Cryptography Service for Immediate Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed systems face challenges in ensuring immediate and consistent enforcement of security policies across multiple computing resources, leading to potential inconsistencies and inconvenience in data access control.

Innovation Solution

A cryptography service is implemented to manage keys securely, enforce policies, and perform cryptographic operations, ensuring authorized access and preventing unauthorized use through advanced encryption standards, key rotation, and policy-based access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If configuration changes are propagated throughout a distributed system, then security policy consistency is improved, but the time required for policy effectiveness increases

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidpolicy effectiveness delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the distributed computing environment into multiple zones or regions, allowing security policies to be enforced locally at each segment rather than requiring system-wide propagation. This enables immediate policy effectiveness in the relevant segment while avoiding the time delay of updating the entire distributed system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary component is introduced that receives security policy configurations and immediately enforces them at the appropriate computing resources without waiting for propagation throughout the entire distributed system. This intermediary acts as a mediator that decouples policy configuration from system-wide distribution, enabling immediate policy effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are enforced across all computing resources, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy enforcement functionality is extracted from the core distributed system operations and placed into a dedicated security management component. This extraction allows security policies to be enforced effectively while isolating the complexity into a separate module, reducing the overall system complexity and making security management more manageable.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A universal security policy enforcement mechanism is implemented that can handle multiple security requirements and policy types through a single integrated system. This multi-functional approach improves data security across all computing resources while reducing system complexity by avoiding the need for separate enforcement mechanisms for different security policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10911457B2Immediate policy effectiveness in eventually consistent systems
Publication Date: 2021.02.02 AMAZON TECH INC
  • US10911457B2 patent drawing
  • US10911457B2 patent drawing
  • US10911457B2 patent drawing

AI summary

Policy changes are propagated to access control devices of a distributed system. The policy changes are given immediate effect without having to wait for the changes to propagate through the system. A token comprises the policy change and can be provided in connection with access requests. Before an access control device has received a propagated policy change, the access control device can evaluate a token provided in connection with a request to determine, consistent with the policy change, whether to fulfill the request.