Virtual Private Gateways for Scalable Data Center Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center connectivity solutions using proprietary network devices and complex routing protocols often lead to high costs, sub-optimal routing, and increased false positive/false negative failure detection rates, especially when establishing secure VPN connections between customer data centers and provider networks.

Innovation Solution

Implementing virtual private gateways (VPGs) using compute instances within a provider network, which enables scalable, fault-resilient, and cost-effective connectivity by utilizing protocol processing engines (PPEs) and a multi-layer health monitoring service for proactive failure management and optimized routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary network devices are used for gateways, then connectivity between data centers and provider networks is established, but costs increase and device complexity increases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidgateway device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses virtual machine instances as software copies of gateway functionality instead of physical proprietary network devices. These virtual gateway instances replicate the routing and connectivity functions of traditional hardware gateways, eliminating the need for expensive proprietary equipment while maintaining the same operational capabilities through software-based routing protocols and network address translation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces mechanical/physical proprietary network devices with software-based virtual machine instances running on standard hardware. This substitution eliminates dependence on specialized hardware while achieving the same gateway functions through virtualized routing protocols, BGP speakers, and network address translation implemented in software.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If complex routing protocols are used, then routing functionality is provided, but routing efficiency decreases and false positive/false negative failure detection rates increase

Engineering Contradiction:
Improverouting protocol compatibilityVSAvoidrouting efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the routing functionality into separate virtual machine instances, with each instance running a single BGP speaker or routing function. This segmentation isolates routing processes, allowing independent failure detection and recovery without affecting the entire routing system. Each virtual gateway instance can be independently monitored and restarted, improving overall routing efficiency and reducing false failure detections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a control plane component that acts as an intermediary between the data plane virtual gateways and the routing infrastructure. This control plane manages route propagation, monitors health status, and coordinates failover events, simplifying the routing protocol interactions and reducing the complexity of failure detection while maintaining full routing protocol compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional failure detection techniques are used, then failure monitoring is provided, but false positive rates and false negative rates increase

Engineering Contradiction:
Improvefailure detection accuracyVSAvoidfailure detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements a control plane that continuously monitors the health status of virtual gateway instances and provides feedback for automatic failover decisions. This feedback mechanism tracks routing table updates, BGP session status, and instance health metrics, enabling precise failure detection with reduced false positives. The system only triggers failover when genuine failures are detected, improving measurement precision while maintaining high reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10313225B1Scalable routing service
Publication Date: 2019.06.04 AMAZON TECH INC
  • US10313225B1 patent drawing
  • US10313225B1 patent drawing
  • US10313225B1 patent drawing

AI summary

A message indicating a route to a network destination is received at a routing service from a particular routing device of a provider network. The message is formatted in accordance with a set of APIs implemented using a stateless protocol, and indicates a route to a particular network destination associated with a particular RIB stored at a persistent data store accessible from various nodes of the routing service. The RIB is modified accordingly. A routing service back-end node generates an entry of a forwarding information base (FIB) associated with the particular RIB. The FIB entry is transmitted to one or more routing devices including the particular routing device, and is used to forward data packets of one or more other services.