Tiered Scalability Sandbox Fleet With Secure Internet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to providing a secure and scalable cloud-based managed service for untrusted code lack sufficient isolation capabilities and are hampered by resource utilization limits, particularly in efficiently managing and scaling sandbox environments to handle various workloads and internet access.

Innovation Solution

A tiered scalability sandbox fleet system is implemented, comprising a sandbox fleet controller, sandbox network stacks with stack isolation devices, and sandboxes with virtual machines, allowing for flexible scaling by adjusting the number of sandboxes and network stacks, and providing secure internet access through isolation devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sandboxes are isolated by denying or heavily restricting network access and OS calls, then security is improved, but resource utilization efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the sandbox fleet into multiple independent sandbox network stacks, each containing multiple sandboxes. This segmentation allows granular control over network access at the stack level while maintaining isolation, enabling efficient resource utilization through selective connectivity without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a sandbox fleet controller as an intermediary that manages network access for sandbox network stacks. The controller receives requests, evaluates security policies, and grants controlled access to the WAN, allowing sandboxes to maintain isolation while enabling legitimate network communication through the mediator.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the number of sandboxes is increased to handle more workloads, then productivity is improved, but device complexity deteriorates

Engineering Contradiction:
Improveworkload handling capacityVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system organizes sandboxes into sandbox network stacks grouped by operating system types (e.g., Windows stacks, Linux stacks). This segmentation allows the system to scale horizontally by adding stacks while maintaining manageable complexity through organized grouping and standardized management of each stack.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sandbox fleet controller provides universal management functionality across all sandbox network stacks, handling provisioning, scaling, and access control for heterogeneous sandbox environments. This multi-functional controller simplifies management complexity by providing a unified interface for diverse sandbox types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If sandbox network stacks are scaled horizontally to improve resource utilization, then productivity is improved, but device complexity deteriorates

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidfleet management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The sandbox fleet controller dynamically manages the horizontal scaling of sandbox network stacks based on workload demands and resource availability. It can automatically provision new stacks, load-balance requests across existing stacks, and de-provision underutilized stacks, enabling adaptive resource utilization without manual intervention and managing complexity through automation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11106785B2Tiered scalability sandbox fleet with internet access
Publication Date: 2021.08.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11106785B2 patent drawing
  • US11106785B2 patent drawing
  • US11106785B2 patent drawing

AI summary

A cloud-based fleet of sandboxes is scalable along two tiers. Additional sandboxes may be added to a particular sandbox network in a particular sandbox stack, or additional sandbox stacks may be added. Isolation of individual sandboxes within a sandbox network is provided by virtual switches or routers, and subnetting. Isolation of sandbox networks is provided by network or port address translation, and by running hypervisors in respective infrastructure-as-a-service virtual machines. Provisioning efficiency can be provided by the two-tiered architecture, by use of differencing disks, by use of virtual machine scale sets, and by hybrid core-count sandboxes. Sandboxes may be secured but still have outgoing internet connectivity. Workloads run in the sandbox may include builds, tests of development code, investigations of possible malware, and other tasks.