Relationship modeling for network address domains
By generating access point graphs, modeling the relationship between the access point and its associated domain and subdomain, the security and compliance issues of the existing certificate management system when generating access point certificates are solved, and certificate generation without wildcard entries is realized, ensuring the accuracy and effectiveness of the certificate.
Patent Information
- Application Number
- CN202411617086.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-11-13
- Publication Date
- 2025-06-27
AI Technical Summary
When generating access point certificates, existing certificate management systems have difficulty effectively managing the complex relationships between multiple access points and multiple domains and subdomains associated with them, resulting in security and compliance issues.
By generating an access point graph, model the relationship between the access point and its associated domain, subdomain, source server and agent, independently list each domain and subdomain, and contains information about data service routing, thereby generating a certificate without wildcard entries.
It realizes certificate generation without wildcard entries, avoids security and compliance issues, ensures the accuracy and effectiveness of access point certificates, and adapts to complex domain relationship changes.
Smart Images

Figure CN120223349A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to relationship modeling for network address domains. Background Art
[0002] One or more computing devices utilize a communication infrastructure to facilitate the exchange of data between the computing devices. The communication infrastructure can include devices, applications, or services that are sources or destinations of data transmission within a network, referred to as endpoints. Example endpoints include web service applications. The communication infrastructure assigns access points for the endpoints for computing devices to interact with the endpoints. An access point is a physical or virtual location that provides a connection for a computing device to an endpoint.
[0003] A key aspect in facilitating data transfer is trust, which is established between endpoints (e.g., a client device and a web service application) when accessing data via an access point. Trust is typically established through a secure communication protocol to ensure the legitimacy of the transmitted data, for example, by using a certificate signed by a trusted authority. Summary of the Invention
[0004] Techniques are described for generating an access point certificate based on a graph that defines a relationship between one or more access points and at least one domain associated with the access point (e.g., a domain and subdomains associated with a network address accessible by a computing device, application, etc.). The techniques described herein are implemented using methods, systems, computer-readable storage media, and combinations thereof. Relationship data that describes how to route data between an access point and a domain (e.g., via at least one source server hosting the data, at least one proxy for the source server, etc.) is received by a certificate management system. The relationship data can include how to route data in the event of an interruption of service at the access point. The certificate management system (e.g., implemented at or by one or more computing devices) generates an access point graph that represents the access point, network address, domain, its subdomains, source server, proxy, records, etc. as nodes in the graph, where edges connect the various nodes to model the relationship between the network address and the various domains.
[0005] Using the access point graph, a certificate for the access point is generated that individually lists each domain and subdomain associated with the access point and includes information that describes the routing of data traffic between the access point and the domain or subdomain. In this way, an access point certificate is generated without a wildcard entry that represents multiple domains or multiple subdomains via a single entry. The certificate is used to control data communication traffic via the access point and / or network address and is continuously updated in response to changes in the domain relationship data of the access point.
[0006] The present invention content introduces a series of concepts in a simplified form that will be further described in the following detailed implementation. Therefore, the present invention content is not intended to identify the basic features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] The detailed implementation is described with reference to the accompanying drawings. In some implementations, the entities represented in the figures indicate one or more entities, and thus the entities in the singular or plural form may be interchangeably referred to in the discussion.
[0008] Figure 1 is an illustration of an environment in an example implementation that is operable to use a certificate management system to generate a certificate for an access point based on a graph of domain relationship data of the access point.
[0009] Figure 2 depicts an example of a graph of domain relationship data used by Figure 1 the certificate management system to generate a certificate for an access point.
[0010] Figure 3 depicts an example of a different graph of domain relationship data used by Figure 1 the certificate management system to generate a different certificate for an access point.
[0011] Figure 4 depicts an example of a different graph of domain relationship data used by Figure 1 the certificate management system to generate a different certificate for an access point.
[0012] Figure 5 depicts an example of a different graph of domain relationship data used by Figure 1 the certificate management system to generate a different certificate for an access point.
[0013] Figure 6 depicts an example of a different graph of domain relationship data used by Figure 1 the certificate management system to generate a different certificate for an access point.
[0014] Figure 7 is a flowchart depicting a process in an example implementation in which Figure 1 the certificate management system generates a certificate for an access point based on a graph of domain relationship data of the access point.
[0015] Figure 8 is a flowchart depicting a process in an example implementation in which the certificate generated by Figure 1 the certificate management system is used to control data communication via the access point.
[0016] Figure 9illustrates an example system that includes various components of an example device for implementing the techniques described with reference to Figures 1 to 5 the description. DETAILED DESCRIPTION
[0017] Overview
[0018] A computing device may implement digital certificates to secure communications over a network. For example, a computing device may utilize digital certificates to authenticate the authenticity of an entity (e.g., a web service application or a server) and / or establish an encrypted connection. To obtain a certificate, the entity may notify a trusted certificate provider, known as a certificate authority, of the intention to host a service. In a variant, if the service is a web service application, the entity may use the domain name of the web service application (e.g., www.example.com) to notify the certificate authority of the web service application. The entity may request that the certificate authority issue a certificate authorizing data communication via an access point such that the data communication can be trusted by client devices accessing the web service application via the access point. The certificate authority generates a certificate that is used to secure communications between the client device and a domain with a specified domain name via the access point. In a variant, the certificate includes information about the domain (e.g., the entity associated with the domain, its public key, expiration date, etc.).
[0019] In some examples, one or more web service applications implement a Domain Name System (DNS) topology to manage the translation of human-readable domain names (e.g., www.example.com) to Internet Protocol (IP) addresses representing the domain. The DNS topology includes, but is not limited to, a root domain at the highest level in the hierarchy and top-level domains (TLDs) below the root domain. For the example domain name “www.example.com,” “example.com” is the root domain and “.com” is the TLD. Systems implementing the DNS topology include one or more servers for storing and accessing domain information, such as DNS servers storing the domain information and proxies serving as intermediate servers between client devices accessing the domain information and the DNS servers. As the DNS topology scales up, the organization and structure of DNS servers, proxies, and client devices accessing domains hosted on the DNS servers become increasingly complex and difficult to manage.
[0020] To accommodate this increase in DNS scale, Subject Alternative Names (SANs) are typically implemented to provide a single certificate for multiple domain names or sub-domains to be used in association with an access point. For example, a certificate for an entity including different domains and sub-domains that can be accessed via a common access point includes a SAN list of the different domains and sub-domains. Unused domain names (e.g., domain names that an entity previously used but no longer uses) are not routinely removed from the certificate SAN list, resulting in a bloated SAN list that includes domain names that are not actively used.
[0021] This problem is further exacerbated when an entity introduces multiple region-specific (e.g., country- or other geographical location-specific) domain names (e.g., example.com.uk for the UK and example.com.de for Germany) and implements a proxy to handle traffic via an access point and one or more servers that store domain data. For example, due to different rules for data traffic in different regions, the entity experiences a significant increase in network traffic within its own infrastructure and at the proxy level. As an example at the proxy level, entities often employ a content delivery network (CDN), which improves the performance, availability, and security of websites, applications, and other domain data by distributing data across multiple servers located in different geographical locations. A CDN proxy, also known as a hypertext transfer protocol (HTTP) proxy or reverse proxy, acts as an intermediary between a client device and a source server that hosts content and / or services associated with a domain name. In an implementation where an entity uses a CDN proxy, when a client device requests content from a website or application, the CDN proxy processes the request and determines the most efficient way to serve the content.
[0022] For example, when a CDN proxy receives a request for content, the CDN proxy accesses a cached copy of the content stored locally (e.g., in one or more local servers of the CDN proxy). If the content is cached and valid (e.g., not expired), the CDN proxy serves the content directly from the local server. If the requested content is not in the local server or if the content has expired, the CDN proxy fetches the content from the source server and stores a copy at the local server. In some implementations, the CDN proxy distributes the content to edge servers located in different geographical locations. By strategically positioning the edge servers in different regions, different Internet service provider data centers, etc., the CDN proxy stores the content closer to the client device, which reduces latency and ensures faster content delivery. The CDN proxy additionally provides load balancing techniques to distribute traffic among the edge servers in an efficient manner, thereby distributing data traffic and preventing a single endpoint (e.g., a server) from being overwhelmed with requests.
