VXLAN Tunneling for Private Network to VPC Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for connecting a private network to a Virtual Private Cloud (VPC) face limitations such as inability to support layer 2 applications, unbalanced traffic load, and high costs due to the need for multiple gateways, as well as security and performance issues when using public internet connections.

Innovation Solution

The implementation of Virtual Extensible Local Area Network (VXLAN) tunneling technology for secure and scalable network traffic transmission from a cloud data center's edge router to gateway hardware, allowing for efficient layer 2 traffic handling and load balancing across multiple gateway servers, enabling secure and cost-effective access to VPCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional methods are used to connect private network to VPC, then connection is established, but layer 2 applications cannot be supported and traffic load is unbalanced

Engineering Contradiction:
Improvelayer 2 application supportVSAvoidtraffic load balance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a gateway virtual machine as an intermediary component between the private network and VPC. This gateway VM implements VXLAN tunneling to establish layer 2 connectivity while distributing traffic across multiple physical gateways, thereby supporting layer 2 applications and balancing traffic load simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the network tunneling parameter from conventional methods to VXLAN (Virtual Extensible LAN) tunneling. This parameter change enables layer 2 application support and provides mechanisms for load balancing across multiple gateways, resolving both the adaptability and reliability issues.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If multiple gateways are deployed to support multiple users, then connection capacity increases, but system complexity and cost increase

Engineering Contradiction:
Improveconnection capacityVSAvoidgateway quantity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The gateway virtual machine is designed with multi-functionality, serving multiple users and VPCs simultaneously through VXLAN tunneling. A single physical gateway can host multiple gateway VMs, each handling different user connections, thereby increasing connection capacity without proportionally increasing physical gateway quantity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of deploying separate physical gateways for each user, the patent creates virtual copies (gateway VMs) of the gateway function on shared physical hardware. This virtualization approach increases connection capacity while reducing overall system complexity and cost.

Inventive Principle:
Principle #26Copying

3Ease of operation

If public internet connection is used, then accessibility is improved, but security and performance deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity and performance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces encrypted VXLAN tunnels as an intermediary communication channel between the private network and VPC. This tunneling mechanism provides secure and high-performance connectivity while maintaining accessibility, effectively replacing vulnerable public internet connections with dedicated encrypted pathways.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10367655B2Network system and method for connecting a private network with a virtual private network
Publication Date: 2019.07.30 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10367655B2 patent drawing
  • US10367655B2 patent drawing
  • US10367655B2 patent drawing

AI summary

A networking method including receiving, at an edge router of a cloud data center, a virtual private cloud (“VPC”) network communication from a private network via a dedicated physical connection line to the edge router. The VPC network communication is forwarded to a gateway hardware group via a first connection using Virtual Extensible Local Area Network (“VXLAN”) technology. The VPC network communication is then forwarded from the gateway hardware group to VPC of a user of the private network via a second connection using VXLAN technology to access a virtual machine (“VM”).