Method for optimizing selection of hardware security server and apparatus therefor
By sending queries to candidate hardware security servers and generating compliance scores, the problem of choosing suitable hardware security servers is solved, and server capability comparison and backup server selection are achieved based on specific requirements, improving the usability of the system.
Patent Information
- Application Number
- CN202380088519.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-23
- Filing Date
- 2023-12-08
- Publication Date
- 2025-08-15
AI Technical Summary
When selecting a hardware security server, it is difficult for the prior art to effectively compare the capabilities of the hardware security server provided by different vendors and select the most suitable server, which makes selection difficult.
By sending an operation status request or capability query to the candidate hardware security server, receiving data and generating compliance scores, ranking candidate servers based on the scores, recommending a suitable hardware security server.
The selection process of hardware security servers is optimized, allowing the ability of multiple servers to be compared according to specific requirements, and selecting a backup server when the host is unavailable, improving the availability and applicability of the system.
Smart Images

Figure CN120500832A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to U.S. application No. 18 / 087,955, filed on December 23, 2022, which is hereby incorporated by reference in its entirety. Technical Field
[0003] The present technology relates to methods and systems for optimizing the selection of hardware security servers. Background Art
[0004] Hardware security server agents provide users with a single interface on the front end, while enabling multiple hardware security server implementations on the back end. The challenge with hardware security servers is that different vendors or providers offer hardware security servers with varying capabilities. Because each hardware security server has varying capabilities, selecting the appropriate hardware security server for a given client can be challenging. For example, a client might be deployed in one location, and some hardware security servers might be closer to the client than others.
[0005] In this example, perhaps one of the hardware security servers, while it may be further away than the others, may be able to better support the client's other needs or requirements. In this and other similar situations, choosing a recommended hardware security server can be difficult. Summary of the Invention
[0006] A method for optimizing the selection of a hardware security server for a given client includes receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, the method being implemented in collaboration with a cloud service or a network traffic management system, the network traffic management system including one or more network traffic management modules, server modules, or client modules. The hardware security requirements may consist of one or more server operating rules. A compliance score for the candidate hardware security server is then generated based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server. The method may then include generating a ranking of the candidate hardware security servers based on their compliance scores, and providing a hardware security server recommendation for one of the candidate hardware security servers to the client based on the generated ranking of the candidate hardware security servers having a compliance score above a predetermined threshold.
[0007] A network traffic management device includes receiving data from a candidate hardware security server after sending an operation status request or capability query to the candidate hardware security server, the network traffic management device including: a memory including programming instructions stored thereon; and one or more processors configured to execute the stored programming instructions to optimize the selection from the hardware security servers. The hardware security requirements may be composed of one or more server operation rules. A compliance score for the candidate hardware security server is then generated based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server. The executed instructions may then generate a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers, and provide a hardware security server recommendation for one of the candidate hardware security servers to the client based on the generated ranking of the candidate hardware security servers having a compliance score above a predetermined threshold.
[0008] A non-transitory computer-readable medium includes receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, the non-transitory computer-readable medium having instructions stored thereon for including executable code that, when executed by one or more processors, causes the processor to optimize the selection from the hardware security servers. The hardware security requirements may be composed of one or more server operating rules. A compliance score for the candidate hardware security server is then generated based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server. The processor may then generate a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers, and provide a hardware security server recommendation for one of the candidate hardware security servers to the client based on the generated ranking of the candidate hardware security servers having a compliance score above a predetermined threshold.
[0009] A network traffic management system includes: one or more traffic management modules, server modules or client modules; a memory including programming instructions stored thereon; and one or more processors configured to execute the stored programming instructions to optimize the selection from hardware security servers, the network traffic management system including receiving data from a candidate hardware security server after sending an operation status request or capability query to the candidate hardware security server. The hardware security requirements may be composed of one or more server operation rules. A compliance score of the candidate hardware security server is then generated based on the hardware security server requirements, the built-in hardware security server requirements and the data received from the candidate hardware security server. The executed instructions may then generate a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers, and provide a hardware security server recommendation for one of the candidate hardware security servers to the client based on the generated ranking of the candidate hardware security servers whose compliance scores are higher than a predetermined threshold.
[0010] The present technology provides several advantages for helping optimize the selection of hardware security servers, including providing methods, non-transitory computer-readable media, network traffic management devices, and network traffic management systems. The technology allows for comparing the various capabilities of multiple hardware security servers against the requirements required for hardware security server recommendations. Additionally, the technology advantageously provides a method for selecting a backup hardware security server that can be used if a hardware security server is unavailable. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 is a block diagram of an exemplary network traffic management system having a network traffic management device;
[0012] Figure 2 is a block diagram of an exemplary network traffic manager device;
[0013] Figure 3 is a flow chart of an exemplary method for optimizing selection of a hardware security server;
[0014] Figure 4 is a flow chart of an exemplary method for optimizing selection of backup hardware security servers; and
[0015] Figure 5 is an exemplary sequence flow diagram illustrating a method for optimizing selection of hardware security servers. DETAILED DESCRIPTION
[0016] The proposed technology is a method for optimizing the selection of hardware security servers for a given client. The technology solves the problem by measuring and scoring the various capabilities of hardware security servers to determine the recommended hardware security servers.
[0017] The proposed technology can also shield backend failures from the user infrastructure at the front end of the hardware security server agent by selecting the most suitable hardware security server as a redundant unit for real-time key migration, thereby promoting overall high availability. In some examples, because the hardware security agent is connected to multiple hardware security servers at the back end, if any of the hardware security servers becomes unavailable, the hardware security server agent can select an alternative hardware security server where key information has been replicated. This allows users to increase the availability of hardware security servers to the user infrastructure.
