Distributed Ledger Authentication for Cloud Service Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for providing authentication, authorization, and accounting in managed cloud services rely on third-party entities like PKI and syslog, which face scalability issues and are prone to errors, compromising security and traceability.
Innovation Solution
Implementing a distributed ledger system, specifically a permissioned blockchain, to facilitate authentication, authorization, and accounting processes, eliminating the need for third-party entities by using a decentralized framework for secure transaction recording and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party entities like PKI and syslog are used for authentication, authorization, and accounting, then security and traceability are provided, but scalability and reliability deteriorate when managing hundreds or thousands of services and customers
Solution Approach 1:
The system enables self-service by allowing cloud service providers to autonomously manage authentication, authorization, and accounting without third-party intermediaries. The distributed ledger and smart contracts automatically handle identity verification and access control, eliminating dependency on external PKI authorities and syslog servers while maintaining security and enabling horizontal scaling across thousands of services.
Solution Approach 2:
The patent introduces a distributed ledger system as a new intermediary that replaces traditional third-party entities. This mediator provides decentralized verification through cryptographic protocols and consensus mechanisms, enabling scalable trust establishment without centralized control points, thus resolving the contradiction between reliability and scalability.
2Ease of operation
If third-party systems like syslog and PKI are configured to work in limited circumstances, then authentication and traceability are achieved, but error resistance and security deteriorate due to human error and sensitive data compromise
Solution Approach 1:
The system eliminates human configuration errors by using self-service mechanisms where smart contracts automatically enforce authentication and authorization policies. Identity verification and access control decisions are executed autonomously by the distributed ledger system, removing human intervention points that could introduce errors or security vulnerabilities.
Solution Approach 2:
The patent replaces mechanical/manual configuration systems (syslog and PKI requiring human setup and management) with automated cryptographic mechanisms. The distributed ledger uses algorithmic consensus and cryptographic proofs instead of manual configuration, eliminating human error while maintaining ease of operation through programmatic interfaces.
3Loss of information
If traditional log file storage systems like syslog are used, then traceability is accomplished, but scalability and security deteriorate when managing large numbers of services and customers
Solution Approach 1:
The patent transitions from centralized hierarchical log storage to a decentralized distributed ledger structure. This dimensional change distributes traceability information across multiple nodes in the network, enabling parallel processing and linear scalability. The distributed nature allows the system to handle thousands of services simultaneously without the bottlenecks inherent in traditional centralized syslog architectures.
Solution Approach 2:
The distributed ledger system provides self-service traceability where each node independently maintains and verifies log entries through cryptographic hashing and consensus mechanisms. This eliminates the need for centralized log collection and processing, enabling scalable traceability across distributed cloud environments without single points of failure or performance bottlenecks.
Data Source
AI summary
In an embodiment, a computer implemented method comprises receiving, at a first computing device associated with a managing entity, a request to perform an operation of a managed service; publishing to a first block of a distributed ledger system, by the first computing device associated with the managing entity, identification information of the managing entity; identifying, by a second computing device associated with the managed service, the identification information published to the first block of the distributed ledger system; publishing to a second block of the distributed ledger system, by the second computing device associated with the managed service, acknowledgement information comprising an indication that the identification information of the managing entity published to the first block was received and verified; publishing to a third block of the distributed ledger system, by the second computing device associated with the managed service, management request information comprising an operation request for the managing entity; identifying, by the first computing device associated with the managing entity, the management request information published to the third block of the distributed ledger system; publishing to a fourth block of the distributed ledger system, by the first computing device associated with the managing entity, management request acknowledgment information comprising an indication that the management request information of the third block was received; and in response to a performance of an operation included in the management request information published to the third block, publishing to a fifth block of the distributed ledger system, by the first computing device associated with the managing entity, management operation record information including a history of operations performed by the managing entity.


