Partitionable Virtual I/O Server with Kerberos Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing, virtualized environments face challenges in securely sharing physical resources among multiple tenants due to the high cost of single-tenant virtual I/O servers, which cannot be shared effectively, leading to resource inefficiency and lack of privacy for users accessing shared resources.
Innovation Solution
Implementing a partitionable virtual input/output server (VIOS) with Kerberos security, where physical resources are allocated to working load partitions (WPARs) and access is authenticated through a remote Kerberos server hosted in a private domain, providing secure access to tenants by issuing valid tickets for controlled access periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single-tenant virtual I/O server is used to ensure security and privacy, then user privacy and security are improved, but resource efficiency and cost-effectiveness deteriorate due to inability to share resources
Solution Approach 1:
The patent segments the virtual I/O server into multiple isolated WPARs (Working Load Partitions), each representing a separate tenant with dedicated resource access. This segmentation allows physical resources to be shared across multiple tenants while maintaining logical isolation, thus achieving both resource efficiency and user privacy/security simultaneously
Solution Approach 2:
The patent introduces Kerberos authentication as an intermediary mechanism between tenants and physical resources. The Kerberos server verifies tenant credentials and manages access tickets, enabling secure authenticated access to shared resources without requiring dedicated single-tenant servers
2Productivity
If physical resources are shared among multiple tenants to improve resource efficiency, then cost and resource utilization are improved, but security and privacy control deteriorate
Solution Approach 1:
By dividing the shared virtual I/O server into distinct WPARs for different tenants, the system enables resource sharing while maintaining logical separation. Each WPAR provides isolated access to its designated tenant, ensuring that shared physical resources remain secure and privately controlled for each tenant
Solution Approach 2:
The Kerberos authentication system acts as an intermediary that enforces security policies on shared resources. It verifies tenant identities and issues time-limited access tickets, allowing secure multi-tenant access to shared physical resources without compromising security or privacy control
3Reliability
If Kerberos authentication with remote server is implemented to provide secure access, then security and access control are improved, but system complexity and authentication overhead increase
Solution Approach 1:
The patent employs Kerberos authentication as an intermediary security layer between tenants and the virtual I/O server. The remote Kerberos server handles credential verification and ticket issuance, providing robust secure access control while centralizing authentication logic to minimize local system complexity
Data Source
AI summary
A system may be configured to provide secure access to a physical resource through the use of a partitionable virtual input/output server in a virtualized environment. A server may receive a request to access the physical resources from a cloud tenant administrator. The cloud tenant may be assigned to a particular working load partition (WPAR), and the physical resources may be assigned to the particular WPAR. A remote Kerberos server may be accessed in response to the request. The Kerberos server may be hosted in a private domain, and it may be used to authenticate access to the physical resource. The server may receive a valid ticket from the Kerberos server. The administrator may be granted access to the physical resources via access to the WPAR, based on the valid ticket and for the lifetime of the ticket.