[0018] An example of the proposed technology includes a network environment 10 incorporating a network traffic management system for optimizing the selection of hardware security servers and a network traffic manager device 14. Figure 1 and Figure 2 . The exemplary environment 10 includes a plurality of client computing devices 12(1) to 12(n), a network traffic manager device 14, a network traffic manager device 14, and a plurality of hardware security servers 16(1) to 16(n) coupled together via a communication network 30, but the environment may include other types and numbers of systems, devices, components and / or elements and other topologies and deployments. Although not shown, the exemplary environment 10 may include additional network components, such as routers, switches, and other devices, which are well known to those of ordinary skill in the art and therefore will not be described herein.
[0019] More specifically refer to Figure 1 and Figure 2 , the network traffic manager device 14 of the network traffic management system is coupled to the plurality of client computing devices 12(1) to 12(n) via a communication network 30, but the plurality of client computing devices 12(1) to 12(n) and the network traffic manager device 14 may also be coupled together via other topologies. Additionally, the network traffic manager device 14 is coupled to the network traffic manager device 14 via the communication network 30, but the network traffic manager device 14 and the network traffic manager device 14 may also be coupled together via other topologies.
[0020] like Figure 2As shown, a network traffic manager device 14 of a network traffic management system is coupled to a client computing device 12(1), a recommended hardware security server 16(1), and a backup hardware security server 16(2) via a communications network 30. In some examples, the network traffic manager device 14 can use both the recommended hardware security server 16(1) and the backup hardware security server by directing traffic to both. The recommended hardware security server 16(1) and the backup hardware security server 16(2) can be replicated, and the keys of the recommended hardware security server 16(1) and the backup hardware security server 16(2) can be replicated. This can allow the network traffic manager device 14 to shield backend failures from user infrastructure because it can ensure that the recommended hardware security server 16(1) and the backup hardware security server have copies of the keys so that if one of these devices or services fails, the network traffic manager device 14 can select an alternative location where critical information has been replicated.
[0021] The network traffic manager device 14 assists in optimizing the selection of hardware security servers, as shown and described herein by way of example, but the network traffic manager device 14 can perform other types and / or quantities of functions. The network traffic manager device 14 includes a processor or central processing unit (CPU), memory, and a communication system coupled together by a bus arrangement, but the network traffic manager device 14 can include other types and quantities of elements in other configurations. In this example, the bus is a PCI Express bus, but other bus types and links can be used.
[0022] The processor within the network traffic manager device 14 may execute one or more computer-executable instructions stored in memory for the methods shown and described with reference to the examples herein, but the processor may execute other types and numbers of instructions and perform other types and numbers of operations. The processor 18 may include one or more central processing units ("CPUs") or general-purpose processors having one or more processing cores, such as a processor 18. processor, but other types of processors may be used (e.g., ).
[0023] The memory within the network traffic manager device 14 may include one or more tangible storage media, such as RAM, ROM, flash memory, CD-ROM, floppy disk, hard drive, solid-state memory, DVD, or any other memory storage type or device known to those of ordinary skill in the art, including combinations thereof. The memory 20 may store one or more non-transitory computer-readable instructions of the present technology, as shown and described with reference to the examples herein, which instructions may be executed by the processor. Figure 3 and Figure 4The exemplary flow charts shown represent example steps or actions of the present technology, which may be embodied or expressed as one or more non-transitory computer or machine-readable instructions stored in a memory, which may be executed by a processor and / or implemented by configured logic.
[0024] Thus, the memory of the network traffic manager device 14 may store one or more applications that may include computer-executable instructions that, when executed by the network traffic manager device 14, cause the network traffic manager device 14 to perform actions, such as transmitting, receiving, or otherwise processing, for example, messages, and performing the operations described below with reference to Figure 3 and Figure 4 and other actions described and illustrated. An application may be implemented as a module or component of another application. Additionally, an application may be implemented as an operating system extension, module, plug-in, or the like. An application may be implemented as a module or component of another application. Additionally, an application may be implemented as an operating system extension, module, plug-in, or the like. Still further, an application may operate in a cloud-based computing environment. An application may execute within a virtual machine or virtual server that may be managed in a cloud-based computing environment. Additionally, applications, including the network traffic manager device 14 itself, may be located in a virtual server that runs in a cloud-based computing environment rather than being tied to one or more specific physical network computing devices. Additionally, an application may run in one or more virtual machines (VMs) executing on the network traffic manager device 14. Additionally, in at least one of the various embodiments, the virtual machines running on the network traffic manager device 14 may be managed or supervised by a hypervisor.
[0025] The communication system in the network traffic manager device 14 is used to operatively couple and communicate between the network traffic manager device 14, the plurality of client computing devices 12(1) to 12(n), and the network traffic manager device 14, all coupled together via a communication network 30, such as one or more local area networks (LANs) and / or wide area networks (WANs), although other types and numbers of communication networks or systems and other types and numbers of connections and configurations with other devices and elements may be used. By way of example only, the communication networks, such as the local area networks (LANs) and wide area networks (WANs), may use Ethernet-based TCP / IP and industry standard protocols, including NFS, CIFS, SOAP, XML, LDAP, and SNMP, although other types and numbers of communication networks may be used. In this example, the bus is a PCI Express bus, although other bus types and links may be used.
[0026] Each of the plurality of client computing devices 12(1) to 12(n) of the network traffic management system 10 includes a central processing unit (CPU) or processor, memory, input / display device interfaces, configurable logic devices, and input / output systems or I / O systems coupled together by a bus or other link. Additionally, the plurality of client computing devices 12(1) to 12(n) may include any type of computing device capable of receiving, presenting, and facilitating user interactions, such as client computers, network computers, mobile computers, mobile phones, virtual machines (including cloud-based computers), etc. Each of the plurality of client computing devices 12(1) to 12(n) utilizes a network traffic manager device 14 to perform one or more operations with the network traffic manager device 14, such as, by way of example only, communicating with the plurality of hardware security servers 16(1) to 16(n) via a communication network 30 between the network traffic manager device 14 and the plurality of hardware security servers 16(1) to 16(n), but may also perform other functions.
