DOOSAN Digital Innovation

인사이트 콘텐츠

  1. Home
  2. 리소스
  3. 인사이트 콘텐츠

[Case Study] CHANGSHIN INC | MSP for Global Expansion and Amazon Bedrock Cost Control of a Multi-Region Predictive Maintenance AI Service

클라우드 MSP 2026.09.17

🚀 Key Highlights at a Glance

✅Integrated AWS managed services (MSP) for a predictive maintenance AI service built by DDI

✅Multi-region global service operations powered by AWS Global Accelerator

✅Cost control and monitoring framework to prevent excessive Amazon Bedrock usage

✅Enhanced security response framework based on AWS WAF and AWS CloudTrail

✅Architecture validation based on the AWS Well-Architected Framework

✅Operations expanded from Korea to Indonesia, support for expansion to Vietnam, and ongoing PoCs for new services

Company

CHANGSHIN INC is a manufacturing company with overseas production sites, where the operational stability of production equipment is directly linked to business competitiveness. To reduce unplanned downtime caused by equipment failures, the company introduced a predictive maintenance framework that collects and analyzes equipment data to identify signs of anomalies in advance.

Doosan Corporation Digital Innovation BU (DDI) built CHANGSHIN INC’s predictive maintenance service directly on AWS. DDI subsequently became the managed services partner for the entire AWS account, supporting multi-region operations, generative AI cost control, security enhancements, and expansion to overseas sites.

Engagement Overview

  • Customer:

    CHANGSHIN INC

  • Industry:

    Manufacturing (overseas production operations)

  • Initial Service Implementation:

    September 11, 2025–December 31, 2025 (implemented directly by DDI)

  • Managed Services Start Date:

    January 1, 2026

  • Managed Services End Date:

    January 31, 2027 (12-month contract; operations currently ongoing)

  • Countries Served:

    Korea (implementation and operations), Indonesia (in service), and Vietnam (planned expansion)

  • MSP Scope:

    End-to-end AWS account operations, generative AI cost control, security assessment and enhancement, new service reviews and PoCs, and monthly operations reporting

  • Delivery Model:

    Managed Services

Challenge

After moving its predictive maintenance AI service into production, CHANGSHIN INC was simultaneously advancing three priorities: more efficient multi-region operations, stronger generative AI cost management, and enhanced security.

  • Strengthening Professional Operations Across the AWS Account

    In a multi-region environment combining services in the Seoul Region with an acceleration configuration in the Singapore Region, a professional operating model was needed to consistently manage infrastructure monitoring, incident response, and change management. To enable the customer to focus more closely on manufacturing equipment operations and data quality management, CHANGSHIN INC considered collaborating with a specialized partner to manage the AWS account end to end.

  • Advancing Cost Management for Expanded Amazon Bedrock Usage

    As generative AI was applied to predictive maintenance and chatbot capabilities, it became important to manage fluctuations in request volume based on usage patterns. Greater visibility was needed to track usage and costs by model and function and to identify cost changes early. This called for more advanced monitoring and budget management to support stable service operations.

  • Enhancing Security for External Access

    Given that overseas production sites access the service over the internet, a protection framework was needed to reliably address diverse access patterns at the web layer. This required proactive security enhancement across the service, including a comprehensive security review and AWS WAF configuration.

  • Improving Account Activity Tracking and Audit Visibility

    In a multi-region, multi-account environment, resource changes and API activity needed to be recorded and tracked more systematically, with stronger audit visibility to support rapid analysis of security events.

  • Building Operational Scalability for Expansion to Overseas Sites

    Following service operations in Indonesia, expansion to Vietnam was planned. This required the operational capabilities to assess the potential effects of adding new sites—including network latency, availability, and cost—and to scale the service reliably.

  • Establishing a Foundation for Continuous Technology Advancement

    As new generative AI services continue to emerge rapidly, a structured approach was needed to continuously evaluate and validate the latest AWS services that could be applied to the existing solution.

As-Is Architecture

The predictive maintenance service built by DDI was configured as follows.

Existing (As-Is) Predictive Maintenance AI Service Architecture

Existing (As-Is) Predictive Maintenance AI Service Architecture
  • Predictive Maintenance Service Built by DDI:

    DDI built an AWS-based predictive maintenance service that collects and analyzes equipment data to identify signs of anomalies.

  • Service Deployed in the AWS Seoul Region:

    The core service workloads were deployed and operated in the Asia Pacific (Seoul) Region.

