Virtual Overlay Network Segmentation for WAN Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack a mechanism for creating and managing virtual network overlays across Wide Area Networks (WANs), which are essential for segregating and transmitting different types of data efficiently.
Innovation Solution
The method involves receiving data at a network appliance, classifying it based on traffic access policies, assigning an overlay identification, selecting a bonded tunnel for data transfer between appliances, and transferring data packets through this tunnel to ensure separate and secure transmission of various data types across the WAN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is transmitted over a shared WAN infrastructure, then network resource utilization is improved, but data segregation and security are worsened
Solution Approach 1:
The patent segments the shared WAN infrastructure into multiple virtual network overlays, each dedicated to specific traffic types or organizations. Virtual network appliances at each endpoint classify incoming traffic and direct it to the appropriate overlay, enabling simultaneous data segregation while utilizing shared physical infrastructure.
Solution Approach 2:
The patent introduces a virtualization dimension above the physical network infrastructure. By creating overlay networks that operate independently on top of the shared WAN, the system achieves logical separation without requiring physical segmentation, thus maintaining resource utilization while improving data segregation.
2Reliability
If multiple virtual networks are created over WAN, then data segregation is improved, but network complexity is worsened
Solution Approach 1:
The virtual network appliances automatically perform traffic classification, overlay selection, and packet routing without manual intervention. The system self-manages the complexity of multiple virtual networks by autonomously directing traffic based on classification rules, reducing the burden on network administrators.
Solution Approach 2:
The virtual network appliance is designed as a universal device that can handle multiple functions: traffic classification, overlay network management, packet routing, and security enforcement. This multi-functionality consolidates what would otherwise require multiple specialized devices, reducing overall network complexity.
3Reliability
If traffic is classified and routed through separate tunnels, then data security is improved, but processing overhead is worsened
Solution Approach 1:
The virtual network appliance performs traffic classification and overlay assignment in advance, before packets are routed through tunnels. By pre-classifying traffic and determining the appropriate overlay path upfront, the system minimizes per-packet processing overhead while maintaining security through proper segmentation.
Data Source
AI summary
Disclosed herein are systems and methods for the creation, maintenance and management of virtual overlay networks across multiple communication networks managed by service providers. The simple creation and management of network overlays is accomplished via a network orchestrator manager, allowing for automation of configuration of connected network devices throughout an entire organization's network, regardless of the physical location of each device.


