Managed Virtual Network Private Access to External Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing large-scale computer networks has become increasingly complex due to the scale and scope of data centers and computer networks, with challenges in provisioning, administering, and managing physical computing resources, especially in providing secure and efficient access to network-accessible services for multiple customers.
Innovation Solution
A configurable network service that provides managed virtual computer networks by overlaying them on substrate networks, using communication manager modules to facilitate secure and transparent communication with external network-accessible services, allowing clients to access services like LDAP, firewall, and VPN connections, while managing authentication and scaling of resources dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If physical computing resources are directly managed in large-scale data centers, then resource allocation and network access can be provided, but the complexity of provisioning, administering, and managing increases significantly
Solution Approach 1:
A virtualization layer is introduced as an intermediary between physical computing resources and customers. This virtualization layer abstracts the physical infrastructure, providing virtual machines and network services that simplify management while maintaining resource allocation flexibility. The intermediary layer handles the complexity of resource provisioning and network configuration automatically.
Solution Approach 2:
Virtual machines are created as software copies that simulate physical computing systems. Instead of managing physical hardware directly, the system creates virtual instances that provide the same functionality with simplified management. These virtual copies can be deployed, cloned, and migrated easily, reducing operational complexity while maintaining adaptability.
2Productivity
If multiple customers with diverse needs share computing resources, then resource utilization efficiency improves, but security isolation and application isolation become more challenging
Solution Approach 1:
The computing resources are segmented into isolated virtual machines and network segments. Each customer or application gets its own virtual container with dedicated resources, ensuring security isolation while allowing efficient sharing of the underlying physical infrastructure. The network is divided into separate virtual networks that prevent unauthorized access between different customers.
Solution Approach 2:
Different virtual machines and network segments are assigned different security policies and access rights based on their specific requirements. The system provides customized security isolation at the local level for each virtual instance while maintaining overall system efficiency. This allows diverse customers to share resources with appropriate security boundaries.
3Productivity
If network-accessible services are accessed directly from managed virtual networks, then service availability is improved, but secure communication and authentication complexity increases
Solution Approach 1:
A communication manager module is introduced as an intermediary between virtual network nodes and external network-accessible services. This module handles authentication, authorization, and secure communication protocols automatically, simplifying the complexity of managing service access while ensuring security. The intermediary layer translates between different network protocols and manages connection security.
Data Source
AI summary
Techniques are described for managing communications for a managed virtual computer network overlaid on a distinct substrate computer network. The techniques may be used in situations in which a configurable network service provides managed virtual computer networks for clients and also provides one or more network-accessible services that are available to the managed virtual computer networks, with particular managed virtual computer networks being configured to provide local private access to at least one of the provided network-accessible services, despite those provided network-accessible services being located externally to the particular managed virtual computer networks. In some situations, a Lightweight Directory Access Protocol (“LDAP”) network-accessible service is provided, and a logical endpoint for the LDAP service is created within a managed virtual computer network to enable the multiple computing nodes of the managed virtual computer network to communicate with one or more LDAP computer servers from the LDAP service.


