Virtual Machine Data Transmission Management for Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional firewall technologies in data centers are inadequate for dynamically managing network isolation across large-scale virtualized environments, as they struggle to adapt to dynamic resource provisioning and fail to enforce appropriate filtering rules, leading to potential resource outages and manual configuration challenges.

Innovation Solution

Implementing a Data Transmission Management (DTM) system that uses intermediary computing nodes to analyze and manage data transmissions between virtual machines, dynamically determining authorization based on defined policies and group memberships, and negotiating access rights to enforce communication policies automatically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall technologies are used to filter incoming network traffic at the destination, then network traffic filtering is provided, but malicious applications can still cause resource outages by flooding the network with traffic and manual configuration is time-consuming and error-prone

Engineering Contradiction:
Improvenetwork securityVSAvoidmanual configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic firewall rule generation and configuration by having the source computing system autonomously determine authorization requirements and generate corresponding firewall rules at the destination system, eliminating the need for manual configuration while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authorization determination at the source system before traffic reaches the destination, pre-configuring the necessary firewall rules in advance based on the authorization decision, so that subsequent traffic flow is automatically controlled without manual intervention

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional firewalls are configured to block incoming network traffic at the destination, then some network security is provided, but firewalls lack the ability to dynamically determine appropriate filtering rules for highly dynamic resource provisioning

Engineering Contradiction:
Improvenetwork isolationVSAvoiddynamic rule modification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically generates and updates firewall rules based on real-time authorization decisions made at the source system, allowing the filtering rules to adapt automatically to changing resource provisioning conditions without requiring static pre-configuration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the source system's authorization determination is communicated to the destination system's firewall, enabling the firewall to continuously adjust its filtering rules based on the current authorization state and dynamically respond to changing conditions

Inventive Principle:
Principle #23Feedback

3Reliability

If firewalls filter incoming traffic at the destination, then incoming traffic is controlled, but this allows malicious applications to cause resource outages by flooding the network with traffic before the firewall can block it

Engineering Contradiction:
Improvetraffic filteringVSAvoidnetwork flooding
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs authorization determination and firewall rule configuration at the source system before malicious traffic can flood the network, preventing harmful traffic from being generated in the first place by blocking it at the origin based on pre-established authorization rules

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12003548B2Transmissions management rules for virtual machine communications
Publication Date: 2024.06.04 AMAZON TECH INC
  • US12003548B2 patent drawing
  • US12003548B2 patent drawing
  • US12003548B2 patent drawing

AI summary

Techniques are described for managing communications between multiple intercommunicating computing nodes, such as multiple virtual machine nodes hosted on one or more physical computing machines or systems. In some situations, users may specify groups of computing nodes and optionally associated access policies for use in the managing of the communications for those groups, such as by specifying which source nodes are allowed to transmit data to particular destinations nodes. In addition, determinations of whether initiated data transmissions from source nodes to destination nodes are authorized may be dynamically negotiated for and recorded for later use in automatically authorizing future such data transmissions without negotiation. This abstract is provided to comply with rules requiring an abstract, and it is submitted with the intention that it will not be used to interpret or limit the scope or meaning of the claims.