Appliance Service Front-End Nodes for Subnet Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and provisioning physical computing resources in large-scale data centers has become increasingly complex due to the scale and scope of operations, and customers may interfere with or block access needed for monitoring and management of appliance services in virtualized private networks, leading to challenges in resource management and billing.

Innovation Solution

Implementing appliance services with separate interfaces for customer-side access and management purposes, where backend nodes are provisioned in a service provider's subnet instead of the customer's subnet, allowing for independent monitoring and management without interfering with customer traffic, and using multiple interfaces to manage and monitor resources effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If backend nodes are provisioned in the customer's subnet, then customer control and access are improved, but management and monitoring are interfered with or blocked by customer traffic

Engineering Contradiction:
Improvecustomer control and accessVSAvoidmanagement and monitoring access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network into two distinct subnets: a customer subnet for data traffic and a service provider subnet for management traffic. The appliance service is divided into front-end nodes in the customer subnet and backend nodes in the service provider subnet, allowing independent management access without customer interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service provider subnet acts as an intermediary between the customer's data plane and the management plane. Management traffic is routed through this intermediate subnet, which is controlled by the service provider, thereby mediating access to backend nodes without exposing them directly to customer traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate interfaces are implemented for customer-side access and management purposes, then management monitoring is improved, but device complexity increases

Engineering Contradiction:
Improvemanagement monitoringVSAvoidinterface configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The front-end nodes are designed with multi-functionality, serving both as customer-facing access points and as management interfaces. These nodes operate in the customer subnet for data traffic while also providing the service provider with management access, thereby consolidating multiple functions into a single component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a network dimension by creating a separate service provider subnet for management traffic, rather than adding multiple interfaces to existing nodes. This dimensional separation allows management and data traffic to coexist without increasing the complexity of individual device configurations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If backend nodes are provisioned in service provider's subnet, then management and monitoring are improved, but customer network configuration complexity increases

Engineering Contradiction:
Improvemanagement and monitoringVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated provisioning and configuration mechanisms. The service provider can automatically provision backend nodes in their subnet and configure the necessary routing and networking, eliminating the need for customer intervention in complex network configuration tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The service provider acts as an intermediary that abstracts away the complexity of having backend nodes in a separate subnet. The service provider manages the networking, routing, and connectivity between the customer subnet and service provider subnet, shielding customers from the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If management and data traffic are separated, then operational efficiency is improved, but network infrastructure complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidnetwork infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network infrastructure is segmented into distinct subnets for data traffic and management traffic. This segmentation is achieved through logical network division rather than physical duplication, maintaining infrastructure efficiency while enabling separate management of data and management planes.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9319272B1Methods and apparatus for providing composed appliance services in virtualized private networks
Publication Date: 2016.04.19 AMAZON TECH INC
  • US9319272B1 patent drawing
  • US9319272B1 patent drawing
  • US9319272B1 patent drawing

AI summary

Methods and apparatus that enable appliance service instances to be provisioned in a subnet of a customer's private network on a service provider network without provisioning the backend nodes in the customer's subnet. At least one front-end node instance is provisioned in the customer's subnet. Instead of provisioning the backend nodes in the customer's subnet, the appliance service provider provisions the backend node instances in the appliance service provider's subnet. In addition, at least the front-end node instance may be provided with multiple interfaces. At least two of the interfaces face different subnets, with one facing the customer subnet and the other facing the backend subnet operated by the appliance service provider in which the backend node instances are implemented. In some implementations, a third interface may face a management subnet so that the owner of the front-end node instance may manage the instance.