Cloud Identity Management for Ephemeral Container Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management and authentication (IMA) systems struggle to manage and authenticate ephemeral applications and containers, which are challenging due to their lack of persistent identity and inability to store credentials, posing security risks as they become attractive targets for attackers.

Innovation Solution

A cloud-based method for assigning identity and strong authentication credentials to application instances through runtime monitoring, entity classification, security group assignment, unique naming, and digital certificate management, enabling secure identity provisioning and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IMA systems are used to manage containers and applications, then security policy enforcement is simplified, but identity assignment fails because containers are ephemeral and lack persistent identity capabilities

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoididentity assignment capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary identity management service that acts as a mediator between traditional IMA systems and ephemeral containers. This service generates and manages identity tokens that allow containers to participate in security policies without requiring persistent identity storage, thus resolving the contradiction between reliable security enforcement and adaptability to ephemeral workloads.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of identity information in the form of identity tokens and certificates that can be dynamically assigned to containers. Instead of relying on persistent identity storage, the system uses these copied identity representations to enable security policy enforcement for ephemeral containers, maintaining reliability while adapting to temporary workloads.

Inventive Principle:
Principle #26Copying

2Ease of operation

If secret management approaches are used for container authentication, then access control is achieved, but only coarse-grained control is possible because secrets are shared resources not bound to unique processes

Engineering Contradiction:
Improveaccess control implementationVSAvoidaccess control granularity
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the shared secret into unique identity tokens and certificates that are bound to individual container processes. Instead of using a single shared secret for all containers, the system divides authentication credentials into process-specific segments, enabling fine-grained access control where each container can be individually authenticated and authorized.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different identity characteristics to different container processes, giving each process its own unique identity properties rather than using a uniform shared secret. This local differentiation enables precise control over which specific container processes can access which resources, transforming coarse-grained shared access into fine-grained process-specific access control.

Inventive Principle:
Principle #3Local quality

3Reliability

If identity provisioning is tightly coupled with orchestration platform trust chains, then secure identity assignment is achieved, but portability is lost and bootstrapping becomes platform-dependent

Engineering Contradiction:
Improveidentity provisioning securityVSAvoidplatform portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal identity token format that can be used across different orchestration platforms without being tied to a specific platform's trust chain. The identity management service generates platform-agnostic credentials that work with various container orchestration systems, enabling the same identity provisioning mechanism to function reliably across multiple platforms and enhancing portability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the identity provisioning logic from the orchestration platform's native trust chain and separates it into an independent identity management service. This extraction allows the system to maintain secure identity provisioning while decoupling it from platform-specific implementations, thereby improving portability without sacrificing security through the use of external, platform-independent credential verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10673840B2Cloud-based identity management and authentication system for containers and applications
Publication Date: 2020.06.02 NEW RELIC INC
  • US10673840B2 patent drawing
  • US10673840B2 patent drawing
  • US10673840B2 patent drawing

AI summary

The disclosed invention is a new method and apparatus for the management of application/container process identity for authentication and enforcing group-based security policies. Identities and security policies are managed in the cloud. Strong cryptographic identities or digital certificates are provided to each application/container or group of applications/containers. Applications/containers use these digital certificates to mutually authenticate each other before providing access to their resources.