Software-defined microservices
By managing the microservice infrastructure and trusted endpoints within the process virtual machine, the problem of tight coupling of computing environments in microservice systems is solved, secure and flexible fine-grained management and orchestration are achieved, and the scalability and security of the system are improved.
Patent Information
- Application Number
- CN201810403203.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-05-09
- Filing Date
- 2018-04-28
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2038-04-28
AI Technical Summary
In existing microservice systems, the computing environment and microservices are tightly coupled, making the system difficult to modify and lacking flexibility. Traditional virtualization technology makes it difficult to achieve fine-grained orchestration and security management.
By implementing the microservice infrastructure within a process virtual machine, using trusted endpoints and process virtual machines, we ensure the secure deployment and management of microservices and the CIMA approach. We use compilers to generate intermediate code and update and deploy it in a trusted communication session, providing secure access to the underlying computing environment.
It achieves secure, flexible and fine-grained management and orchestration of microservice systems, improves the scalability and flexibility of the system, and ensures the security and integrity of the computing platform.
Smart Images

Figure CN108874501B_ABST
Abstract
Description
Background Art
[0001] Microservices are software components that implement highly cohesive application logic and expose well-defined interfaces through which other system components can interoperate with them. Due to these characteristics, microservices are generally loosely coupled to other system components and can be changed and deployed independently of them. However, microservices are generally not loosely coupled to the computing environment in which they execute. Instead, microservices are compiled and linked to execute within a specific computing environment and execute under the control of a specific operating system. BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Figure 1 is a block diagram illustrating a computing system configured according to an embodiment of the present disclosure to implement a microservices infrastructure.
[0003] Figure 2 This is an example of an embodiment according to the present disclosure. Figure 1 A block diagram of the various components of a host device.
[0004] Figure 3 is a block diagram illustrating a program construction pipeline according to an embodiment of the present disclosure.
[0005] Figure 4 is a flowchart illustrating a method for providing a microservice infrastructure according to an embodiment of the present disclosure.
[0006] Figure 5 is a block diagram illustrating an example of a microservice infrastructure including specific microservices according to an embodiment of the present disclosure.
[0007] Figure 6 is a block diagram of a computing device that may be used to implement various components of a microservices infrastructure according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0008] The microservices infrastructure disclosed herein securely maintains the flow of one or more computing platform microservices implemented within a process virtual machine. In some embodiments, the infrastructure includes source code that defines the properties and methods of the computing platform microservices, a compiler that processes the source code to generate intermediate code to be executed by the process virtual machine, and securely deploys the microservices and methods to trusted endpoints of the process virtual machine. In some embodiments, the computing platform microservices maintained by this infrastructure can provide and control access to components of the underlying computing environment. These components can include, for example, system input / output devices, storage devices, peripheral devices, and network interfaces. Furthermore, these components can be local to the computing device implementing the process virtual machine and / or can be separate from and remote from the computing device.
[0009] The fundamental nature of the platform computing services and access methods provided by these microservices ensures substantial security measures. Therefore, in some embodiments, the process virtual machine allocates a controlled immutable method area (CIMA) and stores methods for accessing the underlying computing environment in this CIMA. Such methods may be referred to herein as CIMA methods. In some embodiments, the process virtual machine protects intermediate code (e.g., CIMA methods) stored in the CIMA from manipulation by programs running within the process virtual machine or elsewhere (e.g., microservices that call CIMA methods).
[0010] Furthermore, to maintain security during the deployment of individual microservices and the CIMA method, in some embodiments, the process virtual machine receives a security challenge from a trusted endpoint and responds to the challenge before performing any deployment activities. In these embodiments, the trusted endpoint may be local to the computing device implementing the process virtual machine or may be separate and remote from the computing device. In either case, the response generated by the process virtual machine and transmitted to the trusted endpoint may include authentication data. The authentication data describes the configuration of one or more components of the process virtual machine and can thus be used to measure the integrity of the process virtual machine. For example, if one of the components examined to generate the authentication data has been altered (e.g., by malware), the authentication data will indicate the alteration in the component. Therefore, while processing the response from the process virtual machine, the trusted endpoint can determine whether the components of the process virtual machine are in an expected, predefined state. In this case, the trusted endpoint transmits a positive acknowledgement to the process virtual machine, thereby establishing a trusted communication session with the process virtual machine. If the trusted endpoint determines that one or more components of the process virtual machine are not in the predefined state, the trusted endpoint will not transmit the positive acknowledgement, thereby signaling a lack of trust to the process virtual machine. How the process virtual machine reacts to the lack of trust can vary, but such a reaction may include terminating the process virtual machine.
