Virtualized Gateway Tunneling for Programmable Logical Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack efficient methods for programmatically configuring and accessing logical networks, particularly for remote communication between client devices and logical networks, which are essential for seamless connectivity and management of user permissions and network resources.

Innovation Solution

The implementation of a logical network configuration manager, user manager, and gateway that facilitate the creation, configuration, and management of logical networks through programmatic service calls, utilizing protocols like TACACS+, RADIUS, and Diameter for authentication, authorization, and accounting, enabling secure and efficient communication via logical network tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access methods are used for remote devices, then network connectivity can be established, but secure and efficient access to logical networks with proper user permission management cannot be achieved

Engineering Contradiction:
Improvesecure accessVSAvoidprogrammatic configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a gateway as an intermediary component that mediates between remote client devices and the logical network. The gateway receives programmatic service calls from remote devices, performs authentication and authorization, and manages network access on behalf of the client devices. This intermediary approach enables secure access while maintaining ease of programmatic operation, as the gateway handles the complexity of security management centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual configuration methods are used for network access, then user permissions can be managed, but efficient and scalable access for multiple remote devices cannot be achieved

Engineering Contradiction:
Improveefficient accessVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where the gateway automatically performs authentication, authorization, and account management functions through programmatic service calls. Remote client devices can independently request network access and user account creation without manual administrative intervention. The gateway autonomously manages the complexity of security policies and user permissions, enabling efficient and scalable access for multiple devices while reducing the perceived complexity for end users.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If existing network gateway approaches are used, then network access can be provided, but programmable service calls for automatic user account creation and permission management cannot be implemented

Engineering Contradiction:
Improveautomatic account creationVSAvoidservice call interface
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent creates a universal gateway interface that handles multiple functions through a standardized set of programmatic service calls. The same gateway infrastructure supports authentication, authorization, automatic user account creation, permission management, and network access control. This multi-functional approach enables high automation through programmatic calls while maintaining ease of operation through a unified, consistent interface that simplifies the complexity of multiple security functions into a single accessible system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12395396B2Techniques for accessing logical networks via a virtualized gateway
Publication Date: 2025.08.19 AMAZON TECH INC
  • US12395396B2 patent drawing
  • US12395396B2 patent drawing
  • US12395396B2 patent drawing

AI summary

Disclosed are various embodiments for receiving, via a network, a request from a client to establish a network tunnel over the network. Various embodiments can create a virtual network comprising a virtual network gateway in response to receiving a service call. Various embodiments can further allocate an available computing resource to the virtual network gateway to augment a first computing resource. Allocating the available computing resource can be performed in response to a usage of the first computing resource assigned to the virtual network gateway.