Hybrid Cloud Credential Management via Virtual Relays

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security architectures for hybrid cloud environments are sub-optimal due to the inability to securely integrate public and private cloud systems, leading to limited flexibility and increased administrative complexity, as they often require separate authentication and communication standards and restrict sensitive data storage in cloud-based systems.

Innovation Solution

A method and system for securely integrating hybrid clouds with enterprise networks using a combination of Stealth technology and virtual machines, which enables secure communication and authentication across public and private domains through community-of-interest groups and dedicated virtual data relays, avoiding the need for shared security keys and allowing independent management of cloud and private domain systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication and communication standards are used for public and private cloud systems, then security is maintained for each domain, but administrative complexity increases and flexibility decreases

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credentialing service that operates across both public and private cloud domains, providing a single authentication standard that works throughout the hybrid cloud environment. This eliminates the need for separate authentication systems while maintaining security through a unified credential verification process that can authenticate workloads regardless of their deployment location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges previously separate authentication and communication standards into a unified security framework. By combining public and private cloud authentication mechanisms into a single system that uses shared credentials and a centralized credentialing service, the patent reduces administrative complexity while preserving the security requirements of both domains.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If encryption keys are provided to cloud-based systems, then authentication can be established, but security is compromised due to potential key exposure

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a credentialing service as an intermediary between workload authentication requests and the actual encryption keys. Instead of providing keys directly to cloud-based systems, the credentialing service acts as a secure mediator that verifies credentials and establishes authentication without exposing the underlying encryption keys, thus maintaining both authentication capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the credential verification function from the key management system. By separating the authentication process from the encryption key storage, the system can provide authentication capabilities to cloud-based systems without exposing the actual encryption keys. The credentialing service handles authentication independently, keeping keys secure while enabling operational authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If sensitive data is stored in cloud-based systems, then flexibility and accessibility are improved, but security risk increases due to potential compromise

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements temporary, workload-specific credentials that are created on-demand and automatically invalidated after use. Instead of storing sensitive data with permanent access credentials in cloud-based systems, the system generates short-lived credentials that provide temporary access only when needed. This enables flexible data accessibility while minimizing security risk through the ephemeral nature of the credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent applies different security characteristics to different data and workload scenarios. Rather than using a uniform security approach, the system provides localized security measures tailored to each workload's specific requirements and sensitivity level. This allows sensitive data to be stored in cloud-based systems with appropriate, granular security controls applied only where needed, maintaining flexibility while managing security risks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9571455B2Remote credential management for hybrid clouds with enterprise networks
Publication Date: 2017.02.14 UNISYS CORP
  • US9571455B2 patent drawing
  • US9571455B2 patent drawing
  • US9571455B2 patent drawing

AI summary

A system and method of initializing a virtual machine within a secure hybrid cloud is disclosed. One method includes transmitting service mode credentials to a cloud broker from a cloud-based virtual machine, receiving a service mode community of interest key from a credentialing service based on the service mode credentials, and establishing a secure service mode connection based on the service mode community of interest key. The method also includes receiving role VPN credentials at the cloud-based virtual machine and establishing a secure role connection to the cloud broker using the role VPN credentials, thereby providing, in response to the role VPN credentials, a role VPN community of interest key to a virtual data relay dedicated to the cloud-based virtual machine. The method further includes receiving role cloud credentials at the cloud-based virtual machine and establishing secure communications at the cloud-based virtual machine based on the role cloud credentials, including receiving a role cloud community of interest key at the cloud-based virtual machine used for secure communication among the cloud-based virtual machine and other cloud-based virtual machines within a common community of interest with the cloud-based virtual machine.