Implied Authentication for Virtualization Administrative Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for accessing administrative functionality in virtualization environments are unsatisfactory and prone to security issues, particularly when administrators at different levels of the hierarchy need to perform tasks like backup and restore operations, often relying on user IDs and passwords which can lead to delays and security vulnerabilities.

Innovation Solution

The implementation of an architecture using implied authentication to provide access to administrative functionality in a virtualization system, which eliminates the need for user IDs and passwords by establishing secure connections and using mechanisms like new communications channels and storage structures for connectivity, ensuring only authorized users can access administrative interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user ID and password authentication is used for administrative access, then access control is provided, but security vulnerabilities and delays occur

Engineering Contradiction:
ImprovesecurityVSAvoidaccess delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the authentication mechanism from traditional user ID/password systems and replaces it with certificate-based authentication. The authentication credentials are taken out of the vulnerable password system and embedded directly into the virtual machine through the virtualization layer, eliminating the need for manual password entry and reducing security risks associated with password management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism at the virtualization layer that mediates between the virtual machine and administrative functions. This intermediary automatically handles certificate validation and authentication, eliminating the need for direct user interaction with password systems and reducing access delays while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple levels of administrators are implemented, then granular control is achieved, but access complexity increases

Engineering Contradiction:
Improveadministrative control flexibilityVSAvoidaccess hierarchy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal certificate-based authentication system that works across all levels of administrative hierarchy. The same authentication mechanism serves multiple functions: identifying virtual machines, validating administrative permissions, and enabling cross-level access. This universal approach simplifies the access hierarchy while maintaining granular control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables virtual machines to self-authenticate using embedded certificates without requiring manual intervention from administrators at higher levels. The authentication process is automated through the virtualization layer, which automatically validates certificates and grants appropriate access rights, reducing the complexity of managing multiple administrative levels.

Inventive Principle:
Principle #25Self-service

3Productivity

If administrators need to access administrative functionality from virtual machines, then operational efficiency improves, but security risks increase

Engineering Contradiction:
Improveadministrative operation efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication by embedding security certificates into virtual machines before they are deployed. This advance preparation ensures that when virtual machines need to access administrative functions, authentication has already been established through the embedded certificates, eliminating the need for real-time password verification and reducing security vulnerabilities while maintaining operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical password entry and verification system with an automated certificate-based authentication mechanism. The virtualization layer automatically handles certificate validation and authentication protocols, substituting the manual password system with a more secure automated process that maintains efficiency while reducing security risks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10362030B2Method and system for providing access to administrative functionality a virtualization environment
Publication Date: 2019.07.23 NUTANIX INC
  • US10362030B2 patent drawing
  • US10362030B2 patent drawing
  • US10362030B2 patent drawing

AI summary

Described is an architecture for providing access to administrative functionality in a virtualization system using implied authentication. This approach avoids the problems associated with the requirements to use a user ID and password to access an admin console. The user ID and password can be rendered completely unnecessary, or where the user ID and password combination is only used as a supplement to the implied authentication.