Distributed Transit Gateway for Policy-Based Cross-VPC Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing transit gateways for virtual private clouds (VPCs) require centralized equipment, leading to increased deployment costs and performance bottlenecks, limiting flexibility and scalability.
Innovation Solution
A distributed transit gateway implementation that utilizes a policy manager and policy propagator to manage cross-VPC connectivity, eliminating the need for centralized equipment by using software components to enforce network isolation and packet forwarding policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized transit gateway equipment is used to manage cross-VPC connectivity, then network isolation and packet forwarding can be enforced, but deployment costs increase and performance bottlenecks occur
Solution Approach 1:
The patent segments the centralized transit gateway functionality into distributed components deployed across multiple network nodes. Each node runs software components (policy propagator, topology manager, packet forwarder) that collectively provide transit gateway services, eliminating the need for a single centralized device and distributing the processing load across the network infrastructure.
Solution Approach 2:
The patent creates universal software components that can be deployed on standard network nodes to perform multiple functions: policy propagation, topology information management, and packet forwarding. These multi-functional software modules replace specialized centralized hardware, allowing existing infrastructure to serve multiple purposes and reducing overall system complexity.
2Adaptability or versatility
If centralized transit gateway equipment is deployed to enforce network policies, then cross-VPC connectivity can be managed, but deployment costs increase
Solution Approach 1:
The patent uses software copies of the transit gateway functionality deployed across multiple nodes instead of expensive proprietary hardware. The policy propagator and topology manager software can be replicated across standard servers, eliminating the need for costly centralized equipment while maintaining the same cross-VPC connectivity management capabilities.
Solution Approach 2:
The patent replaces the mechanical/physical centralized transit gateway device with a software-based distributed system. The physical hardware requirement is substituted with virtualized software components running on standard network infrastructure, significantly reducing deployment costs while maintaining or improving functionality.
3Reliability
If centralized equipment is used for packet forwarding, then policy enforcement is achieved, but throughput bottlenecks occur
Solution Approach 1:
The patent segments the packet forwarding function into distributed packet forwarder components running on multiple network nodes. Instead of all packets passing through a single centralized device, forwarding is distributed across the network, allowing parallel processing and eliminating the throughput bottleneck while maintaining policy enforcement through the distributed architecture.
Solution Approach 2:
The patent enables network nodes to perform packet forwarding locally through distributed software components rather than requiring centralized processing. Each node with the packet forwarder software can independently forward packets according to topology information, allowing the network to serve itself and eliminating the single point of congestion.
Data Source
AI summary
Provided are a method, system, and computer program product in which a cross virtual private cloud (VPC) network connectivity is configured, wherein one or more policies have been defined by entities in the VPC. Policy changes are monitored, and based on the one or more policies, an adding of endpoints or topology information from a source VPC to a target VPC is performed, in response to a policy definition allowing the adding of the endpoints. Operations are performed for removing external endpoints or topology information from an affected VPC, in response to receiving a denial indication.


