Dynamic Parallel Nodes for Secure Cloud Compute Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing infrastructure management systems face challenges in securing access to compute nodes, particularly when exposed to public networks, leading to potential attacks and unauthorized access, and require costly VPNs for secure communication.
Innovation Solution
A system for managing cloud computing infrastructure access using dynamic parallel nodes, including ephemeral bastion nodes configured in a multi-layer structure, which validates user requests through time windows and request sequences to enhance security and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If compute nodes are exposed to public networks for remote access, then accessibility and ease of operation improve, but security and vulnerability to attacks worsen
Solution Approach 1:
The patent introduces bastion nodes as intermediary components between external users and compute nodes. These bastion nodes act as secure gateways that authenticate and authorize access requests before forwarding them to target compute nodes, thereby enabling remote access while maintaining security isolation.
Solution Approach 2:
The system segments the network architecture into multiple isolated layers: external network, bastion node layer, private network, and compute node layer. This segmentation allows compute nodes to remain hidden in private networks while still enabling controlled access through the bastion node gateway layer.
2Reliability
If VPN or dedicated network is used for secure access, then security improves, but cost and device complexity worsen
Solution Approach 1:
The bastion nodes automatically perform authentication, authorization, and command forwarding functions without requiring external VPN infrastructure. The system self-manages security credentials and access control policies, eliminating the need for separate VPN gateways or dedicated network hardware.
3Reliability
If access credentials are protected, then security improves, but ease of operation worsens due to restricted access
Solution Approach 1:
The bastion nodes serve as secure intermediaries that handle credential verification and command authorization. Users interact with the bastion nodes using protected credentials, while the bastion nodes manage the secure forwarding of authenticated commands to compute nodes, balancing security with operational convenience.
Data Source
AI summary
Disclosed herein are an apparatus and method for managing cloud computing infrastructure access based on dynamic parallel nodes. The apparatus for managing cloud computing infrastructure access based on dynamic parallel nodes may be configured to configure at least two of multiple compute nodes included in a computing infrastructure as representative nodes at preset intervals, validate, by the representative nodes, a user with respect to a remote command requested by the user for the computing infrastructure, and forward the remote command requested by a validated user to a target compute node included in the computing infrastructure.