[0027] The plurality of hardware security servers 16(1) to 16(n) may include a plurality of hardware security modules. The plurality of hardware security servers 16(1) to 16(n) may be computer hardware and / or software (e.g., a computing device) configured to store cryptographic keys, perform cryptographic operations (such as generating keys, encrypting data, and decrypting data), and implement security policies for using and / or accessing cryptographic keys. The plurality of hardware security servers 16(1) to 16(n) may include a physical enclosure that reduces the likelihood of observing and / or tampering with sensitive data (such as private keys of the plurality of hardware security servers 16(1) to 16(n)). The enclosure may cover potential electrical probing points and display visible damage if the enclosure is tampered with. The plurality of hardware security servers 16(1) to 16(n) may have different APIs with different functionality that perform the same task. The plurality of hardware security servers 16(1) to 16(n) may also comply with public key cryptography standards (PKCS). PKCS may be a class of public key cryptography standards. PKCS#11 (also known as Cryptoki) can be a platform-specific, independent API for interfacing with multiple hardware security servers 16(1) to 16(n) that can define data types, functions, and other components available to applications that implement the PKCS#11 standard. The data types can represent items stored on the multiple hardware security servers 16(1) to 16(n), such as cryptographic keys. In some examples, the platform-specific, independent API can implement different methods and functions for importing, exporting, encrypting, and decrypting cryptographic keys.
[0028] The network traffic manager device 14 may receive requests transmitted by a plurality of client computing devices 12(1) to 12(n) using a communication network 30. For example, the plurality of hardware security servers 16(1) to 16(n) may perform operations such as load balancing, rate monitoring, caching, encryption / decryption, session management (including key generation), address translation, and / or access control. The network traffic manager device 14 may process the requests and perform various operations on behalf of the plurality of client computing devices 12(1) to 12(n). The network traffic manager device 14 may perform various cryptographic and communication operations to communicate with the plurality of hardware security servers 16(1) to 16(n).
[0029] Typically, a plurality of hardware security servers 16(1) to 16(n) may perform various computing tasks implemented using a computing environment. The computing environment may include computer hardware, computer software, and combinations thereof. As a specific example, the computing environment may include general-purpose and / or special-purpose processors, configurable and / or hard-wired electronic circuitry, communication interfaces, and computer-readable memory for storing computer-executable instructions to enable the processor to perform a given computing task. The logic for performing a given task may be specified within a single module or spread across multiple modules. As used herein, the terms "module" and "component" may refer to an implementation within one or more dedicated hardware devices or appliances (e.g., computers), and / or an implementation within software hosted by one or more hardware devices or appliances that may host one or more other software applications or implementations. Additionally, the network traffic manager device 14 may include a cryptographic offload module for offloading cryptographic operations to the plurality of hardware security servers 16(1) to 16(n).
[0030] The plurality of hardware security servers 16(1) to 16(n) may be implemented using a variety of different computer architectures. For example, the plurality of hardware security servers 16(1) to 16(n) may be implemented as plug-in circuit cards that are connected to the input / output or peripheral interface of a computer, such as a peripheral component interconnect express (PCIe), and may include connectors for connecting to a backplane or other connector of the computer. As another example, the plurality of hardware security servers 16(1) to 16(n) may be implemented as computer appliances connected via a computer network (a plurality of network-based hardware security servers 16(1) to 16(n)). As another example, the plurality of hardware security servers 16(1) to 16(n) may be implemented as virtualized resources within a cloud computing infrastructure (a plurality of cloud-based hardware security servers 16(1) to 16(n)). The plurality of hardware security servers 16(1) to 16(n) may have different storage capacities and / or acceleration capabilities. For example, the physical plurality of hardware security servers 16(1) to 16(n) may be divided into a plurality of logical plurality of hardware security servers 16(1) to 16(n), wherein each logical plurality of hardware security servers 16(1) to 16(n) may have different capabilities and may be accessed using different account credentials. The logical plurality of hardware security servers 16(1) to 16(n) may also be referred to as partitions or tokens of the physical plurality of hardware security servers 16(1) to 16(n). The partitions of the plurality of hardware security servers 16(1) to 16(n) may be isolated from each other so that keys and data on one partition are not visible in different partitions. The partitions may share hardware and other resources, or the partitions may use specific non-shared hardware and resources. The plurality of hardware security servers 16(1) to 16(n) may use various storage technologies, such as random access memory (RAM), non-volatile RAM, flash memory, hard disk drives, solid-state drives, or other storage implementations. The plurality of hardware security servers 16(1) to 16(n) may enable and / or deny access to keys based on security policies. For example, a security policy may specify that a particular key may be used / accessed only when authorized account credentials are presented to the plurality of hardware security servers 16(1) to 16(n).
[0031] In one example, the network traffic manager device 14 can be a dedicated computing device including a processor and a computer-readable memory. The memory of the network traffic manager device 14 can store one or more applications that can include computer-executable instructions that, when executed by the network traffic manager device 14, cause the network traffic manager device 14 to perform actions such as transmitting, receiving, or otherwise processing, for example, messages, and to perform other actions such as offloading cryptographic operations to the plurality of hardware security servers 16(1) to 16(n) and accessing cryptographic keys stored on the plurality of hardware security servers 16(1) to 16(n). Applications can be implemented as components of other applications. Additionally, applications can be implemented as operating system extensions, plug-ins, and the like.
