Dynamic Security Policy Management via Endpoint Change Notifications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based services face challenges in managing dynamic security policies due to frequent changes in user network addresses, leading to resource-intensive and error-prone access control management.

Innovation Solution

Implementing a system that allows customers to subscribe to notification services for endpoint changes, enabling automatic or manual updates of access control lists and security policies based on up-to-date endpoint information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is based on network address tracking, then access security is improved, but resource consumption increases and update timeliness deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service through automated endpoint change detection and notification. The notification service automatically detects endpoint changes and pushes updates to subscribed services without requiring manual intervention, thereby improving access security while reducing resource consumption compared to manual tracking methods

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the notification service continuously monitors endpoint changes and provides real-time updates back to access control systems. This closed-loop feedback ensures access security is maintained through up-to-date endpoint information without requiring continuous manual resource investment

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If manual access control list updates are performed, then security policy accuracy is improved, but update speed deteriorates

Engineering Contradiction:
Improvesecurity policy accuracyVSAvoidupdate speed
Core Design Contradiction:
Manufacturing precisionVSSpeed

Solution Approach 1:

The notification service performs preliminary action by proactively detecting endpoint changes before they impact access control decisions. By subscribing to endpoint change notifications and preparing updates in advance, the system ensures both high security policy accuracy and fast update speed when changes occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual mechanical update processes with automated electronic notification and update mechanisms. The notification service automatically detects endpoint changes and pushes updates to access control lists, eliminating manual intervention while maintaining high accuracy and achieving near real-time update speeds

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If frequent endpoint changes are tracked manually, then access control reliability is improved, but error rate increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoiderror rate
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The notification service performs self-service by automatically detecting and tracking endpoint changes without human intervention. This automation eliminates manual errors while maintaining high access control reliability through consistent, programmatic endpoint change detection and notification

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12301629B2Dynamic security policy management
Publication Date: 2025.05.13 AMAZON TECH INC
  • US12301629B2 patent drawing
  • US12301629B2 patent drawing
  • US12301629B2 patent drawing

AI summary

Security policies can be dynamically updated in response to changes in endpoints associated with those policies. A user can indicate one or more regions or networks from which access is to be granted under a specific security policy. The user can subscribe to receive notifications upon a change relating to those endpoints, such as the addition or removal of one or more endpoints. When a change is detected, new policy information can be generated automatically and published for subscribed policies, which can then have the updates applied automatically or provided for manual review and application. Such a process enables access determinations to be made based upon up-to-date endpoint information.