Appliance Backnet for Vendor Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, customers face challenges in managing dedicated network spaces, where appliance services require specific communication with vendors or other instances, leading to issues like unintended billing and operational decoupling, as existing technologies lack efficient mechanisms for isolating and managing traffic within dedicated customer clouds.

Innovation Solution

The implementation of a 'backnet' – a dedicated, vendor-owned sub-network within the customer cloud, utilizing separate virtual network interfaces for customer and vendor communication, allowing for explicit control and separation of traffic types, enabling appliance vendors to manage and bill for their own bandwidth usage while maintaining customer isolation and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a customer uses a dedicated customer network space to isolate from other users, then network isolation and security are improved, but appliance services cannot communicate with vendors outside the dedicated space and billing control becomes difficult

Engineering Contradiction:
Improvenetwork isolationVSAvoidappliance communication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the network communication into two distinct segments: a customer-facing network interface for customer traffic and a vendor-facing network interface for appliance-vendor communication. This segmentation allows the customer network space to remain isolated and secure while enabling appliances to communicate with vendors through a separate, dedicated channel that bypasses customer network restrictions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network appliance as an intermediary component that resides within the customer network space but maintains separate communication paths. The appliance acts as a mediator between customer traffic and vendor traffic, allowing vendor communication to occur through controlled interfaces without compromising the isolation of the customer network space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If appliance services communicate with vendors outside the customer cloud, then operational functionality is maintained, but customers are incorrectly billed for vendor-related bandwidth usage

Engineering Contradiction:
Improveappliance functionalityVSAvoidbilling accuracy
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent segments network traffic into customer-initiated traffic and vendor-initiated traffic through separate network interfaces and communication paths. Vendor-related bandwidth usage is isolated in a distinct communication channel that is excluded from customer billing metrics, allowing accurate differentiation between billable and non-billable traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements monitoring and control mechanisms that track bandwidth usage by source and destination. The system provides feedback to the billing system to identify and exclude vendor-related traffic from customer billing calculations, ensuring that customers are only charged for their own network consumption.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If customers control all traffic in their dedicated network space, then network autonomy is improved, but appliance operations are restricted by customer traffic restrictions

Engineering Contradiction:
Improvenetwork controlVSAvoidappliance operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates separate network control domains: one where the customer has full control over customer-facing traffic, and another where the vendor has control over appliance-vendor communication. This segmentation allows both customer autonomy and appliance functionality to coexist without conflict.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different control characteristics to different parts of the network infrastructure. Customer network space maintains strict customer control for customer traffic, while appliance network spaces have configured access to vendor interfaces. Each network segment has tailored control properties appropriate to its function.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9614737B1Appliance backnets in dedicated resource environment
Publication Date: 2017.04.04 AMAZON TECH INC
  • US9614737B1 patent drawing
  • US9614737B1 patent drawing
  • US9614737B1 patent drawing

AI summary

A backnet can be created within a dedicated private network of a customer that enables a distinct party to access and/or control a portion of the resources within the private network. In one example, a backnet includes a separate virtual interface for an appliance or other such resource that is not visible or accessible to the customer owning the customer cloud, but can be accessed by another appliance or component in the customer cloud, or an appliance vendor external to the customer cloud. While the customer can control the permission for the backnet, the vendor can control or implement the resources within the backnet in a way that is isolated from the customer. Usage of the backnet can be separately monitored and billed to the vendor, even though the resources are part of the dedicated customer cloud.