[0032] Therefore, the technology disclosed herein should not be construed as limited to a single environment, and other configurations and architectures are also contemplated. For example, Figure 1 and Figure 2 The plurality of hardware security servers 16(1)-16(n) depicted in FIG may operate within the network traffic manager device 14, rather than as stand-alone servers that communicate with the network traffic manager device 14 via the communication network 30. In this example, the plurality of hardware security servers 16(1)-16(n) operate within the memory 20 of the network traffic manager device 14.
[0033] Although the network traffic manager device 14 is shown in this example as comprising a single device, in other examples, the network traffic manager device 14 may include multiple devices or blades, each having one or more processors, each processor having one or more processing cores that implement one or more steps of the present technology. In these examples, one or more of the devices may have a dedicated communication interface or memory. Alternatively, one or more of the devices may utilize memory, a communication interface, or other hardware or software components of one or more other communicatively coupled devices. Additionally, in other examples, one or more of the devices that collectively make up the network traffic manager device 14 may be standalone devices or integrated with, for example, one or more other devices or applications, multiple hardware security servers 16(1) to 16(n), or the network traffic manager device 14, or the network traffic manager device 14, or an application coupled to a communication network. Furthermore, in these examples, one or more of the devices of the network traffic manager device 14 may be located in the same or different communication networks 30, including, for example, one or more public networks, private networks, or cloud networks.
[0034] Although an exemplary network traffic management system 10 having a plurality of client computing devices 12(1) to 12(n), a network traffic manager device 14, a plurality of hardware security servers 16(1) to 16(n), and a communication network 30 is described and shown herein, other types and numbers of systems, devices, blades, components, and elements in other topologies may be used. It should be understood that the example systems described herein are for exemplary purposes, as many variations in the specific hardware and software used to implement the examples are possible, as will be appreciated by those skilled in the relevant art.
[0035] Furthermore, each of the example systems may be conveniently implemented using one or more general purpose computer systems, microprocessors, digital signal processors, and microcontrollers programmed according to the teachings of the examples, as described and illustrated herein and as will be understood by those of ordinary skill in the art.
[0036] One or more of the components depicted in the network traffic management system (e.g., such as the network traffic manager device 14, the plurality of client computing devices 12(1) to 12(n), the network traffic manager device 14, and the plurality of hardware security servers 16(1) to 16(n)) may be configured to operate as virtual instances on the same physical machine. In other words, Figure 1 The network traffic manager device 14, the plurality of client computing devices 12(1) to 12(n), the network traffic manager device 14, or one or more of the plurality of hardware security servers 16(1) to 16(n) shown in FIG. 1 may operate on the same physical device, rather than as a single device. Figure 1 Multiple client computing devices 12(1) to 12(n), network traffic manager device 14, network traffic manager device 14, or multiple hardware security servers 16(1) to 16(n) may be more than Figure 1 The plurality of client computing devices 12 ( 1 ) to 12 ( n ), the network traffic manager device 14 , and the plurality of hardware security servers 16 ( 1 ) to 16 ( n ) may be implemented as applications on the network traffic manager device 14 .
[0037] In addition, two or more computing systems or devices may replace any one of the systems or devices in any example. Thus, the principles and advantages of distributed processing, such as redundancy and replication, may also be implemented as needed to improve the robustness and performance of the devices and systems of the examples. The examples may also be implemented on a computer system that is extended across any suitable network using any suitable interface mechanism and flow technology, including (by way of example only) any suitable form of telephone traffic (e.g., voice and modem), wireless traffic media, wireless traffic networks, cellular traffic networks, G3 traffic networks, public switched telephone networks (PSTN), packet data networks (PDN), the Internet, intranets, and combinations thereof.
[0038] The examples may also be embodied as a non-transitory computer-readable medium having stored thereon instructions for one or more aspects of the techniques described and illustrated by way of example herein, which instructions, when executed by a processor (or configurable hardware), cause the processor to perform the steps necessary to implement the methods of the examples as described and illustrated herein.
[0039] Now refer to Figures 1 to 5 An example of a method for optimizing selection from a plurality of hardware security servers is described. First, in step 305, the network traffic manager device 14 receives or retrieves hardware security server requirements for a hardware security server, such as Figure 3As shown. The hardware security server requirements may be built into the hardware security server by canned defaults or other methods known in the art. In some examples, the hardware security server requirements may include one or more server operation rules, such as meeting the client location, the operating data range of the hardware security server, the availability status indicator of the hardware security server, the required response time, the number of transactions per second per load data requirement, and combinations thereof. The operating data range may be the price of use of the hardware security server 16(1). The client 12(1) may require a hardware security server 16(1) that meets multiple hardware security server requirements. The client 12(1) may require that the hardware security server 16(1) be located at a specific location where the client is located or within a range of the client location. The client 12(1) may have a budget for the price of use of the required hardware security server 16(1) and, in response, may have a price range for use of the hardware security server 16(1). The client 12(1) may also require that the hardware security server 16(1) be available on certain days or times of the week, month, or year. In some embodiments, the client (1) may have a requirement for a specific response time or a range of acceptable response times for the hardware security server 16 (1). The hardware security server 16 (1) may also be required to process a specific number of transactions per second per payload for the client (1). The requirement may include verifying whether the hardware security server 16 (1) meets regulatory compliance requirements. In order to verify whether the hardware security server 16 (1) is compliant, a request may be sent to the hardware security server 16 (1) to request certification of the hardware security server 16 (1) for authentication and verification purposes. Regulatory compliance requirements may include FIPS-140 requirements. In some embodiments, the network traffic manager may retrieve the cloud provider's preferences for requirements for the hardware security server 16 (1). Additionally, the requirement may include comparing the persistence of multiple hardware security servers 16 (1) to 16 (n). For example, each of the hardware security servers 16(1)-16(n) may perform key operations, such as generating random numbers or creating keys internally within the hardware security server 16(1)-16(n), and thus ensuring persistence between the client 12(1) and the hardware security server 16(1)-16(n) may be important. In other examples, requirements for the hardware security servers 16(1)-16(n) may include the ability to support elliptic curve cryptography. Requirements may also include that the hardware security server 16(1) has the ability to support ECC or other desired cryptographic algorithms as an aspect of the logic of the hardware security server 16(1).
