Partitionable Virtual I/O Server with Kerberos Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing, virtualized environments face challenges in securely sharing physical resources among multiple tenants due to the high cost of single-tenant virtual I/O servers, which cannot be shared effectively, leading to resource inefficiency and lack of privacy for users accessing shared resources.

Innovation Solution

Implementing a partitionable virtual input/output server (VIOS) with Kerberos security, where physical resources are allocated to working load partitions (WPARs) and access is authenticated through a remote Kerberos server hosted in a private domain, providing secure access to tenants by issuing valid tickets for controlled access periods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-tenant virtual I/O server is used to ensure security and privacy, then user privacy and security are improved, but resource efficiency and cost-effectiveness deteriorate due to inability to share resources

Engineering Contradiction:
Improveuser privacy and securityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the virtual I/O server into multiple isolated WPARs (Working Load Partitions), each representing a separate tenant with dedicated resource access. This segmentation allows physical resources to be shared across multiple tenants while maintaining logical isolation, thus achieving both resource efficiency and user privacy/security simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces Kerberos authentication as an intermediary mechanism between tenants and physical resources. The Kerberos server verifies tenant credentials and manages access tickets, enabling secure authenticated access to shared resources without requiring dedicated single-tenant servers

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If physical resources are shared among multiple tenants to improve resource efficiency, then cost and resource utilization are improved, but security and privacy control deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity and privacy control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

By dividing the shared virtual I/O server into distinct WPARs for different tenants, the system enables resource sharing while maintaining logical separation. Each WPAR provides isolated access to its designated tenant, ensuring that shared physical resources remain secure and privately controlled for each tenant

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Kerberos authentication system acts as an intermediary that enforces security policies on shared resources. It verifies tenant identities and issues time-limited access tickets, allowing secure multi-tenant access to shared physical resources without compromising security or privacy control

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If Kerberos authentication with remote server is implemented to provide secure access, then security and access control are improved, but system complexity and authentication overhead increase

Engineering Contradiction:
Improvesecure access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs Kerberos authentication as an intermediary security layer between tenants and the virtual I/O server. The remote Kerberos server handles credential verification and ticket issuance, providing robust secure access control while centralizing authentication logic to minimize local system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10171445B2Secure virtualized servers
Publication Date: 2019.01.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10171445B2 patent drawing
  • US10171445B2 patent drawing
  • US10171445B2 patent drawing

AI summary

A system may be configured to provide secure access to a physical resource through the use of a partitionable virtual input/output server in a virtualized environment. A server may receive a request to access the physical resources from a cloud tenant administrator. The cloud tenant may be assigned to a particular working load partition (WPAR), and the physical resources may be assigned to the particular WPAR. A remote Kerberos server may be accessed in response to the request. The Kerberos server may be hosted in a private domain, and it may be used to authenticate access to the physical resource. The server may receive a valid ticket from the Kerberos server. The administrator may be granted access to the physical resources via access to the WPAR, based on the valid ticket and for the lifetime of the ticket.