Extension Resource Groups for Low-Latency Edge Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualized computing services face challenges in providing low-latency, secure, and scalable computing solutions for applications that require data processing at customer premises, as traditional data centers may not be optimal due to latency and security concerns.

Innovation Solution

The implementation of extension resource groups (ERGs) that allow virtual machines to be set up at customer-selected locations, using pre-configured hardware and software, with secure network connections to provider network data centers, enabling secure and low-latency data processing while maintaining security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual machines are hosted at provider network data centers, then security and service management are improved, but latency increases for applications requiring data processing at customer premises

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments virtual machine deployment into two parts: control plane resources remain at provider network data centers for security management, while data plane resources (extension resource groups) are deployed at customer premises. This segmentation allows security policies to be centrally managed while data processing occurs locally, reducing latency for time-sensitive applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary component that establishes secure network channels between provider network data centers and extension resource groups at customer premises. This intermediary enables encrypted communication and centralized control while allowing local data processing, thus maintaining security without sacrificing latency performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If extension resource groups are deployed at customer premises, then latency is reduced for local data processing, but network connectivity requirements increase

Engineering Contradiction:
ImprovelatencyVSAvoidnetwork connectivity requirements
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring extension resource groups with necessary hardware and software before deployment at customer premises. Secure network channels are established in advance, and virtual machine images are prepared beforehand, reducing the complexity of on-site configuration and network setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service capabilities where extension resource groups automatically manage their own deployment, configuration, and network connectivity. The virtualization layer abstracts network complexity, allowing resources to be provisioned and configured without manual intervention, thus reducing network connectivity requirements from the user perspective.

Inventive Principle:
Principle #25Self-service

3Device complexity

If virtualization resources are concentrated at provider data centers, then service management and security control are simplified, but scalability to customer locations is limited

Engineering Contradiction:
Improveservice managementVSAvoidscalability to customer locations
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system creates a universal platform where the same virtualization technology and management interfaces can be used both at provider network data centers and at customer premises extension resource groups. This multi-functionality allows centralized management of distributed resources, maintaining simplified service management while enabling broad scalability to various customer locations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from a single-location data center model to a multi-dimensional distributed architecture. Extension resource groups are deployed across multiple geographical dimensions (customer premises), while management control remains centralized. This dimensional change enables scalability without proportionally increasing management complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Speed

If hardware resources are distributed to customer premises, then data processing speed improves, but security risks increase

Engineering Contradiction:
Improvedata processing speedVSAvoidsecurity risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by deploying extension resource groups with specific security configurations tailored to customer premises requirements. Each distributed hardware resource maintains local data processing capabilities while implementing localized security measures, allowing fast data processing without compromising security through one-size-fits-all approaches.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements beforehand cushioning by pre-configuring security measures, encrypted network channels, and access control policies before deploying hardware resources at customer premises. Virtual machine images are pre-hardened with security configurations, and secure communication protocols are established in advance, cushioning against potential security risks before they can manifest.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11469964B2Extension resource groups of provider network services
Publication Date: 2022.10.11 AMAZON TECH INC
  • US11469964B2 patent drawing
  • US11469964B2 patent drawing
  • US11469964B2 patent drawing

AI summary

At a network manager of an extension resource group of a provider network, a message comprising a command to launch a compute instance is received at an address which is part of a first network configured at a premise external to the provider network. The extension resource group includes a first host at the external premise. Within a second network configured at the external premise, the first host is assigned an address within a second address range. Addresses within the second range are also assigned to hosts within the provider network. The command is transmitted to the first host, and a compute instance is instantiated.