Route Table Ingress Association for Isolated Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtualization technologies do not effectively allow for customizable and secure handling of network traffic within provider networks, limiting the integration of advanced security features and network appliances in logically isolated networks.

Innovation Solution

Associating route tables with ingress traffic to logically isolated networks enables the use of custom network appliances and service chains, allowing for optimized traffic routing and security by directing network packets through specific network appliances without modifying their destination fields.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualization technologies are used to share computing resources among multiple customers, then resource efficiency and security are improved, but customization of network traffic handling is limited

Engineering Contradiction:
Improvecustomization of network traffic handlingVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic handling by introducing logically isolated networks (VPCs) that divide the provider network into separate, customizable virtual networking environments. Each VPC can have its own routing tables, network appliances, and traffic handling rules, allowing customers to customize network traffic handling without affecting other customers or the underlying substrate network complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If advanced security features and network appliances are integrated into logically isolated networks, then security and traffic optimization are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces route tables as an intermediary layer between the substrate network and logically isolated networks. These route tables act as mediators that enable integration of advanced security features and network appliances without directly increasing substrate network complexity. The route tables provide a standardized interface for customers to configure security rules and traffic optimization policies within their VPCs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a virtual networking dimension above the physical substrate network. By introducing VPCs with their own routing tables and network appliances, customers can implement advanced security features and traffic optimization in this new virtual dimension without complicating the underlying physical network infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If route tables are associated with ingress traffic to logically isolated networks, then traffic routing control is improved, but system complexity increases

Engineering Contradiction:
Improvetraffic routing controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates universal route tables that can be applied across multiple logically isolated networks and different ingress traffic sources. This multi-functional routing mechanism allows customers to control traffic routing in their VPCs using standardized route table configurations, improving ease of operation without proportionally increasing system complexity through repetition.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11671365B2Associating route tables with ingress traffic to logically isolated networks
Publication Date: 2023.06.06 AMAZON TECH INC
  • US11671365B2 patent drawing
  • US11671365B2 patent drawing
  • US11671365B2 patent drawing

AI summary

Route tables may be associated with ingress traffic for logically isolated networks. A routing device at the edge of a logically isolated network may receive a route to include in a route table that is associated with ingress traffic to the logically isolated network to forward the ingress traffic to a network appliance hosted in the logically isolated network. Network packets received at the edge routing device may have a destination of a computing resource hosted in the logically isolated network. The edge routing device may identify the route in the route table to override the destination in the network packet with the network appliance and forward the network packet to the network appliance according to the route.