Epoch-Based Security Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing environments, temporary security credentials with fixed expiration times can lead to system failures if the credential service becomes inoperable, causing credentials to expire prematurely and disrupting dependent systems' functionality.

Innovation Solution

Implementing an epoch-based management system for temporary security credentials, where credentials include epoch identifiers and versions, allowing the credential service to extend their validity if operational issues occur, and the epoch service modifies current epoch versions to invalidate old credentials once new ones are issued.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If temporary security credentials are issued with a fixed expiration time far in the future, then dependent systems can continue operating during service disruptions, but the credentials remain valid longer than necessary under normal conditions

Engineering Contradiction:
Improvesystem continuity during service disruptionVSAvoidcredential validity period
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent applies dynamics by making the credential expiration time adaptive rather than fixed. The system dynamically adjusts the effective expiration time based on the operational status of the credential service. When the service is operational, credentials expire at the originally intended time. When the service is disrupted, the expiration time is extended automatically, allowing credentials to remain valid longer than planned without requiring manual intervention or fixed long-duration issuance.

Inventive Principle:
Principle #15Dynamics

2Reliability

If temporary security credentials are refreshed frequently, then security is maintained under normal conditions, but system complexity increases and failure points multiply

Engineering Contradiction:
Improvesecurity credential freshnessVSAvoidcredential management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies self-service by automatically detecting service disruptions and adjusting credential expiration times without requiring external intervention. The credential service monitors its own operational status and autonomously extends expiration times when disruptions occur, eliminating the need for complex manual management or additional external monitoring systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback by having the credential service monitor its own operational status and use this information to adjust credential expiration behavior. The system continuously checks whether it can successfully issue new credentials and adjusts the validity period of existing credentials based on this feedback, creating a closed-loop control system that adapts to changing conditions.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If the credential service becomes inoperable, then security credentials expire prematurely, but extending expiration times indefinitely compromises security

Engineering Contradiction:
Improvesystem operation during service disruptionVSAvoidsecurity credential validity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts credential expiration based on real-time service status. When disruptions occur, expiration is extended to maintain operational continuity. When the service recovers or new credentials can be issued, the system transitions back to normal expiration behavior, ensuring security is maintained without indefinite extension.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the expiration time parameter of credentials based on service operational status. Instead of using a fixed expiration time, the system modifies this parameter dynamically - extending it during disruptions and maintaining normal values during operational periods, thereby adapting security parameters to current system conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9847983B1Epoch-based management of security credentials
Publication Date: 2017.12.19 AMAZON TECH INC
  • US9847983B1 patent drawing
  • US9847983B1 patent drawing
  • US9847983B1 patent drawing

AI summary

Technologies are disclosed herein for epoch-based expiration of temporary security credentials. A temporary security credential is issued that identifies one or more epochs and that specifies one or more versions of the identified epochs during which the temporary security credential is valid. The temporary security credential may then be utilized to request access to another system, service or component. In order to determine whether such a request may be granted, current epoch versions for the epochs identified in the temporary security credential are obtained. The current epoch versions for the identified epochs are then compared to epoch versions specified in the temporary security credential to determine if the request can be granted. The current epoch versions may be periodically modified in order to expire previously issued temporary security credentials. A temporary security credential might also specify an expiration time after which the temporary security credential is no longer valid.