Snapshot Management Across Cloud Security Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud providers face challenges in managing snapshots for remote extensions of their network substrate, particularly in terms of storage capacity and security, as these extensions often have limited resources and require secure key management to prevent data breaches.

Innovation Solution

The solution involves maintaining snapshots at the cloud provider network substrate, allowing the remote extension to access and update them without storing the entire volume, and ensuring secure key management by decrypting and re-encrypting snapshots to prevent key sharing outside the cloud provider network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If snapshots are stored at the remote extension, then access speed is improved, but storage capacity is exceeded

Engineering Contradiction:
Improveaccess speedVSAvoidstorage capacity
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent extracts the snapshot storage function from the remote extension and relocates it to the cloud provider network substrate. The remote extension maintains only the metadata and access pointers, while the actual snapshot data is stored externally in the cloud substrate, which has abundant storage capacity. This resolves the contradiction by removing the storage burden from the resource-constrained remote extension while preserving fast access through local metadata caching.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a new spatial dimension for snapshot storage by creating a hierarchical architecture: local metadata layer at the remote extension and remote data layer in the cloud substrate. This dimensional separation allows the system to achieve both fast local access (through metadata) and abundant storage capacity (in the cloud), resolving the contradiction between access speed and storage capacity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If encryption keys are shared with remote extension, then snapshot accessibility is improved, but security is compromised

Engineering Contradiction:
Improvesnapshot accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption layer managed by the cloud provider. Snapshots are encrypted with cloud-managed keys before being stored in the substrate, and the remote extension accesses them through controlled decryption operations. This intermediary key management system enables snapshot accessibility for authorized remote extensions while preventing direct key exposure and maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the encryption key management into distinct layers: cloud-managed master keys for snapshot encryption and extension-specific access credentials. This segmentation allows the remote extension to access snapshots without obtaining the actual encryption keys, thereby maintaining security while enabling operational accessibility.

Inventive Principle:
Principle #1Segmentation

3Loss of energy

If incremental snapshots are generated at remote extension, then bandwidth usage is reduced, but storage management complexity increases

Engineering Contradiction:
Improvebandwidth usageVSAvoidstorage management complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent enables the remote extension to autonomously generate incremental snapshots locally and upload only the changed blocks to the cloud substrate. The extension's snapshot manager independently identifies modifications, creates incremental snapshots, and manages the upload process without requiring complex centralized coordination. This self-service approach reduces bandwidth usage while keeping management complexity localized at the extension level.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11662928B1Snapshot management across cloud provider network extension security boundaries
Publication Date: 2023.05.30 AMAZON TECH INC
  • US11662928B1 patent drawing
  • US11662928B1 patent drawing
  • US11662928B1 patent drawing

AI summary

Systems and methods for efficient and secure management of encrypted “snapshots” for a remote provider substrate extension (“PSE”) of a cloud provider network substrate are provided. The PSE may request and obtain a snapshot from the cloud provider network substrate, restore a volume from the snapshot, make changes to data in the restored volume, and/or initiate the creation and storage of a new snapshot that includes incremental updates to the original snapshot to reflect the changes made to data in the volume. An encrypted snapshot stored within the cloud provider network substrate may be decrypted using a cloud provider key designed for internal use only, and then re-encrypted using a PSE-specific key before providing the snapshot to the PSE, thereby avoiding the sharing of the cloud provider internal use only key outside the cloud provider network substrate.