Virtual Private Internet Service Mediation Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current private networks face challenges in providing secure, agile, and extensible connectivity due to manual, ad-hoc network configurations and lack of centralized management for service provisioning and access, making it difficult to connect and integrate services across large corporations.
Innovation Solution
Implementing a virtual private internet with standardized service policies managed in a centralized repository, utilizing enhanced service DNS servers, routers, and gateways to perform tasks like security, content-based routing, logging, and protocol bridging, facilitated by a service mediation framework for standardized communication and service request handling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual, ad-hoc network configurations are used in private networks, then security can be maintained through encryption, but connectivity agility and ease of service provisioning deteriorate
Solution Approach 1:
The network is segmented into virtual private internet domains with standardized service policies, allowing security to be enforced at the virtual layer while enabling flexible connectivity configurations without compromising security boundaries
Solution Approach 2:
A service mediation framework acts as an intermediary layer between security policies and network connectivity, enabling automated service provisioning and agile configurations while maintaining security through standardized policy enforcement
2Reliability
If point-to-point connections are customized for each service in a private network, then security is maintained, but service provisioning complexity and time increase
Solution Approach 1:
Service policies and connectivity configurations are pre-standardized and stored in a centralized repository, allowing services to be provisioned by simple policy retrieval and application rather than manual configuration, dramatically reducing provisioning time while maintaining security
Solution Approach 2:
The service mediation framework enables automated, self-service provisioning of network connections by retrieving standardized policies from the centralized repository and automatically configuring services, eliminating manual intervention while preserving security through standardized policy enforcement
3Reliability
If tens of thousands of servers are hard-wired and hand-configured, then network security can be controlled, but network complexity and integration difficulty increase
Solution Approach 1:
Standardized service policies provide universal configuration rules that apply across all servers and services in the private network, simplifying management by replacing individual hand-configurations with universal policy templates that maintain security while reducing complexity
Solution Approach 2:
The service mediation framework serves as an intermediary that manages the complexity of tens of thousands of servers by enforcing standardized policies, allowing security control to be maintained through policy management rather than individual device configuration
4Reliability
If manual network processes are implemented using conventional IT systems, then security capabilities can be procured and deployed, but deployment speed and extensibility decrease
Solution Approach 1:
The service mediation framework enables automated deployment of security capabilities by self-retreiving standardized policies from the centralized repository and automatically configuring services, eliminating manual processes and dramatically increasing deployment speed while maintaining security
Solution Approach 2:
Standardized service policies parameterize security configurations, allowing security capabilities to be deployed by changing policy parameters rather than manual configuration, enabling fast, consistent, and extensible deployment across the private network
Data Source
AI summary
A virtual private internet may include various network components, including an enhanced service domain name server (DNS), an enhanced service router, and an enhanced service gateway, which all access service policy information stored in an enhanced service repository. The network components in the virtual private internet perform common service processing tasks for routing service requests across firewalls and other network boundaries. The network components also execute other service policies, such as logging, message format translation, and protocol bridging for each service request processed by the network. Updates to services may be implemented in the virtual private internet via changes to service policy information stored in the enhanced service repository.


