Cloud Instance Provisioning With Certificate Bundle Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud resource instance provisioning processes face challenges in ensuring secure communications and avoiding downtime due to outdated digital certificates, particularly in virtual cloud networks, as updating CA certificates in OS images is impractical and time-consuming.

Innovation Solution

Distribute a certificate bundle during the provisioning process, including a set of CA certificates, to establish secure communications and ensure compatibility with security protocols, thereby avoiding delays and downtime associated with updating CA certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CA certificates are updated in OS images, then security is improved, but provisioning time increases and downtime occurs

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent separates CA certificates from the OS image by distributing them as independent certificate bundles during the provisioning process. This segmentation allows the OS image to remain static while certificates are updated separately, resolving the contradiction between security updates and provisioning time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs certificate distribution as a preliminary action during instance provisioning, before the instance becomes operational. By pre-distributing certificate bundles during the provisioning phase rather than requiring post-provisioning updates, the system achieves security updates without additional downtime.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If CA certificates are updated in OS images, then security is improved, but the process becomes impractical and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidease of updating
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts CA certificates from the OS image update process and creates independent certificate bundles that can be distributed separately. This extraction makes the certificate update process more practical and easier to manage, as certificates can be updated without re-imaging entire OS systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses certificate bundles as copyable, distributable units that can be replicated and deployed across multiple instances efficiently. Instead of modifying OS images, the system creates and distributes certificate bundle copies during provisioning, simplifying the update process.

Inventive Principle:
Principle #26Copying

3Productivity

If certificate bundles are distributed during provisioning, then provisioning speed is improved, but system complexity increases

Engineering Contradiction:
Improveprovisioning speedVSAvoidprovisioning process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges certificate bundle distribution with the existing provisioning workflow, integrating certificate delivery into the instance creation process rather than treating it as a separate step. This integration improves provisioning speed while managing complexity through unified process management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces certificate bundles as an intermediary mechanism between the provisioning system and security protocols. These bundles serve as pre-packaged certificate sets that simplify the interaction between provisioning processes and security requirements, managing complexity through standardized intermediaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12563029B2Provisioning cloud resource instances associated with a virtual cloud network
Publication Date: 2026.02.24 ORACLE INT CORP
  • US12563029B2 patent drawing
  • US12563029B2 patent drawing
  • US12563029B2 patent drawing

AI summary

Techniques for provisioning a cloud resource instance associated with a virtual cloud network may include detecting a certificate bundle-retrieval trigger during a provisioning process for the cloud resource instance, and responsive to detecting the certificate bundle-retrieval trigger, sending, to an agent executing on a network interface linked to the cloud resource instance, a request for a certificate bundle for the cloud resource instance. Techniques may further include receiving the certificate bundle from the network interface. The certificate bundle may include a set of certificate authority (CA) certificates. Techniques may further include installing the certificate bundle in a storage medium associated with the cloud resource instance. Installing the certificate bundle may represent an operation of the provisioning process.