Virtual Private Cloud Access Across Operator Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for virtual private clouds (VPCs) to access networks fail when the data center and basic bearer network belong to different operators, as they require uniform management by a control system, which is not feasible in such scenarios.

Innovation Solution

A method involving a network side device and a data center device that exchange information to create a VPC, allocate PE interface addresses, VCE uplink and downlink port addresses, and configure access tunnels, enabling the VPC to access a VPN without the need for uniform control system management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a control system uniformly manages VPC and VPN creation at data center and network side, then VPC can access network, but the data center and basic bearer network must belong to same operator, reducing adaptability

Engineering Contradiction:
ImproveVPC network access reliabilityVSAvoidCross-operator network access adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the VPC access system into independent components: data center device, network side device, PE router, and VCE. Each segment operates autonomously with defined interfaces, eliminating the need for unified control system management across operator boundaries while maintaining reliable access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access tunnel as an intermediary mechanism between the VCE and PE router. This tunnel enables direct communication across operator networks without requiring uniform control system management, solving the cross-operator access problem while maintaining connection reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If control system uniformly manages VPC and VPN creation, then network access is enabled, but device resources are consumed by centralized control system

Engineering Contradiction:
ImproveVPC network access reliabilityVSAvoidDevice resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the control functionality from a centralized control system and distributes it to the data center device and network side device. Each device independently performs creation and configuration tasks, eliminating the resource overhead of a centralized control system while maintaining access reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The data center device and network side device perform self-configuration and mutual authentication without external control system intervention. The system enables itself through automated peer-to-peer setup, reducing device resource consumption while ensuring reliable access.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If PE interface address and VCE uplink port address are allocated from VPN configuration resource, then address management is simplified, but VPN configuration resource must be pre-provided by user

Engineering Contradiction:
ImproveAddress management easeVSAvoidVPN configuration resource setup complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The user provides VPN configuration resources in advance, which are then automatically utilized by the system during VPC creation. This preliminary provisioning simplifies ongoing address management while the initial setup complexity is handled once during configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2704372B1Method for virtual private cloud to access network, network side device and data centre device
Publication Date: 2017.09.06 HUAWEI TECH CO LTD
  • EP2704372B1 patent drawingFigure 1
  • EP2704372B1 patent drawingFigure 2
  • EP2704372B1 patent drawingFigure 3~4

AI summary

The present invention provides a method for a virtual private cloud to access a network, a network side device and a data center device. When receiving a VPC configuration resource provided by a user, the network side device and the data center device exchange information, create a VPC, determine a PE interface address, a VCE uplink port address, an access tunnel and a VCE downlink port address for the VPC, and perform a corresponding configuration operation, thereby enabling the VPC to access a VPN in a basic bearer network without the need of uniform management of a control system, so as to solve a problem that the VPC cannot access the network when the basic bearer network and a data center belong to different operators, and meanwhile, save a device resource.