Resource-Based Network Traffic Management via RGM Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face challenges in managing network traffic across virtual private clouds (VPCs) due to complex routing configurations and the need for in-depth knowledge of network architectures, leading to increased administrative burdens and risks of misconfigurations, especially when providing resilient and secure connections to external networks.

Innovation Solution

The introduction of a resource-based internet gateway management (RGM) service that allows customers to define network traffic policies at the resource level, specifying paths through network functions like firewalls and load balancers, which are then translated into network-level configurations, enabling centralized management and reducing the complexity of configuring and securing network traffic across VPCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers configure network traffic paths at the network level with detailed routing configurations, then network traffic management capability is improved, but device complexity and administrative burden increase

Engineering Contradiction:
Improvenetwork traffic management capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic management into two distinct levels: resource-level configuration (simple, customer-facing) and network-level configuration (complex, system-managed). This segmentation allows customers to define high-level traffic paths using simple resource identifiers without dealing with complex network-level details, while the system automatically handles the complex routing configuration translation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary translation mechanism that converts resource-level path definitions into network-level configurations. This intermediary layer abstracts the complexity by automatically translating customer-friendly resource identifiers into detailed network routing rules, eliminating the need for customers to directly configure complex network-level parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If customers directly configure network-level routing, then network traffic control precision is improved, but ease of operation deteriorates due to required expertise

Engineering Contradiction:
Improvetraffic control precisionVSAvoidconfiguration ease
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing customers to define traffic paths using simple resource-level identifiers without requiring network configuration expertise. The system automatically performs the complex translation and configuration tasks, making the service accessible to customers regardless of their technical knowledge while maintaining precise traffic control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses resource identifiers as simplified copies or representations of complex network resources. Instead of requiring customers to configure actual network-level parameters, the system uses high-level resource identifiers that automatically map to the underlying complex network configuration, preserving precision while simplifying operation.

Inventive Principle:
Principle #26Copying

3Reliability

If detailed network-level configurations are used, then network security control is improved, but risk of misconfigurations increases

Engineering Contradiction:
Improvesecurity controlVSAvoidmisconfiguration risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The intermediary translation mechanism acts as a safety layer that automatically translates customer-defined resource paths into network-level configurations. This intermediary process reduces misconfiguration risk by eliminating manual network-level editing, ensuring that security rules are correctly applied through automated translation rather than prone-to-error manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-configuration at the network level based on customer-defined resource-level policies. This self-service approach to network configuration generation reduces human error and misconfigurations by automatically translating high-level intent into precise network security rules without requiring manual intervention in complex network parameters.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If centralized network-level management is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvemanagement simplicityVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the management interface from the implementation complexity by separating resource-level configuration (simple, centralized) from network-level configuration (complex, automated). This segmentation allows centralized management at the user interface while the system handles the complexity of network-level configuration translation automatically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The translation mechanism serves as an intermediary that hides system architecture complexity from users. While the underlying system requires complex network-level configurations, the intermediary translation layer presents a simplified centralized management interface where customers can define traffic paths using simple resource identifiers without perceiving the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12177110B1Resource-based network traffic management
Publication Date: 2024.12.24 AMAZON TECH INC
  • US12177110B1 patent drawing
  • US12177110B1 patent drawing
  • US12177110B1 patent drawing

AI summary

Techniques for resource-based network traffic management are described. A service of a cloud provider network receives a traffic policy, the traffic policy identifying a path to a gateway to an external network, the path identifies at least one network function in the path by a resource identifier of the cloud provider network. Traffic policy association data is received, the traffic policy association data associating the traffic policy with one or more virtual networks hosted by the cloud provider network. A network configuration of the cloud provider network is updated to route network traffic from a first virtual network to the gateway to the external network through the network function.