Gateway Server for Secure Multi-Node Command Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and provisioning large-scale computing resources across distributed networks is complex due to the need for secure and efficient access, authorization, and resource management, especially in virtualized environments where multiple users share physical computing resources.

Innovation Solution

A user command execution interface component that provides a shell-like interface for users to access and manage network-accessible computing resources, utilizing a shell aggregator module to execute commands on multiple nodes, a permission broker to manage authorization, and a shell transport layer for secure connections, allowing for aggregated result handling and efficient management of computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing resources among multiple users, then resource utilization efficiency is improved, but security and authorization management complexity increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidauthorization management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway server as an intermediary component that sits between users and the virtualized computing resources. This gateway server handles authentication, authorization, and command routing, thereby simplifying the authorization management complexity while maintaining secure multi-user access to shared physical computing resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If direct access to computing nodes is provided to users, then ease of operation is improved, but security risks increase

Engineering Contradiction:
Improveaccess to computing nodesVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway server acts as a secure intermediary that mediates all user access to computing nodes. It provides a controlled interface where users can execute commands without direct access to the underlying infrastructure, thereby maintaining ease of operation while mitigating security risks through centralized authorization and monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of computing resources through virtualization, allowing users to interact with virtualized versions rather than physical hardware. This copying approach enables easy access to computing capabilities while isolating users from direct security risks associated with physical node access.

Inventive Principle:
Principle #26Copying

3Reliability

If centralized permission management is implemented, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway server is designed as a universal component that performs multiple functions including authentication, authorization, command routing, and result aggregation. By consolidating these diverse functions into a single multi-functional system, the patent improves centralized security control while minimizing the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11394714B2Controlling user access to command execution
Publication Date: 2022.07.19 AMAZON TECH INC
  • US11394714B2 patent drawing
  • US11394714B2 patent drawing
  • US11394714B2 patent drawing

AI summary

Techniques are described for providing users with access to perform commands on network-accessible computing resources. In some situations, permissions are established for user(s) to execute command(s) on computing node(s) provided by an online service, such as by maintaining various permission information externally to those provided computing nodes for use in controlling users' ability to access, use, and/or modify the provided computing nodes. An interface component may use such external permissions information to determine if a particular user is authorized to execute one or more particular commands on one or more particular computing nodes, and to initiate simultaneous and independent execution of the command(s) on the computing node(s) when authorized. The interface component may further aggregate results from each computing node that executed the command(s), prior to providing the results to the user.