  • AWS Global Accelerator Configuration in the Singapore Region:

    An AWS Global Accelerator configuration using the Asia Pacific (Singapore) Region was applied to reduce access latency for overseas production sites.

  • Amazon Bedrock-Based AI Services:

    Amazon Bedrock was used to deliver generative AI capabilities such as predictive maintenance insights and a chatbot.

  • Overseas Expansion Following the Korea Deployment:

    After completing the Korea deployment, the service began operating in Indonesia, with expansion to Vietnam planned.

Solution

At the time of the MSP transition, DDI prioritized generative AI cost control, security enhancement, standardized multi-region operations, and new service reviews in that order, establishing an integrated operating model across the AWS account.

New (To-Be) Architecture for MSP Operations, Cost Control, and Security Enhancement

New (To-Be) Architecture for MSP Operations, Cost Control, and Security Enhancement

CHANGSHIN INC Global Service Network Architecture

CHANGSHIN INC Global Service Network Architecture

Detailed Configuration After the MSP Transition

  • Amazon Bedrock Usage and Cost Control:

    Bedrock request volume and token usage were collected by model and function through Amazon CloudWatch metrics, aggregated daily, and visualized in dashboards. Budget thresholds were configured by function in AWS Budgets, and AWS Cost Anomaly Detection was applied to automatically identify and notify the team of unusual usage spikes. This enabled proactive action before excessive usage was finalized as cost.

  • Generative AI Request Pattern Optimization:

    Request frequency and response length were analyzed by function to identify unnecessary repeated calls, while prompt and context configurations and model selection were reviewed. A configuration that reduced cost per request while maintaining service quality was applied, lowering Bedrock costs.

  • Web-Layer Security Enhancement and AWS WAF:

    AWS WAF was applied in front of the service’s Application Load Balancer to block web attacks and abnormal requests, including SQL injection and cross-site scripting. Overly broad inbound security group rules and unnecessary IAM permissions were also refined to reduce the attack surface.

  • CloudTrail-Based Audit and Traceability:

    AWS CloudTrail was enabled across regions to record all API activity in the account and retain logs in Amazon S3, providing audit visibility into resource changes and access activity regardless of region.

  • Architecture Validation Based on the AWS Well-Architected Framework:

    The architecture was assessed across five pillars—operational excellence, security, reliability, performance efficiency, and cost optimization. DDI developed an improvement roadmap for identified risks and addressed them in phases.

  • Integrated Multi-Region Monitoring and Operations:

    Metrics and logs from the Seoul and Singapore Regions were monitored through an integrated framework with alerts, enabling early detection of anomalies across regions. Access routes and response latency by overseas site were continuously observed to assess expansion impact in advance.

  • Support for Expansion to Overseas Sites:

    Using operational data from Indonesia, DDI supports planning for expansion to Vietnam by reviewing the required acceleration configuration, capacity, and cost impact in advance.

  • Review and PoC of the Latest AWS Services:

    Based on the existing solution, DDI continuously evaluates the applicability of new AWS services and conducts proofs of concept for promising options to support ongoing technology advancement.

Multi-Region AI Service Operating Model Based on Key AWS Services

  • AWS Global Accelerator:

    Reduces access latency and accelerates traffic for overseas production sites

  • Amazon Bedrock:

    Provides generative AI inference for predictive maintenance and chatbot capabilities

  • Amazon EC2:

    Runs predictive maintenance inference services, chatbot APIs, and data collection and preprocessing workloads

  • Elastic Load Balancing (ALB):

    Distributes service traffic

  • Amazon RDS:

    Manages operational data such as equipment information and prediction results

  • Amazon S3:

    Stores raw equipment sensor data and audit logs

  • AWS WAF:

    Protects against web-layer attacks and strengthens security for externally exposed services

  • AWS CloudTrail:

    Establishes an audit framework by recording and tracking multi-region account activity

  • Amazon CloudWatch:

    Monitors metrics and logs, including Bedrock request volume, and provides alarms

  • AWS Cost Explorer / AWS Budgets:

    Visualizes costs and issues alerts when function-level budgets are exceeded

  • AWS Cost Anomaly Detection:

    Automatically detects abnormal usage spikes, including Amazon Bedrock activity

  • AWS Well-Architected Tool:

    Identifies architecture risks and manages improvements

DDI Support Services

As both the service implementation provider and managed services partner, DDI delivered continuous support from implementation through transition and ongoing operations.

