Security Device Local Authentication Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, user authentication often relies on a central authentication server, which can lead to connectivity issues and disrupt access to computing resources when the network connection is disconnected.

Innovation Solution

Implementing a security device that generates and manages a set of keys for accessing server devices within the cloud computing environment, allowing for local authentication and logging of user actions without requiring a central authentication server, thereby ensuring continuous access and reliable authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central authentication server is used for user authentication in cloud computing environments, then authentication can be centralized and managed, but network connectivity issues can disrupt access to computing resources

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the central authentication server and embeds it directly into the security device. This allows the security device to perform local authentication using stored credentials, eliminating the requirement for network connectivity to a central server while maintaining authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a local credential storage mechanism as an intermediary between the user and the authentication system. Credentials are stored locally in the security device, serving as a mediator that enables authentication without requiring direct communication with a central authentication server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a central authentication server is required for authentication, then centralized credential management is achieved, but access is disrupted when network connection is lost

Engineering Contradiction:
Improveaccess continuityVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by storing user credentials locally in the security device before authentication is needed. This pre-storation of credentials enables the security device to perform authentication independently without requiring real-time network connectivity to a central server.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security device performs self-service authentication by using its own locally stored credentials to authenticate users. This eliminates the need for external authentication services and ensures continuous operation even when network connectivity is unavailable.

Inventive Principle:
Principle #25Self-service

3Reliability

If local authentication is implemented without a central server, then access continuity is maintained during network disconnections, but credential management becomes more complex

Engineering Contradiction:
Improveaccess reliabilityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the credential storage and authentication verification functions into a single security device. This consolidation simplifies the system architecture by eliminating the need for separate central authentication servers while maintaining reliable local authentication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9160544B2Providing secure access to computing resources in a cloud computing environment
Publication Date: 2015.10.13 VERIZON PATENT & LICENSING INC
  • US9160544B2 patent drawing
  • US9160544B2 patent drawing
  • US9160544B2 patent drawing

AI summary

A security device may receive a request, associated with a user, to access a particular device. The security device may authenticate the user based on the request. The security device may determine a key, from a set of keys stored by the security device, that is unassigned, and may assign the key to the user. The security device may mark the key as assigned. The security device may provide the key to the particular device, which may cause the particular device to validate the key by comparing the key to a set of valid keys. The set of valid keys may be stored in a memory accessible by the particular device based on having been previously provided to the particular device by the security device. The security device may establish a session with the particular device, and may provide the user with access to the particular device via the session.