Secure Control Transfer for Distributed Computational Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing systems face security vulnerabilities due to the complexity of modern systems and exposure to network access, allowing malicious parties to gain temporary control over computational entities, leading to unauthorized access and data breaches.

Innovation Solution

Establishing a secure, verifiable chain of control for computational entities within a distributed computing system through the generation of public and private identities, secure three-party transactions, and recording control transfers in a distributed public ledger, ensuring that each entity is controlled by a single authorized entity at all times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated management subsystems are used to control computational entities in distributed systems, then system complexity is reduced and ease of operation is improved, but security vulnerabilities increase and reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a control transfer protocol that acts as an intermediary mechanism between computational entities. This protocol enables secure handover of control through three-party transactions (current controller, target controller, and witness node), preventing direct unauthorized access while maintaining automated management. The intermediary protocol resolves the contradiction by providing structured security measures without complicating the automated operation interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms through the distributed public ledger that records all control transfers. The system continuously monitors and verifies control chain integrity, providing feedback when control attempts are made. This feedback loop ensures reliability by detecting and preventing unauthorized control changes while maintaining ease of automated management through automated verification processes.

Inventive Principle:
Principle #23Feedback

2Reliability

If security measures are strengthened to prevent malicious control acquisition, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security function into distinct modular components: control transfer protocol, three-party transaction verification, distributed public ledger, and witness nodes. This segmentation allows each component to handle specific security tasks independently, improving reliability through specialized security functions while reducing overall system complexity by organizing security measures into manageable modules rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control transfer protocol serves as an intermediary layer that handles security complexities centrally. By implementing security verification logic in this intermediary protocol rather than distributing complex security checks across all system components, the patent improves reliability through dedicated security handling while reducing device complexity by centralizing security management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If control transfers are recorded in a distributed public ledger, then transparency and measurement precision are improved, but loss of time increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The distributed public ledger implements self-service verification where the ledger itself automatically verifies and records control transfers without requiring manual intervention. The system performs its own measurement and recording functions, improving measurement precision through automated verification while minimizing time loss by eliminating human processing delays in the control transfer recording process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10754693B2Secure transfer of control over computational entities in a distributed computing environment
Publication Date: 2020.08.25 VMWARE INC
  • US10754693B2 patent drawing
  • US10754693B2 patent drawing
  • US10754693B2 patent drawing

AI summary

The current document is directed to methods and systems that establish secure, verifiable chains of control for computational entities within a distributed computing system. When a computational entity is first instantiated or introduced into the distributed computing system, public and private identities are generated for the computational entity and secure control is established over the computational entity by an initial controlling entity. Subsequently, control of the computational entity may be transferred from the initial controlling entity to a different controlling entity using a secure, three-party transaction that records the transfer of control in a distributed public ledger. As control of the computational entity is subsequently transferred to different controlling entities by secure three-party transactions, a chain of control from one controlling entity to another is established and recorded in the distributed public ledger. The computational entity is controlled by a single controlling entity at each point in time from the first instantiation or introduction into the distributed computing system to termination or removal from the distributed computing system.