Managed Blockchain Service Access Across Private Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed blockchain services face challenges in enabling access across private networks, requiring complex manual coordination and limited support for external resources, which hinders participation and scalability.

Innovation Solution

Implementing a managed blockchain service with a control plane that manages network access, node management, and routing across private networks using load balancers and virtual traffic hubs, allowing external nodes to communicate with blockchain networks while maintaining privacy and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual coordination is used to enable access across private networks, then access can be established, but the complexity of setup and maintenance increases significantly

Engineering Contradiction:
Improveaccess capabilityVSAvoidcoordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a managed blockchain service as an intermediary layer between external participants and the blockchain network. This service includes components such as a control plane, data plane, and network infrastructure that automatically handle routing, networking, and access management. External participants connect to the managed service rather than directly coordinating with the blockchain network, eliminating the need for manual network configuration and reducing setup complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If external resources are limited in the managed blockchain service, then network security and privacy are maintained, but participation and scalability are hindered

Engineering Contradiction:
Improvenetwork securityVSAvoidparticipant variety
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into distinct layers: the managed blockchain service layer and the external participant layer. The managed service includes segmented components such as the control plane (for management and configuration), data plane (for data transmission), and network infrastructure (for routing and networking). This segmentation allows external resources to be incorporated through controlled interfaces while maintaining security boundaries, enabling both scalability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The managed blockchain service provides universal access capabilities that support multiple types of external participants (different networks, devices, and applications) through a common interface. The service can handle various networking scenarios including cross-network communication, load balancing, and routing to different blockchain nodes, making it adaptable to diverse participant requirements while maintaining a secure managed environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If manual network configuration is required for blockchain access, then access control can be implemented, but the time and effort required for setup increases

Engineering Contradiction:
Improveaccess controlVSAvoidsetup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The managed blockchain service implements self-service capabilities where the system automatically configures networking, routing, and access control policies. When external participants join, the service automatically provisions network connections, configures load balancers, and sets up routing rules without requiring manual intervention. This automation maintains security controls while eliminating time-consuming manual configuration tasks.

Inventive Principle:
Principle #25Self-service

4Reliability

If the managed blockchain service supports only internal private network access, then network privacy is maintained, but external participation is limited

Engineering Contradiction:
Improvenetwork privacyVSAvoidexternal access support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The managed blockchain service acts as an intermediary that enables external participants to access the blockchain network while maintaining privacy boundaries. The service includes a data plane that routes traffic from external participants through controlled network paths to the blockchain nodes. This intermediary layer allows external access without exposing the internal blockchain network directly, preserving privacy while enabling participation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to the network architecture by introducing a managed service layer between external networks and the blockchain network. This creates a multi-layered network structure where external participants can connect through the managed service's network infrastructure, which includes load balancers, routers, and private network connections. This dimensional addition enables external access while maintaining the privacy of the core blockchain network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11411921B2Enabling access across private networks for a managed blockchain service
Publication Date: 2022.08.09 AMAZON TECH INC
  • US11411921B2 patent drawing
  • US11411921B2 patent drawing
  • US11411921B2 patent drawing

AI summary

Access across private networks may be enabled for blockchain networks in a managed blockchain service. Requests to enable access for a node hosted in a private network to one or more nodes hosted in a different private network that hosts the blockchain network as part of a managed blockchain service may be received. Routes to enable the access may be determined and added to networking devices so that communications between the node in the private network to specified nodes in the private network of the managed blockchain service may be correctly routed.