Overlay Network Manager for Virtual Networks with Overlapping Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual network provisioning systems face challenges in managing overlapping address spaces, leading to potential traffic collisions and limitations in scalability and flexibility, particularly in supporting distributed applications with diverse networking requirements.

Innovation Solution

The implementation of an Overlay Network Manager (ONM) system that allows for programmatically provisioning virtual networks with overlapping address spaces, using a resource management system to allocate computing resources and manage communications between virtual and physical networks, enabling flexible network topologies and security features without the need for physical networking devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual networks use unique address spaces, then traffic routing is simple and reliable, but scalability and flexibility are limited when supporting multiple virtual networks

Engineering Contradiction:
Improvetraffic routing reliabilityVSAvoidvirtual network scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network address translation (NAT) gateway as an intermediary component that sits between virtual networks with overlapping address spaces and the physical network. This NAT gateway translates virtual network addresses to physical network addresses, enabling multiple virtual networks to coexist with overlapping address spaces while maintaining reliable traffic routing. The intermediary handles address translation transparently, resolving the contradiction between addressing simplicity and network scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical networking devices are used for each virtual network, then network isolation and security are strong, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork isolation and securityVSAvoidphysical networking device quantity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple physical networking functions into shared physical infrastructure. By using virtualization techniques, multiple virtual networks are consolidated onto common physical networking devices (switches, routers, firewalls). The NAT gateway and virtual network infrastructure provide logical isolation and security boundaries while physically sharing resources, thereby reducing device complexity and cost while maintaining network isolation and security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Physical networking devices are designed to serve multiple virtual networks simultaneously through universal interfaces and multi-functional capabilities. A single physical switch or router can handle traffic from multiple virtual networks, providing routing, switching, and security functions across different virtual networks. This multi-functionality reduces the total number of physical devices needed while maintaining the required isolation and security for each virtual network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If virtual networks are provisioned manually, then configuration accuracy is high, but provisioning time and operational complexity increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidprovisioning time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements automated provisioning systems that pre-configure virtual network templates, address spaces, and security policies. When a virtual network is requested, the system automatically instantiates pre-defined configurations, eliminating manual configuration steps. This preliminary preparation of configuration templates ensures accuracy while dramatically reducing provisioning time and operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service provisioning where virtual networks are automatically configured and deployed based on service level agreements (SLAs) and predefined policies. The automated provisioning system handles address allocation, network topology creation, and security rule configuration without human intervention, maintaining configuration accuracy through consistent automated processes while reducing provisioning time and operational burden.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9112769B1Programatically provisioning virtual networks
Publication Date: 2015.08.18 AMAZON TECH INC
  • US9112769B1 patent drawing
  • US9112769B1 patent drawing
  • US9112769B1 patent drawing

AI summary

Virtualization technologies can be adapted to allow a single physical computing machine to be shared among multiple virtual networks by providing one or more virtual machines simulated in software by the single physical computing machine, with each virtual machine acting as a distinct logical computing system. Virtual network instances with overlapping network addresses can be supported on the same computing system, allowing users to specify the virtual network in greater detail. Techniques are described for programmatically provisioning virtual networks. Each virtual network can have its own virtual address space, allowing multiple networks to have overlapping address spaces. The virtual IP addresses or other addresses for one or more components of a virtual network could share the same address but still operate without interfering with each other.