Virtual Private Gateways for Scalable Data Center Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data center connectivity solutions using proprietary network devices and complex routing protocols often lead to high costs, sub-optimal routing, and increased false positive/false negative failure detection rates, especially when establishing secure VPN connections between customer data centers and provider networks.
Innovation Solution
Implementing virtual private gateways (VPGs) using compute instances within a provider network, which enables scalable, fault-resilient, and cost-effective connectivity by utilizing protocol processing engines (PPEs) and a multi-layer health monitoring service for proactive failure management and optimized routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary network devices are used for gateways, then connectivity between data centers and provider networks is established, but costs increase and device complexity increases
Solution Approach 1:
The patent uses virtual machine instances as software copies of gateway functionality instead of physical proprietary network devices. These virtual gateway instances replicate the routing and connectivity functions of traditional hardware gateways, eliminating the need for expensive proprietary equipment while maintaining the same operational capabilities through software-based routing protocols and network address translation.
Solution Approach 2:
The patent replaces mechanical/physical proprietary network devices with software-based virtual machine instances running on standard hardware. This substitution eliminates dependence on specialized hardware while achieving the same gateway functions through virtualized routing protocols, BGP speakers, and network address translation implemented in software.
2Adaptability or versatility
If complex routing protocols are used, then routing functionality is provided, but routing efficiency decreases and false positive/false negative failure detection rates increase
Solution Approach 1:
The patent segments the routing functionality into separate virtual machine instances, with each instance running a single BGP speaker or routing function. This segmentation isolates routing processes, allowing independent failure detection and recovery without affecting the entire routing system. Each virtual gateway instance can be independently monitored and restarted, improving overall routing efficiency and reducing false failure detections.
Solution Approach 2:
The patent introduces a control plane component that acts as an intermediary between the data plane virtual gateways and the routing infrastructure. This control plane manages route propagation, monitors health status, and coordinates failover events, simplifying the routing protocol interactions and reducing the complexity of failure detection while maintaining full routing protocol compatibility.
3Reliability
If traditional failure detection techniques are used, then failure monitoring is provided, but false positive rates and false negative rates increase
Solution Approach 1:
The patent implements a control plane that continuously monitors the health status of virtual gateway instances and provides feedback for automatic failover decisions. This feedback mechanism tracks routing table updates, BGP session status, and instance health metrics, enabling precise failure detection with reduced false positives. The system only triggers failover when genuine failures are detected, improving measurement precision while maintaining high reliability.
Data Source
AI summary
A message indicating a route to a network destination is received at a routing service from a particular routing device of a provider network. The message is formatted in accordance with a set of APIs implemented using a stateless protocol, and indicates a route to a particular network destination associated with a particular RIB stored at a persistent data store accessible from various nodes of the routing service. The RIB is modified accordingly. A routing service back-end node generates an entry of a forwarding information base (FIB) associated with the particular RIB. The FIB entry is transmitted to one or more routing devices including the particular routing device, and is used to forward data packets of one or more other services.


