Proxy Certificate Mutual Authorization Grid Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Grid computing poses security risks due to the potential for secondary resource machines to lack necessary security levels, be vulnerable to attacks, or be malicious, as users have no control over which machine processes their jobs and may not trust secondary resources.

Innovation Solution

The method involves generating proxy certificates for mutual authorization between primary and secondary resource machines, where the user machine performs authorization checks on the secondary resource, generating a valid proxy certificate if authorized, and an invalid one if not, ensuring secure offloading of jobs while maintaining single sign-on capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a primary resource machine offloads a grid computing job to a secondary resource machine, then processing capacity is increased and job completion time is reduced, but security risk increases because the user cannot trust the secondary resource machine

Engineering Contradiction:
Improvejob processing capacityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy certificate as an intermediary mechanism between the user machine and secondary resource machine. The proxy certificate acts as a trusted mediator that carries authorization information, allowing the user machine to indirectly verify the credibility of secondary resource machines without direct user intervention. This resolves the contradiction by enabling secure offloading to untrusted machines through the intermediary proxy certificate system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization checks by the user machine on secondary resource machines before job offloading. The user machine evaluates security criteria of potential secondary resources and pre-issues proxy certificates only to authorized machines. This preliminary action ensures that while productivity is increased through offloading, security risks are mitigated by pre-verifying the credibility of secondary resources.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the user machine performs authorization checks on secondary resource machines, then security is improved, but system complexity and authorization time increase

Engineering Contradiction:
Improvegrid securityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user machine autonomously performs authorization checks on secondary resource machines without requiring external verification or manual user approval for each offloading decision. The system implements self-service authorization where the user machine independently evaluates security criteria and issues proxy certificates automatically. This reduces system complexity while maintaining high security through automated decision-making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the authorization process by changing parameters from manual user approval to automated machine-based verification. The user machine evaluates specific security parameters of secondary resources (such as security patches, operating system trustworthiness) and makes authorization decisions based on these parameter assessments. This parameter-based automated approach simplifies the system while improving reliability.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If proxy certificates have short validity periods, then security damage is limited, but certificate renewal overhead increases

Engineering Contradiction:
Improvepotential damage from compromised certificatesVSAvoidcertificate management time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements proxy certificates with short validity periods, treating them as disposable security credentials. Each proxy certificate is designed to be short-lived and single-use, limiting the window of opportunity for attackers to exploit compromised certificates. The short validity period acts as a built-in security mechanism where the low cost and brief lifespan of each certificate minimize potential damage from security breaches.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system implements automatic proxy certificate renewal mechanisms with feedback loops. When proxy certificates approach expiration, the user machine automatically detects this and initiates renewal processes without user intervention. This feedback-based automation reduces the manual time overhead for certificate management while maintaining the security benefits of short validity periods through continuous automatic renewal.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7467303B2Grid mutual authorization through proxy certificate generation
Publication Date: 2008.12.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7467303B2 patent drawing
  • US7467303B2 patent drawing
  • US7467303B2 patent drawing

AI summary

A method for mutual authorization of a secondary resource in a grid of resource computers is provided. When a primary resource attempts to offload a grid computing job to a secondary resource, the primary resource sends a proxy certificate request to the user machine. Responsive to a proxy certificate request, the user machine performs authorization with the secondary resource. If authorization with the secondary resource is successful, the user machine generates and returns a valid proxy certificate. The primary resource then performs mutual authentication with the secondary resource. If the authorization with the secondary resource fails, the user machine generates and returns an invalid proxy certificate. Mutual authentication between the primary resource and the secondary resource will fail due to the invalid proxy certificate. The primary resource then selects another secondary resource and repeats the process until a resource is found that passes the mutual authorization with the user machine.