Dynamic Parallel Nodes for Secure Cloud Compute Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing infrastructure management systems face challenges in securing access to compute nodes, particularly when exposed to public networks, leading to potential attacks and unauthorized access, and require costly VPNs for secure communication.

Innovation Solution

A system for managing cloud computing infrastructure access using dynamic parallel nodes, including ephemeral bastion nodes configured in a multi-layer structure, which validates user requests through time windows and request sequences to enhance security and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If compute nodes are exposed to public networks for remote access, then accessibility and ease of operation improve, but security and vulnerability to attacks worsen

Engineering Contradiction:
Improveremote access capabilityVSAvoidattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces bastion nodes as intermediary components between external users and compute nodes. These bastion nodes act as secure gateways that authenticate and authorize access requests before forwarding them to target compute nodes, thereby enabling remote access while maintaining security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network architecture into multiple isolated layers: external network, bastion node layer, private network, and compute node layer. This segmentation allows compute nodes to remain hidden in private networks while still enabling controlled access through the bastion node gateway layer.

Inventive Principle:
Principle #1Segmentation

2Reliability

If VPN or dedicated network is used for secure access, then security improves, but cost and device complexity worsen

Engineering Contradiction:
Improveaccess securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The bastion nodes automatically perform authentication, authorization, and command forwarding functions without requiring external VPN infrastructure. The system self-manages security credentials and access control policies, eliminating the need for separate VPN gateways or dedicated network hardware.

Inventive Principle:
Principle #25Self-service

3Reliability

If access credentials are protected, then security improves, but ease of operation worsens due to restricted access

Engineering Contradiction:
Improvecredential securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The bastion nodes serve as secure intermediaries that handle credential verification and command authorization. Users interact with the bastion nodes using protected credentials, while the bastion nodes manage the secure forwarding of authenticated commands to compute nodes, balancing security with operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250286883A1Apparatus and method for managing cloud computing infrastructure access based on dynamic parallel nodes
Publication Date: 2025.09.11 ELECTRONICS & TELECOMM RES INST
  • US20250286883A1 patent drawing
  • US20250286883A1 patent drawing
  • US20250286883A1 patent drawing

AI summary

Disclosed herein are an apparatus and method for managing cloud computing infrastructure access based on dynamic parallel nodes. The apparatus for managing cloud computing infrastructure access based on dynamic parallel nodes may be configured to configure at least two of multiple compute nodes included in a computing infrastructure as representative nodes at preset intervals, validate, by the representative nodes, a user with respect to a remote command requested by the user for the computing infrastructure, and forward the remote command requested by a validated user to a target compute node included in the computing infrastructure.