[0011] In some embodiments, when a trusted communication session is established between a process virtual machine and a trusted endpoint, the trusted endpoint can, as desired, transmit one or more requests to update microservices and / or CIMA methods to the process virtual machine. These requests may include, for example, an updated CIMA method and a request to load the updated CIMA method. In response to receiving such a request, the process virtual machine parses the request and verifies whether it was received within the trusted communication session. If so, the process virtual machine deploys the update included in the request to CIMA. If the request was not received within the trusted communication session, the process virtual machine aborts deployment of the update.
[0012] In some embodiments, a compiler receives source code and generates intermediate code for execution by a process virtual machine. In these embodiments, the compiler is configured to scan the source code for one or more language constructs that indicate protected methods (e.g., CIMA methods) called by or included in a software-defined microservice. In addition, in these embodiments, if the compiler finds such language constructs, the compiler generates intermediate code defining the protected method and stores the intermediate code in a storage location available to the process virtual machine. Therefore, when the process virtual machine is executed, part of the process virtual machine's initialization process is used to load the newly compiled protected method into CIMA within the process virtual machine.
[0013] In some embodiments, the software-defined computing platform microservices described herein are provisioned and orchestrated by local or cloud-based resource brokers as part of an overall workflow. Within these workflows, the computing platform microservices can communicate with other resources to achieve the overall computing goal. For example, the software-defined computing platform microservices can be part of a peer-to-peer system in which local resource brokers interact to identify and elect a leader node for the overall computing goal. By providing a software-defined microservices layer between the orchestrated workflow and local or remote hardware resources, the embodiments disclosed herein have increased flexibility and scalability when compared to conventional techniques.
[0014] Furthermore, in some embodiments, CIMA methods expose interfaces to the underlying computing environment that are called by computing platform microservices or other microservices. For example, CIMA methods can be part of a class library that is at least partially loaded into CIMA and configured and / or controlled by a trusted cloud-based console. In this way, the embodiments disclosed herein implement a software-driven view of the underlying computing environment at a fine-grained method level.
[0015] Other aspects, embodiments and advantages of these example aspects and embodiments are discussed in detail below. In addition, it should be understood that the foregoing information and the detailed description below are merely illustrative examples of various aspects and embodiments, and are intended to provide an overview or framework for understanding the nature and characteristics of the claimed aspects and embodiments. References to "an embodiment," "other embodiments," "examples," "some embodiments," "some examples," "alternative embodiments," "various embodiments," "one embodiment," "at least one embodiment," "another embodiment," "this embodiment and other embodiments," and the like are not necessarily mutually exclusive and are intended to indicate that a particular feature, structure, or characteristic described in conjunction with the embodiment or example may be included in at least one embodiment or example. The appearance of such terms herein does not necessarily refer to the same embodiment or example. Any embodiment or example disclosed herein may be combined with any other embodiment or example.
[0016] Moreover, the wording and terminology used herein are for descriptive purposes and should not be considered restrictive. Each example, embodiment, component, element or system and method action cited in the singular herein may also include plural embodiments, and any embodiment, component, element or action cited in the plural herein may also include only singular embodiments. Reference in the singular or plural form is not intended to limit the currently disclosed system or method, and its components, actions or elements. "Include," "contain," "have," "include," "involve," and their variations used herein are intended to cover the items listed thereafter and their equivalents and additional items. Reference to "or" may be interpreted as inclusive, so that any term described using "or" may indicate one, more than one, and all of the terms described. Additionally, in the event of inconsistent term usage between this document and the documents combined by reference, the usage in the combined reference should be considered to supplement the usage of this document; for irreconcilable inconsistencies, the term usage in this document shall prevail.
[0017] General Overview
[0018] Computer-implemented systems composed of tightly coupled components are often brittle and difficult to modify. While some advances have been made to achieve more loosely coupled systems, tight coupling between system components remains a troubling problem in some areas. For example, while many conventional management runtime systems support dynamic application updates, system interfaces (such as system input / output, networking, storage, and peripherals) are part of a hard-coded system layer that cannot be modified via programmatic interfaces. While there are many good reasons for this approach, with security being a primary consideration, it also prevents flexibility in how the system provides these system-layer services. While virtualization can help address this issue, some traditional virtualization technologies can introduce service granularity challenges. For example, while system or operating system virtual machines are a good tool for workload-level orchestration (install-start-stop-resume), process virtual machines are best suited for fine-grained orchestration at the application method level.
[0019] Therefore, according to at least some embodiments disclosed herein, a microservices infrastructure is provided in which a virtualized system interface is implemented as a process virtual machine (such as In some embodiments, the microservices infrastructure includes at least trusted endpoints and host devices. The microservices infrastructure provides secure mechanisms for maintaining (e.g., upgrading or otherwise modifying) microservices and / or methods. These microservices and / or methods form a software-based virtualized computing platform that can be securely modified and executed.
