Client-Defined Network Rules for Multi-Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large-scale data centers, managing and provisioning physical computing resources has become increasingly complex due to the scale and scope of operations, and existing technologies lack the ability for clients to define and enforce custom network rules for their resources, leading to potential security and performance issues.

Innovation Solution

Implementing client-defined rules within a provider network environment, allowing clients to configure and manage their resources using application programming interfaces (APIs) and services, enabling them to define and enforce custom security, access control, and routing rules for their virtual machines and networks, using modules or services that execute client-provided code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing resources among multiple clients, then resource utilization efficiency is improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the provider network into multiple isolated virtual networks, each serving a specific client. This segmentation allows resources to be shared within each virtual network while maintaining clear management boundaries, reducing the complexity of managing large-scale multi-tenant environments through modular, client-specific network segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network components (virtual routers, virtual firewalls, network virtualization layers) as intermediaries between physical infrastructure and client resources. These intermediaries abstract and simplify resource management operations, enabling efficient resource sharing while reducing the complexity of direct physical resource management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If standard provider network rules are applied to all clients, then system management is simplified, but client-specific security and performance needs cannot be met

Engineering Contradiction:
Improvesystem management simplicityVSAvoidclient-specific rule customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic, client-configurable network rules that can be customized per virtual network while maintaining a standardized underlying framework. Clients can dynamically adjust security policies, access controls, and routing rules to meet their specific needs, while the provider maintains simplified centralized management of the overall system through standardized interfaces and abstraction layers.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11269673B2Client-defined rules in provider network environments
Publication Date: 2022.03.08 AMAZON TECH INC
  • US11269673B2 patent drawing
  • US11269673B2 patent drawing
  • US11269673B2 patent drawing

AI summary

Methods and apparatus that allow clients to specify custom network rules for their resource instances or network constructs in a provider network environment. Services and interfaces may be provided that allow a client to provide an executable module that implements custom rules for their resources, or alternatively to specify or select custom rules for their resources. The module may be installed on a host device, and may apply the custom rules to packets to and from the client's resources. Alternatively, the client-defined rules may be applied to packet flows according to the custom rules specified by the client and applied by a client rules service implemented on the provider network external to the host device or on a client resource instance on the host device. The custom network rules may, for example, extend or modify standard network rules for the client's resources on the host device.