Secure Subscriber Data Sharing Subsystem

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuration management services face a security risk due to the difficulty in identifying subscribers for whom configuration data should be provided, leading to potential breaches affecting all subscribers of producer services, even if they do not subscribe to the configuration management service.

Innovation Solution

A secure data sharing subsystem is implemented, where the configuration management service shares subscriber data with producer services only for those who have authorized the sharing, reducing the risk of data compromise by limiting data transmission and storage to subscribers of both services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If producer services provide configuration data for all their subscribers to the configuration management service, then the configuration management service can monitor all computing resources, but security risk increases significantly as a breach would compromise data for all subscribers

Engineering Contradiction:
Improveconfiguration monitoring coverageVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the subscriber base into two distinct groups: subscribers of the configuration management service and non-subscribers. Producer services are instructed to provide configuration data only for the segmented group that are configuration management service subscribers, thereby isolating the security risk to only those subscribers while maintaining monitoring coverage for the intended audience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having producer services filter and identify configuration data for authorized subscribers before transmitting it to the configuration management service. This pre-filtering mechanism ensures that only relevant data is transmitted, reducing the attack surface and potential impact of security breaches while maintaining comprehensive monitoring for subscribed entities.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If producer services provide configuration data for all their subscribers, then complete data coverage is achieved, but network bandwidth and storage usage increase significantly

Engineering Contradiction:
Improveconfiguration data coverageVSAvoidnetwork bandwidth and storage
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts and removes configuration data for non-subscriber entities from the data transmission stream. Producer services are configured to identify and exclude configuration data corresponding to non-subscribers, transmitting only the relevant subset to the configuration management service. This extraction process maintains complete coverage for authorized subscribers while eliminating unnecessary data transmission and storage consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If configuration data for all subscribers is stored and processed, then comprehensive monitoring is achieved, but processing efficiency decreases due to handling unnecessary data

Engineering Contradiction:
Improvemonitoring completenessVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by making the data processing operation selective rather than uniform. The configuration management service processes configuration data with different handling rules based on subscriber status: full processing for subscribers and exclusion for non-subscribers. This localized quality approach ensures comprehensive monitoring for authorized entities while improving overall processing efficiency by eliminating unnecessary operations on non-subscriber data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11425140B1Secure and efficient cross-service sharing of subscriber data
Publication Date: 2022.08.23 AMAZON TECH INC
  • US11425140B1 patent drawing
  • US11425140B1 patent drawing
  • US11425140B1 patent drawing

AI summary

A configuration management service provides data identifying its subscribers to a secure sharing service that executes in an account that has a higher security level than a service account used to provide the configuration management service. The secure sharing service securely determines whether each subscriber has authorized producer services to share resource configuration data with the configuration management service. If a subscriber has authorized such sharing, information identifying the subscriber can be stored in a location accessible to the producer services. If a subscriber has not authorized such sharing, the secure sharing service will not make the subscriber's information available to the producer services. The producer services can use the subscriber data to provide resource configuration data to the configuration management service only for those subscribers that subscribe to both the configuration management service and to the producer services.