[0040] In step 310, the network traffic manager device 14 may receive data from the candidate hardware security server after sending an operational status request or capability query to the candidate hardware security server in response to receiving the hardware security server requirement. Some of the criteria in the hardware security requirement may be performance data or other runtime observation data. Some of the received data may come from responses to the status request of the candidate hardware security server. A capability query may also be sent to the candidate hardware security server. The hardware security server requirement may include one or more server operational rules. The operational status request may include a request for the hardware security server location, operational data, availability, actual response time, transactions per second per load capability, persistent elliptic curve cryptography support capability, and other hardware security server 16(1) capabilities known in the art. In this example, as Figure 1 As shown, the network traffic manager device 14 can operate as a proxy between multiple client computing devices 12(1) to 12(n) and multiple hardware security servers 16(1) to 16(n). The network traffic manager device 14 can allow the client 12(1) to interact with a single interface while shielding the underlying implementation details of the multiple hardware security servers 16(1) to 16(n). The proxy is an agent that can be located in the communication path between the client (e.g., multiple client computing devices 12(1) to 12(n)) and the server (e.g., multiple hardware security servers 16(1) to 16(n)), which can intercept communications (e.g., network packets, frames, datagrams, and messages) between the multiple client computing devices 12(1) to 12(n) and the multiple hardware security servers 16(1) to 16(n). In some examples, the network traffic manager device 14 may perform security and / or routing functions for the plurality of client computing devices 12(1) to 12(n), such as performing encryption and / or decryption operations on traffic flowing between the plurality of client computing devices 12(1) to 12(n) and the plurality of hardware security servers 16(1) to 16(n). Specifically, the network traffic manager device 14 may take actions on behalf of the plurality of hardware security servers 16(1) to 16(n), such as encrypting traffic sent by the plurality of hardware security servers 16(1) to 16(n), decrypting traffic sent to the plurality of hardware security servers 16(1) to 16(n), and performing handshake operations to exchange cryptographic information with the plurality of client computing devices 12(1) to 12(n). Additionally, the network traffic manager device 14 may send requests to the plurality of hardware security servers 16(1) to 16(n) to receive responses that include specifications of the plurality of hardware security servers 16(1) to 16(n), as outlined above.
[0041] In step 315, the network traffic manager device 14 may generate a compliance score for each of the candidate hardware security servers 16(1) to 16(n). To generate the compliance score, the network traffic manager device 14 evaluates each of the candidate hardware security servers by determining whether different characteristics of the candidate hardware security servers meet the hardware security server requirements. Various determinations that may be made by the network traffic manager device 14 will now be described. In some examples, the network traffic manager device 14 may determine whether the operational status response meets the hardware security server requirements based on a received operational status response. In some embodiments, the hardware security server may be passively monitored by observing the hardware security server. In some embodiments, performance metrics of the hardware security server may be used to determine whether the operation of the hardware security server also meets the hardware security server requirements. As outlined above, the hardware security requirements may consist of one or more operational rules or requirements. For example, the recommended hardware security server 16(1) may need to be located at the client location, within an operational data range or a usage price range, be certified, and meet the client's availability requirements. If the operational status response meets the hardware security server requirements, the network traffic manager 14 assigns a high score to the candidate hardware security server 16(1). If the operational status response does not meet the hardware security server requirement, the network traffic manager 14 assigns a low score to the candidate hardware security server 16(1). These scores are later used to generate a ranking for each of the candidate hardware security servers 16(1) to 16(n). In one embodiment, the network traffic manager device 14 determines whether the hardware security server location of the candidate hardware security server 16(1) is the client location or is within a determined range of client locations. This determination can be used to generate a score for that particular requirement, which can later be combined with the scores assigned by the network traffic manager device 14 for each requirement to generate a ranking. If the hardware security server location of the candidate hardware security server 16(1) is the same client location, a high score can be assigned. If the hardware security server location of the candidate hardware security server 16(1) is not the same hardware security server location, is not the same client location, but is within a determined range of client locations, a medium score can be assigned. A determined range of hardware security server locations can be received from the client 12(1) as a requirement. The determined range can be set as a default value by the network traffic manager device 14. If the hardware security server location of the candidate hardware security server 16(1) is not within the determined range of the client 12(1), then the requirement may be assigned a low score for calculating or generating the ranking. In some embodiments, if the network traffic manager device 14 determines that the hardware security server location of the candidate hardware security server 16(1) is not within the determined range of the client 12(1), then the candidate hardware security server 16(1) may be excluded from being a possible recommendation for the hardware security server 16(1).In some embodiments, the network traffic manager device 14 may determine whether the candidate hardware security server 16(1) also meets other requirements. In some embodiments, if the network traffic manager device 14 determines that the actual response time of the candidate hardware security server 16(1) is not within the determined range of the required response time, a low score may be assigned to the requirement.
