Multitenant VPC Private Network Exchange for Secure Voice Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions do not provide secure and reliable network exchange capabilities for multitenant virtual private clouds, particularly for entities requiring secure data links or high-performance communication, as existing public internet connections are insecure and unsatisfactory.

Innovation Solution

A system comprising regional exchange systems with secure connection interfaces (VPN, Cross Connect, MPLS) and a multitenant platform in a virtual private cloud, enabling secure and reliable network exchanges by establishing physical collocated networking infrastructure and providing virtualized IP systems for secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public internet connections are used for cloud-hosted computing resources, then accessibility and ease of connection are improved, but security and connection quality deteriorate

Engineering Contradiction:
Improveease of connectionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the network connection into two distinct paths: public internet access for general cloud-hosted computing resource accessibility, and private network exchange connections for secure data transmission. This segmentation allows entities to use public internet for non-sensitive communications while relying on dedicated private connections for sensitive data exchange, thereby maintaining both ease of connection and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network exchange system as an intermediary between entities and cloud-hosted computing resources. This intermediary provides secure private connections that mediate the data transmission, allowing entities to access cloud resources while maintaining security through the intermediary's controlled network path rather than direct public internet exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If public internet connections are used for cloud-hosted computing resources, then connection availability is improved, but connection quality and bandwidth reliability deteriorate

Engineering Contradiction:
Improveconnection availabilityVSAvoidconnection quality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates network traffic into public internet channels for general availability and private network exchange channels for quality-critical communications. This segmentation enables entities to maintain connection availability through public internet while ensuring connection quality for sensitive communications through dedicated private infrastructure with guaranteed bandwidth and uptime.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the network connection parameters by providing dedicated private connections with controlled bandwidth, latency, and uptime characteristics. Unlike public internet connections with variable parameters, the private network exchange offers stable, predictable connection quality parameters while maintaining availability through the dual-path architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure private network connections are established for each entity, then security and connection quality are improved, but system complexity and infrastructure requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network exchange system provides a universal infrastructure that serves multiple entities simultaneously with secure private connections. Rather than requiring each entity to build and maintain separate dedicated infrastructure, the universal network exchange provides multi-functional secure connectivity to multiple cloud-hosted computing resources and entities, reducing individual infrastructure complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple individual secure connection requirements into a single shared network exchange infrastructure. By combining the security functions, routing capabilities, and connection management into one unified system, the overall infrastructure complexity is reduced compared to maintaining separate secure connections for each entity, while still providing individualized security for each connection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11171865B2Systems and methods for providing secure network exchanged for a multitenant virtual private cloud
Publication Date: 2021.11.09 TWILIO INC
  • US11171865B2 patent drawing
  • US11171865B2 patent drawing
  • US11171865B2 patent drawing

AI summary

Systems and methods for routing real-time voice communication via a private network exchange. A virtual private cloud (VPC) system receives first configuration for a first private network exchange for a first account of the VPC system. The VPC system assigns a first regional exchange system to the first private network exchange based on the first configuration. The first private network exchange is established between the first regional exchange system and a first outside entity system of the first account by mapping an identifier of the first account to the first private network exchange. Real-time voice communication data for the first account is routed from a first real-time voice communication service of the VPC system to the first outside entity system via the first private network exchange based on the mapping.