-
公开(公告)号:US11601365B2
公开(公告)日:2023-03-07
申请号:US17218036
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L45/586 , H04L45/02 , H04L45/16
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US20220321470A1
公开(公告)日:2022-10-06
申请号:US17218036
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L12/713 , H04L12/715 , H04L12/761
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US11743122B1
公开(公告)日:2023-08-29
申请号:US17709068
申请日:2022-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Samuel Bayless , John David Backes , Daniel William Dacosta , Vaibhav Katkade , Sagar Chintamani Joshi , Nadia Labai , Syed Mubashir Iqbal , Patrick Trentin , Nathan Launchbury , Nikolaos Giannarakis , Victor Heorhiadi , Nick Matthews
IPC: H04L41/0869 , H04L41/08 , H04L41/22 , H04L41/0816 , H04L41/14 , H04L41/147 , H04L9/40
CPC classification number: H04L41/0869 , H04L41/0816 , H04L41/0883 , H04L41/145 , H04L41/147 , H04L41/22 , H04L63/0263
Abstract: A network change verification (NCV) system is disclosed for checking whether a proposed configuration change on a network alters the way that the network controls recently observed network flows. In embodiments, the system builds an observed flow control model (OFCM) from logs of recent flows observed in the network. The OFCM, which may be periodically updated based on newly observed flows, provides a compact representation of how individual network flows were ostensibly controlled by the network. When a proposed configuration change is received, the system analyzes the change against the OFCM to check whether the change will alter how the network controls recently observed flows. If so, the proposed change is blocked, and an alert is generated identifying flows that are affected by the change. The NCV system thus prevents network operators from accidentally making changes on the network that will materially alter the behavior of the network.
-
公开(公告)号:US20230164076A1
公开(公告)日:2023-05-25
申请号:US17456548
申请日:2021-11-24
Applicant: Amazon Technologies, Inc.
Inventor: Anoop Dawani , Bashuman Deb , Baihu Qian , Omer Hashmi , Nick Matthews , Shridhar Kulkarni , Thomas Nguyen Spendley , Steve Ge , Justin Lin Hsieh , Guru Kannan , Alok Mishra
IPC: H04L45/745 , H04L12/46 , H04L12/66
CPC classification number: H04L45/745 , H04L12/4641 , H04L12/66
Abstract: Systems and methods are provided for management of network segments that cross geographic regions and/or other types of network divisions in a cloud-based network environment. A cloud-based network provider's geographically-dispersed network infrastructure may serve as the core of a client's private wide area network, and the client may define isolated segments to which other networks (virtual private clouds, virtual private networks, etc.) may be attached. The various segments may remain logically isolated from each other even when implemented across some or all of the same regions—and using the same physical and/or virtual routing components—as other segments of the same client and/or other clients.
-
公开(公告)号:US20240333775A1
公开(公告)日:2024-10-03
申请号:US18741445
申请日:2024-06-12
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Justin Lin Hsieh , Daniel William Dacosta , Nick Matthews , Viktor Heorhiadi , Lalith Kumar Ramamoorthi , Anoop Dawani , Omer Hashmi , Thomas Nguyen Spendley
IPC: H04L9/40 , H04L12/46 , H04L41/0893 , H04L45/24 , H04L47/20
CPC classification number: H04L63/205 , H04L12/4675 , H04L41/0893 , H04L45/24 , H04L47/20 , H04L63/0272
Abstract: Systems and methods are provided for obtaining policy data associated with a private network implemented at least partly within a cloud provider network; establishing, based on the policy data, a first segment within the private network, wherein in a first geographic region of the cloud provider network, traffic associated with the first segment is isolated from traffic associated with a second segment of the private network, and wherein in a second geographic region of the cloud provider network, traffic associated with the first segment is isolated from traffic associated with a third segment of the private network; obtaining metadata indicating an isolated network of the cloud provider network is associated with the first segment; and enabling the isolated network to communicate, over the first segment, across the first geographic region and the second geographic region.
