Resource Container Service for Multi-Account Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large sets of computing resources with varying access policies across multiple customer accounts is complex, especially when handling failure modes and enabling resource sharing among customers, as existing solutions require manual workflows and lack efficient policy management across multiple accounts.

Innovation Solution

A resource container service that allows customers to create and manage resource containers, which are data structures that associate various computing resources with policies, enabling access control and sharing across multiple customer accounts through an API, allowing policies to span across multiple accounts and resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual workflows are used to manage access policies for large sets of resources across multiple customer accounts, then individual resource control is maintained, but the complexity of policy management increases significantly and productivity decreases

Engineering Contradiction:
Improvepolicy management complexityVSAvoidresource management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent introduces resource containers as intermediary objects that aggregate multiple resources and apply access policies at the container level rather than individually on each resource. This intermediary layer simplifies policy management by providing a single point of control for managing access to large sets of resources across multiple customer accounts, reducing the operational complexity while maintaining individual resource control through the container abstraction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If resources are shared among multiple customer accounts with varying access policies, then collaboration capability is enhanced, but the device complexity for managing policies across accounts increases

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidpolicy management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management system into hierarchical levels: resource containers at the aggregation level and individual resources within containers. Each container can have its own access policies that apply to all contained resources, while individual resources can also have specific policies. This segmentation allows resources to be shared among multiple customer accounts with varying access policies without requiring a monolithic complex policy management system, as policies can be defined and enforced at the appropriate hierarchical level.

Inventive Principle:
Principle #1Segmentation

3Manufacturing precision

If individual access policies are defined for each resource in large sets, then fine-grained control is achieved, but the time required to manage and update policies increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy management time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent merges the management of access policies for multiple resources by allowing a single access policy to be applied to an entire resource container that holds multiple resources. This combining approach enables fine-grained access control precision to be maintained through container-level policies while dramatically reducing the time required to manage and update policies, as changes can be propagated to all contained resources through the container rather than requiring individual updates to each resource.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11616787B1Mechanism to manage group of resources using virtual resource containers
Publication Date: 2023.03.28 AMAZON TECH INC
  • US11616787B1 patent drawing
  • US11616787B1 patent drawing
  • US11616787B1 patent drawing

AI summary

A set of operations is performed to cause a resource accessible to a first set of entities to also be accessible to a member of a second set of entities, where the set of operations, as a result of being executed, causes a processor to create a project to associate with a set of resources, associate a policy that controls access to the set of resources with the projects, associate the resource with the set of resources of the project, and associate the member of the second set of entities with the project. A request is obtained from the member of the second set of entities to access the resource. The member of the second set of entities is determine to be authorized to access the resource based on the policy. The member of the second set of entities is allowed to obtain access to the resource.