Private Network Layering for Secure Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing and provisioning physical computing resources in large-scale data centers has increased due to the growth in scale and scope, particularly in providing secure and efficient sharing of computing and storage resources among diverse clients, where existing technologies lack a comprehensive solution for layered access and security control.

Innovation Solution

The implementation of private network layering in provider network environments allows clients to establish and manage private networks with layered access control, enabling secure resource sharing and isolation through sub-private networks, where access control rules can be configured to allow or restrict access between parent and sub-private networks, and between sibling networks, using virtualization technologies and encapsulation protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share computing resources among multiple clients, then resource utilization efficiency is improved, but managing and provisioning physical computing resources becomes increasingly complicated

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidcomplexity of managing physical computing resources
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the provider network into multiple hierarchical network layers (first network layer, second network layer, etc.), where each layer serves specific clients with isolated virtual networks. This segmentation allows independent management of each layer's resources and access control policies, reducing the overall complexity of managing large-scale multi-tenant environments while maintaining high resource utilization through virtualization at each layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to network architecture by creating multiple network layers with different access levels. Instead of managing all clients in a single flat network, the system organizes clients across multiple layers where lower layers can access resources in higher layers under controlled conditions. This dimensional organization simplifies resource provisioning and access management by providing structured pathways for resource sharing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple clients share computing resources in large-scale data centers, then resource sharing capability is improved, but security control and isolation become more difficult to implement

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity control and isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements security isolation by segmenting the network into multiple hierarchical layers with controlled access between them. Each layer maintains its own virtual network environment, and access to resources in higher layers is explicitly controlled through defined pathways. This segmentation ensures that security breaches or failures in one layer do not propagate to other layers, maintaining overall system reliability while enabling resource sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network layers as intermediary structures between clients and physical resources. These layers act as controlled intermediaries that enforce security policies, manage access rights, and provide isolation while facilitating resource sharing. The hierarchical layering structure serves as a mediator that balances security requirements with resource sharing needs by providing structured access control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hierarchical network layers are implemented to improve security and access control, then security control capability is improved, but network configuration and management complexity increases

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates universal network layer structures that can be replicated across the provider network, with each layer serving multiple clients and resources. These standardized layer templates provide consistent security controls and access management patterns that can be applied uniformly throughout the hierarchy, reducing configuration complexity despite the multi-layered architecture. The universal design allows administrators to manage security policies at the layer level rather than individually for each client-resource pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11089021B2Private network layering in provider network environments
Publication Date: 2021.08.10 AMAZON TECH INC
  • US11089021B2 patent drawing
  • US11089021B2 patent drawing
  • US11089021B2 patent drawing

AI summary

Methods and apparatus that allow clients to establish sub private networks as resources within private networks on a provider network. A sub private network may be owned and controlled by a different entity than the owner of its parent private network. A parent private network controls access to its sub private networks, and each sub private network also controls access to its resources. This enables a layered topology in which a parent private network may establish access control rules for its sub private networks; the sub private networks may supplement the access control according to their specific needs. Sub private networks may share resources of their parent private network, and a sub private network may allow or restrict access to its resources by its parent private network, by its sibling private networks, and/or by its own sub private network(s).