network is established over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and layer-4 connection proxies, optimized for end-to-end performance, reliability, and security, minimizing Internet routing and leveraging public cloud infrastructure for scalable and cost-effective connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all corporate traffic is routed through secure WAN gateways, then security is improved, but latency and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments traffic into different categories (secure corporate traffic vs. public cloud traffic) and routes them through different paths. Secure traffic goes through WAN gateways while public cloud traffic can use direct Internet routes, eliminating unnecessary detours through secure gateways for non-sensitive traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces SD-WAN controllers and policies as intermediaries that intelligently determine the optimal path for each traffic flow. These controllers act as mediators between the security requirements and performance needs, dynamically routing traffic based on application type, destination, and current network conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If corporate WAN uses expensive leased lines, then reliability is improved, but cost increases

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements dynamic path selection where traffic routing is not static but adapts in real-time based on network conditions, cost considerations, and service requirements. SD-WAN controllers continuously monitor link quality and dynamically adjust routing policies to balance reliability and cost.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of network paths by introducing multiple routing options with different characteristics (cost, reliability, speed). It allows the system to switch between expensive high-reliability leased lines and cheaper consumer Internet connections based on real-time requirements, effectively changing the operational parameters of the network infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Loss of energy

If consumer Internet is used for corporate traffic, then cost is reduced, but quality of service deteriorates

Engineering Contradiction:
ImprovecostVSAvoidquality of service
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent makes the network infrastructure universal by enabling a single network connection (consumer Internet) to serve multiple functions - both general web browsing and critical business applications. Through SD-WAN policies, the same consumer Internet connection can provide QoS guarantees for business traffic while allowing unrestricted access for personal traffic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where SD-WAN controllers continuously monitor the performance of consumer Internet connections and adjust routing decisions based on observed quality. When QoS requirements are not met, the system can dynamically switch to alternative paths or prioritize critical traffic, using feedback from performance monitoring to maintain service quality.

Inventive Principle:
Principle #23Feedback

4Productivity

If SD-WAN appliances are deployed, then traffic optimization is improved, but device complexity and cost increase

Engineering Contradiction:
Improvetraffic optimizationVSAvoidappliance complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces physical SD-WAN appliances with software-based SD-WAN controllers that run on standard servers or cloud infrastructure. This substitution eliminates the need for specialized hardware appliances, reducing device complexity and cost while maintaining traffic optimization capabilities through software-based policy enforcement and intelligent routing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11895194B2Layer four optimization for a virtual network defined over public cloud
Publication Date: 2024.02.06 VMWARE INC
  • US11895194B2 patent drawing
  • US11895194B2 patent drawing
  • US11895194B2 patent drawing

AI summary

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.