Stateful Network Routing Service for Full-Proxy Appliances
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network appliances in data centers lack scalability, security, and fault tolerance, leading to potential errors, data exfiltration, and single points of failure, while also increasing memory demands and complexity.
Innovation Solution
A managed appliance gateway service that enables user-defined arbitrary routing decisions, flexible and elastic routing of network traffic, secure traffic steering, stateful routing, and secure boundary maintenance between availability zones, using a stateful network routing service that processes packets at layer 3 of the OSI model and supports custom tuple definitions for load balancing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network appliances are deployed to provide networking services, then service functionality is achieved, but scalability is limited and memory demands increase
Solution Approach 1:
The patent uses virtual machine copies to represent network appliance instances. Each virtual machine is a software-based copy that can be created, copied, and deployed across multiple physical hosts, replacing traditional hardware appliances and reducing physical memory demands while maintaining service functionality.
Solution Approach 2:
The virtualized network appliance platform provides multi-functionality by allowing a single infrastructure to host multiple network appliance types and instances. The system can dynamically allocate and manage various networking services (firewalls, load balancers, etc.) through software, making the infrastructure universal and adaptable to different service requirements.
2Adaptability or versatility
If network appliances are deployed to provide networking services, then service functionality is achieved, but device complexity increases
Solution Approach 1:
The patent introduces a network virtualization layer and management platform as intermediaries between physical infrastructure and network services. This intermediary layer abstracts the complexity of managing multiple network appliances, providing centralized control, automated provisioning, and simplified service deployment through software-based management.
Solution Approach 2:
The virtualized network appliance system enables self-service capabilities through automated provisioning and management. The platform can automatically deploy, configure, and manage network appliance instances based on service requirements, reducing the need for manual intervention and simplifying operational complexity.
3Adaptability or versatility
If network appliances are deployed to provide networking services, then service functionality is achieved, but security boundaries between availability zones are compromised
Solution Approach 1:
The patent implements segmentation by isolating network appliance instances within specific availability zones through virtualization. Each virtual machine and its associated network functions are confined to designated zones, maintaining security boundaries while allowing service functionality to operate independently within each segmented environment.
Solution Approach 2:
The virtualization platform acts as an intermediary that enforces security policies and maintains boundaries between availability zones. It manages network traffic, access controls, and isolation mechanisms to ensure that services in one zone do not compromise the security or integrity of other zones.
4Adaptability or versatility
If network appliances are deployed to provide networking services, then service functionality is achieved, but fault tolerance is reduced due to single points of failure
Solution Approach 1:
The patent segments network services across multiple virtual machine instances distributed on different physical hosts. This segmentation eliminates single points of failure by ensuring that the failure of one physical host does not take down all network services, as instances can be isolated, restarted, or migrated to other hosts.
Solution Approach 2:
The system dynamically changes the operational parameters of network services by migrating virtual machine instances between physical hosts based on health status, load conditions, and failure detection. This flexibility allows the system to adapt to failures and maintain service functionality by relocating instances to healthy hosts.
Data Source
AI summary
Systems and methods are provided to add flow identification information to packets of network traffic. Each packet can have flow identification information added based on the packet being sent to a full-proxy mode appliance. A stateful network routing service may intercept packets and determine the packets are to be sent to a full-proxy mode appliance. Based on this determination, the stateful network routing service may obtain or generate flow identification information to identify the packet. The stateful network routing service may add the information to the packet and transmit the enriched packet to a full-proxy mode network appliance. The stateful network routing service may receive a second enriched packet from the network appliance. The stateful network routing service can parse the second enriched packet for flow identification information and identify the second enriched packet based on the flow identification information.


