Virtual Network Overlay for Cloud Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in cloud computing due to limited control over key network parameters, security, and the inability to use multicast protocols in third-party controlled environments, which restricts their ability to run applications and manage sensitive data effectively.

Innovation Solution

A system of virtual networks is created using VPN connections that overlay existing cloud networks, allowing customers to establish redundant routes, manage network parameters, and integrate with private infrastructure, enabling control over encryption, addressing, and routing, even in environments where the third party controls the infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud computing is used to reduce infrastructure costs, then computing resource efficiency is improved, but customer control over network parameters deteriorates

Engineering Contradiction:
Improvecomputing resource efficiencyVSAvoidcustomer control over network parameters
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into multiple virtual networks (VNs) that overlay the physical cloud infrastructure. Each VN is isolated and can be independently configured with custom network parameters, allowing customers to maintain control over their specific network requirements while sharing the underlying cloud infrastructure. This segmentation enables both resource efficiency and parameter control to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an additional networking dimension by creating virtual networks that operate above the physical infrastructure layer. This overlay network layer allows customers to define and control their own network parameters (IP addressing, routing, security policies) without modifying the underlying cloud infrastructure, thus maintaining both cloud efficiency and customer adaptability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If third-party controlled cloud infrastructure is used, then infrastructure management complexity is reduced, but network security and control deteriorate

Engineering Contradiction:
Improveinfrastructure management complexityVSAvoidnetwork security and control
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the cloud infrastructure into multiple isolated virtual networks, each with its own security boundaries and control policies. This segmentation allows the third-party provider to manage the physical infrastructure simply while giving customers full security control within their designated virtual network segments, resolving the contradiction between management simplicity and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual network acts as an intermediary layer between the customer's applications and the third-party cloud infrastructure. This intermediary enables customers to enforce their own security policies and control mechanisms without directly managing the complex underlying infrastructure, thus maintaining both infrastructure simplicity and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If standard cloud networking is used, then ease of deployment is improved, but ability to use multicast protocols and custom routing deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidability to use multicast protocols and custom routing
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic virtual networks that can be configured with custom routing protocols and multicast support. These virtual networks dynamically adapt to customer requirements while maintaining easy deployment through automated provisioning. The system allows customers to enable multicast and custom routing within their virtual networks without impacting the simplicity of overall cloud deployment.

Inventive Principle:
Principle #15Dynamics

4Reliability

If multiple virtual networks are created for redundancy, then network reliability is improved, but network complexity increases

Engineering Contradiction:
Improvenetwork redundancyVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates virtual networks that serve multiple functions simultaneously: they provide network isolation, security boundaries, redundancy paths, and custom protocol support. This multi-functionality allows a single virtual network infrastructure to deliver reliability through redundancy without proportionally increasing complexity, as the same virtual network structure fulfills multiple network requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9172615B2System and methods for enabling customer network control in third-party computing environments
Publication Date: 2015.10.27 COHESIVE FLEXIBLE TECHNOLOGIES CORP
  • US9172615B2 patent drawing
  • US9172615B2 patent drawing
  • US9172615B2 patent drawing

AI summary

The present invention relates to a system and methods for enabling a user control in third-party computing environments or cloud computing via a virtual private network created by a control module, which contains parameters defined by the user. The system and methods are used to create a fault tolerant virtual private network that allows user control over addressing, security encryption, routing, and the enablement of multicast protocols, regardless of the prohibition set by the third-party computing environment.