[0023] Generating certificates for the various domains, sub-domains, origin servers, and CDN proxies associated with a given access point is a cumbersome process, especially for entities that have many (e.g., thousands of) sub-domains assigned to different origin servers and proxies while being associated with a single access point. To account for this increased scale, conventional certificate generation methods implement wildcard entries to account for different domains via a single certificate entry. Wildcard entries typically use a single character (e.g., "*") to represent multiple sub-domains of a single domain. For example, the certificate wildcard entry "example.com.*" represents "example.com" as well as "example.com.uk", "example.com.de", "example.com.au", etc. Although wildcard entries allow entities to conveniently adjust domain relationships (e.g., add additional geographical sub-domains without modifying the domain's certificate), wildcard entries pose significant security and compliance issues.
[0024] For example, wildcard entries create an increased attack surface by allowing mimics to easily mimic sub-domains, potentially obscuring the visibility of security configurations (e.g., Secure Sockets Layer and Transport Layer Security encryption), exposing multiple servers to a compromised private key of one server, compliance issues, etc. CDN proxies further exacerbate these security issues, where entities with a large number of sub-domains or continuously creating and destroying sub-domains encounter problems managing the installation location of wildcard certificates, resulting in situations where servers are incorrectly configured or expired or revoked certificates are still in use.
[0025] To address these problems faced by conventional certificate management, a certificate management system is described that generates a graph defining the relationship between an access point and at least one domain associated with the access point (e.g., domains and sub-domains associated with a network address, such as an IP address or virtual IP address accessible by a computing device, application, etc.). In the graph, the access point and each associated domain, sub-domain, origin server, proxy, etc. are represented as nodes in the graph, where edges connect the various nodes to model the relationship between the access point and the various domains / sub-domains. After constructing the graph, the certificate management system generates a certificate for the access point based on the graph such that the certificate individually lists each domain and sub-domain associated with the access point and includes information describing the routing of data traffic (e.g., via an origin server or proxy) between the access point and the domain or sub-domain. Advantageously, the certificate is generated independent of (e.g., without) wildcard entries that represent multiple domains or multiple sub-domains via a single entry. In this way, the certificates generated according to the described techniques do not include wildcard entries and avoid the security and compliance issues faced by conventional certificates as described above. The certificate is then used to control data communication traffic via the access point.
[0026] The certificate management system is configured to receive an indication when a change occurs in the relationship between an access point and one or more domains associated with the access point. In response to a change in the relationship between the access point and one or more domains, the certificate management system generates an updated graph representing the current relationship and generates a new certificate for the access point based on the updated graph. In this way, certificates for the access point are continuously generated, and the certificates are used to control the flow of data traffic between a client device and at least one domain via the access point.
[0027] In one or more examples, a computing device can access an endpoint (e.g., a web service application) from different geographical locations. An access point for the endpoint can be assigned to a geographical region that includes some or all of the geographical locations. For example, an access point can be assigned to a country in which the computing device is accessing the endpoint from different cities within the country. The access point may lose network connectivity, for example, due to a security attack, environmental factors, or other factors, resulting in latency and interruption of services for the computing device accessing the endpoint from the geographical region assigned to the access point. Various endpoints implement a CDN proxy to handle requests to the endpoints. When the access point loses network connectivity, the access point can have a fallback option. For example, a fallback access point for an access point assigned to a country can be an access point assigned to a continent or a neighboring geographical region that includes the country. However, the fallback access point may lack information for generating a certificate for accessing the endpoint.
[0028] As described herein, in addition to mapping the relationship between a service access point and at least one domain associated with the service access point, a certificate management system can also map the relationship between a service access point and one or more alternative access points. The service access point can be an initial access point assigned to a client device to access an endpoint. A portion of a graph that models the relationship between a service access point and alternative access points can include one or more nodes and edges, where each node is an access point and the edges connecting the respective nodes describe the relationship between the service access point and the alternative access points. For example, if the service access point experiences a loss of connection, the certificate management system can identify an alternative access point that is a child node of the node representing the service access point. The graph maintains the relationship between the service access point and at least one domain, so the certificate management system can use the relationship information from the graph to generate one or more certificates for accessing the endpoint from the alternative access point. In some examples, the relationship between a service access point and one or more alternative access points can be dynamic, such that the service access point can fallback to one or more different access points based on data traffic at the access point or the geographical location of the access point, among other factors. In some cases, an access point in the graph can fallback to a data center, for example if the access point experiences a loss of connection simultaneously. In other words, at least one alternative access point includes a data center.
[0029] In the following discussion, an example environment configured to employ the techniques described herein is described. Example processes configured to execute in the example environment and other environments are also described. Thus, the execution of the example processes is not limited to the example environment, and the example environment is not limited to the execution of the example processes.
[0030] Example Environment
[0031] Figure 1 FIG. 100 is an illustration of a digital media environment 100 in an example implementation that is operable to employ the techniques described herein. As used herein, the term "digital media environment" refers to the various computing devices and resources for implementing the techniques described herein. The digital media environment 100 includes computing devices 102 that can be configured in various ways.
[0032] For example, computing device 102 can be configured as a desktop computer, a laptop computer, a mobile device (e.g., in a handheld or wearable configuration such as a tablet or a mobile phone), etc. Thus, computing device 102 ranges from full-resource devices with substantial memory and processor resources (e.g., personal computers, game consoles) to low-resource devices with limited memory and / or processing resources (e.g., mobile devices). Additionally, although described in the context of a single computing device 102, computing device 102 represents multiple different devices, such as multiple servers for performing operations "over the cloud".
[0033] In the illustrated example, computing device 102 includes a certificate management system 104. Certificate management system 104 represents the functionality of computing device 102 to receive domain relationship data 106 of access point 108. As described herein, access point 108 refers to the location where data exchange occurs. For example, in the context of an Internet service provider (ISP), access point 108 represents a public switching facility where ISPs can connect to each other to allow the exchange of traffic between different ISP networks, enabling data of a client from one ISP to reach a client on another ISP network. An access point is a key part of the network infrastructure and includes a physical location (e.g., a data center) where different networks, services, and devices are connected to each other via routers, switches, etc. In the context of wireless network communication, telecommunications, etc., access point 108 represents a device that provides a connection to the network for a device, such as a router or a hub.
[0034] In some implementations, access point 108 is associated with a network address such as an IP address, a virtual IP address, etc., and thus represents a device that provides a connection for data communication between different endpoints (e.g., different devices). For example, in an implementation where access point 108 represents a virtual IP address, access point 108 can be accessed by one or more physical network interfaces, one or more devices, or a combination thereof. In some examples, an IP address is assigned to multiple servers or network devices across different locations. An IP address assigned to multiple servers or network devices across different locations can be referred to as a multicast IP address, or in the case of a virtual IP address, as a multicast virtual IP address.
[0035] In some examples, the certificate management system 104 can receive multicast IP addresses from multiple locations and can route or direct data traffic to a destination based on routing metrics. The routing metrics can include the data load at the destination, the geographical location of the destination, the traffic speed at the destination, and other factors and / or metrics or can be related to the data load at the destination, the geographical location of the destination, the traffic speed at the destination, and other factors and / or metrics. For multicast IP addresses, incoming data traffic is distributed across multiple access points 108, which improves load distribution and prevents overload at the access points 108. Additionally or alternatively, distributing incoming data traffic across multiple access points 108 provides redundancy for directing traffic to available access points 108, which can result in improved network latency and overall responsiveness of the services of the certificate management system 104.
[0036] The domain relationship data 106 represents information that describes the association between the access points 108 and at least one domain. For example, in Figure 1 the illustrated example, the access points 108 are depicted as being associated with multiple domains, which are represented as domains 110(1) through 110(N), where N represents any integer. Each domain 110 associated with the access points 108 is also depicted as including at least one subdomain. For example, domain 110(1) is depicted as including subdomains 112(1) through 112(X), and domain 110(N) is depicted as including subdomains 114(1) through 114(Y), where X and Y each represent any integer. In an example implementation, each subdomain of a domain represents a different service associated with that domain. Alternatively or additionally, each subdomain is associated with a different geographical region of the domain (e.g., in response to a request to access domain 110(1) from a first geographical location, traffic is routed to subdomain 112(1), and in response to a request to access domain 110(1) from a second geographical location, traffic is routed to subdomain 112(X)). These examples of different subdomains of a domain are merely illustrative and are not intended to be limiting, as the techniques described herein are extensible to any suitable configuration of domains and their subdomains associated with the access points 108.