[0042] In some embodiments, a high score may be assigned to a request if the network traffic manager device 14 determines that the actual response time of the candidate hardware security server 16(1) is within a determined range of the response time of the request. In some embodiments, a high score may be assigned if the network traffic manager device 14 determines that the transactions per second per load capability of the candidate hardware security server 16(1) meets the transactions per second per load requirement requested by the client 12(1). A high score may be assigned if the transactions per second per load capability of the candidate hardware security server 16(1) is within a determined range of the transactions per second per load requirement requested by the client 12(1). A low score may be assigned if the transactions per second per load capability of the candidate hardware security server 16(1) is not within the determined range of the transactions per second per load requirement requested by the client 12(1). A high score may also be assigned to a request if the client 12(1) requests that the hardware security server 16(1) have a specific capability and the candidate hardware security server 16(1) has the requested capability. For example, if the client 12(1) requests that the recommended hardware security server 16(1) have persistent elliptic curve cryptography support and the candidate hardware security server 16(1) supports persistent elliptic curve cryptography, a high score may be assigned. If the candidate hardware security server 16(1) does not support persistent elliptic curve cryptography, a high score may be assigned. Other features of hardware security servers 16(1) known in the art may be assigned high scores, medium scores, or low scores, depending on whether the candidate hardware security server 16(1) has the requested feature. The magnitude of the scores may also vary and need not be high, medium, and low, and may be scored differently.
[0043] In some embodiments, the network traffic manager device 14 determines whether the operational data of the candidate hardware security server 16 (1) is within the operational data range of the hardware security server requirement. If the operational data of the candidate hardware security server 16 (1) is within the operational data range of the hardware security server requirement received from the client 12 (1), a high score may be assigned for the requirement. If the operational data of the candidate hardware security server 16 (1) is within the operational data range of the hardware security server requirement received from the client 12 (1) but in a lower range, a higher score may be assigned. If the operational data of the candidate hardware security server 16 (1) is within the operational data range of the hardware security server requirement received from the client 12 (1) but in a higher range, a medium score may be assigned. If the operational data of the candidate hardware security server 16 (1) is not within the operational data range of the hardware security server requirement received from the client 12 (1), a low score may be assigned. In some embodiments, if the network traffic manager device 14 determines that the operational data of the candidate hardware security server 16(1) is not within the range of operational data required for the hardware security server received from the client 12(1), the candidate hardware security server 16(1) may be excluded from being a possible recommendation for the hardware security server 16(1).
[0044] In some embodiments, the network traffic manager device 14 determines whether the availability of the candidate hardware security server 16(1) includes an availability status indicator of the hardware security server 16(1). If the network traffic manager device 14 determines that the availability of the candidate hardware security server 16(1) includes the availability status indicator of the hardware security server 16(1), a high score may be assigned. If the network traffic manager device 14 determines that the availability of the candidate hardware security server 16(1) does not include the availability status indicator of the hardware security server 16(1), a low score may be assigned. In some embodiments, if the network traffic manager device 14 determines that the availability of the candidate hardware security server 16(1) does not include the availability status indicator of the hardware security server 16(1), the candidate hardware security server 16(1) may be excluded from being a possible recommendation for the hardware security server 16(1).
[0045] In step 320, the network traffic manager device 14 generates a ranking for each of the candidate hardware security servers 16(1) to 16(n). In other words, if the network traffic manager device 14 determines in step 325 that the candidate hardware security server 16(1) meets the hardware security server requirements, the candidate hardware security server 16(1) is ranked with other determined compliant candidate hardware security servers 16(1) to 16(n). The generated ranking may also be based on the determinations outlined above, such as location, availability, price of use or scope of operational data, availability, and compliance determinations. In some embodiments, a command may be sent to each of the candidate hardware security servers 16(1) to 16(n) to retrieve a certification from each of the candidate hardware security servers 16(1) to 16(n). The received certification may be compared to the determined criteria to verify whether the certification is authentic and valid. Information about the certification itself may be compared to the determined criteria to verify whether the certificate meets the minimum standards for the hardware security server 16(1). The generated ranking may also be based on comparing the specifications of the candidate hardware security servers 16(1) to 16(n) with the cloud provider's preferences for hardware security servers 16(1).
[0046] Each hardware security server requirement may be given a determined weight. In some embodiments, a score may be assigned to each of the candidate hardware security servers 16(1) to 16(n) based on the determination and weighting of the different requirements. For example, a score may be given to each requirement, and the scores for the requirements may then be combined using the determined weights for each requirement. In other embodiments, the requirements may be used as baseline requirements, and if any of the specifications of the candidate hardware security servers 16(1) to 16(n) do not meet the requirements, the candidate hardware security servers 16(1) to 16(n) may be excluded from possible selection as the recommended hardware security server 16(1). It will be understood in the art that other ranking and scoring methods may be used to generate the generated ranking for each of the candidate hardware security servers 16(1) to 16(n).
[0047] In step 325, the network traffic manager device 14 provides the client with a hardware security server recommendation and the ranked candidate hardware security servers 16(1) to 16(n), and the exemplary process ends at step 330. The hardware security server recommendation may be generated based on the generated ranking of the candidate hardware security servers and the determination of the compliance indication. In some embodiments, after sending the hardware security server recommendation to the client, the network traffic manager device 14 may route new sessions and requests for any operations from the client 12(1) to the recommended hardware security server 16(1). For example, the hardware security server recommendation may include recommending multiple hardware security servers 16(1) to 16(n). In a multi-tenant scenario, the network traffic manager device 14 may load balance operations from the client 12(1) among the multiple hardware security servers 16(1) to 16(n) to maximize the capacity of the multiple hardware security servers 16(1) to 16(n) and reduce overall costs.
[0048] Now refer to Figure 2 、 Figure 4 and Figure 5 An example method for selecting a backup hardware security server from a plurality of hardware security servers 16(1) to 16(n) is described. First, in step 405, the network traffic manager device 14 receives a command from the client 12(1) for a recommended hardware security server 16(1) for hardware security server recommendation. In step 410, the network traffic manager device 14 sends the command to the recommended hardware security server 16(1). In step 415, as a response from the recommended hardware security server 16(1), the network traffic manager device 14 receives a failure message. The recommended hardware security server 16(1) may become unavailable. In some embodiments, no failure message is received from the recommended hardware security server 16(1). The lack of a response from the recommended hardware security server may also indicate a failure of the recommended hardware security server. Instead, the client 12(1) sends a command to be processed directly by the backup hardware security server 16(2) without first receiving a failure message.
