-
公开(公告)号:US20200159719A1
公开(公告)日:2020-05-21
申请号:US16751727
申请日:2020-01-24
Applicant: Amazon Technologies, Inc.
Inventor: Brian Collins , Zachary Mohamed Shalla , Marvin Michael Theimer , John Petry , Michael Hart , Serge Hairanian , Anders Samuelsson , Salvador Salazar Sepulveda , Ji Luo
Abstract: Multiple edits to a hierarchical data structure may be atomically applied. A request to perform modifications with respect to a portion or the entire hierarchical data structure may be received. A copy of the requested portion of the hierarchical data structure may be created separate from the hierarchical data structure. The portion of the hierarchical data structure may remain available for read access. Modifications may be applied to the copy of the portion of the hierarchical data structure. In response to a request to commit the modifications to the portion of the hierarchical data structure, the copy of the portion of the hierarchical data structure may atomically replace the portion of the hierarchical data structure
-
公开(公告)号:US20200067791A1
公开(公告)日:2020-02-27
申请号:US16672146
申请日:2019-11-01
Applicant: Amazon Technologies, Inc.
Inventor: Gregory B. Roth , James E. Scharf, JR. , Rajiv Ramachandran , Anders Samuelsson , Keith A. Carlson
IPC: H04L12/24
Abstract: Methods and apparatus for a client account versioning metadata manager for cloud computing environments are disclosed. A system includes a plurality of resources, a plurality of service managers coordinating respective multitenant network-accessible services, and a metadata manager. The metadata manager receives a multi-service account state view request. The metadata manager generates a representation of an administrative state of a client account indicated by the request with respect a plurality of services accessible by the client account, as of a time indicated in the request. The administrative state with respect to a particular service comprises an indication of an assignment to the client account of resources participating in implementation of the particular service.
-
公开(公告)号:US10313346B1
公开(公告)日:2019-06-04
申请号:US14553915
申请日:2014-11-25
Applicant: Amazon Technologies, Inc.
Inventor: Kevin Ross O'Neill , Mark Joseph Cavage , Nathan R. Fitch , Anders Samuelsson , Brian Irl Pratt , Yunong Jeff Xiao , Bradley Jeffery Behm , James E. Scharf, Jr.
Abstract: Virtual firewalls may be established that enforce sets of policies with respect to computing resources maintained by multi-tenant distributed services. Particular subsets of computing resources may be associated with particular tenants of a multi-tenant distributed service. A tenant may establish a firewalling policy set enforced by a virtual firewall for an associated subset of computing resources without affecting other tenants of the multi-tenant distributed service. Virtual firewalls enforcing multiple firewalling policy sets may be maintained by a common firewalling component of the multi-tenant distributed service. Firewalling policy sets may be distributed at multiple locations throughout the multi-tenant distributed service. For a request targeting a particular computing resource, the common firewalling component may identify the associated virtual firewall, and submit the request to the virtual firewall for evaluation in accordance with the corresponding firewalling policy set.
-
公开(公告)号:US10089476B1
公开(公告)日:2018-10-02
申请号:US14295129
申请日:2014-06-03
Applicant: Amazon Technologies, Inc.
Inventor: Gregory Branchek Roth , Anders Samuelsson , Bradley Jeffery Behm
Abstract: Customers of a service provider are able to provision compartments of the accounts. The both the accounts and the compartments, in some embodiments, may have associated computing resources and identities. One or more identities of the account may be authorized to perform administrative operations in the compartment. Identities of the compartment may lack the ability to perform any administrative actions outside of the compartment but inside of the account.
-
公开(公告)号:US20180089249A1
公开(公告)日:2018-03-29
申请号:US15275219
申请日:2016-09-23
Applicant: Amazon Technologies, Inc.
Inventor: Brian Collins , Zachary Mohamed Shalla , MARVIN MICHAEL THEIMER , John Petry , Michael Hart , Serge Hairanian , Anders Samuelsson , Salvador Salazar Sepulveda , Ji Luo
CPC classification number: G06F16/2365 , G06F16/282 , H04L67/1095 , H04L67/1097
Abstract: Distributed system resources may be managed by applying user created policies to the resources. To ensure that valid policies are applied, remote validation for the policies may be implemented. A validation event for a policy may be detected. A remote validation agent may be identified for the policy and a validation request sent to the remote validation agent that includes information for validating the policy. The remote validation agent may return a validation result for the policy. If valid, a policy action that triggered the remote validation event for the policy may be allowed. If invalid, the policy action that triggered the remote validation event for the policy may be denied.
-
-
-
-