Virtual Machine Logon Federation via Credential Provider

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers and virtual machine users face security concerns when accessing resources outside their standard security domain, particularly due to the need for multiple credentials and lack of secure, trusted access methods.

Innovation Solution

A credential provider system utilizing SAML or ADFS endpoints to authenticate virtual machine users' credentials from an existing identity provider, issuing security tokens for authorized access to resources in external security domains, thereby eliminating the need for separate credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machine users access resources outside their standard security domain, then access to external resources is enabled, but security risks and credential management complexity increase

Engineering Contradiction:
Improveaccess to external resourcesVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a credential provider as an intermediary component that sits between the virtual machine user and external security domains. This credential provider obtains security tokens from trusted identity providers and uses these tokens to authenticate users when accessing external resources, thereby enabling cross-domain access while maintaining security through a trusted mediation layer rather than direct user credential exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual machine users access resources outside their standard security domain, then access to external resources is enabled, but the number of credentials required increases

Engineering Contradiction:
Improveaccess to external resourcesVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential provider that can obtain security tokens from multiple different identity providers (such as Active Directory Federation Services, Security Assertion Markup Language providers, or other trusted identity sources). This single credential provider component serves multiple functions by supporting various identity providers and handling different authentication protocols, thereby eliminating the need for users to manage separate credentials for each external security domain

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional authentication methods are used for external security domains, then security is maintained through credential verification, but user convenience and access simplicity deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidlogin process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the credential provider to automatically obtain security tokens from identity providers and manage authentication credentials without requiring user intervention. The system performs self-service authentication by automatically acquiring tokens, managing their validity periods, and using them for seamless access to external resources, thereby maintaining strong security verification while eliminating the need for users to manually manage multiple credentials or logins

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10205717B1Virtual machine logon federation
Publication Date: 2019.02.12 AMAZON TECH INC
  • US10205717B1 patent drawing
  • US10205717B1 patent drawing
  • US10205717B1 patent drawing

AI summary

Systems and methods are described for providing federated access to end-users of virtual machines. The method includes receiving a request from a user to access a resource outside of the user's original security domain. The user's existing security credentials are forwarded to an authentication entity, which determines if the user's credentials are authentic. If it is determined that the user's credentials are authentic, the user's target identity provider generates a security token that provides the virtual machine user with access to the resource, the resource residing in an external security domain. The user may log on to the virtual machine with access to the desired resource, subject to the privileges identified in the security token.