Configurable Network Service for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and securing remote access to private computer networks across diverse geographical locations is complex due to the need for efficient and secure connectivity, especially in large-scale data centers with multiple users and resources, where existing solutions often fall short in providing scalable and secure virtualization technologies.

Innovation Solution

A configurable network service that allows users to create and configure private computer networks using APIs and GUIs, enabling secure remote access through VPN connections and other secure mechanisms, with the service managing computing nodes and network topology dynamically, and providing virtual resources across physical resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing resources among multiple users, then resource efficiency and security are improved, but network complexity and management difficulty increase

Engineering Contradiction:
Improveresource efficiencyVSAvoidnetwork complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the physical computing resources into separate virtual machines, each isolated and manageable as a distinct logical unit. This allows multiple users to access different virtual instances simultaneously without interfering with each other, improving resource efficiency while maintaining manageable complexity through virtualization layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between physical hardware and users. This intermediary manages the mapping between physical resources and virtual requests, handling complexity internally while presenting simplified interfaces to users, thus improving productivity without proportionally increasing user-facing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If remote access is enabled for users across multiple geographical locations, then accessibility and versatility are improved, but security risks and network management complexity increase

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates virtual copies of computing resources that can be accessed from any geographical location. Users interact with replicated virtual instances rather than direct connections to physical hardware, enabling remote accessibility while isolating security risks within the virtualization layer. The virtual machines can be copied and deployed across different locations without exposing underlying infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts security management functions from the network infrastructure and embeds them within the virtualization layer. Security policies are applied at the virtual machine level rather than at network boundaries, allowing remote access while concentrating security controls in a manageable manner. This extraction separates accessibility functionality from security complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If dynamic configuration of network resources is implemented, then flexibility and ease of operation are improved, but system complexity and resource management difficulty increase

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements dynamic configuration capabilities where virtual machines can be created, modified, and deleted on demand without affecting physical infrastructure. Resources can be dynamically allocated and reassigned based on user needs, improving flexibility and ease of operation. The virtualization layer absorbs the complexity of dynamic reconfiguration, presenting simple APIs to users while managing system complexity internally.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9756018B2Establishing secure remote access to private computer networks
Publication Date: 2017.09.05 AMAZON TECH INC
  • US9756018B2 patent drawing
  • US9756018B2 patent drawing
  • US9756018B2 patent drawing

AI summary

Techniques are described for providing users with access to computer networks, such as to enable users to interact with a remote configurable network service to create and configure computer networks that are provided by the configurable network service for use by the users. Secure private access between a computer network provided for a user by the configurable network service and one or more other remote computing systems of the user (e.g., a remote private network) may be enabled in various ways. For example, a user may programmatically invoke an API provided by the configurable network service to obtain assistance in establishing remote access from a remote location to a provided computer network of the configurable network service, such as to establish a VPN connection from the remote location to the provided computer network using hardware and/or software supplied to the remote location in response to the API invocation.