[0020] System Architecture
[0021] Figure 1 A distributed computing system 100 implementing a microservices infrastructure according to at least one embodiment is illustrated. As shown, the computing system 100 includes a host device 102, a remote resource agent 106, remote resources 108, a workflow 118, and a communication network 110. The host device 102 includes local hardware resources 114 and a process virtual machine 112. The local hardware resources 114 will be referred to below. Figure 6 104 and microservices 116.
[0022] Figure 1The illustrated communication network 110 may include any of a variety of networks through which computing devices may exchange (e.g., transmit or receive) data. Examples of such networks include wide area networks, local area networks, cellular networks, ordinary telephone networks, and the like. Although data exchanged via the network 110 may be encoded according to various standards, including, for example, the Transmission Control Protocol / Internet Protocol (TCP / IP), the embodiments disclosed herein are not limited to a particular network standard or set of standards.
[0023] In by Figure 1 In some of the illustrated embodiments, each of the host device 102, the remote resource agent 106, and the remote resource 108 utilizes one or more computing devices (such as those described below). Figure 6 In these embodiments, each of the host device 102, the remote resource agent 106, and the remote resource 108 is configured to exchange information via the network 110.
[0024] In some embodiments, the remote resource broker 106 is configured to provision and orchestrate workflows 118. When executed according to this configuration, the remote resource broker 106 can provision and orchestrate remote resources 108 and / or microservices 116 implemented by the host device 102. The remote resources 108 provisioned and orchestrated in this manner can include various real and / or virtual computing resources residing at various levels of abstraction from the underlying computing hardware. For example, the remote resources 108 can include data storage devices such as memory; computing resources such as processors; network resources such as routers; and so on. Additionally or alternatively, the remote resources 108 can include real and / or virtual servers such as application servers, database servers, and so on. These real and / or virtual servers can be organized into a grid or cluster that collaboratively implements the workflow 118. Examples of commercially available remote resource brokers that can be used to implement the remote resource broker 106 and orchestrate the workflow 118 include Amazon Web Services, Microsoft Azure, Google Compute Engine, and IBM Softlayer.
[0025] In some embodiments, the remote resource agent 106 is also a trusted endpoint and is thus configured to maintain circulation of methods and microservices residing on various other computing devices (such as methods stored in CIMA 104 and / or microservices 116 residing on the host device 102). When executed according to this configuration in some embodiments, the remote resource agent 106 maintains circulation of methods and / or microservices 116 stored in CIMA 104 by deploying updated versions of one or more methods to CIMA 104 and / or deploying updated versions of microservices 116 to the host device 102 within a trusted communication session. These updated versions may include one or more classes (including various properties and methods). Methods may include both conventionally stored methods and CIMA methods.
[0026] In some embodiments, to establish and maintain a trusted communication session with host device 102, remote resource agent 106 periodically and / or aperiodically transmits one or more challenges to process virtual machine 112 resident on host device 102 and receives one or more responses from process virtual machine 112. The one or more responses may include attestation data generated by process virtual machine 112. In some embodiments, this attestation data describes the configuration of various components of host device 102. In these embodiments, remote resource agent 106 processes the one or more responses and any included attestation data to ensure that one or more components of host device 102 have not been replaced, altered, or otherwise compromised (e.g., via malware). For example, in some embodiments, remote resource agent 106 performs a bitwise comparison of the attestation data with reference data generated locally by remote resource agent 106 based on a copy of the component recorded as most recently deployed to host device 102. If the bitwise comparison indicates a match (i.e., if the attestation data matches the reference data), remote resource agent 106 can verify the integrity of host device 102 and thereby continue to securely interoperate with it.
[0027] In some embodiments, the process virtual machine 112 is a hardware and / or software component that provides a hardware and / or operating system independent computing platform for executing application logic. This application logic may take the form of a software program encoded in, for example, an intermediate code supported by the process virtual machine 112. In some embodiments, the process virtual machine 112 and its components are configured to protect all intermediate code stored in the CIMA 104 and make all intermediate code immutable except in the event that a trusted endpoint requests changes to the intermediate code within a trusted communication session. For example, in one of these embodiments, the process virtual machine 112 stores information describing memory addresses located within the CIMA 104 and halts execution of any instructions that write to the stored memory addresses that are not transmitted by the trusted endpoint within the trusted communication session. Examples of process virtual machines that may be used to implement the process virtual machine 112 include the Java virtual machine, the Microsoft .Net framework, and the like. Additionally, processes supported by a processor (e.g., reference Figure 6 The process virtual machine described herein is implemented by hardware controlled by a processor 604 described below or by software executed by such a processor.
