Dynamic Digital Certificate Security Level Adjustment in SDDCs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software defined data centers (SDDCs), existing digital certificate provisioning methods do not dynamically adjust security levels based on real-time security monitoring information, leading to potential security vulnerabilities due to either over or under utilization of computational resources for encryption and decryption processes.

Innovation Solution

A method and system that dynamically adjusts the security level of digital certificates for groups of computing resources in SDDCs based on security monitoring information, using a security level management unit to determine and implement a second security level for digital certificates, optimizing encryption and decryption processes by communicating the appropriate security level to agents associated with these resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate security levels are increased to enhance security, then security level is improved, but computational resource consumption for encryption and decryption increases

Engineering Contradiction:
Improvesecurity levelVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic adjustment of digital certificate security levels based on real-time security monitoring information. The security level management unit continuously monitors threat levels and adjusts the security level of digital certificates accordingly, transitioning from static to dynamic security management. This allows the system to use higher security levels only when threats are detected, rather than maintaining maximum security levels continuously.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security level parameter of digital certificates based on monitored threat conditions. When security monitoring information indicates high threat levels, the system increases the security level parameter; when threats are low or absent, the system decreases the security level parameter. This dynamic parameter adjustment optimizes the balance between security and computational resource consumption.

Inventive Principle:
Principle #35Parameter changes

2Use of energy by moving object

If digital certificate security levels are decreased to reduce computational resource consumption, then computational resource consumption is reduced, but security level deteriorates

Engineering Contradiction:
Improvecomputational resource consumptionVSAvoidsecurity level
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system dynamically adjusts security levels based on real-time monitoring, allowing lower security levels to be used during periods of low threat activity. This dynamic approach ensures that computational resources are conserved during normal operation while maintaining adequate security protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security level parameter is adjusted based on threat assessment results. When monitoring indicates low threat levels, the system safely reduces the security level parameter to optimize computational resource usage, while maintaining the capability to rapidly increase security levels when threats are detected.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If static security levels are used for digital certificates, then system complexity is reduced, but adaptability to changing security threats deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to security threats
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic security level adjustment mechanisms that automatically adapt to changing threat conditions. The security level management unit monitors security information and adjusts digital certificate security levels in real-time, enabling the system to adapt to evolving security threats without requiring complex manual configuration or intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where security monitoring information is continuously collected, analyzed, and used to adjust security levels. This feedback mechanism enables automatic adaptation to changing security conditions, with the monitoring system providing input that drives security level adjustments in response to detected threats or security events.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11032295B2Security monitoring information-based provisioning of digital certificates in software defined data centers
Publication Date: 2021.06.08 VMWARE INC
  • US11032295B2 patent drawing
  • US11032295B2 patent drawing
  • US11032295B2 patent drawing

AI summary

Techniques for provisioning of digital certificates in software defined data centers (SDDCs) based on security monitoring information are disclosed. In one example, a set of digital certificates may be assigned to a group of computing resources of an SDDC. Each digital certificate may include a different security level. The group of computing resources may include applications that use a first digital certificate with a first security level for data communication. Further, security monitoring information associated with the group of computing resources may be received. Furthermore, a second security level to be used for the group of computing resources may be determined based on the security monitoring information. The group of computing resources may be managed by communicating the second security level to an agent associated with the group of computing resources. The agent may then implement a second digital certificate with the second security level for the applications.