Bastion Host Gateway for Secure Remote Instance Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network-based computing solutions for accessing remote computing instances are insecure, add operational overhead, and fail to automate user access control, particularly due to the need for opening inbound ports and managing SSH keys and certificates, which complicates compliance with corporate security policies.

Innovation Solution

A message gateway service provides a secure, browser-based shell and command-line interface for managing computing instances, enabling secure communication tunnels, centralized authentication, and auditable access control, eliminating the need for inbound port openings and SSH key management, while enforcing access privileges and logging commands for compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional VPN solutions or SSH access are used to enable remote computing instance access, then user access capability is improved, but security is worsened due to open inbound ports and SSH key management requirements

Engineering Contradiction:
Improveuser access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a bastion host as an intermediary system between the client and the computing instance. The bastion host runs a gateway service that mediates all access requests, eliminating the need for direct SSH connections to instances. This intermediary architecture allows secure access by centralizing authentication and control, while instances remain isolated with no direct inbound ports opened.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If inbound ports are opened on computing instances to enable access, then accessibility is improved, but security is worsened due to increased attack surface

Engineering Contradiction:
ImproveaccessibilityVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the access control functionality from the computing instances themselves and relocates it to a dedicated gateway service on the bastion host. By taking out the SSH server and authentication mechanisms from instances, the system eliminates the need for instances to have open inbound ports, thereby removing the attack surface on instances while maintaining accessibility through the gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If SSH keys and certificates are manually managed for secure access, then authentication security is improved, but operational overhead is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway service implements automatic authentication mechanisms that eliminate manual SSH key and certificate management. The system provides self-service capabilities where authentication credentials are automatically provisioned, rotated, and managed by the gateway service itself, reducing operational overhead while maintaining strong authentication security through centralized control.

Inventive Principle:
Principle #25Self-service

4Reliability

If bastion hosts or jump boxes are deployed for secure access, then access control is improved, but system complexity is worsened

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway service on the bastion host provides multiple functions in a single system: authentication, authorization, session management, logging, and command forwarding. By consolidating these previously separate functions into a universal gateway service, the system maintains strong access control while reducing overall system complexity compared to traditional multi-component bastion host architectures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11038847B1Facilitation of secure communications between a client and computing instance
Publication Date: 2021.06.15 AMAZON TECH INC
  • US11038847B1 patent drawing
  • US11038847B1 patent drawing
  • US11038847B1 patent drawing

AI summary

This disclosure is directed to one or more computing services that provide users with secure access to a computing instance, which is auditable and accessible via a cross-platform browser-based shell or command-line interface (CLI). The computing service(s) forego any need to open up inbound ports, thereby improving security. The computing service(s) employ centralized authentication and auditing to ensure compliance with policies and to log activities for auditing, forensics, or other purposes. A message gateway service creates secure channels with a client device and the computing instance to establish a secure communication tunnel between the client device and computing instance. Once the tunnel is established, a user can send a command via the client device to the computing instance, via the message gateway service. The command output is uploaded to this tunnel and is sent back to the client device, via the message gateway service.