-
公开(公告)号:US12021902B1
公开(公告)日:2024-06-25
申请号:US17643769
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Justin Lin Hsieh , Daniel William Dacosta , Nick Matthews , Viktor Heorhiadi , Lalith Kumar Ramamoorthi , Anoop Dawani , Omer Hashmi , Thomas Nguyen Spendley
CPC classification number: H04L63/205 , H04L12/4675 , H04L41/0893 , H04L45/24 , H04L47/20 , H04L63/0272
Abstract: Systems and methods are provided for evaluation of communication paths through networks to determine whether communication is permitted across one or more internal network boundaries. The analysis may be used to determine whether a node in one isolated network (e.g., VPC, VPN, client on-premise network, etc.) is able to communicate with a node in another isolated network across region and/or segment boundaries. The automated analysis can allow users (e.g., network administrators) to see what high-level policies (e.g., Cloud WAN policies written in a declarative language) are interfering with or permitting communication between the nodes.
-
公开(公告)号:US20230179517A1
公开(公告)日:2023-06-08
申请号:US18160997
申请日:2023-01-27
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L45/586 , H04L45/02 , H04L45/16
CPC classification number: H04L45/586 , H04L45/04 , H04L45/16
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US11855893B2
公开(公告)日:2023-12-26
申请号:US17456548
申请日:2021-11-24
Applicant: Amazon Technologies, Inc.
Inventor: Anoop Dawani , Bashuman Deb , Baihu Qian , Omer Hashmi , Nick Matthews , Shridhar Kulkarni , Thomas Nguyen Spendley , Steve Ge , Justin Lin Hsieh , Guru Kannan , Alok Mishra
IPC: H04L45/745 , H04L12/66 , H04L12/46
CPC classification number: H04L45/745 , H04L12/4641 , H04L12/66
Abstract: Systems and methods are provided for management of network segments that cross geographic regions and/or other types of network divisions in a cloud-based network environment. A cloud-based network provider's geographically-dispersed network infrastructure may serve as the core of a client's private wide area network, and the client may define isolated segments to which other networks (virtual private clouds, virtual private networks, etc.) may be attached. The various segments may remain logically isolated from each other even when implemented across some or all of the same regions—and using the same physical and/or virtual routing components—as other segments of the same client and/or other clients.
-
公开(公告)号:US11799755B2
公开(公告)日:2023-10-24
申请号:US17456549
申请日:2021-11-24
Applicant: Amazon Technologies, Inc.
Inventor: Anoop Dawani , Bashuman Deb , Baihu Qian , Omer Hashmi , Nick Matthews , Shridhar Kulkarni , Thomas Nguyen Spendley , Indira Radhika Pulla , David Jonathan Adams , Nicholas Ryan Lombardi , Brandon Michael LaRue , Aaron Scott DeBruin , Ramin Ali Dousti
IPC: H04L45/00 , H04L45/02 , H04L45/302 , H04L45/44 , H04L9/40 , H04L45/50 , H04L45/021 , H04L41/0895 , H04L49/00
CPC classification number: H04L45/04 , H04L45/02 , H04L45/306 , H04L45/44 , H04L45/566 , H04L41/0895 , H04L45/021 , H04L45/507 , H04L49/3009 , H04L63/0272
Abstract: Systems and methods are provided for management of network segments that cross geographic regions and/or other types of network divisions in a cloud-based network environment. Gateway may manage traffic across regions using routing metadata that includes a segment identifier. The gateways may also signal their routes across regions based on segment data, and implement the signaled routes using segment-based routing policies. Route selection may be performed using optimization data.
-
公开(公告)号:US20220321469A1
公开(公告)日:2022-10-06
申请号:US17218031
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Indira Radhika Pulla , Ramin Ali Dousti , Nicholas Ryan Lombardi , Steve Ge , Nick Matthews , Anoop Dawani
IPC: H04L12/713 , H04L12/707 , H04L12/717 , H04L12/733 , H04L12/46
Abstract: A pair of virtual routers is configured. In response to programmatic requests, dynamic transfer of routing information between the routers in accordance with configuration settings indicated by a client is enabled. The routing information is associated with a set of isolated networks to which the virtual routers are attached. A network packet originating at an address in a first isolated network is transmitted to an address in a second isolated network using a route determined from routing information transmitted between the virtual routers according to the configuration settings.
-
-
-
-
-
-
-
-
-