Cross-boundary Data Backup Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and maintaining the security of computer systems and networks is complex, especially as the number and types of users and operations expand, making it difficult to ensure that access rights grant access to resources users should have while denying access to those they shouldn't.

Innovation Solution

Implementing a security policy that enforces permissions across logical boundaries within a computing resource service provider, using a system that includes an activity manager, policy manager, and resource manager to manage and enforce access rights, ensuring that only authorized users can perform backup operations across accounts within an organization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access rights are expanded to support more users and operations, then system functionality and versatility improve, but security management complexity and difficulty increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a security policy as an intermediary mechanism that mediates between users and computing resources. The security policy contains predefined rules and conditions that automatically evaluate access requests, eliminating the need for manual security management of each user-resource interaction. This resolves the contradiction by maintaining expanded access rights while automating security enforcement through the policy intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security policy operates autonomously to evaluate and enforce access rights without requiring manual intervention from security administrators. The system self-manages security by automatically applying the policy rules to each access request, thereby maintaining security control even as the number of users and operations expands indefinitely.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual security management is used to control access rights, then security control precision is maintained, but operational efficiency and productivity decrease

Engineering Contradiction:
Improvesecurity control precisionVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security policy autonomously evaluates access requests and enforces decisions without requiring manual security administration. This automation maintains precise security control through consistent policy application while dramatically improving operational efficiency by eliminating manual review processes for each access request.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security policy continuously evaluates access requests against predefined rules and automatically enforces decisions. This closed-loop feedback mechanism ensures that security control precision is maintained through consistent rule application while operational efficiency improves because the system self-regulates without human intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If security policies are enforced across logical boundaries, then data security and protection improve, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy is designed as a universal mechanism that can be applied across multiple logical boundaries and different computing resources. Rather than implementing separate security controls for each boundary, the single security policy framework provides multi-functional protection across accounts, organizations, and resources, thereby improving data security while reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If access rights are restricted to prevent unauthorized access, then security and protection improve, but system adaptability and ease of operation decrease

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security policy automatically evaluates access requests and makes authorization decisions based on predefined rules, eliminating the need for manual security approvals that would hinder usability. This self-service approach maintains strong security protection while improving ease of operation because legitimate access requests are automatically granted without human intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11914731B1Cross-boundary data backup background
Publication Date: 2024.02.27 AMAZON TECH INC
  • US11914731B1 patent drawing
  • US11914731B1 patent drawing
  • US11914731B1 patent drawing

AI summary

Aspects described herein relate to securely performing cross-boundary backup operations. A service of a computing resource service provider may enable backup operations between a source account and a destination account of an organization based at least in part on a security policy allowing such operations.