Secure Cloud Host Provisioning via Static Path Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Provisioning virtual machines in a cloud environment poses security challenges due to ephemeral virtual machine states and abstracted hardware, making it difficult to authenticate and secure the provisioning process.

Innovation Solution

A method and system that determine a physical path between a provisioning system and a host in the cloud using static mapping via SNMP, ensuring secure communication by pre-configuring a fixed path and using DHCP for confirmation of successful provisioning, thereby preventing man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are provisioned remotely in a cloud environment, then provisioning flexibility and scalability are improved, but security risks increase due to ephemeral states and abstracted hardware

Engineering Contradiction:
Improveprovisioning flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a static mapping between the provisioning system and host before the virtual machine provisioning process begins. This pre-configured path is recorded in network device tables (such as ARP tables) beforehand, ensuring that subsequent communication occurs only through this predetermined secure channel, preventing unauthorized interception or spoofing during the ephemeral provisioning process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses network devices (switches, routers) as intermediaries to enforce the static mapping path. These network devices act as mediators that control and verify the communication path between the provisioning system and host, ensuring that provisioning traffic passes through authorized channels and preventing man-in-the-middle attacks by blocking unauthorized direct connections

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If hardware is abstracted away in cloud environment, then resource virtualization and flexibility are improved, but authentication difficulty increases

Engineering Contradiction:
Improveresource virtualizationVSAvoidauthentication difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a copy of the physical path information in the form of static mapping records stored in network device tables. Instead of relying on the physical hardware itself for authentication, the system uses these recorded path copies (static ARP entries, MAC address mappings) to verify and control communication flows, enabling authentication in the abstracted virtualized environment

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The static mapping information is prepared and recorded in advance before the virtual machine provisioning occurs. This preliminary configuration of path information allows the system to establish authentication mechanisms based on pre-known physical topology, overcoming the authentication challenges posed by hardware abstraction and ephemeral virtual machine states

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9503392B2Enhance private cloud system provisioning security
Publication Date: 2016.11.22 RED HAT INC
  • US9503392B2 patent drawing
  • US9503392B2 patent drawing
  • US9503392B2 patent drawing

AI summary

A method and system for securely provisioning a host, the method including determining, by a provisioning system, a physical path from the host in a cloud to the provisioning system, wherein the physical path includes static mapping for a device between the host and the provisioning system. The provisioning system receives a request to provision a virtual machine on a guest host in a cloud, and sends installation information for the virtual machine via the determined physical path.