Cross-Vendor Device Authentication With Steward-Mediated Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud and edge infrastructures with multi-vendor components face challenges in credential management, including security vulnerabilities, credential updates, device interaction limitations, and cumbersome node addition or removal processes due to centralized credential storage.

Innovation Solution

Implementing a credential-less management system using a trusted secure channel for management data exchange, where a compound certificate is generated and distributed among devices, enabling encrypted token generation and authentication without decrypting the certificate itself, with a steward node facilitating key exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized credential storage is used for multi-vendor infrastructure, then device authentication can be managed centrally, but security vulnerabilities increase and device interaction is limited

Engineering Contradiction:
Improvecentralized credential managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized credential storage into distributed credential management. Each vendor's credentials are stored and managed independently at their respective data nodes, eliminating the single point of failure and reducing security vulnerabilities associated with centralized storage while maintaining authentication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a credentialless management system where a steward node acts as an intermediary. Instead of direct centralized authentication, the steward facilitates key exchange and authentication through encrypted token passing between data nodes, enabling secure device interaction without centralized credential control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized credential storage is used, then authentication can be simplified, but node addition or removal becomes cumbersome

Engineering Contradiction:
Improveauthentication simplicityVSAvoidnode addition/removal process
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent implements dynamic credential management where credentials are not static but can be dynamically added or removed from the compound certificate as nodes join or leave the cluster. This allows flexible node addition/removal without cumbersome reconfiguration of centralized authentication systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent merges multiple vendor credentials into a single compound certificate that can be dynamically updated. This combining approach allows multiple nodes to be authenticated through one unified mechanism while enabling easy addition or removal of individual nodes by updating the compound certificate without affecting other nodes.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If compound certificate is encrypted and distributed among devices, then decentralized authentication is enabled, but key management complexity increases

Engineering Contradiction:
Improvedecentralized authentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management complexity from individual devices by introducing a dedicated steward node. The steward handles the complex operations of key generation, encryption, and distribution, while individual devices only need to store and use their specific credentials, significantly reducing their complexity burden.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The steward node serves as an intermediary that manages the compound certificate and key exchange operations. It facilitates secure key distribution and authentication without requiring each device to manage complex key relationships, thereby reducing device complexity while maintaining decentralized authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If credential-less management system is implemented, then security is enhanced, but device interaction requirements become more complex

Engineering Contradiction:
Improveinfrastructure compromise riskVSAvoiddevice interaction protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication mechanism through the compound certificate that can be used across all vendors and device types in the cluster. This multi-functional approach simplifies device interactions by providing a common authentication language while maintaining enhanced security through decentralized credential management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12457107B2Cross-vendor device authentication for multi-vendor infrastructure
Publication Date: 2025.10.28 DELL PROD LP
  • US12457107B2 patent drawing
  • US12457107B2 patent drawing
  • US12457107B2 patent drawing

AI summary

Techniques described herein relate to a method for establishing communication sessions. The method may include sending, by a first data node, a request to establish a session to a second data node, wherein the request is encrypted using a compound certificate associated with a data cluster; obtaining, an encrypted token from the second data node; verifying the encrypted token using the compound certificate; performing steward selection to select a third data node to be a steward; generating a unique key and providing a copy of the unique key to the steward; generating an encrypted authentication token using the unique key; sending the encrypted authentication token to the steward; obtaining an authentication token from the second data node, wherein the authentication token is decrypted; verifying the authentication token using the encrypted authentication token; and performing remaining communications associated with the session using the steward.