Virtual Network Gateway for Scalable Security Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions rely on expensive hardware that is difficult to configure and maintain, and do not automatically scale with demand or threat levels, leading to productivity disruptions and inefficiencies.

Innovation Solution

A system that provides network connectivity and related services through scalable computing resources, allowing customer entities to access network-related services such as DDoS protection, firewalling, and spam control via a computing resource provider, which can be configured and maintained programmatically, using APIs or UIs, and scaled based on demand.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based threat management solutions are deployed, then network security protection is improved, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvenetwork security protectionVSAvoidhardware configuration and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware appliances with virtualized software instances that replicate security functions. Virtual appliances can be deployed as copies across multiple hosts, enabling easy provisioning and scaling without physical hardware manipulation. This resolves the contradiction by maintaining security functionality while eliminating hardware complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes mechanical hardware-based security appliances with software-based virtual appliances managed through automated orchestration systems. The mechanical aspect of physically deploying and configuring hardware is replaced with software deployment mechanisms, eliminating the complexity of hardware maintenance while preserving security protection capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If dedicated hardware security appliances are deployed, then network security capabilities are improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork security capabilitiesVSAvoidconfiguration and maintenance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities where virtual security appliances automatically provision themselves, configure their settings, and manage their deployment lifecycle through orchestration systems. This eliminates the need for manual configuration and maintenance operations, resolving the contradiction by maintaining security capabilities while dramatically improving ease of operation through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the orchestration system continuously monitors the state and performance of virtual security appliances, automatically adjusting configurations and resource allocation based on observed conditions. This closed-loop control enables secure operation without manual intervention, resolving the contradiction between security effectiveness and operational simplicity.

Inventive Principle:
Principle #23Feedback

3Reliability

If hardware-based security solutions are implemented, then network protection is improved, but productivity deteriorates due to disruptions

Engineering Contradiction:
Improvenetwork protectionVSAvoidorganizational productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic virtual security appliances that can be rapidly deployed, moved, scaled, and updated without physical hardware constraints. This dynamic nature allows security protections to be implemented and modified without organizational disruptions, resolving the contradiction by maintaining network protection while preserving productivity through flexible, non-intrusive deployment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables preliminary provisioning and testing of virtual security appliances in isolated environments before production deployment. This allows security configurations to be validated and optimized in advance, ensuring network protection is in place without causing disruptions to organizational productivity during implementation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If hardware security appliances are deployed, then network security is improved, but adaptability deteriorates as they cannot automatically scale

Engineering Contradiction:
Improvenetwork securityVSAvoidautomatic scaling capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic virtual security appliances that can be rapidly deployed, moved, scaled, and updated without physical hardware constraints. This dynamic nature allows security protections to be implemented and modified without organizational disruptions, resolving the contradiction by maintaining network protection while preserving productivity through flexible, non-intrusive deployment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates universal virtual security appliance templates that can be instantiated multiple times across different hosts and network segments, providing consistent security functionality throughout the infrastructure. These virtual appliances can be scaled horizontally by deploying additional instances rather than requiring hardware upgrades, resolving the contradiction between security effectiveness and adaptability to changing demands.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10382561B1Intelligent network service provisioning and maintenance
Publication Date: 2019.08.13 AMAZON TECH INC
  • US10382561B1 patent drawing
  • US10382561B1 patent drawing
  • US10382561B1 patent drawing

AI summary

A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.