Virtual Secure Region for Government Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure computing environments for government agencies and entities require physical separation and strict access controls, leading to high fixed and operational costs due to the need for separate data centers to maintain regulatory compliance.

Innovation Solution

Implementing a virtual secure region within a public computing service environment using data encryption and obfuscation of account relationships, with a region translation device that maps secure region accounts to public region accounts, allowing secure data storage and access only to authorized personnel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical separation and strict access controls are implemented to maintain regulatory compliance, then security and compliance requirements are satisfied, but fixed and operational costs increase due to the need for separate data centers

Engineering Contradiction:
Improvesecurity complianceVSAvoidseparate data center infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines secure computing instances and public computing instances onto the same physical computing infrastructure, eliminating the need for physically separate data centers. The hypervisor enables multiple customers to share the same physical resources while maintaining logical isolation through virtualization, thereby reducing infrastructure complexity and costs while preserving security compliance through virtualized access controls and encryption.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If physical separation is used to secure sensitive workloads, then access control and regulatory compliance are maintained, but resource sharing and cost efficiency are reduced

Engineering Contradiction:
Improveaccess controlVSAvoidresource sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the physical computing infrastructure universal by enabling it to serve multiple customers with different security requirements simultaneously. The hypervisor allows the same physical resources to be dynamically allocated to secure computing instances requiring strict access controls and to public computing instances requiring resource sharing, thereby achieving multi-functionality and improved resource utilization without compromising access control for sensitive workloads.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If separate secure data centers are established to comply with government regulations, then regulatory requirements are met, but operational costs and infrastructure complexity increase

Engineering Contradiction:
Improveregulatory complianceVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges secure and public computing environments into a single data center infrastructure, utilizing virtualization to maintain regulatory compliance while reducing operational costs. The hypervisor enables the same physical hardware to host both secure government workloads with restricted access and public workloads, eliminating the need for duplicate infrastructure and reducing energy consumption, maintenance costs, and operational overhead associated with separate data centers.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10893029B1Secure computing service environment
Publication Date: 2021.01.12 AMAZON TECH INC
  • US10893029B1 patent drawing
  • US10893029B1 patent drawing
  • US10893029B1 patent drawing

AI summary

A technology is described for a virtual secure region. An example method may include receiving a request for data stored in a secure computing service environment executing on computing resources used to provide a public computing service environment, where the secure computing service environment may be separated from the public computing environment using encryption. In response to the request, a secure region account that corresponds to a public region account may be identified using a translation table that maps the secure region account to the public region account. A storage location for the data may be identified within the secure computing service environment specified by the secure region account, and the data may be obtained from the storage location within the secure computing service environment. The data may then be transferred to the public computing service environment.