Overlay Network for Secure Application Group Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging to provide an overlay network that enables secure communication between applications in an enterprise network, especially when scaling the number of applications, as existing solutions require retrofitting each application for secure communication and managing changing security levels.

Innovation Solution

An overlay network is configured to operate using existing network and computing resources, decoupling application development from data protection, allowing secure communication between applications without modifying individual applications, and utilizing a virtualization layer to minimize communication latency between applications on the same host computer system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications are retrofitted for secure communication with other applications in the system, then security between applications is improved, but the complexity of application deployment and maintenance increases

Engineering Contradiction:
ImprovesecurityVSAvoidapplication deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network overlay as an intermediary layer that provides security services between applications without requiring modifications to the applications themselves. The overlay network handles encryption, decryption, and security policy enforcement centrally, allowing applications to communicate securely through this mediator rather than each application needing its own security implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts security functionality from individual applications and consolidates it into a separate network overlay layer. This separation allows security to be managed independently from application logic, reducing deployment complexity while maintaining security. The overlay network handles all security-related operations externally to the applications.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If the number of applications in a system grows, then system functionality is improved, but the difficulty of securing and protecting data flow between applications increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network overlay provides universal security services that work across all applications in the system regardless of the number or type of applications. A single overlay infrastructure handles security for multiple applications simultaneously, providing multi-functional security enforcement without requiring separate security mechanisms for each application pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The overlay network dynamically adapts to changing system conditions, including the addition or removal of applications. Security policies and encryption keys are managed dynamically based on current system state, allowing the security infrastructure to scale with system functionality without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If data is transmitted through the overlay network for encryption and decryption, then security is improved, but communication latency between applications increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The overlay network performs preliminary setup of security contexts, encryption keys, and routing information before actual data transmission occurs. This preconfiguration allows data to be encrypted and decrypted more efficiently during transmission, reducing the time penalty associated with security operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10581737B1Acceleration of data routing in an application group
Publication Date: 2020.03.03 AMAZON TECH INC
  • US10581737B1 patent drawing
  • US10581737B1 patent drawing
  • US10581737B1 patent drawing

AI summary

A method and apparatus for accelerating data routing between applications of an application group are disclosed. In the method and apparatus, a host computer system receives registration information from a first computer system instantiated on the host computer system, whereby the registration information indicates whether a first application is executed on the first computer system. In response to a request from a second computer system that is instantiated on the host computer system to route data to the first application, the host computer system routes the data to the first computer system, whereby the internal routing of the data is determinable by the first computer system.