Communication Manager Overlay Network for Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing communications between virtual machines and physical computing systems in large-scale data centers is complex due to the increased scale and scope of data centers and computer networks.

Innovation Solution

The implementation of a Communication Manager module that creates an overlay network over intermediate physical networks, allowing for the embedding of virtual network address information within physical network addresses, thereby enabling transparent communication between computing nodes without encapsulating communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing machines among multiple users, then resource utilization efficiency is improved, but communication management complexity between virtual machines increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidcommunication management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a communication manager as an intermediary component that handles communication between virtual machines and the physical network. The communication manager translates virtual network addresses to physical network addresses and manages communication protocols, thereby simplifying the complexity faced by individual virtual machines while maintaining efficient resource utilization through virtualization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual network addresses are embedded within physical network addresses, then network isolation and security are improved, but address mapping complexity increases

Engineering Contradiction:
Improvenetwork isolation and securityVSAvoidaddress mapping complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nesting by embedding virtual network address information within physical network address structures. Specifically, virtual network identifiers are incorporated into the physical address format, allowing multiple virtual networks to be isolated and secured within the physical network infrastructure while maintaining a systematic address mapping approach

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If computing nodes are allowed to move and reconfigure dynamically, then network adaptability is improved, but communication stability decreases

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidcommunication stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements preliminary action by pre-configuring communication manager components and establishing address mapping frameworks before computing nodes move or reconfigure. The communication manager maintains persistent connection state information and pre-establishes translation rules, allowing computing nodes to move dynamically while communication stability is maintained through the pre-prepared mapping infrastructure

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12224895B2Proxy computing device for executing virtual network communication manager
Publication Date: 2025.02.11 AMAZON TECH INC
  • US12224895B2 patent drawing
  • US12224895B2 patent drawing
  • US12224895B2 patent drawing

AI summary

Techniques are described for managing communications between multiple computing nodes, such as computing nodes that are separated by one or more physical networks. In some situations, the techniques may be used to provide a virtual network between multiple computing nodes that are separated by one or more intermediate physical networks, such as from the edge of the one or more intermediate physical networks by modifying communications that enter and/or leave the intermediate physical networks. In some situations, the computing nodes may include virtual machine nodes hosted on one or more physical computing machines or systems, such as by or on behalf of one or more users (e.g., users of a program execution service). The managing of the communications may include determining whether communications sent to managed computing nodes are authorized, and providing the communications to the computing nodes only if they are determined to be authorized.