Virtual Private Gateways for Data Center Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center connectivity solutions using proprietary network devices and complex routing protocols often result in high costs, sub-optimal performance, and increased failure detection rates due to inefficient routing and resilience issues.

Innovation Solution

Implementing virtual private gateways (VPGs) using compute instances within a provider network, which enable secure and scalable connectivity between customer data centers and isolated virtual networks, leveraging protocol processing engines (PPEs) for efficient routing and health monitoring to ensure high availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary network devices are used for gateways, then connectivity between data centers and virtual networks is established, but costs increase and device complexity increases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidgateway device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces proprietary physical gateway devices with virtual gateway instances that replicate gateway functionality through software. These virtual gateways are implemented as virtual machine instances on standard server hardware, copying the essential routing and networking functions of proprietary devices without requiring specialized hardware, thereby reducing cost and complexity while maintaining connectivity reliability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes mechanical/physical proprietary network devices with software-based virtual gateway implementations running on virtualized infrastructure. This replacement transitions from hardware-dependent gateway functions to software-defined networking capabilities, eliminating the need for specialized proprietary equipment while preserving gateway functionality through virtualized network functions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If complex routing protocols are implemented, then network connectivity is achieved, but performance decreases and false failure detection increases

Engineering Contradiction:
Improvenetwork connectivityVSAvoidrouting performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the routing functionality into distributed virtual gateway instances that independently handle routing decisions using simplified protocols. Rather than implementing complex centralized routing logic, each virtual gateway instance autonomously manages its own routing table and forwarding decisions, dividing the routing task into manageable segments that improve overall performance and reduce false failure detections

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the routing protocol parameters by implementing simplified routing logic in the virtual gateways compared to complex proprietary protocols. The virtual gateways use standard化的 routing mechanisms with optimized parameters for the virtualized environment, changing the operational characteristics of routing to achieve better performance while maintaining reliable network connectivity

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional failure detection methods are used, then component failures are detected, but false positive and false negative rates increase

Engineering Contradiction:
Improvefailure detection accuracyVSAvoidfailure detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where virtual gateway instances continuously monitor each other's health status and connectivity states. Health check protocols provide feedback loops that allow the system to dynamically adjust failure detection based on actual network conditions, reducing false positives by confirming failures through multiple verification steps and reducing false negatives by maintaining continuous monitoring of gateway instances

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary health checks and connectivity verification before declaring component failures. By implementing pre-failure detection mechanisms that monitor gateway instance health proactively, the system can distinguish between temporary network fluctuations and actual failures, improving measurement precision in failure detection by taking preliminary actions to verify true failure states before triggering failure responses

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230336449A1Multi-mode health monitoring service
Publication Date: 2023.10.19 AMAZON TECH INC
  • US20230336449A1 patent drawing
  • US20230336449A1 patent drawing
  • US20230336449A1 patent drawing

AI summary

A first analysis based on at least a subset of collected health metrics of a monitored resource is performed at a health monitoring service. If the first analysis indicates that the probability that the monitored resource is in an unhealthy state is above a threshold, a mitigation action that includes directing at least some of the workload away from the monitored resource is implemented. In addition, a remediation analysis of the monitored resource is started to determine, using at least one additional health metric that was not examined in the first analysis, whether a longer-term remediation action is to be initiated.