Managed Virtual Network Private Access to External Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large-scale computer networks has become increasingly complex due to the scale and scope of data centers and computer networks, with challenges in provisioning, administering, and managing physical computing resources, especially in providing secure and efficient access to network-accessible services for multiple customers.

Innovation Solution

A configurable network service that provides managed virtual computer networks by overlaying them on substrate networks, using communication manager modules to facilitate secure and transparent communication with external network-accessible services, allowing clients to access services like LDAP, firewall, and VPN connections, while managing authentication and scaling of resources dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical computing resources are directly managed in large-scale data centers, then resource allocation and network access can be provided, but the complexity of provisioning, administering, and managing increases significantly

Engineering Contradiction:
Improveresource allocation capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A virtualization layer is introduced as an intermediary between physical computing resources and customers. This virtualization layer abstracts the physical infrastructure, providing virtual machines and network services that simplify management while maintaining resource allocation flexibility. The intermediary layer handles the complexity of resource provisioning and network configuration automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Virtual machines are created as software copies that simulate physical computing systems. Instead of managing physical hardware directly, the system creates virtual instances that provide the same functionality with simplified management. These virtual copies can be deployed, cloned, and migrated easily, reducing operational complexity while maintaining adaptability.

Inventive Principle:
Principle #26Copying

2Productivity

If multiple customers with diverse needs share computing resources, then resource utilization efficiency improves, but security isolation and application isolation become more challenging

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The computing resources are segmented into isolated virtual machines and network segments. Each customer or application gets its own virtual container with dedicated resources, ensuring security isolation while allowing efficient sharing of the underlying physical infrastructure. The network is divided into separate virtual networks that prevent unauthorized access between different customers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different virtual machines and network segments are assigned different security policies and access rights based on their specific requirements. The system provides customized security isolation at the local level for each virtual instance while maintaining overall system efficiency. This allows diverse customers to share resources with appropriate security boundaries.

Inventive Principle:
Principle #3Local quality

3Productivity

If network-accessible services are accessed directly from managed virtual networks, then service availability is improved, but secure communication and authentication complexity increases

Engineering Contradiction:
Improveservice availabilityVSAvoidcommunication management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

A communication manager module is introduced as an intermediary between virtual network nodes and external network-accessible services. This module handles authentication, authorization, and secure communication protocols automatically, simplifying the complexity of managing service access while ensuring security. The intermediary layer translates between different network protocols and manages connection security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9654340B2Providing private access to network-accessible services
Publication Date: 2017.05.16 AMAZON TECH INC
  • US9654340B2 patent drawing
  • US9654340B2 patent drawing
  • US9654340B2 patent drawing

AI summary

Techniques are described for managing communications for a managed virtual computer network overlaid on a distinct substrate computer network. The techniques may be used in situations in which a configurable network service provides managed virtual computer networks for clients and also provides one or more network-accessible services that are available to the managed virtual computer networks, with particular managed virtual computer networks being configured to provide local private access to at least one of the provided network-accessible services, despite those provided network-accessible services being located externally to the particular managed virtual computer networks. In some situations, a Lightweight Directory Access Protocol (“LDAP”) network-accessible service is provided, and a logical endpoint for the LDAP service is created within a managed virtual computer network to enable the multiple computing nodes of the managed virtual computer network to communicate with one or more LDAP computer servers from the LDAP service.