[0037] In an implementation, access point 108 facilitates access to content hosted on domain 110—and / or its sub-domains, such as sub-domain 112 or sub-domain 114—by routing data communications between domain 110 and access point 108 via one or more intermediate devices. For example, in a basic implementation, data retrieved from each domain 110 associated with access point 108 is hosted on a single source server, and access point 108 facilitates data transfer between the source server and one or more clients (e.g., computing devices, applications, services, combinations thereof, etc.). In other implementations, data retrieved from different domains 110, sub-domains 112, and sub-domains 114 is routed to one or more clients via the access point, via one or more proxies, multiple source servers, or combinations thereof. Domain relationship data 106 also represents information describing how data is routed from different domains 110, sub-domains 112, and sub-domains 114 via access point 108 (e.g., directly from the source server, via a proxy, etc.).
[0038] In an implementation, domain relationship data 106 is received by certificate management system 104 from a listener 116 associated with access point 108. Listener 116 represents a component of access point 108 that identifies configuration settings that define the relationship between access point 108 and domain 110, sub-domain 112, sub-domain 114, source server, proxy, or combinations thereof. For example, domain relationship data 106 defines how a request for data from a particular sub-domain (e.g., sub-domain 112(1)) will be routed from the source server or proxy through access point 108 that received the request to a client.
[0039] In an implementation, listener 116 is configured as a software component or service of access point 108 that monitors and processes incoming network connections and communication requests at access point 108. Alternatively or additionally, although depicted as implemented at access point 108 in the illustrated example of Figure 1 , listener 116 is implemented remote from access point 108. Listener 116 also represents the function of managing incoming connections between clients and domain 110 based on certificate 118 associated with access point 108. Alternatively or additionally, listener 116 operates as a security mechanism to block or limit unauthorized connections, such as connections not expressly permitted by certificate 118.
[0040] In an implementation, a certificate management system 104 generates a certificate 118 for an access point 108. To this end, the certificate management system 104 implements a graph module 120 that generates an access point graph 122 based on domain relationship data 106 of the access point 108. In this way, the access point graph 122 represents a data structure that defines the relationships between the access point 108, domains 110, sub-domains 112 and 114, and any source servers or proxies implemented by entities to serve access to data and / or services represented by the domains 110, sub-domains 112 and 114. For an example of the access point graph 122, consider Figure 2 .
[0041] Figure 2 FIG. 200 depicts an example of a graph of domain relationship data used by the certificate management system 104 to generate a certificate 118 for the access point 108. In the example 200 shown, the access point graph 122 is generated from domain relationship data 106 that describes how the access point 108 is associated with domains 110(1), 110(2), and 110(N). The access point graph 122 also represents how domain 110(1) is associated with multiple sub-domains, which are represented as sub-domains 112(1), 112(2), and 112(X) in the example 200 shown. Similarly, the access point graph 122 represents how domain 110(2) is associated with sub-domain 206 and how domain 110(N) is associated with multiple sub-domains represented as sub-domains 114(1) and 114(Y). The access point graph 122 also includes information describing how domain 110(1) along with its sub-domains 112(1), 112(2), and 112(X) are assigned to a source server 202 such that requests for data from domain 110(1) and / or sub-domains 112(1) through (X) are routed from the source server 202 to a requesting client via the access point 108.
[0042] In a similar manner, the access point map 122 includes information describing how multiple proxies are used to serve data from domain 110(2) and domain 110(N), where the multiple proxies are represented by proxy 204(1) and proxy 204(Z) in example 200. Although only two proxies 204 are depicted in the illustrated example for simplicity, the access point map 122 is configured to represent any suitable number of proxies, such that Z represents any integer. Thus, the access point map 122 represents how requests for data from domain 110(2) and / or subdomain 206 are routed from proxy 204(1) to the requesting client via access point 108. Similarly, the access point map 122 represents how requests for data from domain 110(N) and / or subdomains 114(1) through (Y) are routed from proxy 204(Z) to the requesting client via access point 108. In this way, the access point 108 and its associated domains, subdomains, servers, and proxies are each represented as nodes in the access point map 122, where the edges define how data traffic will be routed between endpoints (e.g., client and subdomain) via access point 108.
[0043] Returning to Figure 1 , the certificate management system 104 implements a certificate generation module 124 to generate a certificate 118 for the access point 108 based on the access point map 122 generated by the graph module 120. The certificate generation module 124 generates the certificate 118 by listing each node of the access point map 122 as a separate entry in the certificate 118. Advantageously, contrary to conventional methods that list multiple domains, multiple subdomains, or combinations thereof using a single wildcard entry, the certificate generation module 124 generates a certificate 118 without wildcard entries (e.g., by listing each node of the access point map 122 as a separate entry in the certificate 118). Thus, the certificate 118 does not include one or more wildcard entries. In a similar manner, contrary to conventional systems that retain expired or vanished domains and / or subdomains in the certificate, the certificate 118 is continuously updated based on changes to the domain relationship data 106, as described in further detail below. In this way, the certificate 118 only describes the current relationships between the access point 108, the domains 110, its subdomains, the source servers, and the proxies that route communications between the access point 108 and the domains 110.
[0044] The certificate generation module 124 additionally generates a certificate 118 to include information describing the associations between different nodes. For example, consider the following example scenario: The source server 202 represents a first provider hosted by an entity, and the proxy 204(1) represents a second provider hosted by a content delivery network different from the entity. In this example scenario, the certificate 118 is generated to include information describing how the domain 110(1) and sub-domains 112(1) through (X) are linked to the first provider and how the domain 110(2) and sub-domain 206 are linked to the second provider, thereby informing the listener 116 how to route incoming access requests. In an implementation, the certificate generation module 124 additionally includes in the certificate 118 security information of the access point 108, such as the public key of the access point 108, the digital signature of a trusted authority vouching for the authenticity of the certificate 118, etc. In this way, according to one or more implementations, the certificate management system 104 represents a trusted security authority.
[0045] For example, Figure 1 The illustrated example depicts a scenario where a client device 126 implementing an application 128 (e.g., a web browser, a dedicated application corresponding to a web service application hosted via one or more of the domains 110, etc.) sends an access request 130 to the access point 108. The access request 130 represents a connection between the client device 126 and the access point 108 using a secure protocol such as HTTPS (e.g., HTTP based on TLS / SSL), which initiates a secure handshake. For example, the access request 130 triggers a TLS handshake, which is a known process by which the client device 126 and the access point 108 establish a secure encrypted connection. As part of the TLS handshake, the access point 108 sends the certificate 118 to the client device 126. Then, the client device 126 uses known certificate verification techniques to verify the certificate 118, such as by checking the expiration date of the certificate 118 to ensure its validity, by performing trust chain verification to ensure the signature of the trusted authority is valid using the public key of the trusted authority, performing hostname verification with the access point 108, and so on.
[0046] In an implementation, performing hostname verification with the access point 108 involves the client device 126 generating a random session key, encrypting the random session key using the public key of the access point 108 included in the certificate 118, and sending the encrypted session key back to the access point 108. The access point 108 (e.g., using the listener 116) then decrypts the encrypted session key using the private key of the access point 108 to establish a session key for secure communication between the client device 126 and the domain 110 via the access point 108. The secure communication between the client device 126 and the access point 108 is in Figure 1In the illustrated example, it is represented as data service 132. For example, data service 132 represents a request for data from sub - domain 206, which is routed from proxy 204(1) to client device 126 via access point 108, as defined by certificate 118 and executed by access point 108 (e.g., using listener 116).
[0047] In an implementation, data is transmitted between computing device 102, access point 108, and client device 126 via network 134. Network 134 represents any suitable communication architecture configured to connect computing device 102 to access point 108 and / or connect client device 126 to access point 108. For example, network 134 represents a local area network, a wide area network, the Internet, etc.
