Configurable Computing Resource Service Security via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face challenges in securely managing access to computing resources, particularly in preventing inappropriate access and responding to security incidents in dynamic, remote, and multi-user environments.

Innovation Solution

A configurable computing resource service that allows users to create, configure, and manage computing resources over public networks, providing secure private access through VPN connections and authentication techniques, with an interface for users to indicate security concerns and automate responses such as restricting access or revoking credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share computing resources among multiple users, then resource utilization efficiency is improved, but security risks and access control complexity increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments computing resources into virtual machines that can be independently allocated to different users. Each virtual machine acts as an isolated security domain, allowing resource sharing while maintaining security boundaries. The system divides physical computing resources (CPU, memory, storage) into separable virtual units that can be dynamically assigned and revoked based on user needs and security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a computing resource service manager as an intermediary between users and physical computing resources. This manager handles authentication, authorization, and access control, mediating all interactions between users and virtualized resources. The intermediary enforces security policies, manages credentials, and coordinates security responses without requiring users to directly manage underlying infrastructure security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access to computing resources is made available over public networks, then user accessibility and convenience are improved, but exposure to security incidents and inappropriate access increases

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity incidents
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before granting access to computing resources. Users must provide credentials and undergo security verification before being allocated virtual machine access. Security policies are pre-configured and enforced before any resource interaction occurs, preventing inappropriate access before it can happen rather than responding after security incidents occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes feedback mechanisms where the computing resource service manager continuously monitors access patterns and security events. When security concerns are detected or users report incidents, the system responds by adjusting access controls, isolating affected resources, or revoking credentials. This closed-loop feedback system enables dynamic security adaptation while maintaining public network accessibility.

Inventive Principle:
Principle #23Feedback

3Reliability

If security measures such as authentication and access control are implemented, then security is improved, but system complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal computing resource service manager that handles multiple security functions through a single system component. This manager performs authentication, authorization, credential management, security policy enforcement, and incident response coordination all through one intermediary. By consolidating security functions into a multi-functional system rather than separate specialized components, the patent reduces overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10070195B1Computing resource service security method
Publication Date: 2018.09.04 AMAZON TECH INC
  • US10070195B1 patent drawing
  • US10070195B1 patent drawing
  • US10070195B1 patent drawing

AI summary

Techniques are described for providing users with computing resources, such as to enable users to interact with a remote configurable computing resource service in order to create and configure computing resources that are provided by the configurable computing resource service for use by the users. Computing resources provided by the configurable computing resource service may be configured to be private computing resources that are accessible only by the users who create them. The configurable computing resource service provides one or more interfaces that allow a user to provide to the computing resource service an indication of a security concern related to the provided computing resources, and responds to a received indication of a security concern by taking one or more actions to secure the provided computing resources.