Provider Network Extensions for Low-Latency Edge Compute Launch

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualized computing services are limited by latency and security issues when processing large amounts of data stored outside the provider network, as services relying on hardware located within data centers may not be optimal for low-latency operations and secure data handling.

Innovation Solution

The implementation of extension resource groups (ERGs) that allow virtual machines to be set up at customer-selected locations, using pre-configured hardware and secure network connections to maintain security and functionality equivalent to provider network data centers, with isolated virtual networks and outbound command communicators ensuring secure administrative commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If provider networks are siloed and operate independently, then each network maintains its own control and security policies, but service portability and user experience deteriorate as services cannot be easily accessed across different networks

Engineering Contradiction:
Improveservice portabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a service extension mechanism that acts as an intermediary between siloed provider networks. Service extensions are deployed at the network edge and can be invoked by applications across different networks, enabling service portability without requiring direct integration between networks. This mediator approach maintains network independence while enabling cross-network service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the service delivery architecture into distinct components: service extensions deployed at the network edge, service extension frameworks that manage deployment and invocation, and applications that consume services. This segmentation allows each component to operate independently while maintaining defined interfaces, reducing overall system complexity while enabling service portability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If service extensions are deployed across multiple provider networks, then service portability improves, but the complexity of managing deployment and updates across networks increases

Engineering Contradiction:
Improveservice portabilityVSAvoidservice extension management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal service extension framework that can deploy and manage service extensions across multiple provider networks using a consistent interface and process. The framework handles deployment, updates, and lifecycle management in a network-agnostic manner, making service extension management as easy as traditional application deployment while enabling cross-network service portability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If traditional siloed network architecture is maintained, then network security and control are preserved, but innovation speed and time-to-market for new services decrease

Engineering Contradiction:
Improveinnovation speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary security measures by deploying service extensions at the network edge before services are accessed. Service extensions are pre-authenticated and pre-configured with appropriate security policies, allowing fast service deployment while maintaining security. The service extension framework enforces security policies during deployment, ensuring that security considerations are addressed before services become operational.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3884628B1Provider network service extensions
Publication Date: 2026.05.20 AMAZON TECH INC
  • EP3884628B1 patent drawingFigure 1
  • EP3884628B1 patent drawingFigure 2
  • EP3884628B1 patent drawingFigure 3

AI summary

A request to launch a compute instance is received at a control plane of a provider network. At an outbound command communicator, an indication that a compute instance is to be established at a target host at a client premise is obtained. A first address is associated with the target host at the control plane and also assigned to the communicator. A message with a second address within a first network of the client premise as a destination is transmitted. The message comprises a command to establish the compute instance at the target host. The first address is assigned to the target host within a second network of the client premise. Processing of the command at the target host results in establishment of a compute instance.