[0048] In some examples, for example, for a anycast IP address, the IP address may not be specific to a geographical location. A CDN can use an anycast IP address to distribute content to different geographical locations so that when a client device sends a request for content, the anycast IP address can direct the request to the nearest CDN node or access point 108. Using anycast IP address technology to distribute content to different geographical locations can reduce latency and improve the overall delivery speed of the content.
[0049] In some examples, certificate management system 104 can cause map module 120 to generate a modified access point map 122 for an anycast IP address. For an example of the modified access point map 122 (e.g., a modified access point map relative to the access point map depicted in Figure 2 ), consider Figure 3 .
[0050] Figure 3 Example 300 depicts a modified graph of domain - relationship data used by certificate management system 104 to generate certificate 118 for network address 302 and / or access point 108. In the illustrated example 300, domain - relationship data 106 can be an example of the domain - relationship data 106 as described with reference to Figure 2 . Certificate management system 104 can use domain - relationship data 106 to generate access point map 122.
[0051] The access point graph 122 may include one or more nodes representing records 304, where the records 304 include records 304(1) through (X), and X is any integer value. In some examples, the records 304 may represent relationships between the corresponding domain 110 and sub-domains 112, 206, and / or 114. The records 304 may have one or more different types (e.g., record type 306) and corresponding functions. For example, the records 304 may be an address record type that maps a domain name to an IP address (e.g., network address 302 or other IP address associated with the access point 108). Additionally or alternatively, the records 304 may be a canonical name (CNAME) record type, which may represent an alias relationship between domains. The certificate management system 104 may use CNAME records to create sub-domains, including sub-domains 112, 206, and / or 114 as described with reference to Figure 2 The access point graph 122 may include a marker indicating the record type 306 of the records 304.
[0052] In some examples, the records 304 may represent a domain with a defined domain type. For example, the records 304 may represent a root domain. In some examples, there may be a set of defined criteria to control data transfer between the root domain and a device. For example, the root domain may not be accessed via the access point 108 or other intermediate components or systems, but may be directly linked to the network address 302. However, the certificate management system 104 may implement the access point 108, proxy, CDN provider, and other systems and components for transferring data between the domain and the device requesting data. Thus, to ensure that the root domain remains directly linked to the network address 302, the certificate management system 104 may introduce a record with a new record type 306 (referred to as an alias record type). The alias record type may indicate to the certificate generation module 124 that the record 304 is a version of the record 304 representing the root domain or points to the record 304 representing the root domain. By creating the alias record type, the certificate management system 104 may utilize the existing infrastructure including components or systems to generate a certificate for the record 304 representing the root domain. For example, the certificate management system 104 may utilize the access point graph 122 (including the network address 302, access point 108, and / or one or more relationships between one or more records 304) to generate a certificate.
[0053] To generate a certificate, the certificate generation module 124 may traverse the access point graph 122 to determine relationship information between the network address 302, access point 108, and one or more records 304. The certificate generation module 124 may use the relationship information to generate a certificate, as described with reference to Figure 1 and Figure 2As described. In some examples, the certificate generation module 124 can generate a certificate that includes a record 304 indicating at least one domain and one or more subdomains.
[0054] In some cases, multiple providers, including a CDN and one or more other providers (e.g., entities other than the CDN), can serve a domain. The certificate management system 104 can control data transfer between the domain and a device based on the certificate. For example, the certificate management system 104 can determine whether the certificate is valid (e.g., not expired or revoked and includes a matching key or signature) before transferring data between the domain and the device. If the certificate is valid, the certificate management system 104 delivers the data. If the certificate is invalid, the certificate management system 104 can refrain from delivering the data. Alternatively, the certificate management system 104 can generate a new certificate, can notify the device that the certificate is invalid, etc.
[0055] In some cases, the certificate management system 104 can determine that the network address 302 includes a multicast IP address or is otherwise related to a multicast IP address. The certificate management system 104 can assign an access point type 308 to the access point 108. For example, if the certificate management system 104 determines that the network address 302 and / or the access point 108 is related to a multicast IP address, the certificate management system can assign a multicast access point type to the access point 108. In some other cases, the certificate management system 104 can determine that the network address 302 does not include a multicast IP address or is not otherwise related to a multicast IP address, and can assign an alternative access point type to the access point 108. Examples of alternative access point types include, but are not limited to, DNS access points. In addition to the nodes representing the access point 108, the access point map 122 can also include a labeled or assigned access point type 308 (e.g., a multicast access point type or another access point type 308).
[0056] In some examples, e.g., if the access point 108 is labeled as a multicast access point type, the CDN provider can verify the validity of the certificate for the access point 108. For example, the CDN provider can request the certificate generation module 124 to generate a certificate based on receiving a request to access data at a domain indicated by the record 304 (e.g., records 304(1) to (X)). The CDN provider and / or the certificate generation module 124 can determine that the domain corresponds to a multicast IP address. The CDN provider can receive a request to access data from a geographical location from which the domain is accessible (e.g., the geographical location specified for the multicast IP address). Since the network address can be accessed from multiple different geographical locations, the CDN provider can perform certificate verification for the access point 108 (e.g., for the multicast IP address). If the certificate is valid, the CDN provider can indicate that data transfer between the device and the domain is allowed.
[0057] As described above, the certificate management system 104 is configured to update the certificate 118 for the access point 108 in an ongoing manner, such as at defined intervals, in response to changes in the domain relationship data 106, or a combination thereof. For example, in response to a configuration change associated with the access point 108, the certificate management system 104 receives updated domain relationship data 106 from the listener 116.
[0058] In accordance with the techniques described herein, changes in the domain relationship data 106 occur in response to certain services and / or data associated with a domain or subdomain being hosted by a different infrastructure (e.g., the source server 202 or the proxy 204), being consolidated into a common infrastructure, being allocated to different access points, combinations thereof, and the like.
[0059] As a specific example, a change in the domain relationship data 106 is detected in response to consolidating different services for a web application associated with one or more domains previously associated with multiple access points into a common access point (e.g., the access point 108). Such consolidations are typically used when an application programming interface is implemented as the access point 108 to facilitate data communication for different aspects of a web service application, when single sign-on is implemented to perform authentication at a single access point 108, when locally hosted services are offloaded to a CDN, when a service mesh is implemented by a single access point 108 to provide load balancing and fault tolerance, and the like.
[0060] As another example, a change in the domain relationship data 106 occurs in response to different domains 110 or subdomains previously associated with the access point 108 being allocated to different access points. In implementations, the allocation of services and / or data associated with a domain or subdomain is typically performed to provide scalability, fault isolation, security, geographic distribution, regulatory compliance, and service-specific optimizations. For example, as a web service application grows, some services may require more resources than others, and allocating different access points for each service avoids bottlenecks at a given access point. Similarly, allocation among multiple access points mitigates issues that arise in the event of a failure or performance problem at a given access point, reduces latency, enables different access points to cater to different regulatory guidelines, and so on. As yet another example, a change in the domain relationship data 106 occurs in response to the expiration of the certificate 118.
[0061] In response to receiving updated domain relationship data 106 for the access point 108 (e.g., based on changes to the domain relationship data 106 previously used to generate the access point map 122), the certificate management system 104 causes the map module 120 to generate a modified access point map 122. For an example of the modified access point map 122 (e.g., a modified access point map relative to the access point map 122 depicted in Figure 2 ), consider Figure 3 .
[0062] Figure 4 Example 400 of a modified diagram depicting the domain relationship data used by the certificate management system 104 to generate an updated certificate 118 for the access point 108. In the illustrated example 400, the domain relationship data 106 represents Figure 2 the domain relationship data 106 depicted in the illustrated example 200 of Figure 3 and / or changes to the domain relationship data 106 depicted in the illustrated example 300 of Figure 2 . Specifically, example 400 reflects how the source server 202 and the subdomain 112(2) are no longer associated with the access point 108. Example 400 also shows how the domain 110(1) and its subdomains 112(1) through (X) (excluding the subdomain 112(2)) are now routed via the proxy 204(1) (e.g., instead of the source server 202 indicated previously in Figure 4 ). The certificate generation module 124 uses the modified access point diagram 122 depicted in Figure 4 to generate a new certificate 118 for the access point 108, and the new certificate 118 replaces any certificate previously used by the access point. Thus, while a certificate generated from the access point diagram 122 of Figure 2 would include entries for the subdomain 112(2) and the source server 202, the updated certificate generated from the modified access point diagram 122 of Figure 4 will not include entries for the subdomain 112(2) and the source server 202. In this way, the certificate management system 104 generates certificates for the access point 108 in a continuous manner in response to changes in the domain relationship data 106 of the access point 108, thereby ensuring that the access point 108 includes a certificate 118 that accurately represents the associated domain relationship data 106. Thus, the certificate 118 can be used to control traffic between a device and one or more domains via the access point 108 in a manner that avoids security vulnerabilities associated with wildcard entries of conventional certificates.
