Dedicated Secure Entry Points for Flexible Cloud Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in securely provisioning and accessing cloud resources while ensuring compliance with varying access conditions and security levels for different users and resources.

Innovation Solution

A system with dedicated secure entry points and network load balancers that map computing entities to specific target resources, enforcing access conditions through network addresses and validation processes to establish secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single secure entry point is used to access cloud resources, then security is improved, but access flexibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the single secure entry point into multiple dedicated secure entry points (DSEPs), each associated with specific target resources. This allows different computing entities to access different resources through dedicated pathways, maintaining security while improving access flexibility and reducing connectivity issues.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network load balancer as an intermediary that maps computing entities to appropriate DSEPs. This intermediary component receives access requests, validates them against access conditions, and routes them to the correct dedicated secure entry point, thereby enhancing both security and operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple dedicated secure entry points are provisioned for different target resources, then access flexibility and reliability are improved, but device complexity increases

Engineering Contradiction:
Improveaccess reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network load balancer serves multiple functions: it acts as a mapping service between computing entities and DSEPs, validates access conditions, routes requests appropriately, and provides a unified interface for access management. This multi-functionality reduces the need for separate management systems for each DSEP, thereby limiting the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access conditions are strictly enforced at dedicated secure entry points, then security is improved, but access speed and productivity deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary validation of access conditions at the network load balancer before requests reach the DSEPs. By pre-authorizing and pre-routing requests based on validated access conditions, the system reduces the validation overhead at each DSEP, thereby maintaining security while improving access speed and reducing latency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250274453A1Dedicated Secure Entry Points For Accessing Target Resources
Publication Date: 2025.08.28 ORACLE INT CORP
  • US20250274453A1 patent drawing
  • US20250274453A1 patent drawing
  • US20250274453A1 patent drawing

AI summary

A system identifies a secure entry point for accessing a target resource of a virtual cloud network. The system determines a mapping that maps the secure entry point to a particular addressable network entity of a plurality of addressable network entities. Based on the mapping, the system selects the particular addressable network entity as a destination for requests associated with the target resource. The system transmits a network address corresponding to the particular addressable network entity to a computing entity as a destination address for the requests associated with the target resource. The computing entity transmits the requests associated with the target resource to the network address corresponding to the particular addressable network entity, and the addressable network entity forwards the requests to the secure entry point.