Identity Controlled Data Center Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for deploying software services over networks face challenges in secure, automated deployment due to the need for manual pre-configuration and vulnerability to security breaches, especially in environments where digital certificates and keys can be compromised, leading to increased administrative costs and legal liabilities.

Innovation Solution

The implementation of identity-controlled data centers, where random data is sent to a remote identity service, encrypted, and verified to establish a secure channel, allowing for the acquisition of unique metadata and identity for authentication and policy enforcement within the remote processing environment, ensuring secure and automated deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If services are deployed over the Internet with manual pre-configuration, then security can be maintained through conventional techniques, but automation benefits are negated and administrative costs increase

Engineering Contradiction:
Improveservice deployment automationVSAvoidpre-configuration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing secure channels and obtaining authentication credentials before service deployment. The identity service retrieves certificates and establishes trusted communication paths in advance, so that when services are deployed automatically, the security infrastructure is already in place without requiring manual pre-configuration of each service target environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An identity service acts as an intermediary between service providers and target environments. This intermediary handles authentication, credential management, and secure channel establishment, eliminating the need for manual pre-configuration while maintaining security. The identity service mediates the deployment process by verifying targets and providing authenticated access paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional security techniques like digital certificates and encryption are used, then security measures are implemented, but keys can be exposed on the network or discovered in the target environment

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidkey exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts sensitive cryptographic operations from the network transmission path. Private keys never leave the target environment; only encrypted proofs of identity and authenticated tokens are transmitted. The identity verification process separates key storage (remains local) from key usage (performed remotely through encrypted channels), eliminating the risk of key exposure during network transactions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system replaces traditional key-based authentication mechanisms with certificate-based identity verification. Instead of transmitting or storing private keys, the system uses public key infrastructure where identities are proven through cryptographic signatures and certificates. This substitution eliminates the mechanical vulnerability of key exposure while maintaining authentication reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If services are automatically deployed without pre-configuration, then deployment efficiency increases, but services may be deployed on rogue environments or compromised systems

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidenvironment authenticity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification actions before deployment. The identity service authenticates target environments, checks their credentials, and establishes secure channels in advance. This preliminary authentication ensures that services are deployed only to verified, legitimate environments, preventing deployment on rogue systems while maintaining automated efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the identity service continuously verifies environment authenticity during the deployment process. Target environments must prove their identity and compliance with security policies, and the system responds by granting or denying deployment access. This feedback loop ensures environment authenticity is maintained throughout automated deployment operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2755162B1Identity controlled data center
Publication Date: 2018.08.29 ORACLE INT CORP
  • EP2755162B1 patent drawingFigure 1
  • EP2755162B1 patent drawingFigure 2
  • EP2755162B1 patent drawingFigure 3

AI summary

Techniques for identity controlled data centers are provided. Remote processing environments are authenticated via identity associations (160). Virtual remote processing environments are subsequently installed and authenticated (320) on the remote processing environments on which they are deployed and they receive unique virtual remote processing environment identities, which are locally and independently assigned within their remote processing environments (170). Applications deployed (171) to the virtual remote processing environments are also authenticated and acquire identities (540) for the virtual remote processing environments in which they are deployed. The processing of the remote virtual processing environments and the applications are circumscribed by independently acquired policies (162,550) within the remote processing environments.