-
公开(公告)号:US11843589B2
公开(公告)日:2023-12-12
申请号:US17404126
申请日:2021-08-17
Applicant: Amazon Technologies, Inc.
Inventor: Mark Edward Stalzer , Christian Arthur Arllen
IPC: H04L9/40 , H04L43/0811 , H04L45/302 , H04L67/14 , H04L41/046 , H04L12/14 , H04L41/0896
CPC classification number: H04L63/061 , H04L9/40 , H04L41/046 , H04L43/0811 , H04L45/306 , H04L63/0428 , H04L63/08 , H04L63/0853 , H04L63/10 , H04L67/14 , H04L12/1435 , H04L41/0896 , H04L63/0272
Abstract: A computing resource service provider receives a request from a customer to establish a physical connection between a provider network device and a customer network device in a colocation center. Once the connection has been established, the customer may transmit cryptographic authentication information, through the physical connection, to the provider network device. The provider network device transmits this information to an authentication service operated by the computing resource service provider to verify the authenticity of the information. If the information is authentic, the authentication service may re-configure the provider network device to allow the customer to access one or more services provided by the computing resource service provider. The authentication service may transmit cryptographic authentication information to the customer to verify the identity of the computing resource service provider.
-
公开(公告)号:US20230351458A1
公开(公告)日:2023-11-02
申请号:US18312525
申请日:2023-05-04
Applicant: Amazon Technologies, Inc.
Inventor: Shuai Ye , Mark Edward Stalzer , Patrick Brigham Cullen
IPC: G06Q30/04 , H04L43/0894 , H04L43/16 , H04L43/0876
CPC classification number: G06Q30/04 , H04L43/0894 , H04L43/16 , H04L43/0876
Abstract: Methods and apparatus for partitioned private interconnects to provider networks are described. At least a portion of available bandwidth of a private physical interconnect between a provider network and a connectivity intermediary's network is designated as the bandwidth limit of an interconnect partition set up on behalf of a customer at the request of the intermediary. The intermediary's network comprises one or more devices to which at least one of the customer's devices is connected. Access to one or more resources of the provider network via the interconnect is enabled. Traffic monitoring results associated with the interconnect are used to enforce the designated bandwidth limit of the partition.
-
公开(公告)号:US11682055B2
公开(公告)日:2023-06-20
申请号:US17156363
申请日:2021-01-22
Applicant: Amazon Technologies, Inc.
Inventor: Shuai Ye , Mark Edward Stalzer , Patrick Brigham Cullen
IPC: G06Q30/04 , H04L43/0876 , H04L43/0894 , H04L43/16
CPC classification number: G06Q30/04 , H04L43/0876 , H04L43/0894 , H04L43/16
Abstract: Methods and apparatus for partitioned private interconnects to provider networks are described. At least a portion of available bandwidth of a private physical interconnect between a provider network and a connectivity intermediary's network is designated as the bandwidth limit of an interconnect partition set up on behalf of a customer at the request of the intermediary. The intermediary's network comprises one or more devices to which at least one of the customer's devices is connected. Access to one or more resources of the provider network via the interconnect is enabled. Traffic monitoring results associated with the interconnect are used to enforce the designated bandwidth limit of the partition.
-
公开(公告)号:US20210392122A1
公开(公告)日:2021-12-16
申请号:US17404126
申请日:2021-08-17
Applicant: Amazon Technologies, Inc.
Inventor: Mark Edward Stalzer , Christian Arthur Arllen
IPC: H04L29/06 , H04L12/26 , H04L12/725 , H04L29/08 , H04L12/24
Abstract: A computing resource service provider receives a request from a customer to establish a physical connection between a provider network device and a customer network device in a colocation center. Once the connection has been established, the customer may transmit cryptographic authentication information, through the physical connection, to the provider network device. The provider network device transmits this information to an authentication service operated by the computing resource service provider to verify the authenticity of the information. If the information is authentic, the authentication service may re-configure the provider network device to allow the customer to access one or more services provided by the computing resource service provider. The authentication service may transmit cryptographic authentication information to the customer to verify the identity of the computing resource service provider.
-
公开(公告)号:US11108805B2
公开(公告)日:2021-08-31
申请号:US16020865
申请日:2018-06-27
Applicant: Amazon Technologies, Inc.
Inventor: Catherine Dodge , Nikhil Reddy Cheruku , John Byron Cook , Temesghen Kahsai Azene , William Jo Kocik , Sean McLaughlin , Mark Edward Stalzer , Blake Whaley , Yiwen Wu
IPC: G06F21/00 , H04L29/06 , G06F16/2455 , H04L12/24 , H04L12/26
Abstract: Methods, systems, and computer-readable media for automated packetless network reachability analysis are disclosed. An analysis is performed of network configuration data for a network comprising a host computer. Based at least in part on the analysis, one or more ports at the host computer that are reachable from another computer are determined. Based at least in part on the analysis, one or more routes to the one or more ports are determined. A report is generated that is descriptive of the one or more ports and the one or more routes.