[0028] In some embodiments, the microservice 116 is a program that can be executed by the process virtual machine 112 and is used to provide one or more hardware and / or operating system independent computing platform services to other programs that can be executed by the process virtual machine 112. Examples of computing platform services that the microservice 116 can be configured to provide include networking, storage, and / or peripheral devices. For example, in one embodiment, the microservice 116 is configured to receive and process requests to transmit information via a virtualized network interface card. In another embodiment, the microservice 116 is configured to receive and process requests to store data on a virtualized data storage device. In another embodiment, the microservice 116 is configured to receive and process requests to display information on a virtualized display. Therefore, in these embodiments, the microservice 116 is configured to implement computing platform services by exposing a system interface to a virtualized computing platform component, receiving requests to use the virtualized computing platform component via the system interface, and processing these usage requests. In processing a usage request, the microservice 116 may access and utilize local hardware resources 114 (e.g., via the process virtual machine 112), transmit a request to the remote resource broker 106 to provision and / or utilize remote resources 108, and / or transmit a request to the remote resource 108 to access and use a previously provisioned remote resource. Additionally or alternatively, in processing a usage request, the microservice 116 may call a CIMA method stored in CIMA 104 that controls and provides access to components of the underlying computing environment. Specific examples of processes performed by some embodiments of the microservice 116 will be referenced. Figure 4 and 5 This is further described below.
[0029] Figure 2 The host device 102 is illustrated in more detail. Figure 2 As shown, host device 102 includes process virtual machine 112, local hardware resources 114, and a trusted endpoint 210 local to host device 102. Process virtual machine 112 includes loader 202, method area 206, and meter 214. Method area 206 includes CIMA 104. CIMA 104 stores CIMA methods (e.g., Method 3 and Method 4). Method area 206 stores regular methods (e.g., Method 1 and Method 2). One or more of these methods can be implemented and / or called by microservice 116 or other microservices / programs.
[0030] exist Figure 2 In some of the illustrated embodiments, the local hardware resources 114 implement both the process virtual machine 112 and the trusted endpoint 210. For example, the process virtual machine 112 and the trusted endpoint 210 may be implemented by shared components of the local hardware resources (e.g., one or more processors). In other embodiments, the trusted endpoint 210 may be implemented using components of the local hardware resources that are fixed to and / or dedicated to the trusted endpoint 210. Similarly, the process virtual machine 112 and the trusted endpoint 210 may each be implemented as one or more processes executing under the control of a single operating system, or may each be implemented as one or more processes executing under the control of different operating systems. In these embodiments and other embodiments in which both the trusted endpoint and the process virtual machine are implemented within a single computing device, the trusted endpoint 210 may communicate with the process virtual machine 112 using a connection local to the host device 102 (i.e., a connection that does not traverse a network such as the network 110) (e.g., via CIMA methods to load requests, security challenges, and confirmations). In some embodiments, the trusted endpoint 210 is configured as a local resource agent that orchestrates the workflow implemented by several microservices executing within the process virtual machine 112.
[0031] In some embodiments, the trusted endpoint 210 is configured to maintain the flow of microservices residing on the host device 102. For example, in these embodiments, the trusted endpoint 210 can establish trusted communication sessions with the process virtual machine 112 and maintain the flow of microservices 116 within these trusted communication sessions. Figure 2In the illustrated embodiment, when executed according to this configuration, to establish a trusted communication session, the trusted endpoint 210 generates a security challenge 216 and transmits the security challenge 216 to the measurer 214. The measurer 214 is configured to receive and parse the security challenge and, in response, generate a security response 218 and transmit the security response 218 to the trusted endpoint 210. The security response 218 may include authentication data describing the configuration of one or more components of the process virtual machine 112. This authentication data may include, for example, one or more hash values calculated for the loader 202. The trusted endpoint 210 receives and processes the security response 218. If the trusted endpoint 210 matches the authentication data with reference data generated by the trusted endpoint 210, the trusted endpoint 210 transmits a confirmation 220 to the process virtual machine 112, thereby establishing the trusted communication session.
[0032] In some embodiments, the trusted endpoint 210 is configured to generate and transmit a microservice update request including a CIMA method load request 212 within the trusted communication session. Additionally or alternatively, in some embodiments, the trusted endpoint 210 is configured to generate and transmit the CIMA method load request 212 within the trusted communication session independently of any microservice update request. The CIMA method load request 212 may include, for example, at least a portion of the microservice 116 (e.g., method 3 and / or method 4) or another CIMA method encoded as intermediate code, may include differences between a previous version of a microservice or a portion of a CIMA method and a new version of the microservice or CIMA method, and / or may include other information specifying an updated version of a microservice, method included within or used by the microservice and / or another CIMA method.
