Asymmetric Key Distribution in Utility Computing via Isolated Virtual Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In utility computing environments, the manual distribution of authentication credentials is impractical due to dynamic resource allocation and lack of local storage, making it difficult to ensure secure and automated initial authentication.

Innovation Solution

An automated method for securely distributing asymmetric key security credentials by associating them with logical device identifiers and establishing isolated virtual networks for secure communication between management servers and provisionable resources, allowing for secure authentication and credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual distribution of authentication credentials is used, then security is maintained through physical access control, but automation and dynamic resource allocation become impractical

Engineering Contradiction:
ImprovesecurityVSAvoidautomation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent introduces a credential distribution server as an intermediary between administrators and computing resources. This server automatically manages the distribution of authentication credentials (public keys, private keys, certificates) to resources dynamically, eliminating the need for manual technician intervention while maintaining security through controlled credential issuance and revocation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables resources to automatically receive and manage their own authentication credentials through the credential distribution server. Resources can self-provision security credentials when allocated and automatically have credentials revoked when deallocated, without requiring manual technician intervention for each credential management operation.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual credential distribution is implemented, then secure authentication is established, but physical access and technician intervention are required

Engineering Contradiction:
Improvesecure authenticationVSAvoidphysical access requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/physical process of technician-mediated credential distribution with an automated electronic system. The credential distribution server electronically issues credentials to resources through network communication, eliminating the need for physical technician access to each resource while maintaining secure authentication through cryptographic methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If dynamic resource allocation is implemented, then resource utilization efficiency improves, but credential management complexity increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidcredential management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The credential distribution server provides a universal platform that handles all credential management operations for all computing resources in the utility computing environment. It manages public key distribution, private key secure storage, certificate issuance, and credential revocation through a single automated system, reducing overall credential management complexity despite dynamic resource allocation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the credential distribution server continuously monitors resource allocation status and automatically adjusts credential distribution accordingly. When resources are allocated or deallocated, the server receives feedback and automatically provisions or revokes credentials, maintaining security without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8577044B2Method and apparatus for automatic and secure distribution of an asymmetric key security credential in a utility computing environment
Publication Date: 2013.11.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8577044B2 patent drawing
  • US8577044B2 patent drawing
  • US8577044B2 patent drawing

AI summary

Embodiments of the invention provide a method and an apparatus for automatic, secure, and confidential distribution of an asymmetric key security credential in a utility computing environment. In one method embodiment, the present invention provides an asymmetric key at a management server, the asymmetric key automatically associated with a logical device identifier of a provisionable resource. Additionally, an isolated virtual network is established between the management server and the provisionable resource for providing the asymmetric key to the provisionable resource. Then, after the asymmetric key is provided to the provisionable resource the isolated virtual network between the management server and the provisionable resource is dissolved.