Private Endpoints for Cross-IVN Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing provider networks face challenges in securely and efficiently accessing customer-owned services across isolated virtual networks (IVNs) without exposing them to the public Internet, which can increase the risk of Internet-based attacks and compromise performance.

Innovation Solution

The implementation of private endpoints for services within isolated virtual networks, allowing service requests and responses to flow through private network pathways within the provider network, thereby avoiding public Internet exposure and enhancing security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public IP addresses are used to access services across isolated virtual networks, then service accessibility is improved, but security and exposure to Internet-based attacks worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidexposure to Internet-based attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces private endpoints as intermediary components that enable service access between isolated virtual networks without requiring public Internet exposure. These endpoints act as mediators that facilitate communication while maintaining network isolation, allowing services to be accessible across IVNs through private network pathways rather than public IP addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If public Internet pathways are used for service requests, then service accessibility is improved, but network performance and latency worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidnetwork performance and latency
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent segments network pathways into public Internet routes and private network pathways. By creating distinct routing paths, services can be accessed through optimized private network infrastructure for improved performance, while public Internet access remains available when needed. This segmentation allows traffic to be routed through the most appropriate pathway based on performance requirements.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network isolation is maintained across IVNs, then security is improved, but service accessibility across networks worsens

Engineering Contradiction:
Improvenetwork isolation and securityVSAvoidservice accessibility across networks
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Private endpoints serve as controlled intermediaries that enable cross-IVN service access while preserving network isolation. These endpoints provide a managed interface that allows services to be discovered and accessed across virtual network boundaries without compromising the fundamental isolation architecture. The intermediary maintains security boundaries while facilitating legitimate service communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12284253B2Private service endpoints in isolated virtual networks
Publication Date: 2025.04.22 AMAZON TECH INC
  • US12284253B2 patent drawing
  • US12284253B2 patent drawing
  • US12284253B2 patent drawing

AI summary

A service implemented at a first isolated virtual network of a provider network is added to a database of privately-accessible services. Configuration changes that enable network packets to flow between the first isolated virtual network and a second isolated virtual network without utilizing a network address accessible from the public Internet are implemented. Service requests originating at the second isolated virtual network are transmitted to the first isolated virtual network via private pathways of the provider network. Metrics corresponding to service requests directed from the second isolated network to the service are collected and provided to the respective owners of one or both isolated virtual networks.