Resource management for services

US12063166B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-12063166-B1
Application numberUS-202217709265-A
CountryUS
Kind codeB1
Filing dateMar 30, 2022
Priority dateMar 30, 2022
Publication dateAug 13, 2024
Grant dateAug 13, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for resource management are disclosed. A search request may be received at a resource management service of a provider network. The search request may be received from a client device that does not have permission to access resources in a protected region of a provider network. The search request may specify a query associated with at least one operational health indicator in the protected region. It may be determined, using a secure query service, that the at least one operational health indicator does not exist in the protected region. The secure query service enables the client device to obtain information about the resources in the protected region without gaining access to the resources in the protected region. Sending of a notification indicating that the at least one operational health indicator does not exist in the protected region to the client device may be caused.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for resource management, the method comprising: receiving, from a client device that does not have permission to access resources in a protected region of a provider network, a search request at a resource management service of the provider network, the search request specifying a query associated with at least one operational health indicator in the protected region, wherein the protected region has restricted connectivity with at least one other region in the provider network; determining, using a secure query service, that the at least one operational health indicator does not exist in the protected region, wherein the secure query service enables the client device to obtain information about the resources in the protected region without gaining access to the resources in the protected region by sending the query regarding the status of the operational health indicator and receiving filtered results without receiving information retrieved by the query; and causing, by the resource management service, sending to the client device of a notification indicating that the at least one operational health indicator does not exist in the protected region. 2. The method of claim 1 , wherein determining, using the secure query service, that the at least one operational health indicator does not exist in the protected region by sending the query regarding the status of the operational health indicator and filtering the results comprises forwarding the search request to the secure query service, wherein the secure query service: sends a filtered search request validated by one or more attributes of a first schema to a storage location in the protected region; executes the search request on the at least one operational health indicator in the protected region using the name of the at least one operational health indicator; generates a search result including metadata associated with the at least one operational health indicator; and returns a search response based on filtering the search result by validating one or more attributes with a second schema. 3. The method of claim 1 , further comprising: causing creation of the at least one operational health indicator in the protected region using a secure transfer service, wherein the at least one operational health indicator is developed in an unprotected region of the provider network and the secure transfer service is configured to transfer the developed at least one operational health indicator to the protected region of the provider network. 4. The method of claim 3 , wherein the secure transfer service is configured to: determine, in the unprotected region, whether the developed at least one operational health indicator is free of malicious components; package, in the unprotected region, the developed at least one operational health indicator for transfer to the protected region by generating a manifest file for the developed at least one operational health indicator; and transfer, via the secure transfer service, the packaged, developed at least one operational health indicator from the unprotected region to the protected region. 5. The method of claim 3 , wherein the developed at least one operational health indicator comprises an infrastructure as code (IaC) to create the at least one operational health indicator in the protected region. 6. A system for resource management, the system comprising: at least one processor in communication with at least one memory, the at least one processor configured at least to: receive in a first region of a provider network a request from a client, the request indicative of performing a query associated with at least one operational health indicator in a protected region of the provider network, wherein the protected region has restricted access and restricted connectivity with the first region in the provider network; determine, by a query service with access to the protected region, that the at least one operational health indicator does not exist in the protected region, wherein the query service performs the query on the at least one operational health indicator in the protected region and returns filtered information indicative of the presence without sending the information retrieved from the at least one operational health indicator; and sending to the client device of a notification indicating that the at least one operational health indicator does not exist in the protected region. 7. The system of claim 6 , wherein determining, by the query service, that the at least one operational health indicator does not exist in the protected region comprises executing the query on the at least one operational health indicator in the protected region. 8. The system of claim 7 , wherein the at least one processor is further configured to: cause creation of the at least one operational health indicator in the protected region using a secure transfer service, wherein the at least one operational health indicator is developed in an unprotected region of the provider network and the secure transfer service is configured to transfer the developed at least one operational health indicator to the protected region of the provider network. 9. The system of claim 8 , wherein the secure transfer service is configured to: determine, in the unprotected region, whether the developed at least one operational health indicator is free of malicious components; package, in the unprotected region, the developed at least one operational health indicator for transfer to the protected region by generating a manifest file for the developed at least one operational health indicator; and transfer, via the secure transfer service, the packaged, developed at least one operational health indicator from the unprotected region to the protected region. 10. The system of claim 9 , wherein the developed at least one operational health indicator comprises an infrastructure as code (IaC) to create the at least one operational health indicator in the protected region. 11. The system of claim 7 , wherein the at least one operational health indicator exists in at least one different region of the provider network. 12. The system of claim 7 , wherein the at least one operational health indicator comprises an alarm. 13. The system of claim 7 , wherein the at least one operational health indicator comprises a metric. 14. A non-transitory computer-readable medium storing instructions that, when executed, causes at least one computing node to perform the operations comprising: receiving in a first region of a provider network a request from a client, the request indicative of performing a query associated with at least one operational health indicator in a protected region of the provider network, wherein the protected region has restricted access and restricted connectivity with the first region in the provider network; determining, by a query service with access to the protected region, that the at least one operational health indicator does not exist in the protected region, wherein the query service performs the query on the at least one operational health indicator in the protected region and returns filtered information indicative of the presence of the at least one operational health indicator without sending the information retrieved from the at least one operational health indicator; and causing sending information to the client indicating that the at least one operational health indicator does not exist in the protected region. 15. The non-transitory computer-readable medium of claim 14 , wherein determining, by the query s

Assignees

Inventors

Classifications

  • H04L47/808Primary

    User-type aware · CPC title

  • Centralised allocation of resources · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12063166B1 cover?
Systems and methods for resource management are disclosed. A search request may be received at a resource management service of a provider network. The search request may be received from a client device that does not have permission to access resources in a protected region of a provider network. The search request may specify a query associated with at least one operational health indicator i…
Who is the assignee on this patent?
Amazon Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L47/808. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 13 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).