Edge Modules for Virtual Network Communication Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large-scale computer networks has become increasingly complex due to the scale and scope of data centers, with existing technologies struggling to efficiently provision, administer, and manage physical computing resources across diverse geographical locations and virtual environments.

Innovation Solution

A system for managing communications in a managed virtual computer network that overlays a substrate network, using configurable network services, edge modules, and communication manager modules to integrate and manage computing nodes and external nodes, enabling efficient communication and resource sharing across diverse locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing resources among multiple customers, then resource utilization efficiency is improved, but network management complexity increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a network virtualization layer as an intermediary between physical computing resources and multiple customers. This virtualization layer abstracts and manages the complexity of physical resource sharing, enabling efficient multi-tenant resource utilization while isolating management complexity within the virtualization infrastructure rather than propagating it to end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network management function into distinct virtualized components that can be independently managed and allocated to different customers. By dividing the monolithic network management task into modular virtual network instances, the system achieves efficient resource sharing while containing management complexity within manageable segments.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If external nodes are integrated into the managed virtual computer network, then network versatility and connectivity are improved, but network security and isolation are compromised

Engineering Contradiction:
Improvenetwork versatilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a nested virtualization architecture where external nodes are integrated through multiple layers of virtualization. External nodes are encapsulated within virtual network boundaries that are themselves nested within the managed virtual computer network, allowing versatile connectivity while maintaining security isolation through the nested virtualization layers.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent applies different security and isolation characteristics to different parts of the network based on their function and sensitivity. External nodes receive appropriate levels of access and isolation tailored to their specific requirements, allowing the network to achieve overall versatility while maintaining localized security controls where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9491002B1Managing communications involving external nodes of provided computer networks
Publication Date: 2016.11.08 AMAZON TECH INC
  • US9491002B1 patent drawing
  • US9491002B1 patent drawing
  • US9491002B1 patent drawing

AI summary

Techniques are described for managing communications for a managed virtual computer network overlaid on a distinct substrate computer network, including for communications involving computing nodes of the managed virtual computer network connected to the substrate network and/or other external nodes of the managed virtual computer network that are not connected to the substrate network. The managed virtual computer network may have multiple associated virtual network addresses, and the managing of the communications may further include using one or more edge modules to direct all communication that have a destination virtual network address within a range or other group of multiple virtual network addresses assigned to one or more external nodes to be forwarded over the substrate network to an edge module associated with the one or more external nodes, including to route communications between different external nodes via the substrate network.