Host-Prefixed IPv6 Access for On-Demand Code Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional on-demand code execution systems face limitations in allowing direct external access to virtual computing components due to a lack of publicly-available IPv4 addresses and the need for TLS termination or destination port network address translation, which restricts port selection and communication security.

Innovation Solution

Assigning unique sets of publicly-available IPv6 addresses with a host computing device-specific prefix to virtual computing components, enabling direct communication without proxies or NAT, and using firewalls for security and separation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If TLS termination or destination port network address translation is used to enable external access to virtual computing components, then access is enabled, but port selection is restricted and communication security is compromised

Engineering Contradiction:
Improveexternal access capabilityVSAvoidport selection flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transitions from IPv4 address space to IPv6 address space, adding dimensional capacity to the network addressing system. This allows each virtual computing component to have its own publicly-accessible IPv6 address without requiring NAT or port translation, thereby restoring full port selection flexibility while maintaining security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If TLS termination is used to enable external access to virtual computing components, then access is enabled, but communication security is compromised

Engineering Contradiction:
Improveexternal access capabilityVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

By moving to IPv6 addressing, the system eliminates the need for TLS termination at the network level. Each virtual computing component can be directly addressed via its unique IPv6 address, allowing end-to-end encryption to be maintained throughout the communication path, thus preserving communication security while enabling external access.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If conventional on-demand code execution systems are used, then code execution is provided, but direct external access to virtual computing components is restricted

Engineering Contradiction:
Improvecode execution capabilityVSAvoiddirect external access
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The adoption of IPv6 addresses provides an additional dimensional resource for network identification. Each virtual computing component can be assigned a unique publicly-accessible IPv6 address from a pool allocated to its host computing device, enabling direct external access without compromising the multi-tenant code execution capabilities of the on-demand system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Quantity of substance

If IPv4 address pools are used for virtual computing components, then addressing is available, but the number of available addresses is insufficient for direct access to each component

Engineering Contradiction:
Improvenumber of available addressesVSAvoiddirect access capability
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent leverages the expanded address space of IPv6, which provides 128-bit addresses compared to IPv4's 32-bit addresses. This dimensional expansion in address space capacity allows each virtual computing component to receive a unique publicly-accessible address, enabling direct external access without the address exhaustion problems inherent in IPv4.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12417115B1On-demand code execution computing resource access management
Publication Date: 2025.09.16 AMAZON TECH INC
  • US12417115B1 patent drawing
  • US12417115B1 patent drawing
  • US12417115B1 patent drawing

AI summary

Systems and methods are provided for assigning, to a host computing device of an on-demand code execution system comprising a plurality of host computing devices, a set of network addresses available for virtual computing components instantiated on the host computing device, wherein a prefix of each network address of the set of network addresses comprises a same host computing device-specific prefix, and wherein each network address of the set of network addresses is to be accessible from outside the on-demand code execution system; determining to configure a virtual computing component on the host computing device for execution of application code, wherein the virtual computing component is associated with an identifier; and assigning, to the virtual computing component, a network address of the set of network addresses, wherein the network address comprises the prefix and is based on the identifier.