Network Entity Registry for Automated Policy Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network traffic policies across multiple virtual machines becomes burdensome and time-consuming, especially when scaling up or down, as each security group must be manually updated, leading to costly and inefficient changes in response to changing network conditions.

Innovation Solution

Implementing a network entity registry that maintains entries for network entities, including network address information and handles, allowing for centralized management of network traffic policies, enabling automatic updates and enforcement across multiple compute resources without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates are performed for each security group when scaling virtual machines, then network traffic policy control is maintained, but management complexity and time consumption increase significantly

Engineering Contradiction:
Improvenetwork traffic policy controlVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple security group management operations into a single centralized entity registry. When virtual machines are scaled, the registry automatically updates all relevant network traffic policies in one operation, eliminating the need to manually update each security group separately. This combining approach maintains policy control reliability while dramatically reducing management time.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The entity registry acts as an intermediary between virtual machine scaling operations and network traffic policy enforcement. Instead of directly updating each security group when VMs are scaled, the system communicates changes to the registry, which then automatically propagates updates to all affected policies. This mediator approach ensures reliable policy control while eliminating manual intervention time.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual updates are performed for each security group when network conditions change, then network traffic policies are enforced, but operational efficiency decreases

Engineering Contradiction:
Improvenetwork traffic policy enforcementVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system transitions from static manual policy updates to dynamic automatic updates. The entity registry continuously monitors network conditions and automatically updates security groups in real-time when changes occur. This dynamic approach maintains reliable policy enforcement while dramatically improving operational efficiency by eliminating repetitive manual updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The entity registry provides self-service functionality by automatically detecting network condition changes and updating relevant security groups without human intervention. The system monitors itself and performs necessary policy updates autonomously, ensuring reliable enforcement while maximizing operational efficiency through automation.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If centralized management with entity registry is implemented, then automation and efficiency improve, but system complexity increases

Engineering Contradiction:
Improveautomatic policy updatesVSAvoidsystem architecture
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The entity registry is designed as a universal system that handles multiple functions: storing entity information, monitoring network conditions, triggering policy updates, and communicating with security groups. By consolidating these diverse functions into a single multi-functional component, the system achieves high automation while minimizing the complexity that would otherwise be distributed across multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3095214B1An entity handle registry to support traffic policy enforcement
Publication Date: 2021.11.03 AMAZON TECH INC
  • EP3095214B1 patent drawingFigure 1
  • EP3095214B1 patent drawingFigure 2
  • EP3095214B1 patent drawingFigure 3

AI summary

A provider network may implement network entity registry for network entity handles included in network traffic policies enforced for a provider network. Network entity entries may be maintained in a network entity registry that specify network address information for network entity handles included in network traffic control policies. Network traffic control policies may be enforced by a network traffic controller. When an update to an network entity entry is received, the network entity entry may be updated and network address information specified in the network entity entry may be provided to a subset of network traffic controls implemented in a provider network for those network traffic controls enforcing network traffic policies including the network entity handle for the updated network entity entry. Network entity entries may, in some embodiments, not be updated by a network entity entry owner.