-
公开(公告)号:US20230079670A1
公开(公告)日:2023-03-16
申请号:US17933067
申请日:2022-09-16
Applicant: Amazon Technologies, Inc.
Inventor: Bashuman Deb , Paul John Tillotson , Thomas Nguyen Spendley , Omer Hashmi , Baihu Qian , Mohamed Nader Farahat Hassan
Abstract: Network pathways are identified to transfer packets between a pair of regional virtual traffic hubs of a provider network. At a first hub of the pair, a first action is performed, resulting in a transmission of a packet received from a first isolated network to the second hub along a pathway selected using dynamic routing parameters. At the second hub, a second action is performed, resulting in the transmission of the packet to a destination within a second isolated network.
-
公开(公告)号:US11601365B2
公开(公告)日:2023-03-07
申请号:US17218036
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L45/586 , H04L45/02 , H04L45/16
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US20220321471A1
公开(公告)日:2022-10-06
申请号:US17218039
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Bashuman Deb , Omer Hashmi , Thomas Nguyen Spendley , Baihu Qian , Guru Kannan , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Yuxin Ren , Fahed Hijazi , Xiyuan Gou , Steve Ge , Nicholas Ryan Lombardi , Brandon Michael LaRue , Jaywant U. Kapadnis , Anoop Dawani
IPC: H04L12/713 , H04L12/741 , H04L29/06 , H04L29/08
Abstract: A message indicating an auxiliary task associated with traffic transmitted via a virtual router between a pair of isolated networks is received at an offloading device. A stack multiplexer at the offloading device selects a protocol stack instance to process the message. A result of the auxiliary task is obtained by the multiplexer from the selected protocol stack instance and transmitted to the virtual router, where it is used to transmit a packet between the isolated networks.
-
公开(公告)号:US20220321470A1
公开(公告)日:2022-10-06
申请号:US17218036
申请日:2021-03-30
Applicant: Amazon Technologies, Inc.
Inventor: Baihu Qian , Omer Hashmi , Thomas Nguyen Spendley , Bashuman Deb , Shridhar Kulkarni , Paul John Tillotson , Ramin Ali Dousti , Indira Radhika Pulla , Steve Ge , Nicholas Ryan Lombardi , Nick Matthews , Anoop Dawani
IPC: H04L12/713 , H04L12/715 , H04L12/761
Abstract: An indication of a set of premises between which network traffic is to be routed via a private fiber backbone of a provider network is obtained. Respective virtual routers are configured for a first premise and a second premise, and connectivity is established between the virtual routers and routing information sources at the premises. Contents of at least one network packet originating at the first premise are transmitted to the second premise via the private fiber backbone using routing information obtained at the virtual routers from the routing information source at the second premise.
-
公开(公告)号:US11025483B1
公开(公告)日:2021-06-01
申请号:US15277929
申请日:2016-09-27
Applicant: AMAZON TECHNOLOGIES, INC.
Inventor: Omer Hashmi
Abstract: A provider network includes a service that creates fault tolerant virtual private network (VPN) endpoint nodes. Each such VPN endpoint node is created as a plurality of virtual machines executing on host computers. Each of the virtual machines is configured from a common machine image that includes software capable of causing the respective virtual machine to configure a secure communication tunnel such as an IPSec tunnel. One of the virtual machines, however, is operated in an active mode to actively configure the tunnel and send and receive encrypted traffic over the tunnel, while another virtual machine is configured to operate in a standby mode. The standby mode VPN endpoint virtual machine can be quickly transitioned to the active mode to take over the role of configuring and exchanging encrypted packets over the tunnel should the active mode VPN endpoint experience a failure.
-
公开(公告)号:US10785146B2
公开(公告)日:2020-09-22
申请号:US16136142
申请日:2018-09-19
Applicant: Amazon Technologies, Inc.
