Secure Peering Parameter Sharing via Shared Secret Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems face security concerns due to direct information exchange between cloud service providers and network service providers, leading to potential oversharing of user data, and lack standard integration, resulting in high development costs for custom interfaces.

Innovation Solution

A method for securely sharing peering connection parameters between cloud service providers and network service providers using a shared secret mechanism, where a user-generated service key and temporary access key are used to authenticate and authorize the exchange of connection parameters, reducing the need for formal onboarding and account management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct information exchange between cloud service provider and network service provider is implemented, then peering connection setup is enabled, but security concerns arise due to potential oversharing of user data

Engineering Contradiction:
Improvepeering connection setupVSAvoidsecurity concerns
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using shared secrets (service keys and temporary access keys) that mediate between the cloud service provider and network service provider. This intermediary layer enables direct information exchange for peering connection setup while preventing unauthorized access and oversharing of user data, as the shared secrets act as a trusted mediator that validates identities without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If custom interfaces are developed for each network service provider, then specific integration requirements are met, but development costs increase

Engineering Contradiction:
Improveintegration capabilityVSAvoiddevelopment cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal authentication interface using standardized shared secret mechanisms (service keys and temporary access keys) that can be applied across multiple network service providers. This universal approach eliminates the need to develop custom interfaces for each provider, as the same authentication protocol and key management system serve multiple integration scenarios, thereby reducing development costs while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11012431B2Secure sharing of peering connection parameters between cloud providers and network providers
Publication Date: 2021.05.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11012431B2 patent drawing
  • US11012431B2 patent drawing
  • US11012431B2 patent drawing

AI summary

A method, computer system, and a computer program product for sharing a peering connection parameter is provided. The present invention may include receiving a peering connection order from a user. The present invention may also include assigning at least one shared secret to the received peering connection order. The present invention may then include receiving a request from a network service provider of the user for at least one connection parameter associated with the received peering connection order, wherein the received request includes the at least one shared secret for the received peering connection order. The present invention may further include, in response to determining that the at least one shared secret included in the received request is valid, returning the at least one connection parameter associated with the received peering connection order to the network service provider of the user.