Versioned Access Controls for Data Center Role Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As data centers grow in scale and complexity, managing and storing increasing amounts of data becomes increasingly costly and complicated, with existing technologies struggling to efficiently manage and store data while maintaining simplicity and reducing storage requirements.

Innovation Solution

Implementing versioned and custom access controls within a configurable workflow service that allows for the management of roles and permissions, enabling flexible and secure access to computing resources, and using a role management service to automatically assign and manage roles for nodes and workflows, ensuring compatibility with evolving resource availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data centers grow in scale to store and manage increasing amounts of data, then data storage capacity and management capability are improved, but system complexity and operational costs increase

Engineering Contradiction:
Improvedata storage capacityVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the monolithic access control system into versioned role definitions that can be independently managed and updated. Each role version encapsulates a specific set of permissions, allowing the system to scale by adding new role versions without restructuring the entire access control framework, thereby managing complexity while supporting growth in data storage capacity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies parameter changes by versioning role definitions with version identifiers. This allows the system to evolve access control parameters (permissions, resources, conditions) over time without breaking existing workflows. Each version represents a parameter snapshot that can be applied to multiple workflows, enabling scalable management of access controls as data center complexity increases

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access control policies are updated to improve security, then security level is improved, but compatibility with existing workflows may be compromised

Engineering Contradiction:
Improvesecurity levelVSAvoidworkflow compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by creating and storing multiple versions of role definitions before deploying security updates. This allows administrators to prepare new secure configurations in advance, test them, and then selectively apply them to workflows. Existing workflows continue to use their compatible role versions until explicitly updated, preventing compatibility issues while enabling progressive security improvements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating role version copies that can be referenced by multiple workflows. When a role is updated, the system creates a new version copy rather than modifying the original in place. This allows existing workflows to continue referencing the old version copy, maintaining compatibility, while new workflows can adopt the updated version, balancing security improvements with system adaptability

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If role permissions are expanded to provide more flexible access control, then access control flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidrole management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing role definitions as multi-functional entities that can serve multiple workflows across different versions. A single role version can be assigned to numerous workflows, and workflows can reference different role versions based on their specific needs. This universal structure provides flexible access control without requiring separate complex configurations for each workflow, managing role management complexity while enhancing flexibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10346626B1Versioned access controls
Publication Date: 2019.07.09 AMAZON TECH INC
  • US10346626B1 patent drawing
  • US10346626B1 patent drawing
  • US10346626B1 patent drawing

AI summary

Methods and systems for implementing versioned access controls are disclosed. A first task is added to a first workflow with a first version of a default role. A second version of the default role is generated after the first task is added. A second task is added to a second workflow with the second version of the default role. The first version and the second version each comprise one or more permissions for using one or more computing resources. The first task is performed using the permissions in the first version of the default role. The second task is performed using the permissions in the second version of the default role.