Hybrid Cloud Credential Management via Virtual Relays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security architectures for hybrid cloud environments are sub-optimal due to the inability to securely integrate public and private cloud systems, leading to limited flexibility and increased administrative complexity, as they often require separate authentication and communication standards and restrict sensitive data storage in cloud-based systems.
Innovation Solution
A method and system for securely integrating hybrid clouds with enterprise networks using a combination of Stealth technology and virtual machines, which enables secure communication and authentication across public and private domains through community-of-interest groups and dedicated virtual data relays, avoiding the need for shared security keys and allowing independent management of cloud and private domain systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and communication standards are used for public and private cloud systems, then security is maintained for each domain, but administrative complexity increases and flexibility decreases
Solution Approach 1:
The patent implements a universal credentialing service that operates across both public and private cloud domains, providing a single authentication standard that works throughout the hybrid cloud environment. This eliminates the need for separate authentication systems while maintaining security through a unified credential verification process that can authenticate workloads regardless of their deployment location.
Solution Approach 2:
The patent merges previously separate authentication and communication standards into a unified security framework. By combining public and private cloud authentication mechanisms into a single system that uses shared credentials and a centralized credentialing service, the patent reduces administrative complexity while preserving the security requirements of both domains.
2Ease of operation
If encryption keys are provided to cloud-based systems, then authentication can be established, but security is compromised due to potential key exposure
Solution Approach 1:
The patent introduces a credentialing service as an intermediary between workload authentication requests and the actual encryption keys. Instead of providing keys directly to cloud-based systems, the credentialing service acts as a secure mediator that verifies credentials and establishes authentication without exposing the underlying encryption keys, thus maintaining both authentication capability and security.
Solution Approach 2:
The patent extracts the credential verification function from the key management system. By separating the authentication process from the encryption key storage, the system can provide authentication capabilities to cloud-based systems without exposing the actual encryption keys. The credentialing service handles authentication independently, keeping keys secure while enabling operational authentication.
3Adaptability or versatility
If sensitive data is stored in cloud-based systems, then flexibility and accessibility are improved, but security risk increases due to potential compromise
Solution Approach 1:
The patent implements temporary, workload-specific credentials that are created on-demand and automatically invalidated after use. Instead of storing sensitive data with permanent access credentials in cloud-based systems, the system generates short-lived credentials that provide temporary access only when needed. This enables flexible data accessibility while minimizing security risk through the ephemeral nature of the credentials.
Solution Approach 2:
The patent applies different security characteristics to different data and workload scenarios. Rather than using a uniform security approach, the system provides localized security measures tailored to each workload's specific requirements and sensitivity level. This allows sensitive data to be stored in cloud-based systems with appropriate, granular security controls applied only where needed, maintaining flexibility while managing security risks.
Data Source
AI summary
A system and method of initializing a virtual machine within a secure hybrid cloud is disclosed. One method includes transmitting service mode credentials to a cloud broker from a cloud-based virtual machine, receiving a service mode community of interest key from a credentialing service based on the service mode credentials, and establishing a secure service mode connection based on the service mode community of interest key. The method also includes receiving role VPN credentials at the cloud-based virtual machine and establishing a secure role connection to the cloud broker using the role VPN credentials, thereby providing, in response to the role VPN credentials, a role VPN community of interest key to a virtual data relay dedicated to the cloud-based virtual machine. The method further includes receiving role cloud credentials at the cloud-based virtual machine and establishing secure communications at the cloud-based virtual machine based on the role cloud credentials, including receiving a role cloud community of interest key at the cloud-based virtual machine used for secure communication among the cloud-based virtual machine and other cloud-based virtual machines within a common community of interest with the cloud-based virtual machine.


