Data Center Security Control System for Physical Exception Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security mechanisms in data centers primarily focus on preventing unauthorized access but fail to address the protection of assets and information once a security exception has occurred, such as unauthorized entry.

Innovation Solution

Implementing a security mechanism that includes a security exception response plan to physically secure data by isolating and relocating computing resources, encrypting data, and changing routing tables to prevent access to compromised areas, based on user-defined security preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing computer security mechanisms are used to prevent unauthorized access, then access control is improved, but protection of assets and information after a security exception occurs is not addressed

Engineering Contradiction:
Improvesecurity protectionVSAvoidresponse to security exceptions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by establishing security exception response plans in advance that automatically execute when security exceptions are detected. These pre-configured plans include predetermined actions such as isolating computing resources, relocating data, and notifying security personnel, allowing the system to respond immediately without human intervention when exceptions occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adapts its security measures based on the type and severity of security exceptions detected. Different response plans are triggered depending on the specific exception scenario, allowing the security mechanism to adjust its behavior in real-time rather than using static, one-size-fits-all security approaches.

Inventive Principle:
Principle #15Dynamics

2Reliability

If computing resources are isolated and relocated during a security exception, then data protection is improved, but service disruption may occur

Engineering Contradiction:
Improvedata protectionVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments computing resources into isolated units that can be individually controlled and relocated. By dividing the infrastructure into manageable segments, the system can isolate only the affected resources during a security exception rather than shutting down entire systems, thereby maintaining service availability for unaffected segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses virtualization technology as an intermediary layer between physical hardware and computing workloads. This intermediary enables rapid migration and isolation of virtualized resources without direct physical intervention, minimizing disruption to service delivery while effectively protecting data during security exceptions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data is encrypted and resources are relocated rapidly, then security response effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where the security mechanism automatically detects exceptions, selects appropriate response plans, executes protective actions, and monitors outcomes without requiring manual intervention. This automation reduces the operational complexity of managing complex security measures while maintaining high response effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms that continuously monitor security conditions and adjust response actions accordingly. Sensors and detection mechanisms provide real-time feedback about security exceptions, enabling the system to dynamically adjust its complexity by activating only the necessary protective measures rather than always employing all available security mechanisms.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8984651B1Integrated physical security control system for computing resources
Publication Date: 2015.03.17 AMAZON TECH INC
  • US8984651B1 patent drawing
  • US8984651B1 patent drawing
  • US8984651B1 patent drawing

AI summary

A computing data center that contains a set of physically isolatable units of computing resources for which a physical security exception action plan is to be provided. Upon determining that a security event has occurred for one or more physically isolatable units, the computing data center implements physical security settings on potentially affected computing resources so that a physical security exception action plan can be met. The computing data center may, for example, remove data from the physically isolatable units and make the removed data available elsewhere.