Parallel Tagging System with Identity Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current tagging systems in data centers lack security and integrity features, allowing unauthorized access and changes to tags, which limits their effectiveness in managing and securing computing resources and workflows.

Innovation Solution

A parallel tagging system with identity and access control, version control, and logging of changes is implemented to authenticate and authorize users, ensuring only authorized personnel can view or edit tags, and providing cryptographic binding for integrity and non-repudiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a parallel tagging system with identity and access control is implemented, then security and integrity of tags are improved, but device complexity increases

Engineering Contradiction:
Improvetag security and integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The tagging system is divided into multiple independent components: identity verification module, access control module, version control module, logging module, and cryptographic binding module. Each component handles a specific security function, allowing the system to achieve comprehensive security while maintaining modularity and manageable complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Identity verification and access authorization are performed before any tag operations. The system pre-establishes user credentials, defines access policies, and validates permissions before allowing tag viewing or editing, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If version control and logging of changes are implemented, then reliability and traceability are improved, but loss of time increases

Engineering Contradiction:
ImprovetraceabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The version control and logging system operates automatically without requiring manual intervention. Change logs are self-generated whenever tags are modified, version numbers are automatically incremented, and the system maintains its own audit trail, reducing the time burden on users while ensuring complete traceability.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic binding is implemented, then integrity and non-repudiation are improved, but use of energy increases

Engineering Contradiction:
Improveintegrity and non-repudiationVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Cryptographic binding is applied selectively to critical tag operations and data elements rather than all operations uniformly. The system uses cryptographic validation for authentication and integrity-critical functions while employing lighter verification methods for routine operations, balancing security requirements with energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9712535B1Security recommendation engine
Publication Date: 2017.07.18 AMAZON TECH INC
  • US9712535B1 patent drawing
  • US9712535B1 patent drawing
  • US9712535B1 patent drawing

AI summary

Users are authorized to access tagged metadata in a provider network. A revision control and binding mechanism may be applied to tagged metadata that is added or modified by the user. A recommendation pertaining to security and compliance for the computing resource may be determined based on an analysis of the computing resource, scoring criteria, and data pertaining to customer and system data.