IP Library › Granted Patent US 12,381,850
Granted Patent B2
US 12,381,850 · App. 18/487,575 · Granted Aug 5, 2025

Virtual private gateway for encrypted communication over dedicated physical link

Inventors: Po-Chun Chen (Oak Hill, VA); Omer Hashmi (Chevy Chase, MD); Sanjay Bhal (Germantown, MD)
Assignee: Amazon Technologies, Inc.
H04L63/0272H04L12/4633H04L12/66H04L63/0428H04L63/18H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,850
App. No.
18/487,575
Filed
Oct 16, 2023
Granted
Aug 5, 2025
Kind
B2
Examiner
KHAN, MOEEN
Art Unit
2436
USPC
713/153
Abstract

A request to establish an encrypted VPN connection between a network and the provider network via a dedicated direct physical link and a set of resources of the provider network is received. An isolated virtual network (IVN) is established to implement an encryption virtual private gateway to be used for the connection. Protocol processing engines (PPEs) are instantiated within the IVN, address information of the PPEs is exchanged with the external network and an encrypted VPN tunnel is configured between the PPEs and the external network. Routing information pertaining to the set of resources is provided to the external network via at least one of the encrypted VPN tunnels, enabling routing of customer data to the set of resources within the provider network from the external network via an encrypted VPN tunnel implemented over a dedicated direct physical link between the external network and the provider network.

Claims (55)

1. A system comprising:

a plurality of instance hosts comprising computing devices configured to host one or more instances; and

one or more computing devices of a provider network configured to implement a connectivity manager configured to provide a high availability virtual private network (VPN), wherein to provide the high availability VPN, the connectivity manager is configured to cause a virtual private gateway to be established for a virtual network including the one or more hosted instances, wherein to establish the virtual private gateway, the connectivity manager is configured to:

assign the one or more instances to the virtual private gateway;

provide one or more virtual network interfaces to the one or more instances; and

implement one or more protocol processing engines for exchanging routing information with a network external to the provider network,

wherein the one or more protocol processing engines are configured to:

establish a border gateway protocol (BGP) session to exchange routing information for the one or more instances assigned to the virtual private gateway with the network external to the provider network, wherein the BGP session is established via the one or more virtual network interfaces and a network link established between the provider network and the network external to the provider network;

establish, using the exchanged routing information, a plurality of VPN tunnels between the network external to the provider network and the one or more instances assigned to the virtual private gateway via the network link;

establish additional respective BGP sessions within respective ones of the plurality of VPN tunnels to exchange routing information of one or more instances included in the virtual network with the network external to the provider network, wherein establishment of the additional respective BGP sessions within the respective ones of the plurality of VPN tunnels provides encrypted communication channels for the exchange of the routing information to the network external to the provider network; and

enable encrypted communications to flow between the one or more instances included in the virtual network and the network external to the provider network via the plurality of VPN tunnels implemented via the network link.

2. The system of claim 1 , wherein two or more instances are assigned to the virtual private gateway, and wherein each of the two or more instances are configured to perform said establishing a BGP session, said establishing a VPN tunnel, said establishing additional respective BGP sessions, and said enabling encrypted communications, such that two or more VPN tunnels are established that each enable encrypted communications to flow between the one or more instances included in the virtual network and the network external to the provider network.

3. The system of claim 1 , wherein the plurality of VPN tunnels are implemented in accordance with an IPSec protocol.

4. The system of claim 1 , wherein the plurality of instance hosts implement one or more virtual machines.

5. The system of claim 1 , wherein said establishing the plurality of virtual private network (VPN) tunnels between the external network and the one or more instances assigned to the virtual private gateway comprises establishing two VPN tunnels between the external network and the one or more instances assigned to the virtual private gateway.

6. The system of claim 1 , wherein one or more edge routers used to implement the network link are located at a co-location facility.

7. The system of claim 1 , wherein the one or more protocol processing engines are implemented on one or more virtual machines.