Inventor: Paul John Tillotson , Bashuman Deb , Thomas Spendley , Omer Hashmi , Baihu Qian , Alexander Justin Penney
IPC: H04L12/725 , H04L12/741 , H04L12/747 , H04L12/859 , H04L12/931 , H04L12/46 , G06F9/455 , H04L12/26
Abstract: An isolated packet processing cell of a packet processing service, comprising an action implementation node and a decision master node, is assigned to an application. An indication of processing rules of the application is transmitted to the decision master node. In response to receiving a particular packet, the action implementation node obtains a representation of an action (which is based on the processing rules) from the decision master node and executes the action.
-
公开(公告)号:US10742554B2
公开(公告)日:2020-08-11
申请号:US16196709
申请日:2018-11-20
Applicant: Amazon Technologies, Inc.
Inventor: Bashuman Deb , Paul John Tillotson , Thomas Nguyen Spendley , Omer Hashmi , Baihu Qian , Mohamed Nader Farahat Hassan
IPC: H04L12/741 , H04L12/931 , H04L12/721 , H04L12/751 , H04L29/06 , G06F9/455 , H04L29/08
Abstract: At an action implementation layer of a virtual traffic hub, a packet is obtained from a first isolated network. A first action, generated at a decision making layer of the hub based on a first route table of the hub, is performed, resulting in transmission of at least one network packet to a first destination. In response to a second packet, obtained at the action implementation layer from a source outside the first isolated network, a second action is performed, resulting in transmission of at least one packet to a second destination. The second action is generated based on a second route table of the hub.
-
公开(公告)号:US20200092193A1
公开(公告)日:2020-03-19
申请号:US16136137
申请日:2018-09-19
Applicant: Amazon Technologies, Inc.
Inventor: Paul John Tillotson , Bashuman Deb , Thomas Spendley , Omer Hashmi , Baihu Qian , Alexander Justin Penney
IPC: H04L12/715 , G06F17/30 , H04L12/713 , H04L12/851 , H04L12/751 , H04L29/12
Abstract: Metadata indicating that an action implementation node and a routing decision master node have been assigned to a virtual traffic hub programmatically associated with one or more isolated networks is stored. The routing decision master node determines a first action to be implemented for packets of a network flow using state information of the isolated networks, and provides a representation of a first action to the first action implementation node. Based on performing the first action at the action implementation node, contents of a data packet received from one isolated network are transmitted to another isolated network.
-
29.
公开(公告)号:US20200092138A1
公开(公告)日:2020-03-19
申请号:US16136133
申请日:2018-09-19
Applicant: Amazon Technologies, Inc.
Inventor: Paul John Tillotson , Bashuman Deb , Thomas Spendley , Omer Hashmi , Baihu Qian , Alexander Justin Penney
IPC: H04L12/46 , H04L29/12 , H04L12/851 , H04L12/931 , G06F9/455
Abstract: Configuration operations to enable connectivity, using a virtual traffic hub, between a plurality of isolated networks including a first isolated network with a first private address range, are initiated. The hub includes a plurality of nodes including a decision master node responsible for determining routing actions for packets received at the hub. At the decision master node, a translation mapping is obtained for a second private address range of a second isolated network, which overlaps with the first private address range. At a particular node of the hub, using the mapping, a header of a network packet received from the second isolated network and directed to a destination outside the second isolated network is modified.
-
公开(公告)号:US10560431B1
公开(公告)日:2020-02-11
申请号:US15369626
申请日:2016-12-05
Applicant: Amazon Technologies, Inc.
Inventor: Po-Chun Chen , Omer Hashmi , Sanjay Bhal
Abstract: A request to establish an encrypted VPN connection between a network external to a provider network connected to the provider network via a dedicated direct physical link and a set of resources of the provider network is received. A new isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. One or more protocol processing engines (PPEs) are instantiated within the IVN, address information of the one or more PPEs is exchanged with the external network and a respective encrypted VPN tunnel is configured between each of the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.
-
-
-
-
-
-
-
-
-