Multitenant VPC Private Network Exchange for Secure Voice Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions do not provide secure and reliable network exchange capabilities for multitenant virtual private clouds, particularly for entities requiring secure data links or high-performance communication, as existing public internet connections are insecure and unsatisfactory.
Innovation Solution
A system comprising regional exchange systems with secure connection interfaces (VPN, Cross Connect, MPLS) and a multitenant platform in a virtual private cloud, enabling secure and reliable network exchanges by establishing physical collocated networking infrastructure and providing virtualized IP systems for secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If public internet connections are used for cloud-hosted computing resources, then accessibility and ease of connection are improved, but security and connection quality deteriorate
Solution Approach 1:
The system segments the network connection into two distinct paths: public internet access for general cloud-hosted computing resource accessibility, and private network exchange connections for secure data transmission. This segmentation allows entities to use public internet for non-sensitive communications while relying on dedicated private connections for sensitive data exchange, thereby maintaining both ease of connection and security.
Solution Approach 2:
The patent introduces a network exchange system as an intermediary between entities and cloud-hosted computing resources. This intermediary provides secure private connections that mediate the data transmission, allowing entities to access cloud resources while maintaining security through the intermediary's controlled network path rather than direct public internet exposure.
2Ease of operation
If public internet connections are used for cloud-hosted computing resources, then connection availability is improved, but connection quality and bandwidth reliability deteriorate
Solution Approach 1:
The system separates network traffic into public internet channels for general availability and private network exchange channels for quality-critical communications. This segmentation enables entities to maintain connection availability through public internet while ensuring connection quality for sensitive communications through dedicated private infrastructure with guaranteed bandwidth and uptime.
Solution Approach 2:
The patent changes the network connection parameters by providing dedicated private connections with controlled bandwidth, latency, and uptime characteristics. Unlike public internet connections with variable parameters, the private network exchange offers stable, predictable connection quality parameters while maintaining availability through the dual-path architecture.
3Reliability
If secure private network connections are established for each entity, then security and connection quality are improved, but system complexity and infrastructure requirements worsen
Solution Approach 1:
The network exchange system provides a universal infrastructure that serves multiple entities simultaneously with secure private connections. Rather than requiring each entity to build and maintain separate dedicated infrastructure, the universal network exchange provides multi-functional secure connectivity to multiple cloud-hosted computing resources and entities, reducing individual infrastructure complexity while maintaining security.
Solution Approach 2:
The patent merges multiple individual secure connection requirements into a single shared network exchange infrastructure. By combining the security functions, routing capabilities, and connection management into one unified system, the overall infrastructure complexity is reduced compared to maintaining separate secure connections for each entity, while still providing individualized security for each connection.
Data Source
AI summary
Systems and methods for routing real-time voice communication via a private network exchange. A virtual private cloud (VPC) system receives first configuration for a first private network exchange for a first account of the VPC system. The VPC system assigns a first regional exchange system to the first private network exchange based on the first configuration. The first private network exchange is established between the first regional exchange system and a first outside entity system of the first account by mapping an identifier of the first account to the first private network exchange. Real-time voice communication data for the first account is routed from a first real-time voice communication service of the VPC system to the first outside entity system via the first private network exchange based on the mapping.


