Isolated Cell Packet Processing Service for Scalable Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large provider networks face scalability issues with ad-hoc solutions for network packet transformation, leading to inefficiencies in managing traffic between hundreds of thousands of virtual or physical machines, particularly in implementing customized policy-based packet processing for virtualization-based services.

Innovation Solution

A multi-layer packet processing service utilizing isolated cells with control plane and data plane resources, where each cell comprises action implementation nodes, decision master nodes, and administration nodes, enabling customized packet processing and isolation to manage traffic efficiently across virtualized computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ad-hoc solutions for packet transformation are used, then customized packet processing can be implemented, but scalability deteriorates in large provider networks with hundreds of thousands of virtual or physical machines

Engineering Contradiction:
Improvecustomized packet processingVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments packet processing into isolated cells, each handling specific traffic workloads. This segmentation enables customized packet processing for different applications while maintaining scalability by allowing cells to be independently scaled or replaced without affecting the entire network infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs copying by instantiating multiple identical or similar cells that can be replicated across the network. These cells can be copied and distributed to handle different traffic streams, enabling scalable customized processing without requiring unique complex infrastructure for each application.

Inventive Principle:
Principle #26Copying

2Productivity

If resources are shared among multiple customers, then hardware utilization increases, but security and isolation between customers deteriorates

Engineering Contradiction:
Improvehardware utilizationVSAvoidsecurity and isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system divides the shared hardware resources into logically isolated cells, each dedicated to specific customers or applications. This segmentation allows multiple customers to share physical hardware while maintaining strict logical isolation and security boundaries between them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested virtualization where virtual machines are hosted within isolated cells that run on shared physical hardware. This nesting structure enables multiple layers of isolation and virtualization, allowing secure multi-tenancy while maximizing hardware utilization through efficient resource sharing.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Productivity

If more virtual machines are instantiated on the same host, then hardware utilization increases, but system complexity and failure impact deteriorates

Engineering Contradiction:
Improvehardware utilizationVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the host into isolated cells that encapsulate virtual machine workloads. This segmentation simplifies system management by creating clear boundaries between different virtual machine instances, making it easier to monitor, maintain, and isolate failures even as the number of virtual machines increases.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If customized policy-based packet processing is implemented for specific traffic, then application requirements are met, but processing overhead and CPU efficiency deteriorates

Engineering Contradiction:
Improvepolicy-based packet processingVSAvoidCPU efficiency
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-configuring cells with customized packet processing policies and forwarding information bases before traffic needs to be processed. This allows traffic to be handled efficiently using pre-established rules rather than requiring complex real-time decision-making, improving CPU efficiency while maintaining customized processing capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10785146B2Scalable cell-based packet processing service using client-provided decision metadata
Publication Date: 2020.09.22 AMAZON TECH INC
  • US10785146B2 patent drawing
  • US10785146B2 patent drawing
  • US10785146B2 patent drawing

AI summary

An isolated packet processing cell of a packet processing service, comprising an action implementation node and a decision master node, is assigned to an application. An indication of processing rules of the application is transmitted to the decision master node. In response to receiving a particular packet, the action implementation node obtains a representation of an action (which is based on the processing rules) from the decision master node and executes the action.