Intermediate Destination Nodes for Managed Network Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of large-scale computer networks has become increasingly complex due to the scale and scope of data centers and the need for efficient provisioning, administration, and management of physical computing resources, especially with the integration of virtualization technologies.

Innovation Solution

The implementation of a system that manages communications within a managed computer network by using intermediate destination computing nodes to handle communications, which includes configuring and selecting intermediate nodes based on criteria such as source and destination nodes, network addresses, and quality of service, and providing functionalities like firewall, NAT, and intrusion detection, through a network-accessible configurable service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing resources among multiple customers, then resource utilization efficiency is improved, but network security and isolation between customers may be compromised

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a network controller as an intermediary device that manages and controls network traffic between virtual machines from different customers. The network controller implements policy-based routing, firewall rules, and access control lists to ensure proper isolation while allowing legitimate communication, thus maintaining security in the multi-tenant virtualized environment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into virtual network segments or VLANs that logically separate traffic from different customers or departments. This segmentation allows multiple customers to share the same physical infrastructure while maintaining logical isolation, enabling both high resource utilization and network security

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If the scale and scope of data centers increase to accommodate more customers and resources, then service capacity is improved, but management complexity increases

Engineering Contradiction:
Improveservice capacityVSAvoidmanagement complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements a universal network controller that provides multiple management functions including traffic routing, security policy enforcement, quality of service management, and monitoring across the entire data center network. This single multi-functional controller replaces numerous specialized devices, simplifying management while supporting large-scale operations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network controller implements continuous monitoring and feedback mechanisms that automatically adjust network policies, detect anomalies, and optimize traffic flow based on real-time conditions. This automated feedback loop reduces manual intervention and simplifies management of large-scale data centers

Inventive Principle:
Principle #23Feedback

3Reliability

If intermediate destination computing nodes are used to handle communications, then network control and security are improved, but communication overhead and latency increase

Engineering Contradiction:
Improvenetwork controlVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network controller pre-configures routing tables, firewall rules, and quality of service policies before communications occur. By preparing these control mechanisms in advance, the system can enforce network policies without adding significant processing delays during actual data transmission

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic routing and policy adjustment capabilities that adapt network paths and control parameters in real-time based on traffic conditions. This allows the system to optimize communication paths dynamically, reducing latency while maintaining control through the intermediate nodes

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9794116B2Managing use of intermediate destination computing nodes for provided computer networks
Publication Date: 2017.10.17 AMAZON TECH INC
  • US9794116B2 patent drawing
  • US9794116B2 patent drawing
  • US9794116B2 patent drawing

AI summary

Techniques are described for providing managed computer networks. In some situations, the techniques include managing communications for computing nodes of a managed computer network by using one or more particular computing nodes of the managed computer network that are configured to operate as intermediate destinations to handle at least some communications that are sent by and/or directed to one or more other computing nodes of the managed computer network. For example, a manager module associated with a source computing node may select one or more particular intermediate destination computing nodes to use for one or more particular communications from the source computing node to an indicated final destination, such as based on a configured logical network topology for the managed computer network. The manager module then forwards those communications to a first of the selected intermediate destination computing nodes for further handling.