Host-Prefixed IPv6 Access for On-Demand Code Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional on-demand code execution systems face limitations in allowing direct external access to virtual computing components due to a lack of publicly-available IPv4 addresses and the need for TLS termination or destination port network address translation, which restricts port selection and communication security.
Innovation Solution
Assigning unique sets of publicly-available IPv6 addresses with a host computing device-specific prefix to virtual computing components, enabling direct communication without proxies or NAT, and using firewalls for security and separation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If TLS termination or destination port network address translation is used to enable external access to virtual computing components, then access is enabled, but port selection is restricted and communication security is compromised
Solution Approach 1:
The patent transitions from IPv4 address space to IPv6 address space, adding dimensional capacity to the network addressing system. This allows each virtual computing component to have its own publicly-accessible IPv6 address without requiring NAT or port translation, thereby restoring full port selection flexibility while maintaining security.
2Ease of operation
If TLS termination is used to enable external access to virtual computing components, then access is enabled, but communication security is compromised
Solution Approach 1:
By moving to IPv6 addressing, the system eliminates the need for TLS termination at the network level. Each virtual computing component can be directly addressed via its unique IPv6 address, allowing end-to-end encryption to be maintained throughout the communication path, thus preserving communication security while enabling external access.
3Productivity
If conventional on-demand code execution systems are used, then code execution is provided, but direct external access to virtual computing components is restricted
Solution Approach 1:
The adoption of IPv6 addresses provides an additional dimensional resource for network identification. Each virtual computing component can be assigned a unique publicly-accessible IPv6 address from a pool allocated to its host computing device, enabling direct external access without compromising the multi-tenant code execution capabilities of the on-demand system.
4Quantity of substance
If IPv4 address pools are used for virtual computing components, then addressing is available, but the number of available addresses is insufficient for direct access to each component
Solution Approach 1:
The patent leverages the expanded address space of IPv6, which provides 128-bit addresses compared to IPv4's 32-bit addresses. This dimensional expansion in address space capacity allows each virtual computing component to receive a unique publicly-accessible address, enabling direct external access without the address exhaustion problems inherent in IPv4.
Data Source
AI summary
Systems and methods are provided for assigning, to a host computing device of an on-demand code execution system comprising a plurality of host computing devices, a set of network addresses available for virtual computing components instantiated on the host computing device, wherein a prefix of each network address of the set of network addresses comprises a same host computing device-specific prefix, and wherein each network address of the set of network addresses is to be accessible from outside the on-demand code execution system; determining to configure a virtual computing component on the host computing device for execution of application code, wherein the virtual computing component is associated with an identifier; and assigning, to the virtual computing component, a network address of the set of network addresses, wherein the network address comprises the prefix and is based on the identifier.


