Asymmetric Key Management for Cloud Service Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing environments face inefficiencies and security risks due to repetitive authentication requirements when managing multiple cloud service components, as asymmetric cryptography protocols often necessitate manual configuration of secure connections, which can lead to operational inefficiencies and authentication failures.

Innovation Solution

A key manager system is implemented to facilitate asymmetric key management by providing a graphical user interface for users to select and provision asymmetric key pairs across cloud service components, automatically configuring secure connections using the private key, thereby streamlining provisioning and reducing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cryptography protocols are used for secure access to cloud service components, then security is improved, but operational efficiency deteriorates due to manual configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The key manager system enables self-service by automatically configuring secure connections using asymmetric key pairs without requiring manual user configuration. The system autonomously provisions keys to cloud service components and sets up authentication mechanisms, eliminating the need for users to manually handle key configuration while maintaining security benefits of asymmetric cryptography.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key manager acts as an intermediary between users and cloud service components. It receives asymmetric key pairs from users, automatically provisions them to cloud service components, and configures secure connections. This intermediary role eliminates the manual configuration step while preserving the security advantages of asymmetric cryptography protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual configuration of secure connections is performed, then flexibility is maintained, but authentication failures increase and productivity decreases

Engineering Contradiction:
ImproveflexibilityVSAvoidauthentication success rate
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The key manager performs preliminary actions by automatically provisioning asymmetric key pairs to cloud service components before authentication is needed. It pre-configures secure connections and authentication mechanisms in advance, ensuring that when authentication occurs, everything is already in place and ready, thereby eliminating authentication failures and improving productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key manager implements feedback mechanisms to monitor and verify the successful provisioning of key pairs and configuration of secure connections. By receiving confirmation from cloud service components that keys have been successfully provisioned, the system ensures authentication readiness and can identify and correct any configuration issues before they lead to authentication failures.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple cloud service components are managed with separate authentication credentials, then system functionality is maintained, but time consumption increases due to repetitive authentication

Engineering Contradiction:
Improvesystem functionalityVSAvoidauthentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The key manager system provides universal functionality by managing authentication credentials for multiple cloud service components through a single interface. Instead of requiring separate authentication processes for each component, the key manager consolidates key pair management and secure connection configuration across all components, enabling efficient access to multiple services without repetitive authentication time loss.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11539678B2Asymmetric key management for cloud computing services
Publication Date: 2022.12.27 RED HAT INC
  • US11539678B2 patent drawing
  • US11539678B2 patent drawing
  • US11539678B2 patent drawing

AI summary

A key manager receives one or more asymmetric key pairs associated with a user to be associated with remote access of cloud computing resources, selects a first asymmetric key pair of the one or more asymmetric key pairs, determines one or more cloud service providers associated with the user, selects a first cloud service provider of the one or more cloud service providers to be associated with the first asymmetric key pair, determines one or more cloud service components associated with the first cloud service provider that are accessible to the user, provisions at least one of the one or more cloud service components with the first public key, and configures a connection component to establish a secure connection to the at least one of the one or more cloud service components using the first private key.