Individualized Audit Credential Injection for Virtual Machine Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems in cloud computing environments lack the ability to manage access to resources accessed by virtual machines, particularly in providing individualized authentication and authorization for virtual machines instantiated or replicated from the same virtual image.

Innovation Solution

A method is provided where individualized audit credentials are generated and managed for virtual machines, allowing selective authorization and de-authorization, and reporting of de-authorized machines, enabling secure access control to data resources and audit logging.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are replicated from the same virtual image to improve scalability and deployment speed, then productivity and adaptability are improved, but the ability to provide individualized access control and auditing is lost

Engineering Contradiction:
Improvedeployment speedVSAvoidindividualized access control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments the access control mechanism by injecting unique identifiers into each virtual machine instance during replication. This allows the system to treat replicated VMs as individual entities with distinct identities, enabling individualized audit logging and access control while maintaining the efficiency of replication-based deployment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential injection mechanism that bridges the gap between replicated VM instances and the access control system. By injecting unique credentials as an intermediary layer, the system can provide individualized access control without modifying the replication process itself, thus maintaining deployment speed while enabling fine-grained control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individualized audit credentials are provided to each virtual machine instance, then access control security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidcredential management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by injecting unique credentials into virtual machine instances during the replication process itself, before the VMs are deployed. This upfront credential injection eliminates the need for complex post-deployment credential management, reducing system complexity while maintaining strong individualized access control security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically generating and injecting unique credentials into each replicated virtual machine instance without requiring manual intervention. This automation reduces the operational complexity of managing individualized credentials across numerous VM instances while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9985970B2Individualized audit log access control for virtual machines
Publication Date: 2018.05.29 CYBER ARK SOFTWARE LTD
  • US9985970B2 patent drawing
  • US9985970B2 patent drawing
  • US9985970B2 patent drawing

AI summary

To provide enhanced operation of computing systems to control access to audit logging resources by virtual machines, various systems, apparatuses, methods, and software are provided herein. In a first example, a method of operating a computing system is provided. The method includes receiving requests for audit credentials from virtual machines, and responsively providing individualized audit credentials to the virtual machines based at least on identities of the virtual machines. The method also includes, in the audit system, authorizing storage of audit data transferred by the virtual machines based at least on the individualized audit credentials accompanying the audit data. The method also includes, in the authorization system, selectively de-authorizing one or more of the virtual machines and reporting information regarding the de-authorized one or more of the virtual machines to the one or more audit systems.