Asymmetric Session Credentials for Secure Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing session credential systems using symmetric keys are vulnerable to unauthorized access and inefficient in invalidating compromised keys, as any service that can decrypt session credentials can misuse the secret key, and managing access across regions is complex and computationally expensive.

Innovation Solution

Implementing asymmetric session credentials that use a public key encryption pair, where the private key is maintained securely by the user and the public key is used for verification, and managing session tokens with global and account-specific encryption keys to enable secure access and rapid key rotation across regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If symmetric session credentials are used, then session verification is simplified, but security is compromised as any service that can decrypt credentials can misuse the secret key

Engineering Contradiction:
Improvesession verificationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies asymmetry by transitioning from symmetric key cryptography to asymmetric key cryptography. Session credentials are signed with the user's private key and verified with the corresponding public key. This resolves the contradiction by enabling simplified verification (services only need the public key) while maintaining security (the private key never leaves the user's device, preventing service misuse).

Inventive Principle:
Principle #4Asymmetry

2Reliability

If a secret key is compromised, then access security is breached, but invalidating all current access is time consuming and computationally expensive

Engineering Contradiction:
Improveaccess securityVSAvoidkey invalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the authentication system into long-term credentials (user's private/public key pair) and short-term session credentials (signed tokens). When a session credential is compromised, only that specific short-term credential needs to be invalidated, not the user's entire authentication system. This allows rapid, targeted invalidation without affecting other sessions or requiring computationally expensive global key rotation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of credential lifespan from long-term (requiring infrequent but expensive rotation) to short-term (allowing frequent but cheap rotation). Session credentials have limited validity periods and can be individually revoked. This parameter change enables faster response to compromises while reducing the computational burden of key management.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If session credentials are encrypted with a secret key, then verification is possible, but the secret key can be misused by services to sign additional requests

Engineering Contradiction:
Improveverification accuracyVSAvoidkey misuse
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent uses asymmetric cryptography where the signing operation (creating credentials) and verification operation (checking credentials) use different keys. The user's private key signs credentials, while services verify them using the public key. This asymmetry prevents service misuse because services never possess the private key needed to create valid credentials, yet can still verify them accurately.

Inventive Principle:
Principle #4Asymmetry

4Ease of operation

If global session management is implemented, then access control is simplified, but managing keys across regions becomes complex and computationally expensive

Engineering Contradiction:
Improveaccess controlVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key management burden from the service side and places it on the user's client device. Users generate and retain their private keys locally, and services only need to verify signatures using public keys. This extraction eliminates the need for services to securely store, manage, or rotate secret keys across regions, dramatically reducing key management complexity while maintaining global access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10182044B1Personalizing global session identifiers
Publication Date: 2019.01.15 AMAZON TECH INC
  • US10182044B1 patent drawing
  • US10182044B1 patent drawing
  • US10182044B1 patent drawing

AI summary

Techniques for personalizing short-term session credentials are described herein. A global session key is provided to a plurality of regions of a computing resource service provider and an account key is also provided to one or more of the plurality of regions based at least in part on those regions being trusted by a customer of the computing resource service provider. When a request for short-term session credentials is received at the trusted region by that customer, a session token is generated and encrypted with a combination of the global session key and the account key, thereby creating a session token that can be uniquely associated with the customer and that may only be used in regions that that customer has designated as trusted regions.