Shared Subnet Management for Multi-Account Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing network configuration at the level of granularity provided by client accounts in provider networks becomes challenging as the scale of networks and infrastructure increases, making it difficult to stitch together hundreds of client accounts and individual logically isolated networks using peering and network meshes.
Innovation Solution
Implementing the sharing of subnets within logically isolated networks across client accounts allows for centralized management, enabling hybrid architectures and varying degrees of centralization, while using permission graphs to represent relationships and determine resource hosting permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If peering and network meshes are used to stitch together hundreds of client accounts and individual logically isolated networks, then network connectivity and isolation are maintained, but device complexity and management difficulty increase significantly
Solution Approach 1:
The patent merges multiple client accounts' subnet management into a shared subnet infrastructure. Instead of maintaining separate logically isolated networks for each client account through complex peering and mesh configurations, the system combines subnets into shared network pools that multiple accounts can utilize, thereby reducing management complexity while preserving connectivity
Solution Approach 2:
The patent creates universal shared subnets that serve multiple client accounts simultaneously. A single subnet can be shared across numerous accounts, allowing the same network infrastructure to fulfill multiple functions and serve diverse clients without requiring individualized network configurations for each account
2Ease of operation
If centralized management of networking resources is implemented across multiple accounts, then ease of operation and management efficiency improve, but network security and isolation requirements become more challenging to maintain
Solution Approach 1:
The patent segments network management into two distinct layers: shared subnet infrastructure management (centralized) and resource-level security control (decentralized). The control plane enables centralized provisioning and management of shared subnets, while the data plane maintains account-specific security policies and isolation, allowing efficient centralized operation without compromising security
Solution Approach 2:
The patent introduces a control plane as an intermediary between the centralized management system and the distributed client accounts. The control plane handles subnet sharing configurations, permission management, and resource allocation, while maintaining security boundaries and isolation policies, thus enabling efficient centralized management without directly compromising network security
3Productivity
If subnets are shared across client accounts, then productivity and resource utilization improve, but difficulty of detecting and measuring permission relationships increases
Solution Approach 1:
The patent implements feedback mechanisms through the control plane that automatically track and report permission relationships, subnet sharing configurations, and resource allocation states. The system provides real-time visibility into which accounts share which subnets and what resources are allocated where, making permission relationships easily detectable and measurable while enabling high resource utilization
Data Source
AI summary
A subnet of a logically isolated network within a provider network may be shared between client accounts of the provider network. A request to share a subnet of a logically isolated network created for one client account with another client account may be received. A link between an account object for the other client account and a shared subnet object for the subnet may be stored. When a request to host a resource with the subnet is received, an evaluation of the graph may indicate whether the request to place the host is permitted. If permitted, the resource for the other client host may be hosted within the subnet.


