Virtualized Endpoints for Multi-Tenant Credential Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant cloud environments, customers face challenges in ensuring authorized access and managing credentials to prevent unauthorized access to resources, as resources are typically under the control of the provider and may be vulnerable to tampering or malicious requests.

Innovation Solution

Implementing a virtual private network (VPN) gateway or agent within the customer environment to intercept and authenticate requests, adding necessary credentials or signatures to ensure secure communication and authentication, and utilizing a virtual machine manager to manage customer traffic and authenticate requests within the multi-tenant environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If resources are hosted in a provider-controlled environment for cloud computing scalability, then resource scalability and accessibility are improved, but customer control and security assurance deteriorate

Engineering Contradiction:
Improveresource scalabilityVSAvoidcustomer control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a customer-controlled endpoint device as an intermediary between the customer and provider environment. This endpoint hosts a local instance of the application and manages credentials locally, serving as a mediator that maintains customer control while enabling access to provider resources. The endpoint acts as a trusted intermediary that can verify provider responses and manage authentication without requiring full resource control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If request authentication is implemented to prevent unauthorized access, then security is improved, but system complexity and credential management burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the customer's endpoint device autonomously manages credentials and authentication. The local application instance on the endpoint automatically handles credential verification, response validation, and authentication management without requiring customer intervention. This self-service approach maintains high security while reducing the operational complexity for customers.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The endpoint device serves as an intermediary that simplifies credential management by locally storing and managing authentication credentials. Instead of requiring customers to directly manage complex credential systems, the endpoint intermediary handles credential verification, token management, and authentication workflows automatically, reducing the perceived complexity for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If credentials are managed directly by customers for authentication, then customer control is improved, but security risk from credential exposure increases

Engineering Contradiction:
Improvecustomer controlVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts credential management from the provider environment and places it locally on the customer's endpoint device. By taking out the credential storage and management functionality from the centralized provider system and embedding it in the distributed endpoint, the system maintains customer control while reducing credential exposure risk. Credentials never leave the customer's controlled environment, eliminating transmission and storage vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local credential management where each customer endpoint maintains its own secure credential storage and verification capabilities. Instead of centralized credential management, each endpoint has localized authentication functionality tailored to its specific security requirements. This local quality approach allows credentials to remain in the customer's secure environment while enabling robust authentication.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9485234B1Virtualized endpoints in a multi-tenant environment
Publication Date: 2016.11.01 AMAZON TECH INC
  • US9485234B1 patent drawing
  • US9485234B1 patent drawing
  • US9485234B1 patent drawing

AI summary

Customers accessing resources or services in a multi-tenant environment can obtain assurance that a provider of that environment will honor only requests associated with the customer and will reject any requests that might have been tampered with or otherwise falsely generated. Various endpoints or interfaces can be used, which can be located in the multi-tenant environment, in a customer environment, or in a separate location. These endpoints or interfaces can sign unsigned requests, or otherwise increase the credentials of a signed request, on behalf of a customer. In some embodiments, additional metadata can be added that can increase the authentication level of the requests. Such an approach can enable a customer to provide or delegate access to the resources without exposing the credentials outside a secure environment.