Secure Query Service for Asynchronous Protected Area Search

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data centers, accessing and managing resources in protected areas is cumbersome for users without clearance, requiring them to rely on cleared administrators, leading to inefficiencies and potential human errors due to the need for manual requests and information relay.

Innovation Solution

A secure query service that allows uncleared users to programmatically obtain unclassified metadata about resources in protected areas through a search orchestration agent, secure transfer service, and resource identification service, using schemas to filter requests and responses to ensure security and accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual request and information relay processes are used for accessing protected area resources, then security clearance requirements are maintained, but user efficiency deteriorates and administrative burden increases

Engineering Contradiction:
Improveuser efficiencyVSAvoidaccess complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

A declassification service is introduced as an intermediary component between protected area resources and uncleared users. This service receives search requests from users, automatically retrieves and declassifies relevant metadata, and returns results without requiring manual administrator intervention. The intermediary handles the security clearance process automatically, improving user efficiency while maintaining security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service access for uncleared users through automated declassification. Users can directly submit search requests and receive declassified metadata without needing to contact cleared administrators manually. The automated process allows users to independently obtain necessary information, significantly reducing administrative burden and improving operational efficiency.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual information relay is used, then security control is maintained, but human errors increase and time consumption increases

Engineering Contradiction:
Improveerror rateVSAvoidinformation retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The manual mechanical process of information relay between administrators and users is replaced with an automated electronic declassification service. The service uses computerized search and retrieval mechanisms to automatically obtain, declassify, and deliver metadata, eliminating human manual intervention. This substitution reduces both time consumption and human error while maintaining security control through automated clearance verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cleared administrators manually manage resource information requests, then security requirements are satisfied, but administrative workload increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidadministrative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The declassification service implements self-service functionality that automatically handles security compliance checks and metadata declassification. When users submit search requests, the service autonomously verifies clearance requirements, retrieves appropriate metadata, and returns results without requiring administrator involvement. This maintains security compliance while completely eliminating the administrative workload associated with manual information relay.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11416448B1Asynchronous searching of protected areas of a provider network
Publication Date: 2022.08.16 AMAZON TECH INC
  • US11416448B1 patent drawing
  • US11416448B1 patent drawing
  • US11416448B1 patent drawing

AI summary

Techniques for asynchronous searching of protected areas of a provider network are described. A method of asynchronous searching of protected areas of a provider network comprises receiving a search request at a secure query service of a provider network, the search request specifying a search condition for one or more resources in a protected area of the provider network, filtering the search request using a first filter to produce a filtered search request, providing the filtered search request to the protected area of the provider network, obtaining a search result based on execution of the search request in the protected area, filtering the search result using a second filter to produce a filtered search result, and generating a search response based on the filtered search result.