Virtual Network Overlay for Cloud Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Businesses face challenges in cloud computing due to limited control over key network parameters, security, and the inability to use multicast protocols in third-party controlled environments, which restricts their ability to run applications and manage sensitive data effectively.
Innovation Solution
A system of virtual networks is created using VPN connections that overlay existing cloud networks, allowing customers to establish redundant routes, manage network parameters, and integrate with private infrastructure, enabling control over encryption, addressing, and routing, even in environments where the third party controls the infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud computing is used to reduce infrastructure costs, then computing resource efficiency is improved, but customer control over network parameters deteriorates
Solution Approach 1:
The patent segments the network into multiple virtual networks (VNs) that overlay the physical cloud infrastructure. Each VN is isolated and can be independently configured with custom network parameters, allowing customers to maintain control over their specific network requirements while sharing the underlying cloud infrastructure. This segmentation enables both resource efficiency and parameter control to coexist.
Solution Approach 2:
The patent introduces an additional networking dimension by creating virtual networks that operate above the physical infrastructure layer. This overlay network layer allows customers to define and control their own network parameters (IP addressing, routing, security policies) without modifying the underlying cloud infrastructure, thus maintaining both cloud efficiency and customer adaptability.
2Device complexity
If third-party controlled cloud infrastructure is used, then infrastructure management complexity is reduced, but network security and control deteriorate
Solution Approach 1:
The patent divides the cloud infrastructure into multiple isolated virtual networks, each with its own security boundaries and control policies. This segmentation allows the third-party provider to manage the physical infrastructure simply while giving customers full security control within their designated virtual network segments, resolving the contradiction between management simplicity and security control.
Solution Approach 2:
The virtual network acts as an intermediary layer between the customer's applications and the third-party cloud infrastructure. This intermediary enables customers to enforce their own security policies and control mechanisms without directly managing the complex underlying infrastructure, thus maintaining both infrastructure simplicity and security reliability.
3Ease of manufacture
If standard cloud networking is used, then ease of deployment is improved, but ability to use multicast protocols and custom routing deteriorates
Solution Approach 1:
The patent implements dynamic virtual networks that can be configured with custom routing protocols and multicast support. These virtual networks dynamically adapt to customer requirements while maintaining easy deployment through automated provisioning. The system allows customers to enable multicast and custom routing within their virtual networks without impacting the simplicity of overall cloud deployment.
4Reliability
If multiple virtual networks are created for redundancy, then network reliability is improved, but network complexity increases
Solution Approach 1:
The patent creates virtual networks that serve multiple functions simultaneously: they provide network isolation, security boundaries, redundancy paths, and custom protocol support. This multi-functionality allows a single virtual network infrastructure to deliver reliability through redundancy without proportionally increasing complexity, as the same virtual network structure fulfills multiple network requirements.
Data Source
AI summary
The present invention relates to a system and methods for enabling a user control in third-party computing environments or cloud computing via a virtual private network created by a control module, which contains parameters defined by the user. The system and methods are used to create a fault tolerant virtual private network that allows user control over addressing, security encryption, routing, and the enablement of multicast protocols, regardless of the prohibition set by the third-party computing environment.


