Virtual Private Gateways for Data Center Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center connectivity solutions using proprietary network devices and complex routing protocols often result in high costs, sub-optimal performance, and increased failure detection rates due to false positives and negatives, particularly in virtualized environments.

Innovation Solution

Implementing virtual private gateways (VPGs) using compute instances within a provider network, which establish secure VPN connections through protocol processing engines (PPEs) and a health monitoring service for fault resilience and scalable routing, reducing reliance on proprietary devices and simplifying routing protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary network devices are used for gateways, then connectivity between data centers and provider network is established, but costs increase and performance decreases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidgateway device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces proprietary physical gateway devices with virtual gateway instances that replicate gateway functionality through software. These virtual gateways are implemented as compute instances within the provider network, copying the essential routing and connectivity functions of traditional hardware gateways without requiring specialized physical devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes mechanical/physical gateway devices with a software-based virtualization system. Instead of relying on physical network appliances, the solution uses virtualized compute instances with integrated routing capabilities, replacing the mechanical hardware system with an information-processing software system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If complex routing protocols with complicated route selection logic are used, then routing between networks is achieved, but routing efficiency decreases and false failure detection increases

Engineering Contradiction:
Improverouting configurationVSAvoidrouting efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent changes the fundamental parameters of routing by transitioning from complex protocol-based route selection to simplified policy-based routing. The virtual gateway instances use configurable routing rules and priorities rather than complex protocol negotiations, fundamentally altering how routing decisions are made to improve efficiency and reduce false failure detections.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional failure detection techniques are used, then component failures are detected, but false positive and false negative rates increase

Engineering Contradiction:
Improvefailure detection accuracyVSAvoidfailure detection precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements health monitoring services that continuously monitor the state of virtual gateway instances and provide feedback for failure detection. The system uses health checks, status reporting, and automated monitoring to detect actual failures while filtering out false positives, improving both reliability and measurement precision of failure detection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9813379B1Virtual private gateways using compute instances
Publication Date: 2017.11.07 AMAZON TECH INC
  • US9813379B1 patent drawing
  • US9813379B1 patent drawing
  • US9813379B1 patent drawing

AI summary

A request to establish a VPN connection between a customer data center and a set of resources of a provider network is received. A new isolated virtual network (IVN) is established to implement a virtual private gateway to be used for the connection. One or more protocol processing engines (PPEs) are instantiated within the IVN, and a respective VPN tunnel is configured between each of the PPEs and the customer data center. Routing information pertaining to the set of resources is provided to the customer data center via at least one of the VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the customer data center.