Overlay Network Communication Manager for Data Center Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing communications between multiple computing nodes separated by physical networks is complex, especially in large-scale data centers, where existing solutions do not effectively provide network isolation and security while allowing dynamic reconfiguration of virtual networks.

Innovation Solution

The implementation of an overlay network using Communication Manager modules that embed virtual network addresses within physical network addresses, allowing for transparent communication routing and dynamic reconfiguration of virtual networks without encapsulating physical network devices, using Stateless IP/ICMP Translation (SIIT) or similar techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing machines among multiple users, then resource utilization efficiency is improved, but network management complexity and security isolation difficulty increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the physical network into multiple virtual networks using virtual switches and routing instances. Each virtual network is isolated with its own addressing scheme, allowing multiple users to share physical infrastructure while maintaining separate network contexts. This segmentation resolves the contradiction by enabling resource sharing through virtualization while managing complexity through structured network division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual switches and routing instances as intermediary components between physical network devices and virtual machines. These intermediaries handle address translation, routing decisions, and security policies, shielding users from physical network complexity while enabling secure multi-tenant resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If computing nodes are separated by physical networks, then physical network security is improved, but communication management flexibility and reconfiguration ease deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a virtual network dimension overlaying the physical network infrastructure. Virtual network addresses and routing paths operate in this additional dimension, allowing flexible reconfiguration of communication patterns without altering physical network topology. This resolves the contradiction by maintaining physical network security boundaries while enabling flexible virtual network management through address translation and virtual routing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements dynamic virtual network configuration where routing instances and virtual switches can be reconfigured without physical network changes. Virtual network addresses can be reassigned and routing paths dynamically adjusted, providing communication management flexibility while the underlying physical network maintains its secure, stable structure.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If virtual network addresses are embedded in physical network addresses, then communication transparency is improved, but address resolution complexity increases

Engineering Contradiction:
Improvecommunication transparencyVSAvoidaddress resolution complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent performs preliminary address resolution by maintaining mapping tables that associate virtual network addresses with physical network addresses before communication occurs. Routing instances pre-compute routing paths and perform address translation in advance, so that during actual communication, the process is transparent and does not require complex real-time resolution. This resolves the contradiction by making communication transparent through pre-established address mappings.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2260402B1Configuring communications between computing nodes
Publication Date: 2020.05.06 AMAZON TECH INC
  • EP2260402B1 patent drawingFigure 1
  • EP2260402B1 patent drawingFigure 2A
  • EP2260402B1 patent drawingFigure 2B

AI summary

Techniques are described for configuring communications between multiple computing nodes, such as computing nodes that are separated by one or more physical networks. In some situations, the techniques may be used to provide a virtual network between multiple computing nodes that are separated by one or more intermediate physical networks, such as from the edge of the one or more intermediate physical networks by modifying communications that enter and/or leave the intermediate physical networks.