Stateful Network Routing Service for Full-Proxy Appliances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network appliances in data centers lack scalability, security, and fault tolerance, leading to potential errors, data exfiltration, and single points of failure, while also increasing memory demands and complexity.

Innovation Solution

A managed appliance gateway service that enables user-defined arbitrary routing decisions, flexible and elastic routing of network traffic, secure traffic steering, stateful routing, and secure boundary maintenance between availability zones, using a stateful network routing service that processes packets at layer 3 of the OSI model and supports custom tuple definitions for load balancing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network appliances are deployed to provide networking services, then service functionality is achieved, but scalability is limited and memory demands increase

Engineering Contradiction:
Improveservice functionalityVSAvoidmemory usage
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent uses virtual machine copies to represent network appliance instances. Each virtual machine is a software-based copy that can be created, copied, and deployed across multiple physical hosts, replacing traditional hardware appliances and reducing physical memory demands while maintaining service functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtualized network appliance platform provides multi-functionality by allowing a single infrastructure to host multiple network appliance types and instances. The system can dynamically allocate and manage various networking services (firewalls, load balancers, etc.) through software, making the infrastructure universal and adaptable to different service requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If network appliances are deployed to provide networking services, then service functionality is achieved, but device complexity increases

Engineering Contradiction:
Improveservice functionalityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a network virtualization layer and management platform as intermediaries between physical infrastructure and network services. This intermediary layer abstracts the complexity of managing multiple network appliances, providing centralized control, automated provisioning, and simplified service deployment through software-based management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtualized network appliance system enables self-service capabilities through automated provisioning and management. The platform can automatically deploy, configure, and manage network appliance instances based on service requirements, reducing the need for manual intervention and simplifying operational complexity.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If network appliances are deployed to provide networking services, then service functionality is achieved, but security boundaries between availability zones are compromised

Engineering Contradiction:
Improveservice functionalityVSAvoidsecurity boundaries
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements segmentation by isolating network appliance instances within specific availability zones through virtualization. Each virtual machine and its associated network functions are confined to designated zones, maintaining security boundaries while allowing service functionality to operate independently within each segmented environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtualization platform acts as an intermediary that enforces security policies and maintains boundaries between availability zones. It manages network traffic, access controls, and isolation mechanisms to ensure that services in one zone do not compromise the security or integrity of other zones.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If network appliances are deployed to provide networking services, then service functionality is achieved, but fault tolerance is reduced due to single points of failure

Engineering Contradiction:
Improveservice functionalityVSAvoidfault tolerance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network services across multiple virtual machine instances distributed on different physical hosts. This segmentation eliminates single points of failure by ensuring that the failure of one physical host does not take down all network services, as instances can be isolated, restarted, or migrated to other hosts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes the operational parameters of network services by migrating virtual machine instances between physical hosts based on health status, load conditions, and failure detection. This flexibility allows the system to adapt to failures and maintain service functionality by relocating instances to healthy hosts.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11088948B1Correlating network flows in a routing service for full-proxy network appliances
Publication Date: 2021.08.10 AMAZON TECH INC
  • US11088948B1 patent drawing
  • US11088948B1 patent drawing
  • US11088948B1 patent drawing

AI summary

Systems and methods are provided to add flow identification information to packets of network traffic. Each packet can have flow identification information added based on the packet being sent to a full-proxy mode appliance. A stateful network routing service may intercept packets and determine the packets are to be sent to a full-proxy mode appliance. Based on this determination, the stateful network routing service may obtain or generate flow identification information to identify the packet. The stateful network routing service may add the information to the packet and transmit the enriched packet to a full-proxy mode network appliance. The stateful network routing service may receive a second enriched packet from the network appliance. The stateful network routing service can parse the second enriched packet for flow identification information and identify the second enriched packet based on the flow identification information.