Stateless Network Routing Service Bidirectional Flow Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network appliances in data centers lack scalability, security, and fault tolerance, leading to potential errors, data exfiltration, and single points of failure, while also increasing memory demands and complexity.

Innovation Solution

A managed appliance gateway service that enables user-defined arbitrary routing decisions, flexible and elastic routing of network traffic, secure traffic steering, stateful routing, and secure traffic steering across availability zones, using a stateful network routing service that processes packets at layer 3 of the OSI model and supports custom tuple definitions for load balancing and network address translation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network appliances are deployed to provide networking services, then security and traffic control capabilities are improved, but scalability and fault tolerance deteriorate due to single points of failure

Engineering Contradiction:
Improvefault toleranceVSAvoidappliance deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network appliance functionality into distributed virtual network functions (VNFs) that can be independently deployed and managed across multiple physical hosts. This segmentation eliminates single points of failure by distributing security and traffic control capabilities across multiple instances, allowing the system to maintain functionality even when individual components fail.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal virtual network function platform that can host multiple types of network appliances (firewalls, load balancers, intrusion detection systems) as software instances. This multi-functionality allows a single infrastructure to provide diverse networking services, improving reliability through redundancy while reducing the need for specialized hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If network appliances are deployed to secure traffic and provide services, then security capabilities are improved, but memory demands and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple network appliance functions into a shared virtualized infrastructure where security services, traffic control, and networking functions coexist on common hardware resources. This consolidation eliminates redundant memory usage across separate physical appliances while maintaining security capabilities through virtualized instances that share the underlying memory pool efficiently.

Inventive Principle:
Principle #5Merging (Combining)

3Speed

If stateless routing service is used to route traffic, then routing speed and simplicity are improved, but ability to maintain bidirectional flow consistency deteriorates

Engineering Contradiction:
Improverouting speedVSAvoidflow consistency
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-computing and caching routing decisions based on flow identifiers before traffic arrives. The stateless routing service uses预先 established routing rules and hash-based lookup tables to determine appliance assignments in advance, enabling fast stateless forwarding while maintaining flow consistency through pre-configured routing policies that ensure bidirectional traffic follows the same path.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11310149B1Routing bidirectional flows in a stateless routing service
Publication Date: 2022.04.19 AMAZON TECH INC
  • US11310149B1 patent drawing
  • US11310149B1 patent drawing
  • US11310149B1 patent drawing

AI summary

Systems and methods are provided to enable packets of network traffic to be routed to a network appliance. Bidirectional flows of network traffic can be routed to the same network appliance based on flow information of the corresponding packets. A network device may intercept the packet corresponding to a first flow and route the packet to a specific network appliance based on the first flow information. The network device may generate a direction agnostic tuple value based on data groups of the first flow information. The network device may propagate the direction agnostic tuple value across availability zones to a second network device in a different availability zone to store the direction agnostic tuple value for use for subsequent packets. The second network device can receive a second packet and transmit the second packet to the same network appliance based on the direction agnostic tuple value.