Virtual Networking Devices for Managed Computer Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large-scale computer networks has become increasingly complex due to the scale and scope of data centers, requiring efficient and secure provisioning, administration, and management of physical computing resources, while existing virtualization technologies do not fully address the need for flexible and scalable network configurations.

Innovation Solution

A configurable network service (CNS) that enables users to specify and manage network topologies for managed computer networks by creating virtual overlay networks on intermediate physical networks, allowing for the emulation of networking devices and routing without physical implementation, using modules like the Network Routing Manager (NRM) and Communication Manager to handle communications and routing information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical networking devices are deployed to manage large-scale computer networks, then network functionality can be provided, but device complexity and management difficulty increase significantly

Engineering Contradiction:
Improvenetwork configuration flexibilityVSAvoidphysical infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements virtual networking devices that replicate the functionality of physical networking devices (routers, switches, firewalls) in software form. These virtual devices can be instantiated, configured, and managed through software interfaces rather than physical deployment, reducing infrastructure complexity while maintaining network management capabilities. The virtual devices are deployed within virtualized environments to provide networking functions without requiring corresponding physical hardware for each function.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical networking infrastructure with virtualized networking components that operate through software and hypervisor layers. Instead of deploying physical routers and switches for each network function, the system uses virtual machine instances and software-defined networking components that can be dynamically allocated and configured through virtualization platforms, eliminating the need for complex physical infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If more physical networking devices are added to support diverse network topologies, then network functionality is enhanced, but provisioning and administration become increasingly complicated

Engineering Contradiction:
Improvenetwork topology configurationVSAvoidprovisioning and administration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent uses virtual networking devices that can be cloned and instantiated through software interfaces. Network topologies can be provisioned by deploying virtual devices and configuring their connections through virtualization management systems rather than physically installing and configuring multiple networking devices. This virtualized approach simplifies provisioning by allowing automated deployment and configuration of network topologies through software tools.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements a universal virtualization platform that can provide multiple network functions through a single virtualized infrastructure. The same virtualized environment can support various network topologies and configurations by dynamically instantiating different virtual networking devices as needed, eliminating the requirement for specialized physical devices for each network function and simplifying administration through unified management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If virtualization technologies are used to share computing resources, then resource efficiency improves, but network isolation and security management become more challenging

Engineering Contradiction:
Improveresource sharing efficiencyVSAvoidnetwork isolation and security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments network traffic and resources at multiple levels within the virtualized environment. Virtual networking devices create logical separation between different virtual machines and network segments, ensuring that network isolation and security policies can be enforced independently for each virtual network. This segmentation allows efficient resource sharing while maintaining distinct security boundaries through virtual network segments that can be independently managed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network infrastructure as an intermediary layer between physical hardware and virtual computing resources. This intermediary virtual networking layer handles security and isolation functions by mediating all network traffic between virtual machines and the physical network. The virtual networking devices act as intermediaries that enforce security policies, manage isolation between different virtual networks, and provide centralized security management while allowing efficient resource sharing underneath.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240275689A1Providing virtual networking device functionality for managed computer networks
Publication Date: 2024.08.15 AMAZON TECH INC
  • US20240275689A1 patent drawing
  • US20240275689A1 patent drawing
  • US20240275689A1 patent drawing

AI summary

Techniques are described for providing virtual networking functionality for managed computer networks. In some situations, a user may configure or otherwise specify a logical network topology for a managed computer network with multiple computing nodes that includes one or more virtual networking devices each associated with a specified group of the multiple computing nodes. Corresponding networking functionality may be provided for communications between the multiple computing nodes by emulating functionality that would be provided by the networking devices if they were physically present and configured to support the specified network topology. In some situations, the managed computer network is a virtual computer network overlaid on a substrate network, and the networking device functionality emulating includes receiving routing communications directed to the networking devices and using included routing information to update the specified network topology for the managed computer network.