Automated AWS Account Discovery and Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for managing and securing computing environments, especially in large organizations with complex account hierarchies, are prone to errors and require significant manual effort, relying heavily on the expertise of IT administrators, leading to potential oversight of important components and increased complexity with ephemeral AWS accounts.

Innovation Solution

An automated system for continuous discovery of computing components and services within organizational units, which uses a high-level account combined with organizational API capabilities to obtain temporary credentials, automatically determining the importance and service type of machines or components without manual registration, and providing a hierarchical structure for enhanced accessibility and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual account configuration and monitoring is performed in large organizations with thousands of AWS accounts, then access control and security can be maintained, but the process becomes repetitive, error-prone, and time-consuming

Engineering Contradiction:
Improveaccess control and securityVSAvoidaccount configuration and monitoring efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service automation where the account discovery component automatically discovers, configures, and monitors AWS accounts without requiring manual intervention. The system autonomously performs account hierarchy discovery, credential management, and resource inventory updates, eliminating the repetitive manual work while maintaining security and access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (administrators manually configuring accounts) with an automated computational system. The account discovery component uses API calls and automated credential assumption to discover and configure accounts programmatically, substituting human manual operations with automated software agents that can handle thousands of accounts efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If individual account querying is performed to fetch resources and services, then complete inventory data can be obtained, but the process is tedious and time-consuming for large numbers of accounts

Engineering Contradiction:
Improvecompleteness of resource inventoryVSAvoidtime required for account discovery
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system merges individual account discovery operations into a unified automated process. The account discovery component simultaneously discovers multiple accounts and their hierarchies by making coordinated API calls, combining what would be thousands of separate manual operations into a single automated workflow that efficiently retrieves complete inventory data across all accounts.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary automated account discovery and hierarchy mapping before resource inventory collection. By pre-establishing the account hierarchy structure and credentials through automated assumption processes, the system prepares the groundwork that enables efficient subsequent inventory gathering across all discovered accounts without requiring repeated setup operations.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If control accounts assume roles in linked accounts to obtain temporary credentials, then access to linked accounts is enabled, but there is no way to understand which linked accounts trust which control account

Engineering Contradiction:
Improveaccess to linked accountsVSAvoidvisibility into trust relationships
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The account discovery component implements feedback mechanisms that automatically query and map trust relationships between control accounts and linked accounts. By systematically attempting credential assumption and analyzing API responses, the system builds and maintains an accurate representation of which linked accounts trust which control accounts, providing visibility into the trust topology without manual configuration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11409895B2Automatic discovery of computing components within a hierarchy of accounts defining the scope and services of components within the computing environment
Publication Date: 2022.08.09 VMWARE INC
  • US11409895B2 patent drawing
  • US11409895B2 patent drawing
  • US11409895B2 patent drawing

AI summary

A feature selection methodology is disclosed. In a computer-implemented method, components of a computing environment are automatically monitored, and have a feature selection analysis performed thereon. Provided the feature selection analysis determines that features of the components are well defined, a classification of the features is performed. Provided the feature selection analysis determines that features of the components are not well-defined access to those features are discarded. Results of the feature selection methodology are generated.