Virtualized Network Gateway for Scalable Security Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions rely on expensive hardware that is difficult to configure and maintain, and do not automatically scale with demand or threat levels, leading to productivity disruptions and inefficiencies.

Innovation Solution

A system that provides network connectivity and related services through scalable computing resources, allowing customer entities to access network services via a computing resource provider, which implements and manages network-related services such as DDoS protection, firewalling, and spam control using programmable APIs and interfaces, enabling intelligent provisioning, scaling, and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based network security appliances are deployed to protect against threats, then network security is improved, but device cost and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware configuration and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware security appliances with virtualized security functions implemented as software services on general-purpose computing infrastructure. Network security functions such as firewalling, intrusion detection, and threat protection are delivered as virtual network functions (VNFs) that can be deployed, configured, and managed through software without requiring dedicated hardware devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal security platform that can provide multiple security functions simultaneously on shared infrastructure. A single computing resource pool can host various security services (firewall, IDS/IPS, anti-spam, DDoS protection) that can be dynamically allocated to different customer entities, eliminating the need for separate hardware appliances for each security function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated hardware security appliances are deployed, then network security protection is improved, but ease of operation and maintenance deteriorates

Engineering Contradiction:
Improvenetwork security protectionVSAvoidconfiguration and maintenance difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities where customer entities can automatically provision, configure, and manage security services through software interfaces without requiring specialized hardware knowledge. The virtualized platform enables automated service deployment, dynamic configuration updates, and self-healing mechanisms that eliminate manual hardware intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a software-based intermediary layer (virtualization platform and service management system) between the customer entities and the underlying computing infrastructure. This intermediary abstracts the complexity of security service deployment and management, providing simplified interfaces while handling the intricate configuration and coordination of security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware-based security solutions are implemented, then network threat protection is improved, but adaptability to changing demands and threats deteriorates

Engineering Contradiction:
Improvethreat protectionVSAvoidscaling capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security services that can automatically scale their computational resources based on real-time threat levels and demand. The virtualized platform monitors network conditions and dynamically allocates computing, storage, and networking resources to security functions, enabling seamless scaling up during attacks and scaling down during normal operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables dynamic adjustment of security service parameters such as processing capacity, inspection depth, and resource allocation without requiring hardware changes. The software-based implementation allows parameters like throughput capacity, concurrent connection limits, and security policy complexity to be modified on-the-fly to match changing network conditions and threat landscapes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9294437B1Remotely configured network appliances and services
Publication Date: 2016.03.22 AMAZON TECH INC
  • US9294437B1 patent drawing
  • US9294437B1 patent drawing
  • US9294437B1 patent drawing

AI summary

A network gateway is implemented on behalf of a customer entity. The network gateway may be implemented using a distributed computer system and the network gateway may connect a network of the customer entity to a public communications network. The network gateway may include network-related services without the need for adding specialized hardware. The network gateway may be provisioned programmatically in response to instructions received from the customer entity. The network gateway may be provisionable and accessible over several different types of data connections. The network gateway, by virtue of being implemented on a distributed computer system, is scalable upon demand without additional input by the customer entity.