IP Library Granted Patent US 12671646
Granted Patent B1
US 12671646 · App. 18/542,301 · Granted Jun 30, 2026

Dynamic insertion of intermediate network components

Inventors: Devlin Roarke Dunsmore (Bothell, WA); Sandeep Bajaj (San Ramon, CA); Shridhar Kulkarni (Fremont, CA); Brandon Michael LaRue (Alexandria, VA); Baihu Qian (Chicago, IL); Bashuman Deb (Aldie, VA)
Assignee: Amazon Technologies, Inc.
H04L45/02H04L45/24H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671646
App. No.
18/542,301
Granted
Jun 30, 2026
Kind
B1
Abstract

Systems and methods are provided for automatic generation of routing through a user-specified network appliance. A wide area network (WAN) may include isolated network nodes, such as, VPCs, VPNs, or client-on-premises devices. The WAN may also include network appliances, such as firewalls or load balancers. To manage traffic between isolated network nodes, a management component of the WAN may access instructions including specified network appliances for inclusion in routes between isolated network nodes. Based on these instructions, the management component may then generate segments with routing information relating to steering traffic through the specified network appliances. The routing information may relate to steering traffic across region and/or segment boundaries within the WAN.

Claims (133)

1 . A system comprising:

a cloud provider network comprising a plurality of compute components and a plurality of gateway components, wherein the plurality of gateway components are configured to route network traffic between the plurality of compute components;

a dynamic insertion management system configured to generate, based on policy data originating from a user device regarding a wide area network to be deployed on the cloud provider network and transient metadata regarding a current state of the wide area network, a first route table for a first segment, the first route table specifying a first potential route from a first virtual private cloud in a first region of the wide area network through a first network appliance in the first region and a second potential route from the first virtual private cloud in the first region through a second network appliance in a second region of the wide area network,

wherein the policy data comprises:

an identification of the first virtual private cloud as being an attachment of the first segment, wherein the first segment is a user-managed segment, and wherein the first virtual private cloud is in the first region of the wide area network,

an identification of the first network appliance as being an attachment of a network function group, wherein the network function group is a system-managed group, and wherein the first network appliance is in the first region of the wide area network,

an identification of the second network appliance as being an attachment of the network function group, wherein the second network appliance is in the second region of the wide area network,

an identification that the data from the first virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance, and

an identification of the first region as being a first specified region for routing data from the first virtual private cloud; and

one or more computing devices programmed by executable instructions to at least:

obtain the first route table generated by the dynamic insertion management system;

receive data from the first virtual private cloud;

select, based on the first specified region, the first potential route from the first route table; and

transmit the data from the first virtual private cloud through the first network appliance in the first region according to the selected first potential route.

2 . The system of claim 1 , wherein the policy data further comprises an identification of a second virtual private cloud as being an attachment of a second segment, wherein the second segment is a user managed segment in the second region of the wide area network.

3 . The system of claim 2 ,

wherein the dynamic insertion management system is further configured to generate, based on the policy data and the transient metadata, at least a second route table for the network function group, wherein the second route table specifies that data from the first virtual private cloud in the first region is to be routed to the second virtual private cloud in the second region after going through the first network appliance in the first region;

wherein the policy data further comprises an identification that data from the first virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance prior to reaching the second virtual private cloud, and

wherein the one or more computing devices are further programmed by executable instructions to at least:

obtain the second route table for the network function group;

select, based on the policy data, the route from the second route table; and

transmit the data from the first virtual private cloud to the second virtual private cloud in the second region through the first network appliance in the first region according to the selected route.

4 . The system of claim 2 ,

wherein the dynamic insertion management system is further configured to generate, based on the policy data and the transient metadata, at least a second route table for the network function group, wherein the second route table specifies that data from the first virtual private cloud in the first region is to be routed to the second virtual private cloud in the second region after going through the second network appliance in the second region;

wherein the policy data further comprises an identification that data from the first virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance prior to reaching the second virtual private cloud, and

wherein the one or more computing devices are further programmed by executable instructions to at least:

obtain the second route table for the network function group;

select, based on the policy data, the route from the second route table; and

transmit the data from the first virtual private cloud to the second virtual private cloud in the second region through the second network appliance in the second region according to the selected route.

