Configurable Computing Resource Service Security via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization technologies face challenges in securely managing access to computing resources, particularly in preventing inappropriate access and responding to security incidents in dynamic, remote, and multi-user environments.
Innovation Solution
A configurable computing resource service that allows users to create, configure, and manage computing resources over public networks, providing secure private access through VPN connections and authentication techniques, with an interface for users to indicate security concerns and automate responses such as restricting access or revoking credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization technologies are used to share computing resources among multiple users, then resource utilization efficiency is improved, but security risks and access control complexity increase
Solution Approach 1:
The patent segments computing resources into virtual machines that can be independently allocated to different users. Each virtual machine acts as an isolated security domain, allowing resource sharing while maintaining security boundaries. The system divides physical computing resources (CPU, memory, storage) into separable virtual units that can be dynamically assigned and revoked based on user needs and security requirements.
Solution Approach 2:
The patent introduces a computing resource service manager as an intermediary between users and physical computing resources. This manager handles authentication, authorization, and access control, mediating all interactions between users and virtualized resources. The intermediary enforces security policies, manages credentials, and coordinates security responses without requiring users to directly manage underlying infrastructure security.
2Ease of operation
If access to computing resources is made available over public networks, then user accessibility and convenience are improved, but exposure to security incidents and inappropriate access increases
Solution Approach 1:
The patent implements preliminary authentication and authorization actions before granting access to computing resources. Users must provide credentials and undergo security verification before being allocated virtual machine access. Security policies are pre-configured and enforced before any resource interaction occurs, preventing inappropriate access before it can happen rather than responding after security incidents occur.
Solution Approach 2:
The patent establishes feedback mechanisms where the computing resource service manager continuously monitors access patterns and security events. When security concerns are detected or users report incidents, the system responds by adjusting access controls, isolating affected resources, or revoking credentials. This closed-loop feedback system enables dynamic security adaptation while maintaining public network accessibility.
3Reliability
If security measures such as authentication and access control are implemented, then security is improved, but system complexity and overhead increase
Solution Approach 1:
The patent implements a universal computing resource service manager that handles multiple security functions through a single system component. This manager performs authentication, authorization, credential management, security policy enforcement, and incident response coordination all through one intermediary. By consolidating security functions into a multi-functional system rather than separate specialized components, the patent reduces overall system complexity while maintaining comprehensive security.
Data Source
AI summary
Techniques are described for providing users with computing resources, such as to enable users to interact with a remote configurable computing resource service in order to create and configure computing resources that are provided by the configurable computing resource service for use by the users. Computing resources provided by the configurable computing resource service may be configured to be private computing resources that are accessible only by the users who create them. The configurable computing resource service provides one or more interfaces that allow a user to provide to the computing resource service an indication of a security concern related to the provided computing resources, and responds to a received indication of a security concern by taking one or more actions to secure the provided computing resources.


