Virtual Network Routing Optimization Across Public Clouds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate networks face inefficiencies due to reliance on expensive leased lines and the consumer Internet, which lacks reliability, quality of service guarantees, and security, especially with the rise of mobile access and public cloud migrations, leading to costly and slow communications.
Innovation Solution
Establishing a virtual network over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and middlebox service machines, optimized for end-to-end performance, reliability, and security, while minimizing Internet traffic routing through a logically centralized controller cluster.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If corporate networks use expensive leased lines and traditional WAN infrastructure, then reliability and security are improved, but cost increases significantly
Solution Approach 1:
The patent replaces expensive, long-term leased lines with temporary, on-demand VPN connections through public clouds. These virtual network connections can be established quickly and terminated when no longer needed, reducing long-term infrastructure costs while maintaining reliability through encrypted tunneling protocols.
Solution Approach 2:
The patent introduces public cloud services as intermediary nodes that establish VPN tunnels between corporate networks and external destinations. These cloud-based intermediaries provide secure, reliable connections without requiring direct leased line infrastructure, thereby reducing cost while maintaining network reliability.
2Quantity of substance
If corporate networks rely on consumer Internet for traffic, then cost decreases, but performance and reliability deteriorate
Solution Approach 1:
The patent applies different quality levels to different traffic types by routing time-sensitive, performance-critical traffic through optimized VPN paths in public clouds while allowing non-critical traffic to use standard Internet connections. This selective approach maintains cost efficiency while ensuring reliable performance for important applications.
3Adaptability or versatility
If corporate networks migrate to public clouds and SaaS services, then adaptability and accessibility improve, but traffic security and control worsen
Solution Approach 1:
The patent positions VPN gateways and security appliances in public clouds as intermediaries between corporate networks and SaaS services. These intermediaries maintain encrypted tunnels for all traffic, providing security control and monitoring capabilities while still allowing access to cloud-based services and applications.
4Reliability
If corporate WANs force all traffic through secure gateways, then security is improved, but communication speed decreases
Solution Approach 1:
The patent segments network traffic into different categories and applies appropriate security measures to each segment. Critical business traffic is routed through full VPN tunnels with comprehensive security checks, while less sensitive traffic can use faster, lighter-security paths, thereby maintaining overall security while improving average communication speed.
Data Source
AI summary
Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.


