Network Gateway Services via Virtualized Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions rely on expensive hardware that is difficult to configure and maintain, and do not automatically scale with demand or threat levels, leading to productivity disruptions and inefficiencies.

Innovation Solution

A system that provides network connectivity and related services through scalable computing resources, allowing customer entities to access network-related services such as DDoS protection, firewalling, and spam control via a computing resource provider, which can be configured and scaled programmatically to meet demand, using APIs or UIs, and implemented by third-party service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based threat management solutions are deployed, then network security protection is improved, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork security protectionVSAvoidhardware configuration and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware appliances with software-based security services running on virtualized infrastructure. Security functions like firewalling, spam filtering, and DDoS protection are delivered as software services rather than requiring dedicated hardware devices, thereby reducing device complexity while maintaining security effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal security platform that can deliver multiple security services (firewall, spam control, DDoS protection, intrusion detection) through a single virtualized infrastructure. This multi-functional approach eliminates the need for separate hardware appliances for each security function, reducing overall device complexity and cost

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated hardware security appliances are deployed, then network security capabilities are improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork security capabilitiesVSAvoidconfiguration and maintenance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities where security services automatically provision, configure, and manage themselves through virtualization orchestration. The system can automatically detect security requirements, allocate resources, and adjust configurations without manual intervention, dramatically improving ease of operation compared to manual hardware configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a virtualization layer and service orchestration platform as intermediaries between users and security functions. This intermediary abstraction layer simplifies user interaction by providing standardized interfaces and automated management, eliminating the complexity of direct hardware configuration while maintaining robust security capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware-based security solutions are implemented, then network protection services are improved, but productivity deteriorates

Engineering Contradiction:
Improvenetwork protection servicesVSAvoidorganizational productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security services that can be rapidly provisioned, modified, and scaled based on changing organizational needs. Security capabilities can be activated or adjusted through software configuration rather than physical hardware deployment, minimizing disruption to organizational operations and maintaining productivity while providing robust protection

Inventive Principle:
Principle #15Dynamics

4Reliability

If hardware security appliances are deployed, then network security functions are improved, but adaptability deteriorates

Engineering Contradiction:
Improvenetwork security functionsVSAvoidscaling capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates dynamic security services that can automatically scale resources up or down based on demand and threat levels. The virtualized infrastructure allows security capabilities to be dynamically adjusted through software, enabling the system to adapt to changing security requirements and traffic patterns without fixed hardware constraints

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables parameter changes in security service delivery by adjusting virtual resource allocations (CPU, memory, bandwidth) rather than physical hardware configurations. This allows security functions to be scaled and adapted by changing software parameters, providing flexibility and versatility while maintaining robust security protection

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9288182B1Network gateway services and extensions
Publication Date: 2016.03.15 AMAZON TECH INC
  • US9288182B1 patent drawing
  • US9288182B1 patent drawing
  • US9288182B1 patent drawing

AI summary

A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.