On-Demand Secure Channel for Cloud Operator Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Regulated customers, such as banks and medical providers, face challenges in controlling access to their computing infrastructure when using cloud services, as cloud providers often have significant operational control, which can conflict with regulatory requirements for strict access management and compliance proof.

Innovation Solution

Implementing an on-demand secure communications channel that allows temporary access for cloud provider operators to customer on-premises resources, using an on-demand SSH service with a SSH wrapper to manage access and ensure compliance with regulatory standards, even if the customer system does not allow incoming connections from the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a persistent channel is maintained for cloud provider operators to access customer on-premises devices, then administrative operations can be performed efficiently, but customer control and security are compromised

Engineering Contradiction:
Improveadministrative operations accessVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the static persistent channel into a dynamic on-demand channel that can be established and terminated as needed. The SSH client at the on-premises device initiates connections to the SSH server in the cloud only when administrative operations are required, allowing the access state to change from permanently open to completely closed, thus balancing operational efficiency with security control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Instead of the cloud provider initiating and maintaining a persistent connection to the customer's device, the patent inverts the connection direction by having the on-premises SSH client initiate connections to the cloud SSH server only when needed. This reversal gives the customer's device control over when access occurs, eliminating the security risk of persistent incoming connections while maintaining operational capability.

Inventive Principle:
Principle #13The other way round (Inversion)

2Productivity

If cloud provider operators have full and unfettered access to cloud resources, then administrative tasks can be performed efficiently, but regulated customers cannot prove control compliance

Engineering Contradiction:
Improveadministrative task efficiencyVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an SSH wrapper as an intermediary layer between the cloud provider operators and the on-premises devices. This wrapper enforces organizational policies by controlling when and how connections are established, allowing administrative tasks to proceed efficiently while maintaining an audit trail that proves customer control for regulatory compliance purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms through the SSH wrapper that monitor and log all access requests and operations. This feedback loop provides visibility into when connections are established, who initiated them, and what operations were performed, enabling both efficient administrative task execution and demonstrable compliance with regulatory requirements through auditable records.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11824848B2On demand operations access to cloud customer resources
Publication Date: 2023.11.21 ORACLE INT CORP
  • US11824848B2 patent drawing
  • US11824848B2 patent drawing
  • US11824848B2 patent drawing

AI summary

Disclosed is an approach to implement an on-demand secure communications channel to a cloud-related resource that is located in a customer's on-premises data center, where the on-demand channel provides access to the resource to a cloud provider's operator employees. This creates on a temporary basis all of the infrastructure that is needed to allow the operational access to the customer system, which can then be destroyed once it is no longer needed.