Cloud Infrastructure Authentication with Device-Component-Derived Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud infrastructure deployments face security issues due to centralized storage of credentials, which are vulnerable to compromise, require tedious manual updates, and hinder direct interaction between infrastructure resources.

Innovation Solution

Authentication using keys derived from device component information, such as fingerprints, is implemented through Link Layer Discovery Protocol packets, enabling secure, decentralized management and interaction among network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passwords or credentials are stored in a centralized management module, then management of infrastructure resources is simplified, but security is compromised and credential compromise risk increases

Engineering Contradiction:
Improvemanagement of infrastructure resourcesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized credential storage into distributed device-specific credentials. Each infrastructure resource (compute node, storage node, network switch) maintains its own credentials locally rather than storing them in a centralized management module. This segmentation eliminates the single point of failure and security vulnerability associated with centralized storage while allowing each device to independently manage its authentication credentials.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If centralized storage of credentials is used, then credential management is centralized, but manual intervention is required for credential updates and configuration changes

Engineering Contradiction:
Improvecredential management structureVSAvoidcredential updates and configuration changes
Core Design Contradiction:
Device complexityVSExtent of automation

Solution Approach 1:

The patent implements self-service automation where each infrastructure resource automatically generates and manages its own credentials without requiring manual administrator intervention. When devices join the fabric or configuration changes occur, the system automatically handles credential generation, distribution, and updates through peer-to-peer communication, eliminating the need for tedious manual credential management processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If device component information is used to generate keys, then security is enhanced through decentralization, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing universal device components (BMC, network interfaces, storage controllers) that are already present in modern infrastructure devices to generate authentication keys. By using universally available hardware components with unique identifiers and cryptographic capabilities, the system achieves decentralized security without adding specialized authentication hardware, thus minimizing the increase in device complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12395478B2Authentication system for cloud infrastructure using keys derived from device component information
Publication Date: 2025.08.19 DELL PROD LP
  • US12395478B2 patent drawing
  • US12395478B2 patent drawing
  • US12395478B2 patent drawing

AI summary

An apparatus in an illustrative embodiment comprises at least one processing device including a processor coupled to a memory. The at least one processing device is configured to identify a plurality of components of a first network device, to generate at least one fingerprint based at least in part on the identified plurality of components of the first network device, to encrypt the at least one fingerprint, to generate at least one packet containing at least the encrypted at least one fingerprint, to send the at least one packet to at least a second network device, and to interact with the second network device to obtain at least one key derived at least in part from the at least one fingerprint. The at least one key is utilized in an authentication process carried out between the first network device and the second network device.