8. The system of claim 1 , wherein:

the network link established between the provider network and the network external to the provider network is implemented via a plurality of physical connections; and

the connectivity manager is further configured to:

detect a failure of a first one of the plurality of physical connections; and

automatically failover the encrypted communications to flow over a remaining one of the plurality of physical connections.

9. A method of providing a high-availability virtual private network (VPN), the method comprising:

establishing a virtual private gateway for a virtual network implemented within a provider network, wherein establishing the virtual private gateway comprises:

assigning one or more instances within the provider network to the virtual private gateway;

providing one or more virtual network interfaces to the one or more instances;

implementing one or more protocol processing engines on one or more instance hosts, hosting the one or more instances, for exchanging routing information with an external network, external to the provider network;

establishing, via the one or more protocol processing engines, a border gateway protocol (BGP) session to exchange routing information for the one or more instances assigned to the virtual private gateway with the external network, wherein the BGP session is established via the one or more virtual network interfaces and a network link established between the provider network and the external network;

establishing, using the exchanged routing information, a plurality of VPN tunnels between the external network and the one or more instances assigned to the virtual private gateway via the network link;

establishing, via the one or more protocol processing engines, additional respective BGP sessions within the plurality of VPN tunnels to exchange routing information of one or more instances included in the virtual network with the external network, wherein establishment of the additional respective BGP sessions within the plurality of VPN tunnels provides an encrypted communication channel for the exchange of the routing to the external network; and

enabling encrypted communications to flow between the one or more instances included in the virtual network and the external network via the plurality of VPN tunnels implemented via the network link.

10. The method of claim 9 , wherein said establishing the plurality of virtual private network (VPN) tunnels between the external network and the one or more instances assigned to the virtual private gateway comprises establishing two VPN tunnels between the external network and the one or more instances assigned to the virtual private gateway.

11. The method of claim 10 , wherein the two VPN tunnels encrypt network traffic in accordance with an IPSec protocol.

12. The method of claim 9 , wherein the one or more instances implement one or more virtual machines.

13. The method of claim 9 , wherein one or more edge routers used to implement the network link are located at a co-location facility.

14. The method of claim 9 , wherein the one or more protocol processing engines are implemented on one or more virtual machines.

15. The method of claim 9 , wherein to establish the plurality of virtual private network tunnels, the one or more virtual network interfaces for the protocol processing engines are configured to use VLAN tags.

16. The method of claim 9 , further comprising:

detecting a failure of a first one of the plurality of VPN tunnels; and

causing an automatic failover, wherein the encrypted communications flow over a remaining one of the plurality of VPN tunnels.

17. One or more non-transitory, computer-readable storage media, storing program instructions, that when executed implement a high-availability virtual private network (VPN), wherein to implement the high-availability VPN the program instructions, when executed on or across one or more computing devices, cause the one or more computing devices to:

assign one or more instances within a provider network to a virtual private gateway that is to be established for a virtual network, wherein the virtual network is implemented within the provider network;

cause one or more virtual network interfaces to be provided to the one or more instances;

cause one or more protocol processing engines to be implemented for exchanging routing information with an external network, external to the provider network;

establish, via the one or more protocol processing engines, a border gateway protocol (BGP) session to exchange routing information for the one or more instances assigned to the virtual private gateway with the external network, wherein the BGP session is established via the one or more virtual network interfaces and a network link established between the provider network and the external network;

establish, using the exchanged routing information, a plurality of VPN tunnels between the external network and the one or more instances assigned to the virtual private gateway via the network link;

establish, via the one or more protocol processing engines, additional respective BGP sessions within the plurality of VPN tunnels to exchange routing information of one or more instances included in the virtual network of the customer with the external network, wherein establishment of the additional respective BGP sessions within the plurality of VPN tunnels provides an encrypted communication channel for the exchange of the routing information to the external network; and

enable encrypted communications to flow between the one or more instances included in the virtual network and the external network via the plurality of VPN tunnels implemented via the network link.

