On-Premises Computing Management Entity for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring on-premises computing resources to securely and efficiently access remote computing resources is challenging, particularly in terms of defining a secure access mechanism and managing credentials for accessing these resources.

Innovation Solution

A computing management entity within the on-premises environment is configured to request and manage credentials for accessing remote computing resources, using role-based access control and credential management services provided by the remote computing environment, enabling secure and efficient access through authentication and authorization mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If on-premises computing resources are configured to access remote computing resources, then access capability is improved, but security risk increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A computing management entity is introduced as an intermediary component between on-premises computing resources and remote computing resources. This entity manages credential assignment and access control, enabling secure communication while maintaining security boundaries. The intermediary handles authentication and authorization centrally, allowing on-premises resources to access remote resources without exposing sensitive credentials or creating direct security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are managed for accessing remote computing resources, then access security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Credential management functionality is extracted from individual on-premises computing resources and consolidated into a dedicated computing management entity. This centralization removes the complexity of managing credentials across multiple distributed systems, as the management entity handles credential issuance, rotation, and validation centrally, simplifying the overall system architecture while maintaining strong security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The computing management entity serves multiple functions: it manages credential assignment, controls access permissions, and coordinates communication between on-premises and remote resources. This multi-functional design consolidates what would otherwise require separate systems, reducing overall complexity while improving access security through unified management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10880283B1Techniques for remote access to a computing resource service provider
Publication Date: 2020.12.29 AMAZON TECH INC
  • US10880283B1 patent drawing
  • US10880283B1 patent drawing
  • US10880283B1 patent drawing

AI summary

Method and apparatus for remotely accessing a computing resource service provider are disclosed. In the method and apparatus, a first computing environment sends, to a second computing environment, a request for information usable for accessing the second computing environment. In response to the request, the information that is usable to remotely access a subset of the computing resources of the second computing environment is made available to a computing system of the first computing environment, whereby the subset of the computing resources is provisioned for a customer of the second computing environment and the customer of the second environment operates the first computing environment.