Certificate Manager Automates Trust Validation in Distributed Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing environments require significant manual input and expertise to configure and manage, making it complex for users to leverage their full potential, especially in terms of provisioning and managing virtual machine resources across distributed systems.

Innovation Solution

The implementation of automated management systems, including an application director, cloud manager, and management agents, which facilitate the provisioning, deployment, and management of virtual machines and resources through a centralized interface, reducing the need for manual intervention and enhancing scalability and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated management systems are implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a certificate manager as an intermediary component that automatically handles certificate validation, trust relationship establishment, and security credential management between virtual machines and cloud infrastructure. This mediator eliminates the need for users to manually configure complex security settings, thereby improving ease of operation while the underlying complexity is managed by the automated system

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual configuration is used, then device complexity is reduced, but productivity decreases

Engineering Contradiction:
ImproveproductivityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where the certificate manager automatically provisions, validates, and manages security certificates and trust relationships without requiring manual user configuration. Virtual machines automatically establish trusted connections with cloud services through automated credential verification, enabling rapid deployment and management while maintaining security compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring certificate validation rules, trust relationships, and security policies before virtual machines are deployed. The certificate manager pre-establishes trusted certificate authorities and validation criteria, so that when virtual machines are provisioned, they automatically inherit secure configurations without requiring manual security setup, thereby increasing productivity

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificate validation is performed, then reliability is improved, but processing time increases

Engineering Contradiction:
ImprovereliabilityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The certificate manager performs preliminary validation of certificates during the initial provisioning phase, establishing trust relationships before actual operations begin. By pre-validating certificate authorities and establishing trusted roots in advance, the system ensures reliable security verification while minimizing time loss during runtime operations, as subsequent validations can quickly reference pre-established trust relationships

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11153297B2Systems and methods to facilitate certificate and trust management across a distributed environment
Publication Date: 2021.10.19 VMWARE INC
  • US11153297B2 patent drawing
  • US11153297B2 patent drawing
  • US11153297B2 patent drawing

AI summary

Methods and apparatus to facilitate certificate and trust management across a distributed environment are disclosed. An example apparatus includes a first virtual appliance including a first management endpoint and a first authentication provider including a first certificate validator, the first certificate validator to validate that a first certificate received by the first authentication provider is authentic, virtual appliance to communicate the first certificate via the first management endpoint; and a first component server including a first management agent and a first certificate evaluator, the first management agent to communicate with the first virtual appliance via the first management endpoint, the first management agent to receive the first certificate via the first management endpoint, the first certificate evaluator to evaluate the first certificate to determine a signing authority, the first management agent to restart the first component server and notify the first virtual appliance of acceptance of the first certificate.