Virtual Private Internet Service Mediation Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current private networks face challenges in providing secure, agile, and extensible connectivity due to manual, ad-hoc network configurations and lack of centralized management for service provisioning and access, making it difficult to connect and integrate services across large corporations.

Innovation Solution

Implementing a virtual private internet with standardized service policies managed in a centralized repository, utilizing enhanced service DNS servers, routers, and gateways to perform tasks like security, content-based routing, logging, and protocol bridging, facilitated by a service mediation framework for standardized communication and service request handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual, ad-hoc network configurations are used in private networks, then security can be maintained through encryption, but connectivity agility and ease of service provisioning deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidconnectivity agility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network is segmented into virtual private internet domains with standardized service policies, allowing security to be enforced at the virtual layer while enabling flexible connectivity configurations without compromising security boundaries

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A service mediation framework acts as an intermediary layer between security policies and network connectivity, enabling automated service provisioning and agile configurations while maintaining security through standardized policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If point-to-point connections are customized for each service in a private network, then security is maintained, but service provisioning complexity and time increase

Engineering Contradiction:
ImprovesecurityVSAvoidservice provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Service policies and connectivity configurations are pre-standardized and stored in a centralized repository, allowing services to be provisioned by simple policy retrieval and application rather than manual configuration, dramatically reducing provisioning time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service mediation framework enables automated, self-service provisioning of network connections by retrieving standardized policies from the centralized repository and automatically configuring services, eliminating manual intervention while preserving security through standardized policy enforcement

Inventive Principle:
Principle #25Self-service

3Reliability

If tens of thousands of servers are hard-wired and hand-configured, then network security can be controlled, but network complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Standardized service policies provide universal configuration rules that apply across all servers and services in the private network, simplifying management by replacing individual hand-configurations with universal policy templates that maintain security while reducing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The service mediation framework serves as an intermediary that manages the complexity of tens of thousands of servers by enforcing standardized policies, allowing security control to be maintained through policy management rather than individual device configuration

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If manual network processes are implemented using conventional IT systems, then security capabilities can be procured and deployed, but deployment speed and extensibility decrease

Engineering Contradiction:
Improvesecurity capabilityVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The service mediation framework enables automated deployment of security capabilities by self-retreiving standardized policies from the centralized repository and automatically configuring services, eliminating manual processes and dramatically increasing deployment speed while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Standardized service policies parameterize security configurations, allowing security capabilities to be deployed by changing policy parameters rather than manual configuration, enabling fast, consistent, and extensible deployment across the private network

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8448237B2Virtual private internet
Publication Date: 2013.05.21 BANK OF AMERICA CORP
  • US8448237B2 patent drawing
  • US8448237B2 patent drawing
  • US8448237B2 patent drawing

AI summary

A virtual private internet may include various network components, including an enhanced service domain name server (DNS), an enhanced service router, and an enhanced service gateway, which all access service policy information stored in an enhanced service repository. The network components in the virtual private internet perform common service processing tasks for routing service requests across firewalls and other network boundaries. The network components also execute other service policies, such as logging, message format translation, and protocol bridging for each service request processed by the network. Updates to services may be implemented in the virtual private internet via changes to service policy information stored in the enhanced service repository.