User-Defined Connectors for Serverless Access to Isolated Clouds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing serverless computing systems face challenges in enabling secure and controlled network communications between dynamically created execution environments and isolated cloud resources due to the lack of fixed network addresses, complicating access management and scalability.
Innovation Solution
Implementing user-defined network connectors that operate based on cloud-assigned metadata, allowing end users to manage and control network traffic between serverless functions and isolated cloud resources, ensuring secure and controlled communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional networking technologies relying on fixed MAC or IP addresses are used, then network communication control is simplified, but serverless computing systems cannot provide dynamic execution environments without fixed network addresses
Solution Approach 1:
The patent introduces a connector as an intermediary component that bridges serverless execution environments and isolated cloud resources. The connector operates at the network layer, translating between dynamic serverless function identifiers and the metadata required for network communication, thereby enabling control without relying on fixed MAC or IP addresses.
Solution Approach 2:
The system changes the fundamental parameter for network identification from fixed hardware addresses (MAC/IP) to dynamic function identifiers combined with connector metadata. This parameter transformation allows the network system to adapt to the ephemeral nature of serverless execution environments while maintaining controlled access to cloud resources.
2Ease of operation
If users can directly access execution environments, then network control and security management are simplified, but serverless computing removes the need for users to manage execution environments
Solution Approach 1:
The connector serves as a user-managed intermediary between the serverless execution environment and cloud resources. Users configure the connector with security rules and access policies, which the connector then enforces automatically. This allows users to maintain security control without needing to directly manage or access the underlying execution environment infrastructure.
Solution Approach 2:
The connector enables users to self-configure network access control by defining security rules and permissions through high-level abstractions. The system automatically handles the complex network configuration and enforcement, allowing users to manage security without dealing with low-level network details or execution environment management.
3Ease of operation
If connectors are transparently managed by the serverless computing system, then user control is reduced, but automatic connector creation simplifies the user experience
Solution Approach 1:
The connector is designed to be dynamically configurable by users after creation. Users can modify security rules, update access policies, and adjust network traffic control parameters in real-time based on changing requirements. This dynamic configurability ensures users retain full control over network traffic while benefiting from automated connector provisioning.
Data Source
AI summary
Systems and methods are described for facilitating network traffic between serverless function executions and isolated cloud resources within virtualized network environments. Virtualized network environments, by default, may be isolated such that external traffic is not permitted to enter the environment. Permissions for traffic that may enter the environment are often set on the basis of network addresses. In the context of serverless functions, such permissions may be difficult to establish because executions of serverless functions can occur on a dynamically selected environment without a fixed network address. The present disclosure provides for creation of user-defined connectors that facilitate routing of network traffic between executions of serverless functions and user virtualized network environments without requiring that routing occur on the bases of network addresses.


