Dynamic Authorization for Secured Cloud Instance Bootstrap

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service providers limit the configuration options for instances within a cluster, restricting customers' ability to run certain workloads due to predefined instance images and shapes, which do not accommodate diverse workload requirements.

Innovation Solution

Allowing customers to create custom instance shapes and images, and permitting dynamic or static group membership based on rules, enabling instances to join clusters hosted within the cloud service provider's infrastructure or on customer premises, with authentication using cluster credentials for secure workload distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud service providers use predefined instance images and shapes, then cluster management is simplified and security is improved, but customer flexibility and adaptability to diverse workload requirements deteriorate

Engineering Contradiction:
Improvecustomer flexibilityVSAvoidcluster configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments cluster configuration into modular components: instance shapes define hardware specifications (CPU, memory, storage), instance images define software configurations (operating system, runtime environment), and cluster templates combine these with workload requirements. This segmentation allows customers to mix and match components to create customized configurations without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements pre-configured instance shapes and images that are prepared in advance by the cloud service provider. These pre-configured templates contain standard hardware specifications and software environments, allowing customers to quickly deploy workloads without building configurations from scratch, thus maintaining simplicity while enabling customization.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If cloud service providers allow custom instance configurations, then customer adaptability to diverse workloads is improved, but system complexity and authentication management deteriorate

Engineering Contradiction:
Improveworkload configuration flexibilityVSAvoidauthentication and authorization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization where instance permissions and cluster access rights are not fixed but can be modified based on workload requirements and security policies. Authorization rules can be updated without reconfiguring the entire system, allowing flexible instance customization while maintaining manageable security through dynamic policy adjustments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces cluster templates as an intermediary layer between custom instance configurations and authentication management. Templates encapsulate both the technical configuration (instance shapes, images) and security policies (authorization rules, credentials), separating configuration complexity from authentication complexity and allowing independent management of each aspect.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If predefined cluster configurations are used, then deployment speed is improved, but ability to meet specific workload demands deteriorates

Engineering Contradiction:
Improveinstance deployment speedVSAvoidworkload-specific configuration capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent prepares instance shapes, images, and cluster templates in advance with common workload requirements pre-configured. This preliminary action allows customers to rapidly deploy instances by selecting from pre-prepared configurations, maintaining high deployment speed while the modular nature of templates enables adaptation to specific workload demands through configuration selection and modification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables parameter customization within instance shapes (CPU cores, memory size, storage capacity) and images (software versions, configuration parameters). By allowing parameter changes within predefined templates, the system maintains the deployment speed of using templates while adapting to specific workload requirements through parameter adjustment.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240187232A1Secured bootstrap with dynamic authorization
Publication Date: 2024.06.06 ORACLE INT CORP
  • US20240187232A1 patent drawing
  • US20240187232A1 patent drawing
  • US20240187232A1 patent drawing

AI summary

In some implementations, the techniques may include receiving a request to launch a first instance in a customer partition. The request can identify one or more of a cluster and an instance image. In addition, the techniques may include launching the first instance on a server in the customer partition using the instance image identified by the request. The techniques may include receiving a request to authenticate the first instance. Moreover, the techniques may include in response to a determination that the first instance is authentic: adding the first instance to the cluster identified in the request.