Virtual Network Routing Optimization Across Public Clouds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate networks face inefficiencies due to reliance on expensive leased lines and the consumer Internet, which lacks reliability, quality of service guarantees, and security, especially with the rise of mobile access and public cloud migrations, leading to costly and slow communications.

Innovation Solution

Establishing a virtual network over multiple public cloud datacenters using software-based components like measurement agents, forwarding elements, and middlebox service machines, optimized for end-to-end performance, reliability, and security, while minimizing Internet traffic routing through a logically centralized controller cluster.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If corporate networks use expensive leased lines and traditional WAN infrastructure, then reliability and security are improved, but cost increases significantly

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidnetwork cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces expensive, long-term leased lines with temporary, on-demand VPN connections through public clouds. These virtual network connections can be established quickly and terminated when no longer needed, reducing long-term infrastructure costs while maintaining reliability through encrypted tunneling protocols.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent introduces public cloud services as intermediary nodes that establish VPN tunnels between corporate networks and external destinations. These cloud-based intermediaries provide secure, reliable connections without requiring direct leased line infrastructure, thereby reducing cost while maintaining network reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If corporate networks rely on consumer Internet for traffic, then cost decreases, but performance and reliability deteriorate

Engineering Contradiction:
Improvenetwork costVSAvoidnetwork performance
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies different quality levels to different traffic types by routing time-sensitive, performance-critical traffic through optimized VPN paths in public clouds while allowing non-critical traffic to use standard Internet connections. This selective approach maintains cost efficiency while ensuring reliable performance for important applications.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If corporate networks migrate to public clouds and SaaS services, then adaptability and accessibility improve, but traffic security and control worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidtraffic security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent positions VPN gateways and security appliances in public clouds as intermediaries between corporate networks and SaaS services. These intermediaries maintain encrypted tunnels for all traffic, providing security control and monitoring capabilities while still allowing access to cloud-based services and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If corporate WANs force all traffic through secure gateways, then security is improved, but communication speed decreases

Engineering Contradiction:
Improvetraffic securityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments network traffic into different categories and applies appropriate security measures to each segment. Critical business traffic is routed through full VPN tunnels with comprehensive security checks, while less sensitive traffic can use faster, lighter-security paths, thereby maintaining overall security while improving average communication speed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11894949B2Identifying multiple nodes in a virtual network defined over a set of public clouds to connect to an external SaaS provider
Publication Date: 2024.02.06 VMWARE INC
  • US11894949B2 patent drawing
  • US11894949B2 patent drawing
  • US11894949B2 patent drawing

AI summary

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.