Dedicated Secure Entry Points for Flexible Cloud Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing systems face challenges in securely provisioning and accessing cloud resources while ensuring compliance with varying access conditions and security levels for different users and resources.
Innovation Solution
A system with dedicated secure entry points and network load balancers that map computing entities to specific target resources, enforcing access conditions through network addresses and validation processes to establish secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single secure entry point is used to access cloud resources, then security is improved, but access flexibility and ease of operation deteriorate
Solution Approach 1:
The patent segments the single secure entry point into multiple dedicated secure entry points (DSEPs), each associated with specific target resources. This allows different computing entities to access different resources through dedicated pathways, maintaining security while improving access flexibility and reducing connectivity issues.
Solution Approach 2:
The patent introduces a network load balancer as an intermediary that maps computing entities to appropriate DSEPs. This intermediary component receives access requests, validates them against access conditions, and routes them to the correct dedicated secure entry point, thereby enhancing both security and operational ease.
2Reliability
If multiple dedicated secure entry points are provisioned for different target resources, then access flexibility and reliability are improved, but device complexity increases
Solution Approach 1:
The network load balancer serves multiple functions: it acts as a mapping service between computing entities and DSEPs, validates access conditions, routes requests appropriately, and provides a unified interface for access management. This multi-functionality reduces the need for separate management systems for each DSEP, thereby limiting the increase in system complexity.
3Reliability
If access conditions are strictly enforced at dedicated secure entry points, then security is improved, but access speed and productivity deteriorate
Solution Approach 1:
The system performs preliminary validation of access conditions at the network load balancer before requests reach the DSEPs. By pre-authorizing and pre-routing requests based on validated access conditions, the system reduces the validation overhead at each DSEP, thereby maintaining security while improving access speed and reducing latency.
Data Source
AI summary
A system identifies a secure entry point for accessing a target resource of a virtual cloud network. The system determines a mapping that maps the secure entry point to a particular addressable network entity of a plurality of addressable network entities. Based on the mapping, the system selects the particular addressable network entity as a destination for requests associated with the target resource. The system transmits a network address corresponding to the particular addressable network entity to a computing entity as a destination address for the requests associated with the target resource. The computing entity transmits the requests associated with the target resource to the network address corresponding to the particular addressable network entity, and the addressable network entity forwards the requests to the secure entry point.