[0033] In some embodiments, the loader 202 is configured to manage the retrieval and storage of the intermediate code before it is executed by the process virtual machine 112. Figure 2 When executing according to this configuration in some of the illustrated embodiments, the loader 202 retrieves intermediate code from a data storage device included in the local hardware resource 114 and stores the intermediate code in the CIMA 104 or the method area 206. The loader 202 reserves the CIMA 104 for storage of intermediate code that provides computing platform services (e.g., Method 3 and / or Method 4). The loader 202 stores other intermediate code (e.g., Method 1 and Method 2) to be executed by the process virtual machine 112 in the method area 206.
[0034] In some embodiments, the loader 202 is configured to receive, process, and respond to security challenges generated by trusted endpoints, such as the remote resource agent 106 and / or the local trusted endpoint 210. In other embodiments, the loader 202 is configured to receive, process, and respond to microservice update requests that may or may not include CIMA method load requests, such as CIMA method load request 212. Examples of actions performed by the loader 202 under these configurations are described below with reference to Figure 4 and 5 To further describe.
[0035] Program construction pipeline
[0036] Figure 3 An example of a program construction pipeline according to various embodiments disclosed herein is illustrated. As shown, Figure 3 The CIMA method source code 300, compiler 302, CIMA method intermediate code 304 and process virtual machine 112 are included. The CIMA method source code 300 can be written in any of various human-readable languages (such as Java). The following is an example of a CIMA method declaration in human-readable source code.
[0037]
[0038] As shown in this CIMA method declaration, in some embodiments, an annotation (e.g., "software-definable") can be used to identify a method (writeFlashData()) as a CIMA method. In other embodiments, a keyword (e.g., "software-definable") can be used to similarly identify CIMA methods. While these specific source code language constructs are provided as examples, the embodiments disclosed herein are not limited to any specific source code language construct.
[0039] In some embodiments, compiler 302 comprises a process virtual machine compiler configured to identify and process any of one or more language constructs used to identify CIMA methods. Upon receiving a command to compile CIMA method source code 300, compiler 302 compiles CIMA method source code 300 to generate CIMA method intermediate code 304. As part of this compilation process, compiler 302 identifies any declared CIMA methods and generates intermediate code within CIMA method intermediate code 304. CIMA method intermediate code 304 is configured to cause a loader of the process virtual machine (e.g., loader 202) to store the intermediate code in a CIMA (e.g., CIMA 104). In this manner, CIMA method intermediate code 304 is identified as controllable and upgradable by a trusted endpoint (e.g., remote resource agent 106 or trusted endpoint 210). CIMA method intermediate code 304 is then provided to process virtual machine 112 (e.g., via loader 202) for storage and execution.
[0040] method
[0041] According to some embodiments, a microservices infrastructure implemented within a computing system, such as distributed computing system 100 , performs processes to securely deploy computing platform microservices and / or CIMA methods to a host device. Figure 4 The CIMA maintenance process 400 according to these embodiments is illustrated. Figure 4 As shown, the CIMA maintenance process 400 includes several actions that collectively enable a host device (such as host device 102) to establish a trusted communication session with a trusted endpoint, receive updates to one or more CIMA methods within the trusted communication session, deploy these updates, and execute one or more microservices within a process virtual machine that implements the CIMA method and / or interoperates with the CIMA method.
[0042] like Figure 4 As illustrated, CIMA maintenance process 400 begins at act 402, where the host device initializes a process virtual machine, such as process virtual machine 112. In some embodiments, the actions performed by the host device in act 402 include instantiating a loader (such as loader 202); allocating a CIMA, such as CIMA 104; and allocating a method area, such as method area 206. The actions performed by the host device in act 402 may further include instantiating one or more methods (such as those described above) via the loader. Figure 2 The method 1 and / or method 2 described above are loaded into the method area; one or more CIMA methods (such as method 3 and / or method 4) are loaded into CIMA via a loader; properties and other components of the microservice 116 are loaded via the loader; and the microservice 116 and / or its components are executed.