18. The one or more non-transitory, computer readable storage media of claim 17 , wherein the plurality of VPN tunnels are configured to encrypt network traffic in accordance with:

an IPSec protocol; or

an IKE (Internet Key Exchange) protocol.

19. The one or more non-transitory, computer readable storage media of claim 17 , wherein prior to establishing the BGP session, the program instructions further cause the one or more processors to:

initiate a protocol processing engine at a first one of the one or more instances; and

initiate an additional protocol processing engine.

20. The one or more non-transitory, computer readable storage media of claim 19 , wherein the first and second protocol processing engines comprise an IPSec processing module or an IKE (Internet Key Exchange) processing module.

Continuity (3)
Continuation 16785211 · Feb 7, 2020
Continuation 15369626 · Dec 5, 2016
Related Publication 20240039895A1 · Feb 1, 2024
References Cited (38)
US 6948003B1 · Newman et al. · 2005 [cited by applicant]
US 7590074B1 · Dondeti · 2009 [cited by examiner]
US 8082581B2 · Wu · 2011 [cited by applicant]
US 8209749B2 · Babula et al. · 2012 [cited by applicant]
US 8261341B2 · Stirbu · 2012 [cited by applicant]
US 8443435B1 · Schroeder · 2013 [cited by examiner]
US 8543734B2 · McDysan · 2013 [cited by applicant]
US 8559441B2 · Miyabe · 2013 [cited by applicant]
US 8559449B2 · Rao et al. · 2013 [cited by applicant]
US 8612599B2 · Tung et al. · 2013 [cited by applicant]
US 8656420B2 · Foster et al. · 2014 [cited by applicant]
US 8705394B2 · Venkatachalapathy et al. · 2014 [cited by applicant]
US 8953590B1 · Aggarwal · 2015 [cited by examiner]
US 9712386B1 · Chen et al. · 2017 [cited by applicant]
US 9954763B1 · Ye et al. · 2018 [cited by applicant]
US 10187289B1 · Chen et al. · 2019 [cited by applicant]
US 10560431B1 · Chen et al. · 2020 [cited by applicant]
US 20030191841A1 · DeFerranti et al. · 2003 [cited by applicant]
US 20040223497A1 · Sanderson et al. · 2004 [cited by applicant]
US 20110107413A1 · Chawla et al. · 2011 [cited by applicant]
US 20110145836A1 · Wheeler et al. · 2011 [cited by applicant]
US 20110153724A1 · Raja et al. · 2011 [cited by applicant]
US 20130031424A1 · Srivastava et al. · 2013 [cited by applicant]
US 20130227355A1 · Dake et al. · 2013 [cited by applicant]
US 20140075048A1 · Yuksel et al. · 2014 [cited by applicant]
US 20150089034A1 · Stickle et al. · 2015 [cited by applicant]
US 20150134797A1 · Theimer et al. · 2015 [cited by applicant]
US 20150163158A1 · Ryland · 2015 [cited by applicant]
US 20150163206A1 · McCarthy et al. · 2015 [cited by applicant]
US 20150339136A1 · Suryanarayanan · 2015 [cited by examiner]
US 20170060420A1 · Meyer et al. · 2017 [cited by applicant]
US 20170099159A1 · Abraham · 2017 [cited by applicant]
US 20170366586A1 · Bloesch et al. · 2017 [cited by applicant]
US 20200252375A1 · Chen et al. · 2020 [cited by applicant]
Sheila Frankel, et al., “Guide to IPsec VPNs—Recommendations of the National Institute of Standards and Technology”, NIST, Dec. 2005, pp. 1-126. [cited by applicant]
Amazon Web Services, “AWS Direct Connect User Guide API Version”, Oct. 22, 2013, pp. 1-42. [cited by applicant]
Amazon Web Services, “Amazon Virtual Private Cloud: User Guide API Version”, Oct. 1, 2013, pp. 1-143. [cited by applicant]
Amazon Web Services, “AWS re: Invent Deep Dive: AWS Direct Connect and VPNs”, Oct. 2015, pp. 1-94. [cited by applicant]