-
公开(公告)号:US11088933B2
公开(公告)日:2021-08-10
申请号:US16252185
申请日:2019-01-18
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Mark Edward Stalzer , Marco Eulenfeld
IPC: H04L12/751
Abstract: A system includes a provider network and a client network connected via a dedicated physical connection. The client network and the provider network exchange routing information using routing protocol messages, such as border gateway protocol (BGP) update messages exchanged during a BGP session. A provider network includes tag field values in outgoing routing protocol messages that indicate a portion of the provider network wherein resources of the provider network associated with a corresponding route are located. The client network may use the tag field value to determine whether to add the route to a routing table of the client network. A client network may also include tag field values in outgoing routing protocol messages to a provider network. The tag field values may indicate what portions of the provider network are to receive the routes from the client network. For example a tag field value may indicate that a route is to be propagated within a limited portion of the provider network.
-
公开(公告)号:US20190173774A1
公开(公告)日:2019-06-06
申请号:US16252185
申请日:2019-01-18
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Mark Edward Stalzer , Marco Eulenfeld
IPC: H04L12/751 , H04L12/66
Abstract: A system includes a provider network and a client network connected via a dedicated physical connection. The client network and the provider network exchange routing information using routing protocol messages, such as border gateway protocol (BGP) update messages exchanged during a BGP session. A provider network includes tag field values in outgoing routing protocol messages that indicate a portion of the provider network wherein resources of the provider network associated with a corresponding route are located. The client network may use the tag field value to determine whether to add the route to a routing table of the client network. A client network may also include tag field values in outgoing routing protocol messages to a provider network. The tag field values may indicate what portions of the provider network are to receive the routes from the client network. For example a tag field value may indicate that a route is to be propagated within a limited portion of the provider network.
-
公开(公告)号:US10217145B1
公开(公告)日:2019-02-26
申请号:US14183160
申请日:2014-02-18
Applicant: Amazon Technologies, Inc.
Inventor: Shuai Ye , Mark Edward Stalzer , Patrick Brigham Cullen
Abstract: Methods and apparatus for partitioned private interconnects to provider networks are described. At least a portion of available bandwidth of a private physical interconnect between a provider network and a connectivity intermediary's network is designated as the bandwidth limit of an interconnect partition set up on behalf of a customer at the request of the intermediary. The intermediary's network comprises one or more devices to which at least one of the customer's devices is connected. Access to one or more resources of the provider network via the interconnect is enabled. Traffic monitoring results associated with the interconnect are used to enforce the designated bandwidth limit of the partition.
-
公开(公告)号:US09954763B1
公开(公告)日:2018-04-24
申请号:US14192476
申请日:2014-02-27
Applicant: .Amazon Technologies, Inc.
Inventor: Shuai Ye , Patrick Brigham Cullen , Mark Edward Stalzer
IPC: H04L12/28 , H04L12/56 , H04L12/715 , H04L12/707 , H04L12/24
CPC classification number: H04L45/04 , H04L41/0813 , H04L45/22
Abstract: Methods and apparatus for pre-configured virtual gateways for isolated virtual networks are described. An isolated virtual network (IVN) is configured at a provider network on behalf of a customer. The IVN includes one or more devices whose network addresses are not accessible from the public Internet. In response to a request from a connectivity intermediary, a virtual private gateway (VPG) is established, configurable to enable connectivity between IVNs of the provider network and devices outside the provider network. The VPG is included within a set of candidate VPGs indicated programmatically to the customer. Connectivity is established between the customer's IVN and an external device via the VPG.
-
公开(公告)号:US09935816B1
公开(公告)日:2018-04-03
申请号:US14741188
申请日:2015-06-16
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Mark Edward Stalzer , Andrew Hemstreet Redmon
IPC: G06F15/16 , H04L12/24 , H04L12/751 , H04L12/713
CPC classification number: H04L41/0206 , H04L41/0816 , H04L45/02 , H04L45/586
Abstract: A technology is described for updating an Autonomous System Number (ASN) in a Border Gateway Protocol (BGP) routing configuration. An example method may include receiving a request to update a BGP routing configuration on a gateway with an ASN associated with a customer. In response to the request, the BGP routing configuration on the gateway may be updated to replace a default ASN associated with a computing service provider with the ASN associated with the customer. The BGP routing configuration on the gateway may also be updated to allow the ASN associated with the customer to appear in an Autonomous System (AS) path at least twice, thereby allowing for BGP routes to be exchanged between gateways.
-
-
-
-
-
-
-
-
-