Cross-Vendor Device Authentication With Steward-Mediated Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud and edge infrastructures with multi-vendor components face challenges in credential management, including security vulnerabilities, credential updates, device interaction limitations, and cumbersome node addition or removal processes due to centralized credential storage.
Innovation Solution
Implementing a credential-less management system using a trusted secure channel for management data exchange, where a compound certificate is generated and distributed among devices, enabling encrypted token generation and authentication without decrypting the certificate itself, with a steward node facilitating key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized credential storage is used for multi-vendor infrastructure, then device authentication can be managed centrally, but security vulnerabilities increase and device interaction is limited
Solution Approach 1:
The patent segments the centralized credential storage into distributed credential management. Each vendor's credentials are stored and managed independently at their respective data nodes, eliminating the single point of failure and reducing security vulnerabilities associated with centralized storage while maintaining authentication capability.
Solution Approach 2:
The patent introduces a credentialless management system where a steward node acts as an intermediary. Instead of direct centralized authentication, the steward facilitates key exchange and authentication through encrypted token passing between data nodes, enabling secure device interaction without centralized credential control.
2Ease of operation
If centralized credential storage is used, then authentication can be simplified, but node addition or removal becomes cumbersome
Solution Approach 1:
The patent implements dynamic credential management where credentials are not static but can be dynamically added or removed from the compound certificate as nodes join or leave the cluster. This allows flexible node addition/removal without cumbersome reconfiguration of centralized authentication systems.
Solution Approach 2:
The patent merges multiple vendor credentials into a single compound certificate that can be dynamically updated. This combining approach allows multiple nodes to be authenticated through one unified mechanism while enabling easy addition or removal of individual nodes by updating the compound certificate without affecting other nodes.
3Reliability
If compound certificate is encrypted and distributed among devices, then decentralized authentication is enabled, but key management complexity increases
Solution Approach 1:
The patent extracts the key management complexity from individual devices by introducing a dedicated steward node. The steward handles the complex operations of key generation, encryption, and distribution, while individual devices only need to store and use their specific credentials, significantly reducing their complexity burden.
Solution Approach 2:
The steward node serves as an intermediary that manages the compound certificate and key exchange operations. It facilitates secure key distribution and authentication without requiring each device to manage complex key relationships, thereby reducing device complexity while maintaining decentralized authentication security.
4Reliability
If credential-less management system is implemented, then security is enhanced, but device interaction requirements become more complex
Solution Approach 1:
The patent creates a universal authentication mechanism through the compound certificate that can be used across all vendors and device types in the cluster. This multi-functional approach simplifies device interactions by providing a common authentication language while maintaining enhanced security through decentralized credential management.
Data Source
AI summary
Techniques described herein relate to a method for establishing communication sessions. The method may include sending, by a first data node, a request to establish a session to a second data node, wherein the request is encrypted using a compound certificate associated with a data cluster; obtaining, an encrypted token from the second data node; verifying the encrypted token using the compound certificate; performing steward selection to select a third data node to be a steward; generating a unique key and providing a copy of the unique key to the steward; generating an encrypted authentication token using the unique key; sending the encrypted authentication token to the steward; obtaining an authentication token from the second data node, wherein the authentication token is decrypted; verifying the authentication token using the encrypted authentication token; and performing remaining communications associated with the session using the steward.


