Conditional Flow Policy Rules for Packet Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems lack the flexibility to allow clients to specify complete paths that packets should follow through network appliances between endpoints at the flow level, limiting their ability to control network traffic effectively in virtual networks.

Innovation Solution

The implementation of a flow policy service that enables clients to define flow policies specifying the network appliances that inbound, outbound, and internal virtual network traffic should flow through, using rules that can be applied at various devices within the provider network, including virtual machines and physical devices, to route packets based on packet headers and metadata.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If current network management systems are used, then basic network connectivity is maintained, but clients cannot specify complete paths that packets should follow through network appliances at the flow level

Engineering Contradiction:
Improvepacket flow control flexibilityVSAvoidnetwork management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic control into flow-level units, where each flow policy rule independently specifies the complete path for packets matching particular criteria. This segmentation enables fine-grained control over packet routes through network appliances without requiring complete redesign of the network management system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces flow policy rules as intermediary elements between network traffic and network appliances. These rules act as mediators that intercept packets, evaluate them against defined criteria, and direct them along specified paths through one or more network appliances, thereby enabling flexible flow control without modifying the fundamental network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If flow policy rules are implemented to control packet paths, then network traffic management precision is improved, but system complexity increases

Engineering Contradiction:
Improvepacket flow control precisionVSAvoidflow policy service complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by allowing different flow policy rules to be applied to different packet flows based on their specific characteristics. Each rule can specify unique path requirements, network appliances, and evaluation criteria tailored to particular traffic types, enabling precise control without requiring uniform complexity across all network traffic management.

Inventive Principle:
Principle #3Local quality

3Reliability

If clients specify complete packet paths through network appliances, then network security and efficiency are improved, but ease of operation decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidflow policy configuration difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing clients to independently define and configure flow policy rules for their own network traffic. Clients can specify their desired packet paths, select appropriate network appliances, and establish evaluation criteria without requiring complex manual configuration or deep technical expertise, thereby improving ease of operation while maintaining security and efficiency.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10862709B1Conditional flow policy rules for packet flows in provider network environments
Publication Date: 2020.12.08 AMAZON TECH INC
  • US10862709B1 patent drawing
  • US10862709B1 patent drawing
  • US10862709B1 patent drawing

AI summary

A flow policy service that allows clients to define policies for packet flows to, from, and within their virtual networks on a provider network. Logic may be embedded in a flow policy that dictates what happens to a packet as it enters the network, or after the packet leaves an appliance. Via the service, a client may define conditional rules that specify different paths that packets should follow on the provider network according to conditional evaluations of information about the packets, for example source and/or destination endpoints of the packets, or output codes from appliances that process the packets.