Managed Appliance Gateway Service for Redundant Network Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network appliances in data centers lack scalability, security, and fault tolerance, leading to potential errors, data exfiltration, and single points of failure, which complicates traffic management and security across multiple tenants.

Innovation Solution

A managed appliance gateway service that provides elastic scalability, automatic traffic rerouting, graceful failover, and secure traffic steering, utilizing a stateful network routing service to manage and route traffic transparently across virtualized environments, reducing the need for extensive routing rules and enhancing security through encapsulation and flow validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network appliances are deployed to provide networking services, then service functionality is improved, but scalability and fault tolerance deteriorate due to single points of failure

Engineering Contradiction:
Improveservice functionalityVSAvoidfault tolerance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network appliance is divided into multiple virtual instances (first virtual network appliance and second virtual network appliance) that can operate independently. This segmentation allows the system to maintain service functionality while eliminating single points of failure, as each virtual instance can handle traffic independently and failover can occur if one instance fails.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes the operational parameters of network appliances by adjusting traffic distribution ratios. The network gateway device can modify the first ratio and second ratio to control how traffic is distributed between different virtual appliances, enabling flexible adaptation to changing conditions while maintaining reliability through automated failover when parameters indicate appliance failure.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If traffic is routed through network appliances, then security inspection is improved, but traffic management complexity increases due to extensive routing rules

Engineering Contradiction:
Improvesecurity inspectionVSAvoidrouting rules
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The network gateway device serves as an intermediary between the virtual network appliances and the external network. It centralizes the routing decision-making process, managing traffic distribution to multiple virtual appliances without requiring complex routing rules at each appliance level. The gateway device simplifies security management by providing a single point of control for traffic inspection and routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If network appliances are scaled horizontally, then service capacity is improved, but system complexity increases due to traffic distribution management

Engineering Contradiction:
Improveservice capacityVSAvoidtraffic distribution management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the network gateway device continuously monitors the operational status of virtual network appliances and automatically adjusts traffic distribution based on appliance performance and health status. This feedback loop enables horizontal scaling without proportionally increasing management complexity, as the system self-regulates traffic distribution in response to changing conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11652736B2Transmitting network traffic to a pool of redundant network appliances
Publication Date: 2023.05.16 AMAZON TECH INC
  • US11652736B2 patent drawing
  • US11652736B2 patent drawing
  • US11652736B2 patent drawing

AI summary

Systems and methods are provided to enable packets of network traffic to be hashed to available network gateway. Each packet can include a route table with a pool of network gateways as a next-hop of the packet. A network device may intercept the packet and hash the packet to a network gateway of the pool of network gateways. The network gateway can correspond to a stateful network router and the stateful network router can transmit the packet to a network appliance. The network device can monitor and perform health-checks on the network gateways, the stateful network routers, and the network appliances. The network device can remove components that are no longer healthy or available and can add components that subsequently become healthy.