User-Defined Connectors for Serverless Access to Isolated Clouds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing serverless computing systems face challenges in enabling secure and controlled network communications between dynamically created execution environments and isolated cloud resources due to the lack of fixed network addresses, complicating access management and scalability.

Innovation Solution

Implementing user-defined network connectors that operate based on cloud-assigned metadata, allowing end users to manage and control network traffic between serverless functions and isolated cloud resources, ensuring secure and controlled communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional networking technologies relying on fixed MAC or IP addresses are used, then network communication control is simplified, but serverless computing systems cannot provide dynamic execution environments without fixed network addresses

Engineering Contradiction:
Improvedynamic execution environmentVSAvoidnetwork communication control
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a connector as an intermediary component that bridges serverless execution environments and isolated cloud resources. The connector operates at the network layer, translating between dynamic serverless function identifiers and the metadata required for network communication, thereby enabling control without relying on fixed MAC or IP addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the fundamental parameter for network identification from fixed hardware addresses (MAC/IP) to dynamic function identifiers combined with connector metadata. This parameter transformation allows the network system to adapt to the ephemeral nature of serverless execution environments while maintaining controlled access to cloud resources.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If users can directly access execution environments, then network control and security management are simplified, but serverless computing removes the need for users to manage execution environments

Engineering Contradiction:
Improveuser management of execution environmentsVSAvoidnetwork access control
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The connector serves as a user-managed intermediary between the serverless execution environment and cloud resources. Users configure the connector with security rules and access policies, which the connector then enforces automatically. This allows users to maintain security control without needing to directly manage or access the underlying execution environment infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The connector enables users to self-configure network access control by defining security rules and permissions through high-level abstractions. The system automatically handles the complex network configuration and enforcement, allowing users to manage security without dealing with low-level network details or execution environment management.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If connectors are transparently managed by the serverless computing system, then user control is reduced, but automatic connector creation simplifies the user experience

Engineering Contradiction:
Improveconnector managementVSAvoiduser control over network traffic
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The connector is designed to be dynamically configurable by users after creation. Users can modify security rules, update access policies, and adjust network traffic control parameters in real-time based on changing requirements. This dynamic configurability ensures users retain full control over network traffic while benefiting from automated connector provisioning.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12381877B2User-defined network connectors between serverless functions and isolated cloud resources
Publication Date: 2025.08.05 AMAZON TECH INC
  • US12381877B2 patent drawing
  • US12381877B2 patent drawing
  • US12381877B2 patent drawing

AI summary

Systems and methods are described for facilitating network traffic between serverless function executions and isolated cloud resources within virtualized network environments. Virtualized network environments, by default, may be isolated such that external traffic is not permitted to enter the environment. Permissions for traffic that may enter the environment are often set on the basis of network addresses. In the context of serverless functions, such permissions may be difficult to establish because executions of serverless functions can occur on a dynamically selected environment without a fixed network address. The present disclosure provides for creation of user-defined connectors that facilitate routing of network traffic between executions of serverless functions and user virtualized network environments without requiring that routing occur on the bases of network addresses.