Cloud Infrastructure Authentication with Device-Component-Derived Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud infrastructure deployments face security issues due to centralized storage of credentials, which are vulnerable to compromise, require tedious manual updates, and hinder direct interaction between infrastructure resources.
Innovation Solution
Authentication using keys derived from device component information, such as fingerprints, is implemented through Link Layer Discovery Protocol packets, enabling secure, decentralized management and interaction among network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords or credentials are stored in a centralized management module, then management of infrastructure resources is simplified, but security is compromised and credential compromise risk increases
Solution Approach 1:
The patent segments the centralized credential storage into distributed device-specific credentials. Each infrastructure resource (compute node, storage node, network switch) maintains its own credentials locally rather than storing them in a centralized management module. This segmentation eliminates the single point of failure and security vulnerability associated with centralized storage while allowing each device to independently manage its authentication credentials.
2Device complexity
If centralized storage of credentials is used, then credential management is centralized, but manual intervention is required for credential updates and configuration changes
Solution Approach 1:
The patent implements self-service automation where each infrastructure resource automatically generates and manages its own credentials without requiring manual administrator intervention. When devices join the fabric or configuration changes occur, the system automatically handles credential generation, distribution, and updates through peer-to-peer communication, eliminating the need for tedious manual credential management processes.
3Reliability
If device component information is used to generate keys, then security is enhanced through decentralization, but device complexity increases
Solution Approach 1:
The patent leverages existing universal device components (BMC, network interfaces, storage controllers) that are already present in modern infrastructure devices to generate authentication keys. By using universally available hardware components with unique identifiers and cryptographic capabilities, the system achieves decentralized security without adding specialized authentication hardware, thus minimizing the increase in device complexity while maintaining strong security.
Data Source
AI summary
An apparatus in an illustrative embodiment comprises at least one processing device including a processor coupled to a memory. The at least one processing device is configured to identify a plurality of components of a first network device, to generate at least one fingerprint based at least in part on the identified plurality of components of the first network device, to encrypt the at least one fingerprint, to generate at least one packet containing at least the encrypted at least one fingerprint, to send the at least one packet to at least a second network device, and to interact with the second network device to obtain at least one key derived at least in part from the at least one fingerprint. The at least one key is utilized in an authentication process carried out between the first network device and the second network device.


