Host Machine Token Generation for Virtual Machine Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing, virtual machines lack secure access to services without direct access to long-term credentials, posing security risks and management challenges.

Innovation Solution

Implementing a method where host machines receive long-term security tokens to generate short-term tokens for virtual machines, limiting access and enabling time-bound service access, with the virtual machine authorization process restricting direct access to long-term tokens and using these short-term tokens for service access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual machines are given direct access to long-term credentials, then service access is simplified, but security is compromised

Engineering Contradiction:
Improveservice accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments credentials into two types: long-term credentials stored securely on the host machine and short-term access tokens generated on-demand for virtual machines. This segmentation allows VMs to access services without obtaining permanent credentials, resolving the contradiction between ease of access and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host machine acts as an intermediary between service providers and virtual machines. It generates short-term access tokens based on long-term credentials and grants temporary access to services. This intermediary mechanism enables VM service access while preventing direct exposure of long-term credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If long-term credentials are stored on host machines, then security is improved, but credential management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system enables self-service credential management where the host machine automatically generates short-term access tokens for virtual machines without requiring manual credential distribution. The host machine autonomously manages the token generation lifecycle, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic credential management where short-term access tokens have predetermined expiration times and can be revoked at runtime. This dynamic approach allows flexible credential management without requiring permanent credential storage, balancing security with operational simplicity.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If access tokens are made time-limited, then security is enhanced, but access availability is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccess duration
Core Design Contradiction:
Object-affected harmful factorsVSDuration of action of moving object

Solution Approach 1:

The patent changes the temporal parameter of credentials by introducing time-limited short-term access tokens with predetermined expiration times. This parameter change enhances security while maintaining adequate access availability for the token's valid lifespan, resolving the contradiction between security and access duration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8800009B1Virtual machine service access
Publication Date: 2014.08.05 GOOGLE LLC
  • US8800009B1 patent drawing
  • US8800009B1 patent drawing
  • US8800009B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for accessing services from a virtual machine. One of the methods includes receiving requests for long-term security tokens from a host machine, each request comprising authentication information for a respective service account. The method include providing long-term security tokens to the host machine, wherein the long-term security tokens can be used to generate short-term security tokens for a virtual machine executing on the host machine. The method also includes generating by a process executing in a host operating system of the host machines a short-term security token based on a long-term security token of the long-term security tokens for use by a virtual machine executing on the host machine to access one of the respective service accounts, wherein the short-term security token is useable for a pre-determined amount of time.