[0049] In step 420, the network traffic manager device 14 sends the command to the backup hardware security server 16(2) in response to receiving the failure message. The backup hardware security server 16(2) may be selected from the candidate hardware security servers 16(1) to 16(n). A candidate hardware security server 16(1) that was not recommended as a hardware security server 16(1) but generated with a higher ranking may be selected as a backup hardware security server 16(2). In some embodiments, multiple backup hardware security servers may be selected.
[0050] In step 425, the network traffic manager device 14 receives a response from the backup hardware security server 16(2). In step 430, the network traffic manager device 14 sends the response received from the backup hardware security server 16(2) to the client 12(1), and the exemplary process ends at step 435. As shown in this example, having the network traffic manager device 14 select a backup hardware security server can achieve high availability. By selecting a backup hardware security server, the network traffic manager device 14 can coordinate key migration or synchronization between the recommended hardware security server 16(1) and the backup hardware security server.
[0051] In some examples, the network traffic manager device 14 may use both the recommended hardware security server 16(1) and the backup hardware security server by directing traffic to both. The recommended hardware security server 16(1) and the backup hardware security server 16(2) may be replicated, and the keys of the recommended hardware security server 16(1) and the backup hardware security server 16(2) may be replicated. This may allow the network traffic manager device 14 to shield backend failures from the user infrastructure because it may ensure that the recommended hardware security server 16(1) and the backup hardware security server have copies of the keys so that if one of these devices or services fails, the network traffic manager device 14 can select an alternative location where the critical information has been replicated. In some examples, the backup hardware security server may be selected from a different region in the same cloud or from a different cloud to reduce the risk of key loss due to a cloud provider outage. In other examples, the recommended hardware security server 16(1) may have already been purchased by the user. The user may desire to use the recommended hardware security server 16(1) to a certain extent and then cloud burst to different hardware security servers in the plurality of hardware security servers 16(1) to 16(n). In this example, different hardware security servers in the plurality of hardware security servers 16(1) to 16(n) can help reduce costs and maximize capacity by allowing the user infrastructure to use the recommended hardware security server 16(1) that has already been purchased and then cloud burst to an alternate hardware security server that can provide different capabilities. For example, the different capabilities can include different pricing structures, such as a pay-per-transaction service.
[0052] Having thus described the basic concepts of the present technology, it will be readily apparent to those skilled in the art that the foregoing detailed disclosure is intended to be presented by way of example only and is not restrictive. Although not expressly stated herein, various changes, improvements, and modifications will occur to and are contemplated by those skilled in the art. Such changes, improvements, and modifications are intended to be made accordingly and are within the spirit and scope of the present technology. Additionally, except as may be specified in the claims, the order of the listed processing elements or sequences, or the use of numbers, letters, or other designations is not intended to limit the claimed processes to any order. Therefore, the present technology is limited only by the appended claims and their equivalents.
Claims
1. A method for optimizing selection from a hardware security server, the method being implemented by a cloud service or a network traffic management system, the network traffic management system comprising a network traffic device, a client device, or a server device, the method comprising: receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, wherein the data comprises a response from the candidate hardware security server, performance data, or runtime observation data of the candidate hardware security server, wherein the data is received after receiving or retrieving hardware security server requirements recommended for the hardware security server, and wherein the hardware security server requirements comprise one or more server operating rules; generating a compliance score for the candidate hardware security server based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server; generating a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers; as well as The hardware security server recommendation for one of the candidate hardware security servers is provided to the client based on the generated ranking of the candidate hardware security servers having compliance scores above a predetermined threshold.
2. The method of claim 1 , wherein generating the compliance score of the candidate hardware security server further comprises: determining a proximity match within a set range from a client location based on a location of each of the candidate hardware security servers; determining an operational match for each of the candidate hardware security servers based on an operational data range in the hardware security server requirement; as well as The availability of each of the candidate hardware security servers is determined based on an availability status indicator in the hardware security server requirement.
3. The method of claim 1, further comprising: observing metrics of each of the candidate hardware security servers, wherein the observed metrics include a response time or transactions per second per payload of each of the candidate hardware security servers; and The ranking is updated based on observed metrics for each of the candidate hardware security servers.
4. The method of claim 3, further comprising: One or more backup hardware security servers are selected from the candidate hardware security servers based on the generated ranking of each of the candidate hardware security servers.
5. The method of claim 4, further comprising: receiving a command from a client recommending a recommended hardware security server for the hardware security server; Sending the command to the recommended hardware security server; sending the command to a backup hardware security server in response to receiving a failure message or receiving no response from the recommended hardware security server, wherein the backup hardware security server is one of the selected backup hardware security servers; as well as A response is sent to the client, wherein the response is generated and received by the backup hardware security server after sending the command to the backup hardware security server.
6. A non-transitory computer-readable medium having stored thereon instructions for optimizing selection from a hardware security server, the instructions comprising executable code that, when executed by a processor, causes the processor to: receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, wherein the data comprises a response from the candidate hardware security server, performance data, or runtime observation data of the candidate hardware security server, wherein the data is received after receiving or retrieving hardware security server requirements recommended for the hardware security server, and wherein the hardware security server requirements comprise one or more server operating rules; generating a compliance score for the candidate hardware security server based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server; generating a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers; as well as The hardware security server recommendation for one of the candidate hardware security servers is provided to the client based on the generated ranking of the candidate hardware security servers having compliance scores above a predetermined threshold.
