Virtual Network Layer-4 Optimization for Cloud WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate WANs become costly detours due to the need for all corporate traffic to go through secure WAN gateways, especially with the rise of mobile access and public cloud usage, as they lack the reliability and quality of service expected by business applications, and existing SD-WAN solutions do not adequately address mid-mile connectivity issues or mobile/IoT devices.
Innovation Solution
A virtual network is established over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and layer-4 connection proxies, optimized for end-to-end performance, reliability, and security, minimizing Internet routing and leveraging public cloud infrastructure for scalable and cost-effective connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all corporate traffic is routed through secure WAN gateways, then security is improved, but latency and cost increase
Solution Approach 1:
The patent segments traffic into different categories (secure corporate traffic vs. public cloud traffic) and routes them through different paths. Secure traffic goes through WAN gateways while public cloud traffic can use direct Internet routes, eliminating unnecessary detours through secure gateways for non-sensitive traffic.
Solution Approach 2:
The patent introduces SD-WAN controllers and policies as intermediaries that intelligently determine the optimal path for each traffic flow. These controllers act as mediators between the security requirements and performance needs, dynamically routing traffic based on application type, destination, and current network conditions.
2Reliability
If corporate WAN uses expensive leased lines, then reliability is improved, but cost increases
Solution Approach 1:
The patent implements dynamic path selection where traffic routing is not static but adapts in real-time based on network conditions, cost considerations, and service requirements. SD-WAN controllers continuously monitor link quality and dynamically adjust routing policies to balance reliability and cost.
Solution Approach 2:
The patent changes the parameters of network paths by introducing multiple routing options with different characteristics (cost, reliability, speed). It allows the system to switch between expensive high-reliability leased lines and cheaper consumer Internet connections based on real-time requirements, effectively changing the operational parameters of the network infrastructure.
3Loss of energy
If consumer Internet is used for corporate traffic, then cost is reduced, but quality of service deteriorates
Solution Approach 1:
The patent makes the network infrastructure universal by enabling a single network connection (consumer Internet) to serve multiple functions - both general web browsing and critical business applications. Through SD-WAN policies, the same consumer Internet connection can provide QoS guarantees for business traffic while allowing unrestricted access for personal traffic.
Solution Approach 2:
The patent implements feedback mechanisms where SD-WAN controllers continuously monitor the performance of consumer Internet connections and adjust routing decisions based on observed quality. When QoS requirements are not met, the system can dynamically switch to alternative paths or prioritize critical traffic, using feedback from performance monitoring to maintain service quality.
4Productivity
If SD-WAN appliances are deployed, then traffic optimization is improved, but device complexity and cost increase
Solution Approach 1:
The patent replaces physical SD-WAN appliances with software-based SD-WAN controllers that run on standard servers or cloud infrastructure. This substitution eliminates the need for specialized hardware appliances, reducing device complexity and cost while maintaining traffic optimization capabilities through software-based policy enforcement and intelligent routing.
Data Source
AI summary
Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.


