Domain name system operations implemented using scalable virtual traffic hub

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking solutions in large provider networks struggle to efficiently manage network packet address manipulation and customized policy-based packet processing for virtualized computing services, particularly when handling traffic from hundreds of thousands of virtual or physical machines, as ad-hoc solutions fail to scale effectively.

Innovation Solution

Implementing a multi-layer packet processing service with isolated cells, each comprising action implementation nodes, decision master nodes, and administration nodes, which utilize virtual network interfaces and programmable forwarding metadata to manage traffic between isolated networks, ensuring efficient and secure packet processing without cross-cell interference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ad-hoc networking solutions are used for packet processing, then customization flexibility is improved, but scalability deteriorates when handling traffic from hundreds of thousands of virtual or physical machines

Engineering Contradiction:
Improvecustomization flexibilityVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the packet processing service into multiple isolated cells, each capable of handling traffic for specific virtual machines or networks. This segmentation allows customized packet processing policies to be applied to different cells independently, maintaining customization flexibility while enabling scalable handling of large numbers of virtual machines through parallel processing across multiple cells.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network interfaces as intermediaries between virtual machines and the packet processing service. These virtual network interfaces enable customized packet processing by allowing virtual machines to specify their own networking requirements while the isolated cells provide the scalable infrastructure to handle traffic from hundreds of thousands of virtual machines efficiently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If isolated cells are implemented for packet processing, then security and resource isolation are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and resource isolationVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements packet processing service cells that are logically isolated from each other, with each cell handling traffic for specific virtual machines or networks independently. This segmentation provides security and resource isolation, ensuring that failures or security issues in one cell do not propagate to other cells, while the overall system architecture remains manageable through standardized cell templates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs isolated cells using universal templates and standardized interfaces, allowing the same cell structure to serve multiple purposes across different virtual machine workloads. This universality reduces the actual complexity despite the presence of multiple isolated cells, as cells can be instantiated, configured, and managed through common frameworks and tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If customized policy-based packet processing is applied to all traffic, then application-specific performance is improved, but CPU load increases

Engineering Contradiction:
Improveapplication-specific performanceVSAvoidCPU load
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent segments packet processing workloads across multiple isolated cells, each handling traffic for specific virtual machines. This distribution reduces the CPU load on any single cell, allowing customized policy-based packet processing to be applied efficiently without overwhelming individual processing units, thereby maintaining application-specific performance while managing CPU resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from single-cell centralized processing to multi-cell distributed processing, adding the dimension of cellular distribution to the packet processing architecture. This dimensional change allows customized processing policies to be applied across multiple parallel cells, reducing CPU load through workload distribution while maintaining or improving application-specific performance through optimized per-cell processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250260597A1Domain name system operations implemented using scalable virtual traffic hub
Publication Date: 2025.08.14 AMAZON TECH INC
  • US20250260597A1 patent drawing
  • US20250260597A1 patent drawing
  • US20250260597A1 patent drawing

AI summary

Connectivity is enabled between a first and second isolated network using a virtual traffic hub that includes resources of a cloud computing environment. The connectivity may include respective first and second Virtual Private Network (VPN) connections between the hub and the first and second isolated network at respective premises external to the cloud computing environment. At least a portion of a first packet received at the hub from the first isolated network via the first VPN connection is transmitted from the hub to the second isolated network via the second VPN connection.