Cloud Account Compartments for Granular Access and Cost Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for managing user access and resource usage in cloud computing environments often result in excessive costs and security risks due to the lack of granular control over user permissions and resource allocation within shared accounts.

Innovation Solution

The implementation of 'compartments' within cloud accounts, which are logical entities that allow for varying levels of access to computing services and resources, enabling better control over user permissions, resource allocation, and billing, with features like tagging for resource tracking, quota management, and the ability to transfer ownership and convert compartments into standalone accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple users share a single cloud account, then resource utilization efficiency improves, but security risks and cost control deteriorate

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides a cloud account into multiple isolated compartments, each with its own security policies, resource quotas, and billing parameters. This segmentation allows multiple users to share the account while maintaining distinct security boundaries, thus improving resource utilization without compromising security.

Inventive Principle:
Principle #1Segmentation

2Productivity

If multiple users share a single cloud account, then resource utilization efficiency improves, but cost management deteriorates

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidcost management
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The patent implements compartmentalization that separates cost allocation and billing parameters for different users. Each compartment can have independent billing rules, quotas, and cost centers, enabling precise cost tracking and management while maintaining shared resource utilization.

Inventive Principle:
Principle #1Segmentation

3Reliability

If individual user accounts are created for each user, then security control improves, but financial burden and system complexity worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple user environments into a single shared account through isolated compartments. This approach maintains the security control of individual accounts while eliminating the need for separate account management, reducing overall system complexity and financial burden.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If individual user accounts are created for each user, then security control improves, but financial burden worsens

Engineering Contradiction:
Improvesecurity controlVSAvoidfinancial burden
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines multiple user accounts into a single shared account with isolated compartments, maintaining security control while reducing the financial burden of multiple individual account subscriptions and management overhead.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11687661B2Compartments
Publication Date: 2023.06.27 AMAZON TECH INC
  • US11687661B2 patent drawing
  • US11687661B2 patent drawing
  • US11687661B2 patent drawing

AI summary

Customers of a service provider are able to provision compartments of the accounts. The both the accounts and the compartments, in some embodiments, may have associated computing resources and identities. One or more identities of the account may be authorized to perform administrative operations in the compartment. Identities of the compartment may lack the ability to perform any administrative actions outside of the compartment but inside of the account.