IP Library Granted Patent US 12,712,851
Granted Patent B1
US 12,712,851 · App. 18/750,938 · Granted Aug 18, 2026

Maintaining isolation of clients of a service with connectionless protocols

Inventor: Meher Aditya Kumar Addepalli (Redmond, WA)
Assignee: Amazon Technologies, Inc.
H04L63/0272H04L69/167
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,851
App. No.
18/750,938
Granted
Aug 18, 2026
Kind
B1
Abstract

Systems and methods for configuring a routing device to support routing of connectionless packets are described. Upon receiving a connectionless packet, the routing device establishes a flow between the packet source and a target device for a virtual target address. After a period of inactivity in the flow, the flow is removed. To establish the flow, the routing device constructs an intermediate address for the routing device including a prefix for the routing device and an identifier based on the source address, then creates entries in a routing table to support routing of connectionless packets of the flow. The identifier uniquely associates the intermediate address of the particular flow to the source address such that the intermediate address cannot be reused in a future flow established for a difference source. Thus, late-arriving packets of the flow received after removal of the flow cannot be routed to an incorrect target address.

Claims (50)

1 . A system, comprising:

one or more processors; and

a memory storing program instructions that, when executed on the one or more processors, implement a routing device configured to:

receive a data packet sent from a source address to a target address according to a connectionless protocol, wherein the target address is a virtual address of a target device of a provider network, wherein the data packet is sent from an endpoint that routes data packets to and from a client virtual private network to the provider network, wherein the endpoint encapsulates the data packet received from a client device within the client virtual private network, wherein the data packet comprises an address of the client device, wherein the encapsulation of the data packet identifies the endpoint, and wherein the source address comprises the identifier of the endpoint and the address of the client device; and

establish a flow between the source address and the target device, wherein to establish the flow the routing device is configured to:

create an intermediate address comprising a routable prefix and an identifier based at least in part on the source address; and

create a translation between a first tuple, comprising the source address and the virtual address, and a second tuple, comprising the intermediate address and a target address of the target device, to enable routing of connectionless packets including the data packets between the source address and target device; and

route the connectionless packets between the source address and the target address.

2 . The system of claim 1 , wherein the routing device is further configured to:

remove the intermediate address and the translation between the first tuple and the second tuple response to a period of inactivity of the established route, and subsequent to the removing:

establish another route between another source address, different from the source address, and the target device, comprising creating another intermediate address comprising the routable prefix and another identifier based at least in part on the other source address, wherein the other identifier is different from the identifier;

receive, subsequent to establishing the other route, another data packet of the route according to the connectionless protocol; and

route the other data packet between the source address and the target address.

3 . The system of claim 1 , wherein the intermediate address is an Internet Protocol version six (IPv6) address, wherein the source address is an Internet Protocol version four (IPv4) address, wherein the source address is an address of a virtual private cloud endpoint (VPCE), and wherein the intermediate address comprises a random number for the VPCE and an identifier based at least in part on a portion of the source address common to a plurality of endpoints of the virtual private cloud.

4 . The system of claim 1 , wherein the source address and the intermediate address are Internet Protocol version six (IPv6) addresses, wherein the source address is an address of a virtual private cloud endpoint (VPCE), and wherein the intermediate address comprises a random number for the VPCE and an identifier based at least in part on a portion of the source address common to a plurality of endpoints of the virtual private cloud.

5 . A method, comprising:

performing, by a routing device:

receiving a data packet sent from a source address to a target address according to a connectionless protocol, wherein the target address is a virtual address of a target device of a provider network, and wherein the source address is part of a client virtual private network different from the provider network;

establishing a flow between the source address and the target device, comprising:

creating an intermediate address comprising a routable prefix and an identifier based at least in part on the source address; and

creating a translation between a first tuple, comprising the source address and the virtual address, and a second tuple, comprising the intermediate address and a target address of the target device, to enable routing of connectionless packets including the data packets between the source address and target device; and

routing the connectionless packets between the source address and the target address.

6 . The method of claim 5 , further comprising performing, by the routing device:

removing the intermediate address and the translation between the first tuple and the second tuple responsive to a period of inactivity of the established flow, and subsequent to the removing:

establishing another flow between another source address, different from the source address, and the target device, comprising creating another intermediate address comprising the routable prefix and another identifier based at least in part on the other source address, wherein the other identifier is different from the identifier.

7 . The method of claim 6 , further comprising performing, by the routing device:

receiving, subsequent to establishing the other flow, another data packet of the flow according to the connectionless protocol; and

routing the other data packet between the source address and the target address.

