Bastion Worker Control of Anomaly Commands Across Multi-Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service networks face security vulnerabilities due to limited public IPs, exposing internal instance information, and require cumbersome agent installations for anomaly command control, lacking effective command execution and management through bastion hosts.

Innovation Solution

A system and method for controlling and executing anomaly commands in a multi-network environment using a bastion host, enabling registration and management of anomaly command patterns, setting different command levels, and eliminating the need for instance agents, with features like anomaly command verification tokens and user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a bastion host is installed across all networks to enable secure access to instances, then security is improved and internal instance information is protected, but device complexity increases and ease of operation deteriorates due to the need to directly manage all account information and execute SSH tunneling for each instance

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the bastion host functionality into distributed bastion workers across multiple networks. Each bastion worker handles specific network segments, eliminating the need for a single complex centralized bastion host while maintaining security. This segmentation reduces the complexity burden on any single device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary anomaly command control system that mediates between users and instances. This intermediary automatically manages account information, handles SSH tunneling, and controls command execution, eliminating the need for users to directly manage complex bastion host operations while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a bastion host is installed across all networks to enable secure access to instances, then security is improved and internal instance information is protected, but ease of operation deteriorates due to the need to directly manage all account information and execute SSH tunneling for each instance

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The bastion workers and anomaly command control system operate autonomously, automatically managing account information, establishing SSH tunnels, and controlling command execution without requiring user intervention. This self-service mechanism significantly improves ease of operation while maintaining the security benefits of bastion host deployment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The intermediary anomaly command control system automatically handles all complex operations including account management, SSH tunneling establishment, and command filtering. Users simply interact with the simplified interface while the intermediary manages all the complex backend operations, dramatically improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If an agent is installed on each instance to prevent security threats, then security is improved, but device complexity increases and ease of manufacture deteriorates due to the cumbersome installation process

Engineering Contradiction:
ImprovesecurityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the security control functionality from individual instances by implementing it in the bastion workers and anomaly command control system. This eliminates the need to install agents on each instance, significantly improving ease of manufacture while maintaining security through centralized command filtering and control.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If public IPs are used to connect to instances, then ease of operation is improved, but security deteriorates as internal instance information is exposed to the outside

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The bastion workers and anomaly command control system serve as intermediaries between external users and internal instances. Users connect to the bastion worker through public IPs for ease of operation, while the intermediary maintains security by filtering commands and preventing direct exposure of internal instance information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network access by separating public-facing bastion workers from private instances. This segmentation allows public IP access for ease of operation while maintaining security through the architectural separation that prevents direct exposure of internal instance information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12519751B2System and method for controlling and executing anomaly commands in multi-network environment
Publication Date: 2026.01.06 SAMSUNG SDS CO LTD
  • US12519751B2 patent drawing
  • US12519751B2 patent drawing
  • US12519751B2 patent drawing

AI summary

A method of controlling and executing an anomaly command in a multi-network environment is includes: extracting a command, which is input by a user to a target instance through an accessed bastion worker; determining whether the extracted command is an anomaly command by comparing the extracted command with anomaly command patterns; based on the extracted command being determined to be the anomaly command, determining whether an execution of the anomaly command is permitted in the target instance; and based on the execution of the anomaly command being not permitted, notifying the user of a procedure for approving the execution of the anomaly command based on a level of the anomaly command being one of levels, which are classified in advance based on the anomaly command patterns; either executing or blocking the command input by the user, wherein the procedure is determined differently depending on the level of the anomaly command.