[0043] In act 418, the process virtual machine determines whether a microservice update request including a CIMA method load request (such as CIMA method load request 212) has been received from a trusted endpoint (such as remote resource proxy 106 or trusted endpoint 210). In act 420, the process virtual machine determines whether the microservice update request was received during a trusted communication session. For example, the process virtual machine may compare the time of receipt of the microservice update request with the time of the most recent successful security response. If the microservice update request was received during the trusted communication session (e.g., if the time of receipt of the microservice update request is within a predetermined range of the time of the most recent successful security response), the process virtual machine performs act 422. If the microservice update request was not received during the trusted communication session (e.g., if the time of receipt of the microservice update request is not within a predetermined range of the time of the most recent successful security response), the process virtual machine executes the microservice and / or its components in act 410.
[0044] In action 422, the process virtual machine deploys the CIMA method included in the CIMA method load request to the CIMA within the host device. When deploying the CIMA method, the process virtual machine (e.g., via the loader) stores the intermediate code included in and / or represented in the CIMA method load request in the CIMA. This deployment activity may include copying data or may include more complex manipulation of the data (e.g., decryption, decompression, etc.).
[0045] In action 408, the process virtual machine determines whether all processes executing within the process virtual machine have reached a safe point. If not, the process virtual machine continues executing the microservice in action 410. If all processes have reached a safe point, the process virtual machine executes action 404. In action 404, the process virtual machine determines whether a security challenge, such as security challenge 216, has been received from a trusted endpoint. If so, the process virtual machine executes action 412. Otherwise, the process virtual machine executes action 410.
[0046] In action 412, the process virtual machine measures the integrity of various components of the host device, for example by executing the meter 214, to generate authentication data describing the component configuration. The components for which the authentication data is generated may include, for example, components of the process virtual machine itself (such as the loader, application logic, microservices, and any drivers) or other components used by the process virtual machine to communicate with hardware components local to the host device (such as the local hardware resources 114). In action 414, the process virtual machine transmits a response to the security challenge, such as the security response 218. This response may include the authentication data generated in action 412.
[0047] In action 416, the process virtual machine determines whether the response was successful. For example, the process virtual machine may make this determination based on whether a positive confirmation (such as confirmation 220) was received from the trusted endpoint within a predetermined time period. If so, the trusted communication session is established, and the process virtual machine proceeds to action 418. In some embodiments, in action 416, the process virtual machine stores a timestamp indicating when the trusted communication session was established. If the response was unsuccessful (e.g., if a positive confirmation was not received within a predetermined time period), no trusted communication session is established, and the process virtual machine terminates the CIMA maintenance process 400, and in some embodiments, terminates all processes, including itself, as an additional security measure.
[0048] Each of the processes disclosed herein depicts a specific sequence of actions in a specific example. The actions included in these processes can be performed by or using one or more computing devices specifically configured as discussed herein. Some actions are optional and thus can be omitted depending on one or more examples. Additionally, the order of the actions can be changed, or other actions can be added, without departing from the scope of the systems and methods discussed herein.
[0049] Flash Microservice Example
[0050] Figure 5 A distributed computing system 500 implementing a microservices infrastructure is illustrated in accordance with at least one embodiment. As shown, the computing system 500 includes a host device 102, a remote resource agent 106, a remote data store 506, a remote data store 508, a workflow 118, and a communication network 110. Figure 5 As shown, remote data storage 506 and remote data storage 508 are stored in a manner that allows remote data storage to be accessed by using one or more computing devices (such as those described below). Figure 6 In these embodiments, remote data store 506 and remote data store 508 are configured to exchange information via network 110.
[0051] like Figure 5 As illustrated, the host device 102 includes local flash hardware 504. As shown, the process virtual machine 112 implements and / or controls the flash microservice 502. In some embodiments, the flash microservice 502 is a program that can be executed by the process virtual machine 112 to provide access to flash storage to other programs executed according to the workflow 118. When processing a request to store data in flash memory, the flash microservice 502 can access and utilize the local flash memory 504 and transmit the request to the remote resource broker 106 to provision and / or utilize the remote data store 506 or the remote data store 508.
[0052] For example, in some embodiments, the flash microservice 502 is configured to process requests to store data by storing the data in the flash memory 504 and the remote data store 506. In one example according to these embodiments, if the remote data store 506 becomes unavailable or is compromised, the remote resource agent 106 may transmit a microservice update request including a CIMA method load request to the host device 102. The CIMA method load request may include intermediate code that, when deployed, causes the flash microservice 502 to process requests to store data by storing the data in the remote data store 508.
[0053] computing devices
[0054] Figure 6 A computing device 600 is illustrated that can be used to implement various components of a microservices infrastructure as described herein. As shown, computing device 600 includes memory 602, at least one processor 604, and at least one interface 606. While the specific types and models of these components may vary between computing devices, it will be understood that each computing device includes a processor, memory, and an interface.
