VPC Gateway Address Translation for Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual private cloud (VPC) networks, users face challenges in accessing basic services like Network Time Protocol (NTP) as cloud service providers cannot set unified IP addresses, leading to users needing to purchase public network addresses and bear associated costs.

Innovation Solution

A data transmission method that converts designated addresses outside the configured address range for a virtual private network into actual network addresses within the private network, allowing packets to be sent through a gateway for service access without relying on public networks, using address mapping tables and format conversion between VXLAN and VLAN packet formats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access basic services through designated public network addresses, then service accessibility is improved, but network costs and data traffic increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidnetwork costs
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent introduces a gateway as an intermediary device between the VPC network and basic services. The gateway performs address translation, converting designated addresses (e.g., 100.64.0.0/10) to actual service provider addresses. This mediator enables users to access services without directly using public network addresses, thus reducing network costs while maintaining accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the network address parameter by using a designated address range (100.64.0.0/10) that is separate from both public and private address spaces. This parameter change allows the system to distinguish between internal VPC addresses and addresses intended for basic services, enabling efficient routing and address translation through the gateway without requiring public network addresses.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If cloud service providers cannot set unified IP addresses in VPC, then address space autonomy is improved, but service provisioning capability deteriorates

Engineering Contradiction:
Improveaddress space autonomyVSAvoidservice provisioning capability
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The gateway acts as a mediator that reconciles the conflict between address space autonomy and service provisioning. It maintains the VPC's autonomous address space by not requiring unified IP addresses, while simultaneously enabling service provisioning through address translation. The gateway maps designated addresses to actual service addresses, allowing services to be provided without compromising VPC address independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the address space by introducing a designated address range (100.64.0.0/10) that is distinct from both public and private address spaces. This segmentation allows the VPC to maintain its autonomous address planning while the gateway can translate these segmented designated addresses to appropriate service addresses, thus enabling service provisioning without unified IP addresses.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11233766B2Data transmission method and network device
Publication Date: 2022.01.25 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US11233766B2 patent drawing
  • US11233766B2 patent drawing
  • US11233766B2 patent drawing

AI summary

Embodiments of the disclosure provide a data transmission method. The method can include receiving a first packet sent by a virtual private network user, wherein the first packet carries a first destination address that does not belong to an address range that has been configured for a virtual private network where the virtual private network user is located, converting the first destination address to a second destination address, generating a second packet according to the second destination address and the first packet, and sending the second packet outside the virtual private network where the virtual private network user is located.