Credential Generation for Virtual Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing networks face challenges in effectively managing credentials across multiple devices and virtual machines, particularly in preventing unauthorized access and ensuring secure policy enforcement due to the complexity of these networks.

Innovation Solution

The system generates and distributes credentials based on user-defined subsets and policies, using a centralized policy management service to optimize and enforce policies through a normalized form, and includes a verification mode for evaluating requests and managing credential states to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If credentials are distributed to multiple devices and virtual machines, then access control and policy enforcement are enabled, but security risks increase due to potential unauthorized access and credential compromise

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments credential management by creating unique credential instances for each device or virtual machine. Instead of distributing the same credential to multiple entities, the system generates distinct credentials (e.g., unique identifiers, cryptographic keys) for each recipient, thereby maintaining security while enabling differentiated access control. This segmentation ensures that compromise of one credential does not affect others.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized credential management service as an intermediary between credential issuance and verification. This mediator handles credential generation, distribution, and revocation centrally, enabling policy enforcement without requiring direct trust between all devices. The intermediary validates credentials against stored policies and can revoke access centrally if security risks arise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If centralized policy management is implemented to enforce security policies, then policy consistency is improved, but system complexity increases

Engineering Contradiction:
Improvepolicy consistencyVSAvoidsystem complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent extracts policy management functionality from individual devices and centralizes it in a dedicated credential management service. This extraction allows policy consistency to be maintained centrally while reducing the complexity burden on individual devices. The centralized service handles policy evaluation and credential validation, leaving devices with simpler authentication tasks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal credential management service that handles multiple functions: credential generation, distribution, validation, and revocation. This multi-functional intermediary consolidates what would otherwise require separate systems for each function, reducing overall system complexity while maintaining policy consistency across all devices and virtual machines.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If credential validation is performed for every access request, then security is improved, but processing time increases

Engineering Contradiction:
Improvesecurity validationVSAvoidaccess processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary credential validation by pre-establishing trust relationships and policy rules during credential issuance. The credential management service validates credentials against stored policies in advance, creating a validated state that can be quickly checked during access requests. This preliminary action reduces the computational burden during actual access operations while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates verified copies of credential validation results that can be efficiently referenced during access requests. Instead of performing full validation computations for every access attempt, the system uses pre-validated credential instances with embedded policy information that can be quickly verified through simpler checks, maintaining security while improving processing speed.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10097531B2Techniques for credential generation
Publication Date: 2018.10.09 AMAZON TECH INC
  • US10097531B2 patent drawing
  • US10097531B2 patent drawing
  • US10097531B2 patent drawing

AI summary

A plurality of virtual computing resources is detected to have been provisioned. Credentials are distributed to the plurality of virtual computing resources. A credentials map that maps the credentials to the plurality of virtual computing resources is updated. The credentials for the plurality of virtual computing resources are activated to enable the plurality of virtual computing resources to use the credentials to authenticate to a second computer system that manages a resource service, with the credentials being inaccessible to resources of the resource service. A virtual computing resource of the plurality of virtual computing resources is detected to been deprovisioned, and the credentials for the virtual computing resource are deactivated.