[0063] Although described herein in the context of generating certificates for a single access point, the certificate management system is configured to generate certificates for any number of different access points according to the described techniques.
[0064] The access point 108 can be assigned to a geographic region such that the access point 108 provides connectivity to devices within the geographic region. For example, the access point 108 can receive one or more requests to access content (e.g., a web service application) and can route data communications related to the request, as described with reference to Figure 1 . In some cases, the geographic region can include at least one of a city, state, country, and / or continent. Devices can access content from different geographic locations within the region.
[0065] In some cases, access point 108 may experience a network connection interruption, may experience a security compromise, or may experience an alternative interruption that affects the operation of access point 108. For example, a malicious actor may cut the network connection between access point 108 and network 134. Additionally or alternatively, environmental factors (e.g., weather or other similar environmental factors) may cause access point 108 to disconnect from network 134. When access point 108 is offline (e.g., disconnected), one or more devices within the geographical area served by access point 108 may not be able to access content via access point 108. The inability to access content via access point 108 may result in communication delays and other interruptions to services for the devices.
[0066] When access point 108 loses its network connection, access point 108 may have one or more alternative options, referred to as backup access points. Backup access points may include access points assigned to a related geographical area (e.g., an adjacent geographical area and / or a geographical area that includes the geographical area of access point 108). For example, backup access points assigned to access point 108 in a country may include access points assigned to the continent that includes the country and / or access points assigned to an adjacent country. The backup access point may receive content requests from devices in the geographical area of access point 108 that is experiencing a network connection interruption and address the content request. However, the backup access point may lack information for generating a certificate for accessing the content. This information may include domain and subdomain information of access point 108, as well as other relationship information (e.g., domain relationship data 106 as described with reference to Figures 1 to 4 ).
[0067] In addition, various content hosts implement CDN proxies to handle requests to access content. The CDN proxy can distribute data across multiple servers located in different geographical locations. A device can connect to network 134 via access point 108 and send a request for content (e.g., via access point 108) to the CDN proxy. The CDN proxy can select a server to satisfy the request based on a set of criteria, such as the proximity of the device to the server, the traffic load of content requests at the server, and the availability of the content at the server. The selected server retrieves the content and delivers the content back to the device via the network and via access point 108. The use of the CDN proxy may further complicate the certificate generation process for accessing content.
[0068] Accordingly, the certificate management system 104 can further modify the access point map 122 described with reference to Figure 2 , Figure 3 and Figure 4 to include backup access point information. For the modified access point map 122 (e.g., relative to Figure 2 , Figure 3 andFigure 4 An example of a modified access point diagram of the access point 122 depicted in FIG. 122, considering Figure 5 and Figure 6 .
[0069] Figure 5 FIG. 500 shows an example of a modified diagram of domain relationship data used by the certificate management system 104 to generate an updated certificate 118 for the access point 108 that experiences an interruption affecting content access (e.g., loss of network connection). Specifically, FIG. 500 depicts the relationship between the access point 108 and one or more alternative access points 502. In some cases, the alternative access point 502 can be an example of the access point 108.
[0070] In the illustrated example 500, the domain relationship data 106 can be an example of the domain relationship data as described with reference to Figure 2 , Figure 3 and Figure 4 . For example, the domain relationship data can include information describing the association between the access point 108 and at least one domain. Example 500 can implement the access point diagram 122 as described with reference to Figure 2 , Figure 3 and Figure 4 , or be implemented by the access point diagram 122. For example, although not shown, the access point diagram 122 can include one or more relationships between the proxy 204, domain 110, sub - domain 112, sub - domain 114, sub - domain 206, network address 302, and / or record 304.
[0071] Example 500 represents the hierarchy of alternative access points 502 and the relationship between the alternative access points 502 and the access point 108. For example, the access point 108 can have multiple alternative access points 502, including alternative access points 502(1) to (7). For example, in the case where the security of the access point 108 is compromised and / or the network connection at the access point 108 is interrupted, the certificate generation module 124 uses the Figure 5 modified access point diagram 122 depicted in FIG. 122 to generate a certificate 118 for the access point 108.
[0072] In some examples, the diagram includes nodes representing access points (e.g., access point 108 and alternative access points 502) and edges connecting the respective nodes to model the relationships between the access points. If the access point 108 experiences a condition that causes a delay or inability to access content at the access point 108, one or more alternative access points 502 can take over serving the requests previously monitored by the access point 108. In some examples, the certificate generation module 124 can use the diagram to generate a certificate for the alternative access point 502 that takes over the access point 108. For example, in addition to as described with reference to Figure 2 , Figure 3 andFigure 4 In addition to the associations described between the network address 302, access point 108, sub-domains, domains, and records, the certificate generation module 124 may also include information describing the association between the access point 108 and one or more alternative access points 502.
[0073] As shown in example 500, if the access point 108 becomes unavailable (e.g., the network connection status changes to unavailable), requests sent to the access point 108 may instead be addressed by one of the alternative access points 502(1), alternative access point 502(2), or alternative access point 502(3). Which of the alternative access points 502 (e.g., among alternative access point 502(1), alternative access point 502(2), or alternative access point 502(3)) processes the request may depend on the availability of the alternative access points 502 and / or the connection status of the alternative access points 502. For example, if the access point 108 loses its network connection and / or the security of the access point 108 is compromised, other access points 108 may experience similar connection and / or security issues. The connection status may indicate a change in the connection based on the traffic speed of the data exchanged at the access point 108 and / or the network connection status of the access point 108 (e.g., connected or disconnected from the network 134).
[0074] In some cases, the certificate generation module 124 may traverse the access point graph 122 to detect or determine nodes adjacent to the node representing the access point 108 (e.g., and the corresponding alternative access points 502). Nodes adjacent to the node representing the access point 108 may be nodes directly connected to the access point 108 via an edge. If the alternative access points 502(1), alternative access point 502(2), and alternative access point 502(3) cannot process requests sent to the access point 108, then the alternative access points 502(5), alternative access point 502(6), or alternative access point 502(7) may process the request. The alternative access point 502(5) or alternative access point 502(6) may process any requests that the alternative access point 502(3) cannot process. Similarly, the alternative access point 502(7) may process requests that the alternative access point 502(4) cannot process.
[0075] In some examples, at least one of the standby access points 502(1) through (7) can be a data center. A data center can have a relatively strong network connection and security system, and thus may be less likely to experience an interruption in the network connection and / or experience a security vulnerability than other types of standby access points 502 (e.g., other network devices). Thus, in some cases, the last standby access point 502 for one or more access points 108 can be a data center. For example, if an access point 108 located in a city experiences an interruption in service affecting one or more devices, the standby access point 502 can be the access point 108 assigned to the country that includes the city. If the access point 108 assigned to the country that includes the city also experiences an interruption in service affecting one or more devices, the standby access point 502 can be the access point 108 assigned to the continent that includes the country. The access point 108 assigned to the continent can be a data center.
[0076] In some examples, the relationship between the domains and access points in example 500 can be based on the geographical location of the access point 108. If a device requests access to content with an associated domain, the initial or serving access point 108 is assigned based on the geographical location of the access point 108 relative to the device. For example, if the device is located in a city, the access point 108 can be the access point 108 assigned to serve requests originating within the city. In some cases, the standby access points 502 are sorted and assigned based on the proximity of the geographical location of the access point 108 to the geographical location of the standby access point 502. For example, the standby access point 502 can be the access point 108 assigned to the geographical location that includes the geographical location of the access point 108 initially assigned to serve requests for content (e.g., the access point 108 assigned to the country that includes the city assigned to the initial access point 108).