5 . The system of claim 2 ,

wherein the dynamic insertion management system is further configured to generate, based on the policy data and the transient metadata, a second route table for the second segment, wherein the second route table includes a third potential route from the second virtual private cloud in the second region to the first network appliance in the first region and a fourth potential route from the second virtual private cloud in the second region to the second network appliance in the second region;

wherein the policy data further comprises an identification that data from the second virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance, and

wherein the one or more computing devices are further programmed by executable instructions to at least:

obtain the second route table for the second segment;

determine, based on the policy data, to randomly select the third potential route to route data from the second virtual private cloud to the first network appliance; and

transmit the data according to the selected third potential route.

6 . The system of claim 2 ,

wherein the dynamic insertion management system is further configured to generate, based on the policy data and the transient metadata, a second route table for the second segment, wherein the second route table includes a third potential route from the second virtual private cloud in the second region to the first network appliance in the first region and a fourth potential route from the second virtual private cloud in the second region to the second network appliance in the second region;

wherein the policy data further comprises an identification that data from the second virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance, and

wherein the one or more computing devices are further programmed by executable instructions to at least:

obtain the second route table for the second segment;

determine, based on the policy data, to randomly select the fourth potential route to route data from the second virtual private cloud to the second network appliance; and

transmit the data according to the selected fourth potential route.

7 . The system of claim 2 ,

wherein the dynamic insertion management system is further configured to generate, based on the policy data and the transient metadata, a second route table for the network function group, wherein the second route table includes a third potential route from the second virtual private cloud in the second region to the first network appliance in the first region and a fourth potential route from the second virtual private cloud in the second region to the second network appliance in the second region;

wherein the policy data further comprises:

an identification that data from the second virtual private cloud is to be routed through at least one of the first network appliance or the second network appliance, and

an indication of the second region as being a second specified region for routing data from the second virtual private cloud; and

wherein the one or more computing devices are further programmed by executable instructions to at least:

obtain the second route table for the network function group;

determine, based on the second specified region, to select the fourth potential route to route data from the second virtual private cloud to the second network appliance; and

transmit the data according to the selected fourth potential route.

8 . A non-transitory, computer-readable medium comprising computer-executable instructions for dynamic insertion of network components, wherein the computer-executable instructions, when executed by a computer system, cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on a cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and transient metadata regarding a current state of the wide area network, a first route table for a first segment, wherein the first route table specifies a first potential route from a first component in a first region of the wide area network through a second component in the first region and a second potential route from the first component in the first region through a third component in a second region of the wide area network,

wherein the policy data comprises:

an identification of the first component as being an attachment of the first segment, wherein the first segment is a user-managed segment in the first region of the wide area network,

an identification of the second component as being an attachment of a network function group, wherein the network function group is a system-managed group, and wherein the second component is in the first region of the wide area network,

an identification of the third component as being an attachment of the network function group, and wherein the third component is in the second region of the wide area network,

an identification that the data from the first component is to be routed through at least one of the second component or the third component, and

an identification of the first region as being a first specified region for routing data from the first component;

receive data from the first component;

obtain the first route table;

select, based on the first specified region, the first potential route from the first route table; and

transmit the data from the first component through the second component in the first region according to the selected first potential route.

9 . The non-transitory, computer-readable medium of claim 8 ,

wherein the computer-executable instructions, when executed, further cause the computer system to access policy data comprising an identification of a fourth component as being an attachment of a second segment, wherein the second segment is a user managed segment in the second region of the wide area network.

10 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata regarding a current state of the wide area network, a second route table for the network function group, wherein the second route table specifies that data from the first component in the first region is to be routed to the fourth component in the second region after going through the second component in the first region,

the policy data comprising an identification that data from the first component is to be routed through at least one of the second component or the third component prior to reaching the fourth component;

obtain the second route table;

select, based on the policy data, the route from the second route table; and

transmit the data from the first component to the fourth component in the second region through the second component in the first region according to the selected route.

11 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata regarding a current state of the wide area network, a second route table for the network function group, wherein the second route table specifies that data from the first component in the first region is to be routed to the fourth component in the second region after going through the third component in the second region,

the policy data comprising an identification that data from the first component is to be routed through at least one of the second component or the third component prior to reaching the fourth component;

obtain the second route table for the network function group;

select, based on the policy data, the route from the second route table; and

transmit the data from the first component to the fourth component in the second region through the third component in the second region according to the selected route.

12 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata regarding a current state of the wide area network, a second route table for the second segment, wherein the second route table includes a third potential route from the fourth component in the second region to the second component in the first region and a fourth potential route from the fourth component in the second region to the third component in the second region,

the policy data comprising an identification that data from the fourth component is to be routed through at least one of the second component or the third component;

obtain the second route table for the second segment;

determine, based on the policy data, to select the third potential route to route data from the fourth component to the second component; and

transmit the data according to the selected third potential route.

