Virtual Network Resource Endpoints for Secure Cross-Network Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in providing private and secure connectivity across virtual network boundaries, especially for sensitive data and high-latency use cases, as existing technologies often rely on Internet gateways or virtual network peering, which may not meet security and compliance requirements.

Innovation Solution

The introduction of resource endpoints within virtual networks allows for private and secure connectivity by enabling direct connections between virtual networks, using resource owner and consumer endpoints for selective sharing and addressing of resources, thereby bypassing the Internet and enabling sub-millisecond latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Internet gateways or virtual network peering are used for connectivity across virtual network boundaries, then network connectivity is achieved, but security and compliance requirements for sensitive data are not met

Engineering Contradiction:
ImprovesecurityVSAvoidconnectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces private link endpoints as an intermediary component that enables secure connectivity between virtual networks. These endpoints act as controlled access points that allow private traffic flow while maintaining network isolation, thus achieving both security requirements and connectivity needs without exposing traffic to public Internet gateways or uncontrolled peering relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional network architectures are used for cross-network access, then connectivity is provided, but additional infrastructure like load balancers is required

Engineering Contradiction:
ImproveconnectivityVSAvoidinfrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the networking functionality from traditional infrastructure components like load balancers and gateways, consolidating it into the private link endpoint architecture. By taking out the need for separate load balancing infrastructure and integrating routing and access control directly into the endpoint mechanism, the system achieves connectivity with reduced infrastructure complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If direct connections between virtual networks are established, then latency is reduced to sub-millisecond levels, but security control over specific resources becomes more challenging

Engineering Contradiction:
ImprovelatencyVSAvoidaccess control
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent applies local quality by enabling selective resource sharing at the individual resource level rather than providing blanket network access. Each private link endpoint can be configured to expose specific resources (such as particular virtual machines or storage volumes) while maintaining isolation for other resources, thus achieving low-latency direct connections where needed while preserving granular security control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240205051A1Resource sharing between cloud-hosted virtual networks
Publication Date: 2024.06.20 AMAZON TECH INC
  • US20240205051A1 patent drawing
  • US20240205051A1 patent drawing
  • US20240205051A1 patent drawing

AI summary

Techniques for resource sharing between cloud-hosted virtual networks are described. A first network address of a first virtual network is associated with a resource connected to a second virtual network, the first and second virtual networks within a cloud provider network. A service of the cloud provider network receives a message destined for the first network address. The service translates the first network address to a second network address of the resource in the second virtual private network. The service sends the message to the resource at the second network address in the second virtual network.