[0077] Once the certificate generation module 124 traverses the access point graph 122 and selects a standby access point 502 to serve a request for content, the certificate generation module 124 can use one or more domains, subdomains, and the relationship between the access point 108 and the standby access point 502 to generate a certificate. The access point graph 122 can represent the relationship between the standby access points 502 (e.g., child nodes in the access point graph 122) and the access point 108 (e.g., the root node in the access point graph 122), with reference to Figure 2 , Figure 3 and Figure 4A portion of the access point diagram 122 shown and described may represent the relationship between a domain and the access point 108. The child nodes in the access point diagram 122 may be nodes later in the diagram. For example, the standby access points 502(1) to (7) are child nodes of the access point 108, the standby access points 502(5) and 502(6) are child nodes of the standby access point 502(3), and the standby access point 502(7) is a child node of the standby access point 502(4).
[0078] In some examples, different standby access points 502 may experience different operating conditions. For example, the standby access point 502(1) may have different operating conditions from the standby access point 502(2) or the standby access point 502(3). The operating conditions may include one or more of the amount or numerical quantity of data transmission (e.g., data or communication traffic) experienced by the standby access point 502, the speed of data transmission (e.g., latency) experienced by the standby access point 502, the security strength of the standby access point 502, or the geographical location of the standby access point 502 relative to the access point 108, etc.
[0079] Therefore, the certificate management system 104 may also modify the access point diagram 122 described with reference to Figure 5 to include dynamic standby access point information. For an example of the modified access point diagram 122 (e.g., a modified access point diagram relative to the access point diagram depicted in Figure 5 , consider Figure 6 .
[0080] Figure 6 Example 600 depicts a modified diagram of the domain relationship data used by the certificate management system 104 to generate updated certificates 118 for the access point 108 that experiences an interruption (e.g., loss of network connection) affecting content access. Specifically, example 600 depicts alias relationships 602 between the access points 108 (e.g., access points 108(1) to (3)), and the relationships between the access points 108(1) to (3) and one or more standby access points 502. In some cases, the standby access point 502 may be an example of the access point 108.
[0081] In the shown example 600, the domain relationship data 106 may be an example of the domain relationship data as described with reference to Figure 2 , Figure 3 , Figure 4 and Figure 5 . For example, the domain relationship data may include information describing the associations between the access point 108, at least one domain, sub-domains, and / or one or more standby access points 502. Example 600 may implement as described with reference to Figure 2 , Figure 3 , Figure 4 andFigure 5 The described access point diagram 122 is implemented by or in the access point diagram 122. For example, although not shown, the access point diagram 122 may include one or more relationships between a proxy 204, a domain 110, a subdomain 112, a subdomain 206, a subdomain 114, a network address 302, and a record 304.
[0082] Example 600 represents the hierarchy of backup access points 502 and the relationship between the backup access points 502 and one or more of the access points 108(1) to (3). For example, the access points 108(1) to (3) may have multiple backup access points 502, including backup access points 502(1) to (6). The certificate generation module 124 uses Figure 6 the modified access point diagram 122 depicted in to generate a certificate 118 for the access point 108, such as in the case where the security of the access point 108 is compromised and / or the network connection at the access point 108 is interrupted.
[0083] In some examples, the relationship between the access points 108(1) to (3) may be dynamic, such that there is no formal relationship between the access point 108 among the access points 108(1) to (3) and the backup access point 502 until a change in the connection occurs, where the change in the connection may be related to the network connection status of the access point 108, a security vulnerability at the access point 108, and / or the speed of data traffic at the access point 108, among other factors. If one of the access points 108(1) to (3) experiences an interruption in service (e.g., a change in the connection), the certificate management system 104 may dynamically select an access point 108 (e.g., one of the access points 108(1) to (3)). The alias relationship 602 may define the relationship between the access points 108(1) to (3) to provide for the dynamic selection of the access point 108.
[0084] In some examples, the certificate management system 104 may select the access point 108 according to a set of criteria. The criteria may include, but are not limited to, a threshold amount of data transmission experienced by one or more of the backup access points 502 (e.g., a numerical amount, number, or quantity over a certain duration), a threshold speed of data transmission experienced by one or more of the backup access points 502, a threshold security strength of one or more of the backup access points 502, and the proximity of one or more of the backup access points 502 to the access point 108 among the access points 108(1) to (3) in terms of geographical location.
[0085] The certificate management system 104 can detect a service interruption in one of the access points 108 having an alias relationship 602. For example, the access point 108(1), the access point 108(2), and / or the access point 108(3) may experience a service interruption. The certificate management system 104 can analyze the information related to the service interruption to determine the cause or reason for the service interruption. For example, the certificate management system 104 can receive, via the network 134, information indicating that the access point 108 has lost its network connection, has experienced a security vulnerability, is experiencing a relatively high data traffic load that causes a delay in serving requests for content, and so on.
[0086] In some examples, the certificate management system 104 can receive information related to the current operations of the access points 108 that have not experienced a service interruption and / or the standby access points 502. This information can include one or more of the amount of data transmission experienced by the access points 108 and / or the standby access points 502 (e.g., a numerical amount, number, or quantity over a certain duration), the speed of data transmission experienced by the access points 108 and / or the standby access points 502, the security strength of the access points 108 and / or the standby access points 502, or the geographical location of the access points 108 and / or the standby access points 502 relative to the access points 108 that have experienced a service interruption.
[0087] The certificate management system 104 can compare the information related to the current operations of the access points 108 and the standby access points 502 with the set of criteria for selecting the access points 108 (including a set of standby access points 502). In some cases, the certificate management system 104 can select an access point 108 from the access points 108(1) to (3) having one or more standby access points 502, where the access point 108 has an amount of data transmission that meets (e.g., is less than) a threshold amount of data transmission experienced by the standby access points 502, a speed of data transmission that meets (e.g., is greater than) a threshold speed of data transmission experienced by the standby access points 502, a security strength that meets (e.g., is greater than) a threshold security strength of the standby access points 502, and / or a proximity of one or more standby access points 502 to the access point 108 among the access points 108(1) to (3) that meets (e.g., is greater than or less than) a threshold proximity. For example, the certificate management system 104 can select an access point 108 having a standby access point 502 that is experiencing relatively low data traffic (e.g., below a threshold) and / or experiencing a relatively high data transmission speed (e.g., above a threshold) to ensure that the standby access point 502 has the processing bandwidth to serve one or more devices previously served by the access point 108 that has experienced a service interruption.
[0088] When the access point 108 and / or the standby access point 502 are selected, the certificate management system 104 can additionally or alternatively consider the type of service interruption in consideration of information related to the current operation of the access point 108. For example, if the type of service interruption is a security vulnerability, the certificate management system 104 can select the access point 108 of the standby access point 502 that has a security strength meeting a security strength threshold.
[0089] In some examples, the certificate management system 104 can select the access point 108 of the standby access point 502 that has a geographical location relatively close to (e.g., within a certain proximity) the access point 108 experiencing the service interruption. In some cases, the standby access points 502 can be sorted in the access point map 122 according to the proximity. In some other examples, the certificate management system 104 can select the access point 108 of the standby access point 502 that has a geographical location relatively far from the access point 108 experiencing the service interruption (e.g., to avoid selecting a standby access point 502 that is experiencing the same service interruption). For example, if the service interruption is due to an event affecting multiple geographical locations (e.g., natural disaster or cyber attack), the certificate management system 104 can select the access point 108 of the standby access point 502 that is relatively far from the access point 108 experiencing the service interruption.
[0090] In some examples, the certificate generation module 124 can generate a certificate for the standby access point 502 used to take over the access point 108 according to the selection using a graph. For example, in addition to the associations between the access point 108, network address, record, subdomain, and domain described as Figure 2 , Figure 3 and Figure 4 , the certificate generation module 124 can also include information describing the association between the access point 108 and one or more standby access points 502.
[0091] Having considered example systems and techniques for generating access point certificates, now consider example processes to illustrate aspects of the techniques described herein.
