Cloud Security Intermediary for Third-Party Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing platforms face security challenges when deploying resources in third-party locations over which they have no control, necessitating additional security measures to monitor and respond to potential threats effectively.

Innovation Solution

Implementing a system that uses physical and logical security mechanisms to monitor for suspicious activity, calculates a health score, and performs remediations such as rebooting servers to protect customer data, while providing notifications and options for remediating potential breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud resources are deployed in third-party locations, then resource availability and customer access are improved, but security control and threat monitoring capability deteriorate

Engineering Contradiction:
Improveresource deployment flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces security mechanisms including sensors, monitoring systems, and intermediaries between the cloud resources and third-party locations. These intermediaries enable the cloud provider to maintain security control and monitor threats remotely, resolving the contradiction between deployment flexibility and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional security mechanisms are deployed, then security monitoring and threat detection are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional security mechanisms that perform multiple tasks simultaneously. For example, sensors not only detect physical threats but also monitor environmental conditions, and the system integrates health scoring, automated remediation, and customer notification functions into a unified platform, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates automated remediation capabilities that respond to security threats without requiring constant human intervention. The health scoring system and automated response mechanisms enable the system to self-manage security incidents, reducing operational overhead while maintaining high security monitoring standards.

Inventive Principle:
Principle #25Self-service

3Speed

If real-time security monitoring is implemented, then threat detection speed is improved, but resource consumption and processing overhead increase

Engineering Contradiction:
Improvethreat detection speedVSAvoidprocessing overhead
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements health scoring systems that prioritize security monitoring based on risk levels. Not all resources are monitored with the same intensity at all times - the system adjusts monitoring depth and frequency based on detected threat levels, customer preferences, and resource criticality, reducing processing overhead while maintaining rapid threat detection capability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11496519B1Managing security in isolated network environments
Publication Date: 2022.11.08 AMAZON TECH INC
  • US11496519B1 patent drawing
  • US11496519B1 patent drawing
  • US11496519B1 patent drawing

AI summary

Security can be provided for data stored using resources that are deployed in an environment managed by a third party. Physical and logical detection mechanisms can be used to monitor various security aspects, and the resulting security data can be used to identify potential threats to these resources. In some embodiments, suspicious activity can cause resources such as data servers to be automatically and remotely rebooted such that keys stored in volatile memory on those data servers will be lost from those servers, such that an attacker will be unable to decrypt data stored on those servers. Once a determination of safety is made, the keys can be provided to the respective data servers such that data operations can resume.