-
公开(公告)号:US12021902B1
公开(公告)日:2024-06-25
申请号:US17643769
申请日:2021-12-10
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Justin Lin Hsieh , Daniel William Dacosta , Nick Matthews , Viktor Heorhiadi , Lalith Kumar Ramamoorthi , Anoop Dawani , Omer Hashmi , Thomas Nguyen Spendley
CPC classification number: H04L63/205 , H04L12/4675 , H04L41/0893 , H04L45/24 , H04L47/20 , H04L63/0272
Abstract: Systems and methods are provided for evaluation of communication paths through networks to determine whether communication is permitted across one or more internal network boundaries. The analysis may be used to determine whether a node in one isolated network (e.g., VPC, VPN, client on-premise network, etc.) is able to communicate with a node in another isolated network across region and/or segment boundaries. The automated analysis can allow users (e.g., network administrators) to see what high-level policies (e.g., Cloud WAN policies written in a declarative language) are interfering with or permitting communication between the nodes.
-
公开(公告)号:US20240039895A1
公开(公告)日:2024-02-01
申请号:US18487575
申请日:2023-10-16
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Omer Hashmi , Sanjay Bhal
CPC classification number: H04L63/0272 , H04L67/10 , H04L12/66 , H04L12/4633 , H04L63/0428 , H04L63/18
Abstract: A request to establish an encrypted VPN connection between a network and the provider network via a dedicated direct physical link and a set of resources of the provider network is received. An isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. Protocol processing engines (PPEs) are instantiated within the IVN, address information of the PPEs is exchanged with the external network and an encrypted VPN tunnel is configured between the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.
-
公开(公告)号:US20230179517A1
公开(公告)日:2023-06-08
申请号:US18160997
申请日:2023-01-27
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L45/586 , H04L45/02 , H04L45/16
CPC classification number: H04L45/586 , H04L45/04 , H04L45/16
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US11533231B2
公开(公告)日:2022-12-20
申请号:US16699424
申请日:2019-11-29
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Omer Hashmi , Thomas Nguyen Spendley , Nikhil Reddy Cheruku , Alok Mishra , Alexander Justin Penney
IPC: H04L41/12 , H04L41/0893 , H04L12/46 , H04L41/22
Abstract: This disclosure describes techniques for configuring and managing scalable global private networks associated with a service provider. Different input mechanisms, such as an API, a UI, or a CLI may be utilized to configure, and manage a global private network that spans across the cloud in different geographic locations and connects to different stand-alone networks. The user may proactively use the input mechanisms to configure and query different network resources to reactively configure settings for reacting to one or more events. The input mechanisms may also be utilized to define the network resources to be modeled within the global private network as well as connections within the global network. A user may configure events/metrics to be monitored, tasks/workflows to be performed, and the like. In some configurations, a network management service (NMS) may perform health monitoring and reachability monitoring to identify possible issues in the global network.
-
公开(公告)号:US20210168056A1
公开(公告)日:2021-06-03
申请号:US16699431
申请日:2019-11-29
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Omer Hashmi , Thomas Nguyen Spendley , Nikhil Reddy Cheruku , Alok Mishra , Alexander Justin Penney
Abstract: This disclosure describes techniques for configuring and managing scalable global private networks associated with a service provider. Different input mechanisms, such as an API, a UI, or a CLI may be utilized to configure, and manage a global private network that spans across the cloud in different geographic locations and connects to different stand-alone networks. The user may proactively use the input mechanisms to configure and query different network resources to reactively configure settings for reacting to one or more events. The input mechanisms may also be utilized to define the network resources to be modeled within the global private network as well as connections within the global network. A user may configure events/metrics to be monitored, tasks/workflows to be performed, and the like. In some configurations, a network management service (NMS) may perform health monitoring and reachability monitoring to identify possible issues in the global network.
-
公开(公告)号:US20210168036A1
公开(公告)日:2021-06-03
申请号:US16699446
申请日:2019-11-29
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Bashuman Deb , Omer Hashmi , Thomas Nguyen Spendley , Nikhil Reddy Cheruku , Alok Mishra , Alexander Justin Penney
Abstract: This disclosure describes techniques for configuring and managing scalable global private networks associated with a service provider. Different input mechanisms, such as an API, a UI, or a CLI may be utilized to configure, and manage a global private network that spans across the cloud in different geographic locations and connects to different stand-alone networks. The user may proactively use the input mechanisms to configure and query different network resources to reactively configure settings for reacting to one or more events. The input mechanisms may also be utilized to define the network resources to be modeled within the global private network as well as connections within the global network. A user may configure events/metrics to be monitored, tasks/workflows to be performed, and the like. In some configurations, a network management service (NMS) may perform health monitoring and reachability monitoring to identify possible issues in the global network.
-
公开(公告)号:US10757009B2
公开(公告)日:2020-08-25
申请号:US16196717
申请日:2018-11-20
Applicant: Amazon Technologies, Inc.
Inventor: Bashuman Deb , Paul John Tillotson , Thomas Nguyen Spendley , Omer Hashmi , Baihu Qian , Mohamed Nader Farahat Hassan
IPC: H04L12/715 , H04L12/721
Abstract: Network pathways are identified to transfer packets between a pair of regional virtual traffic hubs of a provider network. At a first hub of the pair, a first action is performed, resulting in a transmission of a packet received from a first isolated network to the second hub along a pathway selected using dynamic routing parameters. At the second hub, a second action is performed, resulting in the transmission of the packet to a destination within a second isolated network.
-
公开(公告)号:US20200252375A1
公开(公告)日:2020-08-06
申请号:US16785211
申请日:2020-02-07
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Omer Hashmi , Sanjay Bhal
Abstract: A request to establish an encrypted VPN connection between a network external to a provider network connected to the provider network via a dedicated direct physical link and a set of resources of the provider network is received. A new isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. One or more protocol processing engines (PPEs) are instantiated within the IVN, address information of the one or more PPEs is exchanged with the external network and a respective encrypted VPN tunnel is configured between each of the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.
-
公开(公告)号:US12212482B2
公开(公告)日:2025-01-28
申请号:US17933067
申请日:2022-09-16
Applicant: Amazon Technologies, Inc.
Inventor: Bashuman Deb , Paul John Tillotson , Thomas Nguyen Spendley , Omer Hashmi , Baihu Qian , Mohamed Nader Farahat Hassan
Abstract: Network pathways are identified to transfer packets between a pair of regional virtual traffic hubs of a provider network. At a first hub of the pair, a first action is performed, resulting in a transmission of a packet received from a first isolated network to the second hub along a pathway selected using dynamic routing parameters. At the second hub, a second action is performed, resulting in the transmission of the packet to a destination within a second isolated network.
-
公开(公告)号:US11831611B2
公开(公告)日:2023-11-28
申请号:US16785211
申请日:2020-02-07
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Omer Hashmi , Sanjay Bhal
CPC classification number: H04L63/0272 , H04L12/4633 , H04L12/66 , H04L63/0428 , H04L63/18 , H04L67/10
Abstract: A request to establish an encrypted VPN connection between a network external to a provider network connected to the provider network via a dedicated direct physical link and a set of resources of the provider network is received. A new isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. One or more protocol processing engines (PPEs) are instantiated within the IVN, address information of the one or more PPEs is exchanged with the external network and a respective encrypted VPN tunnel is configured between each of the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.
-
-
-
-
-
-
-
-
-