Tiered Web Service Classification for Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant hosting environments, service providers face challenges in balancing resource isolation and sharing to maintain security and control while managing websites for various entities, leading to inefficiencies and high costs, especially in preventing malicious code attacks and providing individualized support services.

Innovation Solution

Implementing a tiered web service management system that classifies web services based on security risk levels, using automated tools and trusted code sources, to dynamically configure resource sharing and isolation, allowing zero-risk entities to share resources while isolating high-risk ones, thereby optimizing costs and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If resources are isolated for each website to maintain security, then security between websites is improved, but baseline costs significantly increase and resource efficiency decreases

Engineering Contradiction:
Improvesecurity between websitesVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments websites into different risk tiers (trusted and untrusted) based on code source analysis. Trusted websites (using provider-provided code) share resources in a pooled environment, while untrusted websites (using seller-provided code) receive isolation. This selective segmentation maintains security where needed without unnecessarily isolating all websites, thus reducing baseline costs and improving resource efficiency for trusted sites.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different resource allocation policies to different websites based on their individual risk characteristics. Trusted websites enjoy resource sharing with reduced isolation overhead, while untrusted websites receive enhanced isolation. This local differentiation allows the system to optimize security and efficiency locally for each website type rather than applying uniform isolation to all sites.

Inventive Principle:
Principle #3Local quality

2Reliability

If control of all code is maintained by the provider, then security against malicious code is improved, but customer options for individualized support services are limited

Engineering Contradiction:
Improvesecurity against malicious codeVSAvoidcustomer options for support services
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments code sources into trusted (provider-provided) and untrusted (seller-provided) categories. For untrusted code, the system implements automated analysis and tiered isolation policies rather than complete provider control. This allows customers to maintain autonomy over their code while the provider ensures security through selective monitoring and isolation, preserving customer options for individualized support.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security layer that analyzes and mediates between seller-provided code and the shared hosting environment. This intermediary tiered isolation mechanism allows customer code to execute with appropriate security measures without requiring full provider control, thus maintaining customer autonomy while ensuring security against malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If overprotective inter-seller isolation is implemented, then security between sellers is improved, but operational costs become prohibitively expensive for small businesses

Engineering Contradiction:
Improveisolation between sellersVSAvoidoperational cost efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments sellers into trusted and untrusted categories based on code source analysis. Only untrusted sellers receive tiered isolation resources, while trusted sellers share resources without isolation overhead. This selective approach provides necessary security protection for untrusted sellers while avoiding the prohibitively high costs of overprotective isolation for all sellers, making hosting affordable for small businesses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial isolation only where necessary (for untrusted code) rather than excessive isolation for all code. This partial action approach provides adequate security protection for potentially malicious code while avoiding the excessive costs of universal isolation, thus achieving cost-efficiency for small business merchants.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9818139B1Classifying user-provided code
Publication Date: 2017.11.14 AMAZON TECH INC
  • US9818139B1 patent drawing
  • US9818139B1 patent drawing
  • US9818139B1 patent drawing

AI summary

Processes for classifying, and dynamically adjusting, tiers for web services are described. Depending on the classification of the web service, support resources (e.g. servers, storage, bandwidth or other communications resources, etc.) may be configured in different ways, such as, for example, sharing resources among one or more of the web services, or isolating the resources for particular web services from those of other web services. Various electronic storefronts may be provided by a service provider to merchants/customers of the service provider. The service provider may classify each of the electronic storefronts for the merchants to a plurality of tiers. Such classifying may be performed, for example, during an enrollment of the merchant with the service provider, and/or during operation of the electronic storefront.