[0092] Example Process
[0093] The following discussion describes techniques configured to utilize the previously described systems and devices. Generally, the functions, features, and concepts described in the context of the example processes described in this section can be adopted. In addition, the functions, features, and concepts described with respect to different figures and examples in this document can be interchanged with each other and are not limited to being implemented in the context of a specific figure or process. In addition, the blocks associated with different illustrative processes and corresponding figures herein are configured to be applied together and / or combined in different ways.
[0094] Accordingly, the various functions, features, and concepts described herein with respect to different example environments, devices, components, figures, and processes can be used in any suitable combination and are not limited to the combinations represented by the examples enumerated in this description. Aspects of each of the processes are configured to be implemented in hardware, firmware, software, or a combination thereof. The process is shown as a set of blocks specifying operations to be performed by one or more devices and is not necessarily limited to the order for performing the operations as shown by the respective blocks. In the following discussion sections, reference is made to Figures 1 to 3 .
[0095] Figure 7 Process 700 in an example implementation is depicted, in which a certificate management system generates a certificate for an access point based on a graph of domain relationship data of the access point.
[0096] Receive domain relationship data of an organization that describes one or more domains associated with an access point (block 702). For example, the certificate management system 104 receives the domain relationship data 106 from the listener 116 of the access point 108.
[0097] Then generate a graph based on the domain relationship data (block 704). For example, the certificate management system 104 implements the graph module 120 to generate the access point graph 122 of the access point 108. Determine whether there is a change in the domain relationship data of the access point (block 706). For example, the certificate management system 104 identifies whether new domain relationship data 106 of the access point 108 is received. In some implementations, the certificate management system 104 periodically queries the access point 108 for the domain relationship data 106. Alternatively or additionally, the certificate management system 104 automatically receives the domain relationship data 106 (e.g., without requesting that the domain relationship data 106 be transmitted or otherwise provided to the certificate management system 104). A change in the domain relationship data can include a change in the connection state of the access point 108.
[0098] In response to detecting a change in the domain relationship data 106 (e.g., a "yes" determination at block 706), the operations of process 700 return to block 702, where the certificate management system 104 receives the updated domain relationship data 106. Alternatively, in response to not detecting a change in the domain relationship data 106 (e.g., a "no" determination at block 706), generate a certificate for the access point based on the graph (block 708). For example, the certificate generation module 124 uses the access point graph 122 generated by the graph module 120 to generate the certificate 118. After and / or during generating the certificate 118, the certificate management system 104 continues to monitor for changes in the domain relationship data 106, as indicated by the dashed arrow returning from block 708 to block 706, and when the domain relationship data 106 changes, the operations of process 700 continue from block 706.
[0099] After a certificate is generated, the certificate is used to control traffic between the device and one or more domains via an access point (block 710). For example, the certificate management system 104 transmits the certificate 118 to the access point 108. The listener 116 of the access point 108 then authenticates the access request 130 for the control network 134 between the client device 126 and / or the application 128 and the domain 110 and / or its subdomains via the access point 108 using the certificate 118. In the case of using the certificate 118 to control traffic, the certificate management system 104 continues to monitor changes to the domain relationship data 106, as indicated by the dashed arrow returning from block 710 to block 706, and when the domain relationship data 106 changes, the operation of process 700 continues from block 706.
[0100] Figure 8 Process 800 in an example implementation is depicted, in which a certificate generated by a certificate management system is used to control data communication via an access point.
[0101] First, a request to access a domain via an access point is received from a device (block 802). For example, the access point 108 receives an access request 130 from the client device 126 to access one or more of the domain 110, one or more of the subdomains 112, one or more of the subdomains 114, or a combination thereof. The certificate associated with the access point is identified (block 804). For example, the listener 116 of the access point 108 identifies the certificate 118 generated by the certificate management system 104 for the access point 108.
[0102] Then it is determined whether the domain is included in the certificate (block 806). One or more of the domain 110, one or more of the subdomains 112, one or more of the subdomains 114, or a combination thereof are compared with the entries of the certificate 118 generated by the certificate generation module 124 based on the access point map 122 of the access point 108. In response to identifying that the domain is not included in the certificate (e.g., a "no" determination at block 806), access by the device is denied (block 808). For example, the listener 116 prohibits the client device 126 from accessing the requested domain via the access point 108.
[0103] Alternatively, in response to the domain being included in the certificate (e.g., a "yes" determination at block 806), it is determined whether the device is authenticated via the certificate (block 810). For example, the listener 116 transmits the certificate 118 to the client device 126 as part of a secure handshake and performs a hostname verification with the client device 126 to establish a secure data communication session between the client device 126 and the access point 108. In response to failing to authenticate the device using the certificate (e.g., a "no" determination at block 810), the operation of process 800 returns to block 808 and access by the device is denied.
[0104] Alternatively, in response to authenticating the device using a certificate (e.g., a "yes" determination at block 810), data is transmitted between the device and the domain via an access point (block 812). For example, the listener 116 controls data traffic 132 between the client device 126 and one or more of the requested domains 110, one or more of the sub-domains 112, one or more of the sub-domains 114, or a combination thereof based on the certificate 118 (e.g., according to the communication path represented by the edges of the nodes of the access point graph 122 from which the connection generated the certificate 118).
[0105] Example processes in accordance with one or more implementations have been described. Now, consider example systems and devices for implementing the various techniques described herein.
[0106] Example Systems and Devices
[0107] Figure 9 An example system 900 including an example computing device 902 is shown, which represents one or more computing systems and / or devices implementing the various techniques described herein. This is shown by including a database management system 104. For example, the computing device 902 is configured as a service provider server, a device associated with a client (e.g., a client device), a system-on-chip, and / or any other suitable computing device or computing system.
[0108] The example computing device 902 shown includes a processing system 904, one or more computer-readable media 906, and one or more I / O interfaces 908 communicatively coupled to each other. Although not shown, the computing device 902 is also configured to include a system bus or other data and command transfer system that couples the various components to each other. The system bus includes any one of different bus architectures or a combination of different bus architectures, such as a memory bus or memory controller, a peripheral bus, a universal serial bus, and / or a processor or local bus utilizing any one of various bus architectures. Various other examples are also envisioned, such as control lines and data lines.
[0109] The processing system 904 represents the functionality for performing one or more operations using hardware. Thus, the processing system 904 is shown as including hardware elements 910 that can be configured as a processor, functional blocks, etc. For example, the hardware elements 910 are implemented in hardware as an application-specific integrated circuit or other logic device formed using one or more semiconductors. The hardware elements 910 are not limited by the materials from which they are formed or the processing mechanisms employed therein. For example, alternatively or additionally, the processor includes semiconductors and / or transistors (e.g., electronic integrated circuits (ICs)). In such a context, the instructions executable by the processor are electronically executable instructions.
[0110] The computer-readable storage medium 906 is shown as including a memory / storage device 912. The memory / storage device 912 represents the capacity of the memory / storage device associated with one or more computer-readable media. The memory / storage device 912 represents volatile media (e.g., random access memory (RAM)) and / or non-volatile media (e.g., read-only memory (ROM), flash memory, optical discs, magnetic disks, etc.). The memory / storage device 912 is configured to include fixed media (e.g., RAM, ROM, fixed hard disk drive, etc.) and removable media (e.g., flash memory, removable hard disk drive, optical disc, etc.). In certain implementations, the computer-readable medium 906 is configured in various other ways as further described below.
[0111] The input / output interface 908 represents the functionality that allows a user to input commands and information into the computing device 902 and allows information to be presented to the user and / or other components or devices using a variety of input / output devices. Examples of input devices include a keyboard, a cursor control device (e.g., a mouse), a microphone, a scanner, a touch function (e.g., a capacitive sensor or other sensor configured to detect physical touch), a camera device (e.g., a device configured to recognize movement as a gesture not involving touch using visible or invisible wavelengths such as infrared frequencies), etc. Examples of output devices include a display device (e.g., a monitor or a projector), a speaker, a printer, a network card, a haptic response device, etc. Thus, the computing device 902 represents various hardware configurations that support user interaction as further described below.
[0112] Various techniques are described herein in the general context of software, hardware elements, or program modules. Generally, such modules include routines, programs, objects, elements, components, data structures, etc. that perform particular tasks or implement particular data types. The terms "module", "function", and "component" as used herein generally represent software, firmware, hardware, or a combination thereof. The features of the techniques described herein are platform-independent, which means that these techniques are configured to be implemented on a variety of commercial computing platforms having various processors.