8 . The method of claim 5 , wherein the intermediate address is an Internet Protocol version six (IPv6) address, wherein the source address is an Internet Protocol version four (IPv4) address, wherein the source address is an address of a virtual private cloud endpoint (VPCE), and wherein the intermediate address comprises a random number for the VPCE and an identifier based at least in part on a portion of the source address common to a plurality of endpoints of the virtual private cloud.

9 . The method of claim 5 , wherein the intermediate address is an Internet Protocol version six (IPv6) address, wherein the source address is an Internet Protocol version four (IPv4) address, and wherein the intermediate address comprises a hash of the source address and an identifier based at least in part on the source address.

10 . The method of claim 5 , wherein the source address and the intermediate address are Internet Protocol version six (IPv6) addresses, wherein the source address is an address of a virtual private cloud endpoint (VPCE), and wherein the intermediate address comprises a random number for the VPCE and an identifier based at least in part on a portion of the source address common to a plurality of endpoints of the virtual private cloud.

11 . The method of claim 5 , wherein the source address and the intermediate address are Internet Protocol version six (IPv6) addresses, and wherein the intermediate address comprises a hash of the source address.

12 . The method of claim 5 , wherein the source address and the intermediate address are Internet Protocol version six (IPv6) addresses, wherein the source address is a global universal address (GUA), and wherein the intermediate address and the source address are the same.

13 . The method of claim 5 , wherein the target device is a computing device providing a service of the provider network, wherein the routing device is part of a routing service of the provider network, wherein the data packet is sent from an endpoint that routes data packets to and from the client virtual private network to the provider network, and wherein the source address comprises at least an identifier of the endpoint.

14 . The method of claim 13 , wherein the endpoint encapsulates the data packet received from a client device within the client virtual private network, wherein the client device is different from the endpoint, wherein the data packet comprises an address of the client device, wherein the encapsulation of the data packet identifies the endpoint, and wherein the source address comprises the identifier of the endpoint and the address of the client device.

15 . One or more non-transitory computer-accessible storage media storing program instructions that when executed on or across one or more computing devices cause the one or more computing devices to implement a routing device to perform:

receiving a data packet sent from a source address to a target address according to a connectionless protocol, wherein the target address is a virtual address of a target device of a provider network, and wherein the source address is part of a client virtual private network different from the provider network; and

establishing a route between the source address and the target device, comprising:

creating an intermediate address comprising a routable prefix and an identifier based at least in part on the source address; and

creating a translation between a first tuple, comprising the source address and the virtual address, and a second tuple, comprising the intermediate address and a target address of the target device, to enable routing of connectionless packets including the data packets between the source address and target device; and

routing the connectionless packets between the source address and the target address.

16 . The one or more non-transitory computer-accessible storage media of claim 15 , the routing device further performing:

removing the intermediate address and the translation between the first tuple and the second tuple response to a period of inactivity of the established route, and subsequent to the removing:

establishing another route between another source address, different from the source address, and the target device, comprising creating another intermediate address comprising the routable prefix and another identifier based at least in part on the other source address, wherein the other identifier is different from the identifier;

receiving, subsequent to establishing the other route, another data packet of the route according to the connectionless protocol; and

routing the other data packet between the source address and the target address.

17 . The one or more non-transitory computer-accessible storage media of claim 15 , wherein the intermediate address is an Internet Protocol version six (IPv6) address, wherein the source address is an Internet Protocol version four (IPv4) address, wherein the source address is an address of a virtual private cloud endpoint (VPCE), and wherein the intermediate address comprises a random number for the VPCE and an identifier based at least in part on a portion of the source address common to a plurality of endpoints of the virtual private cloud.

18 . The one or more non-transitory computer-accessible storage media of claim 15 , wherein the intermediate address is an Internet Protocol version six (IPv6) address, wherein the source address is an Internet Protocol version four (IPv4) address, and wherein the intermediate address comprises a hash of the source address and an identifier based at least in part on the source address.

19 . The one or more non-transitory computer-accessible storage media of claim 15 , wherein the source address and the intermediate address are Internet Protocol version six (IPv6) addresses, and wherein the intermediate address comprises a hash of the source address.

20 . The one or more non-transitory computer-accessible storage media of claim 13 , wherein the target device is a computing device providing a service of the provider network, wherein the routing device is part of a routing service of the provider network, wherein the data packet is sent from an endpoint that routes data packets to and from the client virtual private network to the provider network, wherein the endpoint encapsulates the data packet received from a client device within the client virtual private network, wherein the client device is different from the endpoint, wherein the data packet comprises an address of the client device, wherein the encapsulation of the data packet identifies the endpoint, and wherein the source address comprises the identifier of the endpoint and the address of the client device.