Dynamic Authentication Facility Selection in Virtualized Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing technologies lack a mechanism for providing context-sensitive authentication using shared authentication facilities, making it difficult to ensure compliance with varying authentication requirements across multiple services and authentication contexts.

Innovation Solution

A user authentication method that receives a user request, retrieves an authentication rule based on the user context, and instantiates appropriate authentication facilities from a set of shared facilities to generate challenges for authentication, ensuring compliance without individualizing authentication facilities within services or virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authentication facilities are shared across multiple services in a cloud computing environment, then resource utilization and efficiency are improved, but the ability to provide context-sensitive authentication and comply with varying authentication requirements deteriorates

Engineering Contradiction:
Improveauthentication facility utilizationVSAvoidcontext-sensitive authentication capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic instantiation of authentication facilities based on user context. Instead of static configuration, the system dynamically selects and configures authentication facilities from a shared pool according to the specific authentication rule applicable to each user request, enabling context-sensitive authentication while sharing facilities across services.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the configuration parameters of authentication facilities dynamically based on the authentication rule. By modifying parameters such as authentication method, challenge type, and verification criteria according to the applicable rule, the system provides context-sensitive authentication using shared facilities with varying configurations.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If authentication facilities are individualized within each service or virtual machine, then context-sensitive authentication and compliance with specific authentication requirements are improved, but device complexity and resource utilization deteriorate

Engineering Contradiction:
Improveauthentication compliance capabilityVSAvoidauthentication facility configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes authentication facilities universal by creating a shared pool of authentication facilities that can serve multiple services and virtual machines. Each facility is designed to be multi-functional, capable of handling different authentication scenarios by dynamically adjusting its configuration based on the applicable authentication rule, thus eliminating the need for individualized facilities in each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer (the authentication rule retrieval and instantiation mechanism) between the shared authentication facilities and the user requests. This intermediary selectively configures and presents appropriate authentication facilities from the shared pool based on the authentication rule, shielding the complexity of context-sensitive authentication from both the facilities and the services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a one size fits all authentication configuration is used in cloud computing environments, then device complexity is reduced, but the ability to meet varying authentication requirements and provide compliant authentication deteriorates

Engineering Contradiction:
Improveauthentication configurationVSAvoidauthentication compliance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system retrieves authentication rules that define specific parameters for different authentication scenarios. Based on the user context and applicable rule, the system dynamically changes parameters such as authentication method, challenge complexity, and verification criteria, ensuring compliance with varying authentication requirements while maintaining a unified shared facility configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10044698B2Dynamic identity checking for a software service in a virtual machine
Publication Date: 2018.08.07 BRITISH TELECOM PLC
  • US10044698B2 patent drawing
  • US10044698B2 patent drawing
  • US10044698B2 patent drawing

AI summary

A selector apparatus to select one or more shared authentication facilities for a software service executing in a virtualized shared computing environment, the software service including an interface through which a user request to access a restricted resource of the service is receivable, the request having associated a user context defining one or more characteristics of the user, and the software service further having associated a plurality of authentication rules for the service, wherein each rule is associated with one or more user contexts and identifies one or more shared authentication facilities for the computing environment, the selector apparatus comprising: a launcher, responsive to a user request received via the interface, adapted to instantiate one or more authentication facilities in accordance with an authentication rule retrieved based on a user context for the received request, so as to generate one or more challenges for the user to authenticate the user, wherein the authentication rule further defines one or more parameters for the identified authentication facilities.