[0113] Implementations of the modules and techniques are stored on or transmitted via some form of computer-readable medium. Computer-readable media include various media that can be accessed by the computing device 902. By way of example and not limitation, computer-readable media include "computer-readable storage media" and "computer-readable signal media".
[0114] "Computer-readable storage medium" refers to a medium and / or device that can achieve persistent and / or non-transitory storage of information compared to only signal transmission, carrier waves, or signals themselves. Thus, a computer-readable storage medium refers to a non-signal-bearing medium. Computer-readable storage media include hardware such as volatile and non-volatile, removable and non-removable media and / or storage devices implemented in a method or technology suitable for storing information such as computer-readable instructions, data structures, program modules, logic elements / circuits, or other data. Examples of computer-readable storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory, or other storage technologies, CD-ROM, digital versatile disc (DVD), or other optical storage devices, hard disks, cassette tapes, magnetic tapes, magnetic disk storage devices, or other magnetic storage devices, or other storage devices, tangible media, or articles of manufacture suitable for storing the required information accessible by a computer.
[0115] "Computer-readable signal medium" refers to a signal-bearing medium configured to transmit instructions, for example, to the hardware of computing device 902 via a network. Signal media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave, data signal, or other transmission mechanism. Signal media also include any information delivery medium. The term "modulated data signal" means a signal whose one or more characteristics are set or changed in such a way as to encode information in the signal. By way of example, and not limitation, communication media include wired media such as a wired network or direct wired connection, and wireless media such as acoustic, RF, infrared, and other wireless media.
[0116] As previously described, hardware element 910 and computer-readable medium 906 represent modules, programmable device logic, and / or fixed device logic implemented in hardware, which can be used in some embodiments to implement at least some aspects of the technologies described herein, such as to execute one or more instructions. In certain implementations, the hardware includes components of an integrated circuit or system-on-chip, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), complex programmable logic device (CPLD), and other implementations in silicon or other hardware. In such cases, the hardware operates as a processing device that executes program tasks defined by instructions and / or logic embodied in the hardware, and as hardware for storing instructions for execution, such as the previously described computer-readable storage medium.
[0117] The foregoing combinations are used to implement the various techniques described herein. Accordingly, software, hardware, or executable modules are implemented as one or more instructions and / or logic embodied on some form of computer-readable storage medium, and / or by one or more hardware elements 910. The computing device 902 is configured to implement the instructions and / or functions corresponding to the software and / or hardware modules. Accordingly, the implementation of modules that may be executed as software by the computing device 902 is at least partially implemented in hardware, e.g., by using the hardware elements 910 of the processing system 904 and / or the computer-readable storage medium. The instructions and / or functions may be executed / operated by one or more articles of manufacture (e.g., one or more computing devices 902 and / or the processing system 904) to implement the techniques, modules, and examples described herein.
[0118] The techniques described herein are supported by various configurations of the computing device 902 and are not limited to the specific examples of the techniques described herein. The functionality is also configured to be implemented in whole or in part by using a distributed system, e.g., via the platform 916 through the "cloud" 914, as described below.
[0119] The cloud 914 includes and / or represents a platform 916 of resources 918. The platform 916 abstracts the underlying functionality of the hardware (e.g., servers) and software resources of the cloud 914. The resources 918 include applications and / or data utilized when performing computer processing on servers remote from the computing device 902. The resources 918 also include services provided over the Internet and / or over a subscriber network such as a cellular or Wi-Fi network.
[0120] The platform 916 is configured to abstract resources and functionality to connect the computing device 902 with other computing devices. The platform 916 is also configured to abstract the scaling of resources to provide a level of scaling corresponding to the demands encountered for the resources 918 implemented via the platform 916. Accordingly, in an interconnected device implementation, the implementation of the functionality described herein is configured to be distributed throughout the system 900. For example, in some configurations, the functionality is implemented partially on the computing device 902 and via the platform 916 that abstracts the functionality of the cloud 914.
[0121] Conclusion
[0122] Although the present invention has been described in language specific to structural features and / or methodological acts, the invention defined in the appended claims is not necessarily limited to the specific features or acts described. Rather, the specific features and acts are disclosed as example forms of implementing the claimed invention.
Claims
1. A method comprising: generating a graph defining a relationship between a domain and a plurality of different access points, the plurality of different access points comprising a serving access point and one or more backup access points, wherein the plurality of different access points are represented by a plurality of nodes in the graph; upon detecting a change in connectivity of the serving access point, generating credentials for accessing data via the domain based on a relationship between the domain and the one or more backup access points; and Access to the data is controlled using the certificate.
2. The method according to claim 1, wherein: The relationship between the domain and the plurality of different access points is based on the geographic location of the serving access point.
3. The method according to claim 2, wherein: An order of the plurality of nodes in the graph is based on a proximity of corresponding backup access points to the geographic location of the serving access point.
4. The method according to claim 1, wherein: The detection of the change in the connection is based on one or more of a traffic speed associated with the serving access point or a network connection status of the serving access point.
5. The method according to claim 1, further comprising: traversing the graph to detect a node among the plurality of nodes corresponding to a backup access point, the backup access point being adjacent to a node among the plurality of nodes corresponding to the serving access point; as well as A relationship between the domain and the backup access point is determined based on the map, wherein the certificate is generated based on the relationship.
6. The method according to claim 1, wherein: The one or more backup access points are associated with one or more relationships between the domain and corresponding access points corresponding to child nodes of one or more nodes of the plurality of nodes.
7. The method according to claim 1, further comprising: A backup access point is selected from the one or more backup access points based on one or more of a numerical amount of data transmission at the backup access point, a geographic location of the serving access point, or a geographic location of the backup access point.
8. The method according to claim 1, wherein: At least one backup access point is associated with the data center.
9. A method comprising: generating a graph defining a relationship between a network address, an access point, and one or more records associated with at least one domain, the relationship being based on the network address being accessed from a plurality of geographic locations; generating a certificate for the network address based on the graph; as well as Data transfer between the at least one domain and the device is controlled based on the certificate.
10. The method according to claim 9, wherein: The at least one domain is served by a plurality of providers, the plurality of providers comprising a first provider hosted by an entity and a second provider hosted by a content delivery network different from the entity, wherein the first provider is represented in the graph by a first node and the second provider is represented in the graph by a second node.
11. The method of claim 10, further comprising allowing data transfer between the at least one domain and the device based on verifying the validity of the certificate by the second provider.
12. The method according to claim 9, wherein: The one or more records include an indication of one or more of the at least one domain or one or more sub-domains associated with the at least one domain.
13. The method according to claim 9, wherein: Generating the credential is based on receiving a request for the data transfer, the request being received from at least one of the plurality of geographic locations.
14. The method according to claim 9, wherein: The graph further includes a plurality of nodes representing the network address, the access point, and the at least one domain, wherein respective ones of the plurality of nodes are connected by connecting lines representing a relationship between the network address, the access point, and the at least one domain.
15. The method according to claim 9, wherein: The network address is a virtual Internet Protocol address configured for access by at least one of a physical network interface or the device.
16. A method comprising: generating a graph defining a first relationship between a network address and a record associated with a domain and a second relationship between the network address and an alias record associated with the domain, the second relationship being defined based on a type of the domain; generating a credential for accessing data via the domain based on at least one of the first relationship or the second relationship; as well as Data transfer between the domain and the device is controlled based on the certificate.
17. The method according to claim 16, wherein: The graph further includes a plurality of nodes representing the network addresses, the records, and the alias records, wherein corresponding nodes of the plurality of nodes are connected by connecting lines representing the first relationship and the second relationship.
18. The method according to claim 17, wherein: The certificate is generated based on the first relationship that is a neighboring node according to the network address and the record in the graph.
19. The method according to claim 16, wherein: The certificate is generated based on the second relationship between the network address and the record separated by one or more nodes in the graph.
20. The method of claim 16, wherein: The type of the domain is a root domain; and The alias record corresponds to the first relationship.
Citation Information
Cited By
Wildcard-free certificates for network address domains
US12615247B2