  • Pre-Transition Support:

    Because DDI had built the service directly, it already had a clear understanding of the architecture and data flows and developed an operations transition plan aligned with the production launch. DDI assessed the overall AWS account and multi-region configuration and reviewed Bedrock usage patterns and cost structure, security settings, IAM permissions, and network configuration. Based on this assessment, DDI defined post-transition improvement actions and priorities and agreed with the customer on incident response procedures, escalation paths, and handover items.

  • Transition Support:

    AWS WAF and CloudTrail deployment, Bedrock metric collection, budget and anomaly detection configuration, and integrated monitoring dashboards were implemented in phases during maintenance windows that would not affect service availability. Each activity included advance validation and rollback procedures, followed by verification of normal operation and metric collection.

  • Post-Transition Operations Support:

    DDI provides continuous monitoring, incident detection and response, change management, and regular reviews across the AWS account, including the Seoul and Singapore Regions. Bedrock usage and cost are reviewed daily, with immediate action when thresholds are exceeded. DDI also provides monthly operations reports and continues Well-Architected reviews, new service assessments and PoCs, and support for expansion to overseas sites.

Benefit

Through integrated MSP operations, CHANGSHIN INC gained greater control over generative AI costs, improved security and operational visibility, and a stable foundation for expansion to overseas sites.

  • Greater Control over Generative AI Cost Risk:

    By combining usage visibility by model and function with budget thresholds and anomaly detection, the company can identify and address excessive Bedrock usage before it affects costs. Request pattern optimization also reduced AI costs while maintaining service quality.

  • Enhanced Security Response Framework:

    AWS WAF proactively blocks web attacks against services accessed from overseas sites, while multi-region CloudTrail enables account activity tracking and strengthens security event response capabilities.

  • Improved Multi-Region Operational Visibility:

    Integrated monitoring across the Seoul and Singapore Regions enables immediate visibility into service status and anomalies regardless of region.

  • Structured Resolution of Architecture Risks:

    Reviews based on the AWS Well-Architected Framework identified potential risks at the item level and resolved High Risk findings, establishing an operational foundation capable of supporting global expansion.

  • Reliable Expansion to Overseas Sites:

    By assessing the impact of expansion to Vietnam using operational results from Indonesia, the company can reduce quality and cost risks and manage the expansion schedule more predictably.

  • Reduced Operational Burden and Continuous Technology Advancement:

    With DDI operating the AWS account end to end, the customer can focus on equipment operations and data quality management while continuing to enhance the service through regular reviews and PoCs for new technologies.

Metrics for Success

Key implementation and MSP operating metrics were compared.

  • Monthly Amazon Bedrock Cost:

    100% of the initial design baseline → approximately 68% (approximately 32% reduction)

  • Time to Detect Abnormal Bedrock Usage:

    Approximately three days (identified at monthly billing) → automated alert within 15 minutes

  • Bedrock Usage Visibility: Daily aggregation and dashboards by model and function

  • Total Monthly Cloud Cost:

    100% of the initial design baseline → approximately 79% (approximately 21% reduction)

  • Average Monthly Requests Blocked by AWS WAF:

    Not deployed → approximately 6,800 requests blocked

  • Well-Architected High Risk Findings:

    11 → 0 (Medium Risk findings: 21 → 5)

  • Security Review Remediation:

    Based on approximately 140 assessment items, 27 improvement actions identified and completed

  • Mean Time to Detect Incidents (MTTD):

    Approximately 45 minutes → within 5 minutes

  • Regions Under Integrated Operations:

    No integrated management framework → integrated monitoring across two Regions (Seoul and Singapore)

  • Service Availability:

    No measurement framework → maintained at 99.95%

  • New Service PoCs:

    None → two per year

  • Operations Reporting Frequency:

    Ad hoc → monthly reporting

Current Activities Following the MSP Transition

DDI’s engagement did not end with implementation and transition. As the managed services partner, DDI continues to perform the following activities.

  • Support for Continued Service Expansion:

    Following operations in Indonesia, DDI supports the expansion of the service scope—including the planned rollout to Vietnam—from an operational perspective.

  • Review and PoC of the Latest Services:

    Based on the existing solution, DDI evaluates the applicability of new AWS services and conducts proofs of concept.

  • Comprehensive Security Reviews and Validation:

    DDI regularly reviews CloudTrail and AWS WAF configurations and validates the architecture based on the AWS Well-Architected Framework.

  • Continuous Cost Monitoring and Optimization:

    DDI continuously monitors the overall resource environment, including Bedrock usage, identifies optimization opportunities, and reports the results monthly.