Virtual Network Transit Centers for Secure Peering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual network environments, there is no conventional method for establishing peerings between virtual private networks, similar to physical transit centers where physical cables are patched to create peering between data centers, leading to complexities in managing and securing connections between discrete, routed IP containers hosted on provider networks.

Innovation Solution

The implementation of a peering service and API within provider networks allows clients to dynamically establish and manage virtual network transit centers, enabling the creation of virtual peerings between private networks through encapsulation protocol technology, which routes packets over an overlay network, facilitating secure and isolated communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual network environments use conventional routing methods without virtual transit centers, then network connectivity between virtual private networks is achieved, but network security and isolation are compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual transit center as an intermediary component that mediates connections between virtual private networks. This virtual transit center acts as a controlled gateway that enforces security policies and routing rules, providing isolation and security similar to physical transit centers but in a virtualized environment. The intermediary controls traffic flow between VNets, preventing direct peer-to-peer connections that would compromise security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If physical transit centers with patched cables are used for data center peering, then secure and isolated communication is achieved, but adaptability to virtual network environments is lost

Engineering Contradiction:
Improvevirtual network adaptabilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a virtual copy of the physical transit center concept, implementing a virtual transit center that replicates the security and isolation properties of physical transit centers in a virtualized environment. Instead of physically patching cables between data centers, the system creates virtual representations of transit centers that enforce similar security boundaries and routing controls through software-based networking infrastructure.

Inventive Principle:
Principle #26Copying

3Productivity

If virtual private networks are routed over provider networks without virtual peerings, then network scalability is improved, but connection security and traffic isolation are weakened

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidtraffic interference
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the virtual network traffic by introducing virtual peerings that create distinct, isolated connection paths between VNets. Each virtual peering establishes a separate logical channel that segments traffic flows, preventing interference between different virtual networks while maintaining scalability. This segmentation allows multiple isolated connections to coexist on the shared provider network infrastructure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11770364B2Private network peering in virtual network environments
Publication Date: 2023.09.26 AMAZON TECH INC
  • US11770364B2 patent drawing
  • US11770364B2 patent drawing
  • US11770364B2 patent drawing

AI summary

Methods and apparatus for private network peering in virtual network environments in which peerings between virtual client private networks on a provider network may be established by clients via an API to a peering service. The peering service and API 104 may allow clients to dynamically establish and manage virtual network transit centers on the provider network at which virtual ports may be established and configured, virtual peerings between private networks may be requested and, if accepted, established, and routing information for the peerings may be specified and exchanged. Once a virtual peering between client private networks is established, packets may be exchanged between the respective client private networks via the peering over the network substrate according to the overlay network technology used by the provider network, for example an encapsulation protocol technology.