Shared Subnet Management for Multi-Account Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing network configuration at the level of granularity provided by client accounts in provider networks becomes challenging as the scale of networks and infrastructure increases, making it difficult to stitch together hundreds of client accounts and individual logically isolated networks using peering and network meshes.

Innovation Solution

Implementing the sharing of subnets within logically isolated networks across client accounts allows for centralized management, enabling hybrid architectures and varying degrees of centralization, while using permission graphs to represent relationships and determine resource hosting permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If peering and network meshes are used to stitch together hundreds of client accounts and individual logically isolated networks, then network connectivity and isolation are maintained, but device complexity and management difficulty increase significantly

Engineering Contradiction:
Improvenetwork connectivityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple client accounts' subnet management into a shared subnet infrastructure. Instead of maintaining separate logically isolated networks for each client account through complex peering and mesh configurations, the system combines subnets into shared network pools that multiple accounts can utilize, thereby reducing management complexity while preserving connectivity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal shared subnets that serve multiple client accounts simultaneously. A single subnet can be shared across numerous accounts, allowing the same network infrastructure to fulfill multiple functions and serve diverse clients without requiring individualized network configurations for each account

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If centralized management of networking resources is implemented across multiple accounts, then ease of operation and management efficiency improve, but network security and isolation requirements become more challenging to maintain

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network management into two distinct layers: shared subnet infrastructure management (centralized) and resource-level security control (decentralized). The control plane enables centralized provisioning and management of shared subnets, while the data plane maintains account-specific security policies and isolation, allowing efficient centralized operation without compromising security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a control plane as an intermediary between the centralized management system and the distributed client accounts. The control plane handles subnet sharing configurations, permission management, and resource allocation, while maintaining security boundaries and isolation policies, thus enabling efficient centralized management without directly compromising network security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If subnets are shared across client accounts, then productivity and resource utilization improve, but difficulty of detecting and measuring permission relationships increases

Engineering Contradiction:
Improveresource utilizationVSAvoidpermission relationship tracking
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms through the control plane that automatically track and report permission relationships, subnet sharing configurations, and resource allocation states. The system provides real-time visibility into which accounts share which subnets and what resources are allocated where, making permission relationships easily detectable and measurable while enabling high resource utilization

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10785056B1Sharing a subnet of a logically isolated network between client accounts of a provider network
Publication Date: 2020.09.22 AMAZON TECH INC
  • US10785056B1 patent drawing
  • US10785056B1 patent drawing
  • US10785056B1 patent drawing

AI summary

A subnet of a logically isolated network within a provider network may be shared between client accounts of the provider network. A request to share a subnet of a logically isolated network created for one client account with another client account may be received. A link between an account object for the other client account and a shared subnet object for the subnet may be stored. When a request to host a resource with the subnet is received, an evaluation of the graph may indicate whether the request to place the host is permitted. If permitted, the resource for the other client host may be hosted within the subnet.