13 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata regarding a current state of the wide area network, a second route table for the second segment, wherein the second route table includes a third potential route from the fourth component to the second component and a fourth potential route from the fourth component to the third component,

the policy data comprising an identification that data from the fourth component is to be routed through at least one of the second component or the third component;

obtain the second route table for the second segment;

determine, based on the policy data, to select the fourth potential route to route data from the fourth component to the third component; and

transmit the data according to the selected fourth potential route.

14 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata, a second route table for the second segment, wherein the second route table includes a third potential route from the fourth component to the second component and a fourth potential route from the fourth component to the third component,

the policy data comprising:

an identification that data from the second segment is to be routed through at least one of the second component or the third component, and

an indication of the second region as being a second specified region for routing data from the fourth component;

obtain the second route table for the second segment;

determine, based on the second specified region, to select the fourth potential route to route data from the fourth component to the third component; and

transmit the data according to the selected fourth potential route.

15 . The non-transitory, computer-readable medium of claim 9 , wherein the computer-executable instructions, when executed, further cause the computer system to:

in response to reception of policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generate, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata, a second route table for the second segment, wherein the second route table includes a third potential route from the fourth component in the second region to the second component in the first region, a fourth potential route from the fourth component in the second region to the third component in the second region, and a fifth potential route from the fourth component in the second region to a fifth component in a third region;

the policy data comprising:

an identification that data from the second segment is to be routed through at least one of the second component or the third component, and

an identification of a fallback region as being the third region of the wide area network, where the fallback region is to be used to route data from the fourth component if the second component and the third component are inaccessible;

obtain the second route table for the second segment;

determine, based on the fallback region, to select the fifth potential route to route data from the fourth component to the fifth component; and

transmit the data according to the selected fifth potential route.

16 . A computer-implemented method comprising:

in response to receiving policy data from a user device, the policy data regarding a wide area network to be deployed on a cloud provider network, generating, based on the policy data regarding a wide area network to be deployed on the cloud provider network and transient metadata regarding a current state of the wide area network, a first route table for a first segment, wherein the first route table specifies a first potential route from a first component in a first region of the wide area network through a second component in the first region of the wide area network;

wherein the policy data comprises:

an identification of the first component as being an attachment of the first segment, wherein the first segment is a user-managed segment in the first region of the wide area network;

an identification of the second component as being an attachment of a network function group, wherein the network function group is a system-managed group, and wherein the second component is in the first region of the wide area network; and

an identification that the data from the first component is to be routed through at least one of the first region of the wide area network or a second region of the wide area network;

obtaining the first route table for the first segment;

receiving data from the first component;

determining to select the first potential route to route the data from the first component through the second component; and

transmitting the data from the first component through the second component in the first region according to the selected first potential route.

17 . The computer-implemented method of claim 16 , further comprising:

in response to receiving policy data from a user device, the policy data regarding a wide area network to be deployed on the cloud provider network, generating, based on the policy data regarding a wide area network to be deployed on the cloud provider network and the transient metadata, a second route table for the network function group, wherein the second route table includes a second potential route from a third component in the second region to the second component in the first region, and a third potential route from the third component in the second region to a fourth component in a third region,

the policy data comprising:

an identification of the third component as being an attachment of a second segment, wherein the second segment is a user managed segment in the second region of the wide area network;

an identification that data from the second segment is to be routed through the second component; and

an identification of a fallback region as being the third region of the wide area network, where the fallback region is to be used to route data from the network function group if the second component is inaccessible;

obtaining the second route table for the network function group;

determining, based on the fallback region, to select the third potential route to route data from third component to the fourth component; and

transmitting the data from the third component to the fourth component according to the selected third potential route.

18 . The computer-implemented method of claim 16 , further comprising:

accessing updated policy data regarding the wide area network from an external computing device;

generating, based on the updated policy data, an updated first route table; and

deploying the wide area network in the cloud provider network at least by transmitting the updated first route table to the cloud provider network.

19 . The computer-implemented method of claim 18 , wherein generating the first route table further comprises:

accessing existing routes at a memory location corresponding to the first segment of the cloud provider network; and

adding a first priority flag to the first potential route.

20 . The computer-implemented method of claim 19 , wherein determining to select the first potential route is based on the first priority flag.