[0055] Interface 606 includes one or more physical interface devices (such as input devices, output devices, and combined input / output devices) and a software stack configured to drive the operation of the device. The interface device can receive input or provide output. More specifically, the output device can provide information for external presentation and the input device can receive information from an external source or generate information. Examples of interface devices include keyboards, mice, trackballs, microphones, touch screens, printing devices, display screens, speakers, network interface cards, environmental sensors, and the like. Interface devices allow programmable devices to exchange information and communicate with external entities such as users and other systems.
[0056] The memory 602 includes volatile and / or non-volatile (non-transient) data storage that can be read and / or written by the processor 604. The memory 602 stores programs and data used or manipulated during the operation of the computing device 600. The program stored in the memory 602 is a series of instructions that can be executed by the at least one processor 602. The memory 602 may include relatively high-performance data storage, such as registers, caches, dynamic random access memory, and static memory. The memory 602 may further include relatively low-performance, non-volatile, computer-readable and / or writable data storage media, such as flash memory or optical or magnetic disks. Various embodiments may organize the memory 602 into special, and in some cases unique, structures to store data that support the components disclosed herein. These data structures may be specifically configured to save storage space or increase data exchange performance and may be resized and organized to store values for specific data and data types.
[0057] In some embodiments, to implement and / or control specialized components, the processor 604 executes a series of instructions (i.e., one or more programs) that result in manipulated data. The processor 604 can be any type of processor, multiprocessor, microprocessor, or controller known in the art. The processor 604 is connected to and communicates data with the memory 602 and the interface 606 via an interconnection mechanism (such as a bus or some other data connection). This interconnection mechanism is Figure 6 6 is represented by lines connecting components within the computing device. In operation, processor 604 causes data to be read from a non-volatile (i.e., non-transitory) data storage medium in memory 602 and written to a high-performance data storage. Processor 604 manipulates the data within the high-performance data storage and copies the manipulated data to the data storage medium after processing is complete.
[0058] Although computing device 600 is shown as an example of a computing device capable of executing the processes disclosed herein, embodiments are not limited to Figure 6 For example, each process may be executed by a computer with Figure 6 The processes disclosed herein may be performed by one or more computing devices having different architectures or components than those shown. For example, a programmable device may include specially programmed dedicated hardware (such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), and other silicon implementations) or other hardware customized to perform the processes disclosed herein. Thus, the components of a computing device as disclosed herein may be implemented in software, hardware, firmware, or any combination thereof.
[0059] For example, as referenced above Figure 1 As described, in some embodiments, the process virtual machine 112 is implemented in hardware. In other embodiments, the process virtual machine 112 is implemented by a processor 604. As described above, this processor 604 can be a general-purpose processor. However, when executing as described herein (e.g., Figure 3-5 When a specific software process (as depicted in any of the preceding) is executed by the processor 604, the processor 604 becomes a special-purpose processor capable of performing the following operations: being able to make specific logic-based decisions based on the input data received, and further being able to provide one or more outputs that can be used to control or otherwise inform subsequent processing to be performed by the processor 604 and / or other processors or circuits communicatively coupled to the processor 604. The processor 604 reacts to specific input stimuli in a specific way and generates corresponding outputs based on the input stimuli. In this sense, the structure of the processor 604 according to one embodiment is Figure 3-5Furthermore, in some example cases, the processor 604 proceeds through a series of logic transitions in which various internal register states and / or other bit cell states, internal or external to the processor 604, may be set to logic high or logic low. This particular sequence of logic transitions is determined by the state of the electrical input signals to the processor 604, and a dedicated structure is provided by the processor 604 in executing Figure 3-5 Each software instruction of the process shown is effectively assumed to be executed. In particular, those instructions anticipate various stimuli to be received and change the memory state involved accordingly. In this way, the processor 604 can generate and store or otherwise provide useful output signals. Therefore, it can be understood that the processor 604 becomes a special-purpose machine during the execution of the software process, which is capable of processing only specific input signals and presenting specific output signals based on one or more logical operations performed during the execution of each instruction. In at least some examples, the processor 604 is configured to execute a function in which the software is stored in a data storage device (e.g., memory 602) coupled to the processor 604, and the software is configured to cause the processor 604 to proceed with a series of various logical operations that result in the execution of the function.
[0060] Other Example Embodiments
[0061] The following examples relate to further embodiments from which numerous permutations and configurations will be apparent.
[0062] Example 1 is a computing device comprising a memory, at least one processor coupled to the memory, and a process virtual machine executable by the at least one processor. The process virtual machine is configured to initialize at least one controlled immutable method area (CIMA) in the memory; load a CIMA method into the at least one CIMA; receive a first request to update the CIMA method; determine whether the first request is received from a trusted endpoint; and suspend processing of the first request in response to determining that the first request is received from an endpoint other than the trusted endpoint.
