Service VPN Firewall Flow Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large distributed computing systems, ensuring security and consistently applying firewall rules across complex and distributed environments is challenging due to the complexity of communication and the manual nature of vulnerability mitigation, making it difficult to identify, isolate, and troubleshoot issues effectively.

Innovation Solution

A managed network layer security service that provides fine-grained controls for blocking, filtering, and securing network traffic through a service virtual private network (VPN) with a bump-in-the-wire configuration, using consistent hashing to ensure that data packets with the same metadata are routed to the same firewall server for uniform distribution and security application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual mitigation of vulnerabilities is used in distributed computing systems, then security measures can be applied, but the complexity and distribution of computing resources make it difficult to consistently apply firewall rules to all communication

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a service virtual private network (service VPN) as an intermediary layer between customer VPNs and the internet gateway. This service VPN acts as a mediator that centralizes firewall rule application and security management, eliminating the need for manual configuration across distributed computing resources. The service VPN consistently applies security policies to all communications flowing through it, resolving the contradiction between maintaining security reliability and reducing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewall rules are manually applied to distributed computing resources, then security can be implemented, but it becomes difficult to isolate and troubleshoot issues with the system

Engineering Contradiction:
ImprovesecurityVSAvoidtroubleshooting difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the network architecture into distinct layers: customer VPNs, service VPN, and internet gateway. This segmentation isolates security management functions to the service VPN layer, making it easier to detect and troubleshoot issues. When security problems occur, they can be localized to specific segments of the service VPN rather than searching through the entire distributed system, thereby reducing troubleshooting difficulty while maintaining security reliability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If conventional manual security measures are used, then some security protection is provided, but the system cannot scale automatically as network traffic increases

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The service VPN provides universal security management capabilities that automatically scale with network traffic. It implements flow balancing that uniformly distributes network flows across multiple firewall servers, enabling the security infrastructure to scale horizontally. As network traffic increases, additional firewall servers can be added to the service VPN without requiring changes to individual customer VPNs or manual reconfiguration, thus maintaining security reliability while improving scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11140132B1Network flow management
Publication Date: 2021.10.05 AMAZON TECH INC
  • US11140132B1 patent drawing
  • US11140132B1 patent drawing
  • US11140132B1 patent drawing

AI summary

Computing resource service providers provide computing resources to customers in a multi-tenant environment. Communication between resources in a customer's virtual private network and an internet gateway in the form of data packets may be intercepted and processed by a firewall to help ensure that traffic entering or exiting the customer's virtual private network is valid and secure. These data packets are intercepted and analyzed by a service in a separate virtual private network and filtered in a way such that data packets with the same networking flow are provided to the same firewall servers so that firewall rules applied to the data packets are consistent.