Securing White-Box Clusters via Unique Identifier Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deployment and provisioning processes for white-box based virtual clusters face security and operational risks, including unauthorized joining attempts, hardware and firmware certification, and secure traffic encryption.

Innovation Solution

A method for securing white-box clusters by assigning a unique identifier, verifying hardware configurations, deploying software agents, and managing clusters using Network Operating System (NOS) software to ensure eligibility and block unauthorized devices, involving registration, call-home processes, and certificate installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If white-boxes from different manufacturers are aggregated into a virtual cluster, then device versatility and functionality are improved, but security risks and operational complexity increase

Engineering Contradiction:
Improvedevice versatilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cluster manager as an intermediary component that mediates between white-boxes from different manufacturers. The cluster manager enforces security policies, manages authentication credentials, and coordinates cluster operations, thereby enabling multi-vendor aggregation while maintaining security control. This intermediary layer resolves the contradiction by allowing device versatility without proportionally increasing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes security parameters through dynamic credential management, where authentication credentials are issued, revoked, and updated based on cluster policies. The system modifies security parameters such as authentication requirements and access permissions adaptively, allowing versatile multi-vendor integration while maintaining reliable security through parameter control rather than rigid constraints.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strict hardware certification and authentication processes are implemented, then security is improved, but deployment time and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing authentication credentials for white-boxes before they join the cluster. The cluster manager maintains a database of authorized devices with their credentials ready in advance. When a white-box attempts to join, authentication is immediate rather than requiring time-consuming verification processes, thus maintaining security while reducing deployment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by distributing authentication credentials from the cluster manager to authorized white-boxes. Instead of each white-box undergoing individual hardware certification during deployment, the cluster manager copies and issues pre-validated credentials to trusted devices. This copying mechanism maintains security verification while dramatically accelerating the deployment process.

Inventive Principle:
Principle #26Copying

3Reliability

If comprehensive device verification and credential management are performed, then operational reliability is improved, but system complexity increases

Engineering Contradiction:
Improveoperational reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex security management system into distinct functional modules: the cluster manager handles credential issuance and revocation, individual white-boxes handle local authentication verification, and a database stores credential information. This segmentation distributes complexity across multiple components rather than concentrating it in one system, thereby maintaining operational reliability while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

4Reliability

If unauthorized devices are blocked from joining the cluster, then security is improved, but potential legitimate devices may be incorrectly rejected

Engineering Contradiction:
ImprovesecurityVSAvoiddevice eligibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements feedback through a centralized cluster manager that maintains an authoritative database of authorized devices and their credentials. When a device attempts to join, the cluster manager provides feedback by verifying credentials against the database and either granting or denying access based on this verification. This feedback mechanism ensures security by blocking unauthorized devices while preventing false rejections of legitimate devices through accurate credential verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3895463B1Secured deployment and provisioning of a white-box based cluster
Publication Date: 2024.07.10 DRAJVNETS LTD
  • EP3895463B1 patent drawingFigure 1
  • EP3895463B1 patent drawingFigure 2
  • EP3895463B1 patent drawingFigure 2

AI summary

A method for obtaining a secured routing functionality in a white- boxes based cluster which comprises a plurality of standalone white-boxes, wherein at least two of the standalone white-boxes were manufactured by different manufacturers, and wherein the method comprising identifying a serial number (S/N) associated with each white-box to be included in that cluster, determining pre-defined properties of each respective white-box based on the identification, and installing each of the white-boxes together with a respective computing platform software comprising a software agent provided by the manufacturer of that white-box.