Serverless Packet Processing for Isolated Virtual Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing packet processing systems in virtualized environments face challenges in efficiently managing scalable, secure, and reliable network operations across isolated virtual networks, requiring manual provisioning and integration of security and routing rules, which can be complex and resource-intensive.

Innovation Solution

A server-less packet processing service (SPPS) that dynamically provisions and programs nodes for packet processing operations within isolated virtual networks, integrating with IVN configurations to automatically enforce security and routing rules, using fast-path and slower-path nodes for efficient and scalable packet processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning and integration of security and routing rules is implemented, then security and reliability are improved, but device complexity and administrative burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically provisions packet processing nodes and integrates security and routing rules without requiring manual administrative intervention. The packet processing service autonomously configures nodes, applies security policies, and manages routing rules based on service definitions, eliminating the need for administrators to manually integrate these components while maintaining security and reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security and routing rules are pre-configured and integrated into the packet processing service definition before deployment. The system performs preliminary provisioning of nodes and configuration of security policies in advance, so that when the service is activated, all security and routing components are already in place and integrated, avoiding complex manual integration later.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If scalable packet processing is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvepacket processing capacityVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The packet processing system is segmented into multiple independent packet processing nodes that can be dynamically provisioned and scaled. Each node handles a portion of the packet processing workload, and the system can add or remove nodes based on traffic demands. This segmentation enables scalable packet processing capacity while keeping individual node complexity manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The packet processing nodes are designed as universal, multi-functional units that can handle various packet processing tasks including security enforcement, routing, filtering, and transformation. By creating versatile nodes that can perform multiple functions, the system achieves high productivity through scalable deployment without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If automated node provisioning is implemented, then ease of operation is improved, but manufacturing precision requirements increase

Engineering Contradiction:
Improveprovisioning simplicityVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The automated node provisioning system incorporates feedback mechanisms that monitor the configuration and operational status of provisioned nodes. The system validates configurations, detects errors, and automatically corrects or re-provisions nodes that do not meet required specifications. This feedback loop ensures high configuration accuracy is maintained while provisioning remains automated and simple to operate.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-validation and self-correction during the automated provisioning process. When nodes are automatically provisioned, the system autonomously verifies configuration accuracy, checks compliance with security and routing requirements, and remediates any configuration errors without external intervention, thereby maintaining manufacturing precision while preserving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3987746B1Serverless packet processing service with isolated virtual network integration
Publication Date: 2026.01.07 AMAZON TECH INC
  • EP3987746B1 patent drawingFigure 1
  • EP3987746B1 patent drawingFigure 2
  • EP3987746B1 patent drawingFigure 3

AI summary

A program to be executed to perform a packet processing operation on a packet associated with a resource group, as well as security settings of the resource group, are received. The program is transmitted to a set of fast path nodes which were assigned to the resource group based on the group's metadata. With respect to a particular packet, security operations based on the settings are performed and the program is executed at a fast path node. Based at least partly on the results of the program, a packet routing action corresponding to the received packet is performed.