Graphical Composer for Secure Access Policy Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and integrating computing resources across multiple services to define secure access policies is challenging due to complexity and requiring specialized expertise, making it difficult for users to visualize and enforce security policies effectively.

Innovation Solution

A graphical composer is used to create a graphical representation of policies, allowing users to select iconic representations of resources and actions, connect them with allow or deny connectors, and simulate permission models to detect errors, facilitating the creation and application of policies across multiple services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users directly manage and integrate computing resources across multiple services, then security policies can be enforced, but the complexity and expertise required increase significantly

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidresource integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a visual policy management interface that acts as an intermediary between users and the complex resource integration system. This interface provides drag-and-drop templates for defining security policies, automatically generating the necessary resource integration configurations without requiring users to directly manage the underlying complexity. The intermediary translates user-friendly visual definitions into the actual policy enforcement mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing users to define and enforce security policies through intuitive visual templates without requiring specialized expertise. The automated policy generation and resource integration capabilities allow users to independently configure secure access across multiple services using simple drag-and-drop operations, eliminating the need for expert intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If specialized expertise is required to integrate resources across services, then security can be maintained, but ease of operation decreases

Engineering Contradiction:
Improvesecurity maintenanceVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent employs template-based copying where pre-defined visual templates represent common security policy patterns. Users can copy these templates and modify them through simple drag-and-drop operations rather than creating policies from scratch or understanding complex integration details. The templates encapsulate expert knowledge and reproduce it in an easily consumable format for general users.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The visual interface serves as an intermediary that translates complex security requirements into simple visual definitions. It maintains security by ensuring that all policy definitions are properly validated and converted into enforceable configurations, while simultaneously improving ease of operation by presenting users with intuitive drag-and-drop templates instead of requiring them to understand underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If users define policies without visual aids, then system complexity is reduced, but the ability to visualize and enforce security policies effectively deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidpolicy visualization capability
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transitions policy definition from a one-dimensional textual or configuration-based approach to a two-dimensional visual canvas where policies are defined through drag-and-drop operations. This dimensional change provides spatial organization and visual feedback that enhances users' ability to visualize and understand security policies without significantly increasing underlying system complexity. The visual dimension allows users to see policy relationships and enforcement logic in an intuitive graphical format.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10592068B1Graphic composer for service integration
Publication Date: 2020.03.17 AMAZON TECH INC
  • US10592068B1 patent drawing
  • US10592068B1 patent drawing
  • US10592068B1 patent drawing

AI summary

A customer of a computing resource service provider may use an interface to access a graphical composer and generate one or more graphical representations of applications that may be provided to a variety of users of the customer's one or more resources. Once the customer has created a graphical representation of an application, a domain specific language model based at least on the graphical representation of the application may be created such that one or more simulations may be performed to determine whether the requested application includes any errors or conflicts. If the one or more simulations result in the application including no errors or conflicts, the domain specific language model may be compiled in an executable programming language to create the application. The application may then be provided to users who may utilize devices capable of understanding the executable programming language to install the application.