Virtual Overlay Network Segmentation for WAN Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack a mechanism for creating and managing virtual network overlays across Wide Area Networks (WANs), which are essential for segregating and transmitting different types of data efficiently.

Innovation Solution

The method involves receiving data at a network appliance, classifying it based on traffic access policies, assigning an overlay identification, selecting a bonded tunnel for data transfer between appliances, and transferring data packets through this tunnel to ensure separate and secure transmission of various data types across the WAN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted over a shared WAN infrastructure, then network resource utilization is improved, but data segregation and security are worsened

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoiddata segregation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared WAN infrastructure into multiple virtual network overlays, each dedicated to specific traffic types or organizations. Virtual network appliances at each endpoint classify incoming traffic and direct it to the appropriate overlay, enabling simultaneous data segregation while utilizing shared physical infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization dimension above the physical network infrastructure. By creating overlay networks that operate independently on top of the shared WAN, the system achieves logical separation without requiring physical segmentation, thus maintaining resource utilization while improving data segregation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If multiple virtual networks are created over WAN, then data segregation is improved, but network complexity is worsened

Engineering Contradiction:
Improvedata segregationVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual network appliances automatically perform traffic classification, overlay selection, and packet routing without manual intervention. The system self-manages the complexity of multiple virtual networks by autonomously directing traffic based on classification rules, reducing the burden on network administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtual network appliance is designed as a universal device that can handle multiple functions: traffic classification, overlay network management, packet routing, and security enforcement. This multi-functionality consolidates what would otherwise require multiple specialized devices, reducing overall network complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traffic is classified and routed through separate tunnels, then data security is improved, but processing overhead is worsened

Engineering Contradiction:
Improvedata securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The virtual network appliance performs traffic classification and overlay assignment in advance, before packets are routed through tunnels. By pre-classifying traffic and determining the appropriate overlay path upfront, the system minimizes per-packet processing overhead while maintaining security through proper segmentation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10313930B2Virtual wide area network overlays
Publication Date: 2019.06.04 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10313930B2 patent drawing
  • US10313930B2 patent drawing
  • US10313930B2 patent drawing

AI summary

Disclosed herein are systems and methods for the creation, maintenance and management of virtual overlay networks across multiple communication networks managed by service providers. The simple creation and management of network overlays is accomplished via a network orchestrator manager, allowing for automation of configuration of connected network devices throughout an entire organization's network, regardless of the physical location of each device.