Distributed Ledger Authentication for Cloud Service Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for providing authentication, authorization, and accounting in managed cloud services rely on third-party entities like PKI and syslog, which face scalability issues and are prone to errors, compromising security and traceability.

Innovation Solution

Implementing a distributed ledger system, specifically a permissioned blockchain, to facilitate authentication, authorization, and accounting processes, eliminating the need for third-party entities by using a decentralized framework for secure transaction recording and verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party entities like PKI and syslog are used for authentication, authorization, and accounting, then security and traceability are provided, but scalability and reliability deteriorate when managing hundreds or thousands of services and customers

Engineering Contradiction:
Improvesecurity and traceabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by allowing cloud service providers to autonomously manage authentication, authorization, and accounting without third-party intermediaries. The distributed ledger and smart contracts automatically handle identity verification and access control, eliminating dependency on external PKI authorities and syslog servers while maintaining security and enabling horizontal scaling across thousands of services.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a distributed ledger system as a new intermediary that replaces traditional third-party entities. This mediator provides decentralized verification through cryptographic protocols and consensus mechanisms, enabling scalable trust establishment without centralized control points, thus resolving the contradiction between reliability and scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If third-party systems like syslog and PKI are configured to work in limited circumstances, then authentication and traceability are achieved, but error resistance and security deteriorate due to human error and sensitive data compromise

Engineering Contradiction:
Improveconfiguration and operationVSAvoiderror resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system eliminates human configuration errors by using self-service mechanisms where smart contracts automatically enforce authentication and authorization policies. Identity verification and access control decisions are executed autonomously by the distributed ledger system, removing human intervention points that could introduce errors or security vulnerabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces mechanical/manual configuration systems (syslog and PKI requiring human setup and management) with automated cryptographic mechanisms. The distributed ledger uses algorithmic consensus and cryptographic proofs instead of manual configuration, eliminating human error while maintaining ease of operation through programmatic interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of information

If traditional log file storage systems like syslog are used, then traceability is accomplished, but scalability and security deteriorate when managing large numbers of services and customers

Engineering Contradiction:
ImprovetraceabilityVSAvoidscalability
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent transitions from centralized hierarchical log storage to a decentralized distributed ledger structure. This dimensional change distributes traceability information across multiple nodes in the network, enabling parallel processing and linear scalability. The distributed nature allows the system to handle thousands of services simultaneously without the bottlenecks inherent in traditional centralized syslog architectures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The distributed ledger system provides self-service traceability where each node independently maintains and verifies log entries through cryptographic hashing and consensus mechanisms. This eliminates the need for centralized log collection and processing, enabling scalable traceability across distributed cloud environments without single points of failure or performance bottlenecks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11637830B2Authentication, authorization and accounting in managed cloud computing services
Publication Date: 2023.04.25 CISCO TECHNOLOGY INC
  • US11637830B2 patent drawing
  • US11637830B2 patent drawing
  • US11637830B2 patent drawing

AI summary

In an embodiment, a computer implemented method comprises receiving, at a first computing device associated with a managing entity, a request to perform an operation of a managed service; publishing to a first block of a distributed ledger system, by the first computing device associated with the managing entity, identification information of the managing entity; identifying, by a second computing device associated with the managed service, the identification information published to the first block of the distributed ledger system; publishing to a second block of the distributed ledger system, by the second computing device associated with the managed service, acknowledgement information comprising an indication that the identification information of the managing entity published to the first block was received and verified; publishing to a third block of the distributed ledger system, by the second computing device associated with the managed service, management request information comprising an operation request for the managing entity; identifying, by the first computing device associated with the managing entity, the management request information published to the third block of the distributed ledger system; publishing to a fourth block of the distributed ledger system, by the first computing device associated with the managing entity, management request acknowledgment information comprising an indication that the management request information of the third block was received; and in response to a performance of an operation included in the management request information published to the third block, publishing to a fifth block of the distributed ledger system, by the first computing device associated with the managing entity, management operation record information including a history of operations performed by the managing entity.