7. The medium of claim 6, wherein the executable code, when executed by the processor, further causes the processor to: determining a proximity match within a set range from a client location based on a location of each of the candidate hardware security servers; determining an operational match for each of the candidate hardware security servers based on an operational data range in the hardware security server requirement; as well as The availability of each of the candidate hardware security servers is determined based on an availability status indicator in the hardware security server requirement.
8. The medium of claim 6, wherein the executable code, when executed by the processor, further causes the processor to: observing metrics of each of the candidate hardware security servers, wherein the observed metrics include a response time or transactions per second per payload of each of the candidate hardware security servers; and The ranking is updated based on observed metrics for each of the candidate hardware security servers.
9. The medium of claim 8, wherein the executable code, when executed by the processor, further causes the processor to: One or more backup hardware security servers are selected from the candidate hardware security servers based on the generated ranking of each of the candidate hardware security servers.
10. The medium of claim 9, wherein the executable code, when executed by the processor, further causes the processor to: receiving a command from a client recommending a recommended hardware security server for the hardware security server; Sending the command to the recommended hardware security server; sending the command to a backup hardware security server in response to receiving a failure message or receiving no response from the recommended hardware security server, wherein the backup hardware security server is one of the selected backup hardware security servers; as well as A response is sent to the client, wherein the response is generated and received by the backup hardware security server after sending the command to the backup hardware security server.
11. A network traffic manager device, comprising: a memory including programming instructions stored in the memory; and a processor configured to execute the programming instructions stored in the memory to: receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, wherein the data comprises a response from the candidate hardware security server, performance data, or runtime observation data of the candidate hardware security server, wherein the data is received after receiving or retrieving hardware security server requirements recommended for the hardware security server, and wherein the hardware security server requirements comprise one or more server operating rules; generating a compliance score for the candidate hardware security server based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server; generating a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers; as well as The hardware security server recommendation for one of the candidate hardware security servers is provided to the client based on the generated ranking of the candidate hardware security servers having compliance scores above a predetermined threshold.
12. The apparatus of claim 11 , wherein the processor is further configured to execute the programming instructions stored in the memory to: determining a proximity match within a set range from a client location based on a location of each of the candidate hardware security servers; determining an operational match for each of the candidate hardware security servers based on an operational data range in the hardware security server requirement; as well as The availability of each of the candidate hardware security servers is determined based on an availability status indicator in the hardware security server requirement.
13. The apparatus of claim 11 , wherein the processor is further configured to execute the programming instructions stored in the memory to: observing metrics of each of the candidate hardware security servers, wherein the observed metrics include a response time or transactions per second per payload of each of the candidate hardware security servers; and The ranking is updated based on observed metrics for each of the candidate hardware security servers.
14. The apparatus of claim 13, wherein the processor is further configured to execute the programming instructions stored in the memory to: One or more backup hardware security servers are selected from the candidate hardware security servers based on the generated ranking of each of the candidate hardware security servers.
15. The apparatus of claim 14, wherein the processor is further configured to execute the programming instructions stored in the memory to: receiving a command from a client recommending a recommended hardware security server for the hardware security server; Sending the command to the recommended hardware security server; sending the command to a backup hardware security server in response to receiving a failure message or receiving no response from the recommended hardware security server, wherein the backup hardware security server is one of the selected backup hardware security servers; as well as A response is sent to the client, wherein the response is generated and received by the backup hardware security server after sending the command to the backup hardware security server.
16. A network traffic management system, comprising a traffic management device, a client device, or a server device, the network traffic management system comprising: a memory including programming instructions stored thereon; and a processor configured to execute the stored programming instructions to: receiving data from a candidate hardware security server after sending an operating status request or a capability query to the candidate hardware security server, wherein the data comprises a response from the candidate hardware security server, performance data, or runtime observation data of the candidate hardware security server, wherein the data is received after receiving or retrieving hardware security server requirements recommended for the hardware security server, and wherein the hardware security server requirements comprise one or more server operating rules; generating a compliance score for the candidate hardware security server based on the hardware security server requirements, the built-in hardware security server requirements, and the data received from the candidate hardware security server; generating a ranking of the candidate hardware security servers based on the compliance scores of the candidate hardware security servers; as well as The hardware security server recommendation for one of the candidate hardware security servers is provided to the client based on the generated ranking of the candidate hardware security servers having compliance scores above a predetermined threshold.
17. The network traffic management system of claim 16, wherein the processor is further configured to execute the programming instructions stored in the memory to: determining a proximity match within a set range from a client location based on a location of each of the candidate hardware security servers; determining an operational match for each of the candidate hardware security servers based on an operational data range in the hardware security server requirement; as well as The availability of each of the candidate hardware security servers is determined based on an availability status indicator in the hardware security server requirement.
18. The network traffic management system of claim 16, wherein the processor is further configured to execute the programming instructions stored in the memory to: observing metrics of each of the candidate hardware security servers, wherein the observed metrics include a response time or transactions per second per payload of each of the candidate hardware security servers; and The ranking is updated based on observed metrics for each of the candidate hardware security servers.
19. The network traffic management system of claim 18, wherein the processor is further configured to execute the programming instructions stored in the memory to: One or more backup hardware security servers are selected from the candidate hardware security servers based on the generated ranking of each of the candidate hardware security servers.
20. The network traffic management system of claim 19, wherein the processor is further configured to execute the programming instructions stored in the memory to: receiving a command from a client recommending a recommended hardware security server for the hardware security server; Sending the command to the recommended hardware security server; sending the command to a backup hardware security server in response to receiving a failure message or receiving no response from the recommended hardware security server, wherein the backup hardware security server is one of the selected backup hardware security servers; as well as A response is sent to the client, wherein the response is generated and received by the backup hardware security server after sending the command to the backup hardware security server.