Cloud Resource Unit Isolation via Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based platforms face security vulnerabilities due to their centralized administrative entities, which can lead to widespread breaches and performance issues, as attackers can exploit connected components to compromise the entire platform.

Innovation Solution

Implementing certificate-based authentication and granular security boundaries to isolate components, allowing the system to quickly contain breaches and enhance security by ensuring only trusted communications occur between control planes and resource units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized administrative entity is used to manage cloud resources, then ease of operation is improved, but security is worsened due to single point of failure

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized administrative entity into multiple distributed administrative entities, each managing a specific domain. This segmentation eliminates the single point of failure while maintaining operational simplicity through standardized interfaces and protocols for job submission and resource management.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If administrative entities maintain constant network connections to resource units, then ease of operation is improved, but security is worsened due to exploitable connections

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces certificate-based authentication as an intermediary mechanism between administrative entities and resource units. This allows constant network connections for operational efficiency while securing communications through cryptographic verification, preventing exploitation of connection channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If domain accounts with username and password authentication are used, then ease of operation is improved, but security is worsened due to compromised credentials

Engineering Contradiction:
Improveease of operationVSAvoidsecurity breach
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical username and password authentication system with certificate-based cryptographic authentication. This substitution eliminates vulnerabilities associated with credential theft and compromise while maintaining ease of operation through automated certificate management and seamless authentication processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If all jobs are executed by a single administrative entity, then ease of operation is improved, but productivity is worsened due to capacity limitations

Engineering Contradiction:
Improveease of operationVSAvoiddata throughput
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments the job execution function across multiple administrative entities, each capable of independently executing jobs within their domains. This segmentation removes the bottleneck of a single administrative entity, enabling parallel job processing and significantly increasing overall system throughput and productivity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12069042B2Resource unit isolation for increased safety and security in cloud services
Publication Date: 2024.08.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12069042B2 patent drawing
  • US12069042B2 patent drawing
  • US12069042B2 patent drawing

AI summary

The techniques disclosed herein enable improved security as well as more scalable and reliable job execution by utilizing granular security boundaries and certificate-based authentication for all communication within cloud-based platforms. To manage a cloud-based platform, a system receives a plurality of jobs and associated certificates at a first security boundary that are to be executed at various resource units within a second security boundary. The system then authenticates each certificate before transmitting each job to its respective resource unit for execution. In addition, the system is further configured to monitor active certificates for compromise and accordingly isolate various security boundaries in the event of a security breach. By isolating portions of the cloud-based platform within security boundaries, the system can mitigate the impact of security breaches. Furthermore, certificate-based authentication addresses performance constraints to enable more efficient and scalable job execution.