[0063] Example 2 includes the subject matter of Example 1, wherein the process virtual machine is further configured to receive a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; determine whether the second request is received from a trusted endpoint; and load the updated version of the CIMA method into the at least one CIMA in response to determining that the second request is received from a trusted endpoint.
[0064] Example 3 includes the subject matter of Example 1 or Example 2, wherein the process virtual machine is further configured to receive a challenge from the trusted endpoint; respond to the challenge; receive a positive acknowledgement; and continue execution in response to receiving the positive acknowledgement.
[0065] Example 4 includes the subject matter of Example 3, wherein the process virtual machine is further configured to respond to the challenge at least in part by generating authentication data comprising a measurement of the integrity of one or more components of the process virtual machine.
[0066] Example 5 includes the subject matter of Example 3 or Example 4, wherein the process virtual machine is further configured to establish a trusted communication session with the trusted endpoint in response to receiving the positive acknowledgement; and receive the second request from the trusted endpoint within the trusted communication session.
[0067] Example 6 includes the subject matter of any of Examples 1-5, wherein the process virtual machine is further configured to receive a challenge from a trusted endpoint; respond to the challenge; fail to receive a positive confirmation within a predetermined time period; and terminate execution of the process virtual machine in response to failing to receive a positive confirmation within the predetermined time period.
[0068] Example 7 includes the subject matter of any of Examples 3-6, wherein the process virtual machine is further configured to respond to the challenge at a safe point.
[0069] Example 8 includes the subject matter of any of Examples 1-7, wherein the process virtual machine is a Java virtual machine.
[0070] Example 9 includes the subject matter of any of Examples 1-8, wherein the process virtual machine is a hardware component.
[0071] Example 10 includes the subject matter of any of Examples 1-9, further comprising a trusted endpoint.
[0072] Example 11 includes the subject matter of any of Examples 1-10, wherein the CIMA method is included within one or more microservice classes that implement one or more computing platform services.
[0073] Example 12 includes the subject matter of any of Examples 1-11, wherein the at least one CIMA comprises a plurality of different method areas.
[0074] Example 13 includes the subject matter of any of Examples 1-12, further comprising a compiler executable by the at least one processor and configured to receive source code defining a CIMA method, the source code including a language construct identifying the CIMA method as software definable; compile the source code into intermediate code defining the CIMA method, the intermediate code executable by a process virtual machine; and store the intermediate code in a memory at a location accessible by the process virtual machine.
[0075] Example 14 is a method for managing one or more controlled immutable method area (CIMA) methods executable by a process virtual machine. The method includes initializing at least one CIMA within a memory controlled by the process virtual machine; loading a CIMA method into the at least one CIMA; receiving a first request to update the CIMA method; determining whether the first request is received from a trusted endpoint; and suspending processing of the first request in response to determining that the first request is received from an endpoint other than the trusted endpoint.
[0076] Example 15 includes the subject matter of Example 14, further comprising receiving a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; determining whether the second request is received from a trusted endpoint; and loading the updated version of the CIMA method into the at least one CIMA in response to determining that the second request is received from a trusted endpoint.
[0077] Example 16 includes the subject matter of Example 14 or Example 15, further comprising receiving a challenge from a trusted endpoint; responding to the challenge; receiving a positive acknowledgement; and continuing execution in response to receiving the positive acknowledgement.
[0078] Example 17 includes the subject matter of Example 16, wherein responding to the challenge comprises generating authentication data comprising a measurement of the integrity of one or more components of the process virtual machine.
[0079] Example 18 includes the subject matter of Example 16 or Example 17, further comprising: establishing a trusted communication session with the trusted endpoint in response to receiving the positive acknowledgement; and receiving a second request from the trusted endpoint within the trusted communication session.
[0080] Example 19 includes the subject matter of any of Examples 14-18, further comprising receiving a challenge from a trusted endpoint; responding to the challenge; failing to receive a positive acknowledgement within a predetermined time period; and terminating execution of the process virtual machine in response to failing to receive the positive acknowledgement within the predetermined time period.
[0081] Example 20 includes the subject matter of any of Examples 16-19, wherein responding to the challenge comprises responding to the challenge at a secure point.
[0082] Example 21 includes the subject matter of any of Examples 14-20, further comprising initializing a process virtual machine, the process virtual machine being a Java virtual machine.
[0083] Example 22 includes the subject matter of Example 21, wherein initializing the process virtual machine comprises initializing a Java virtual machine implemented in hardware.
[0084] Example 23 includes the subject matter of any of Examples 14-22, wherein the process virtual machine and the trusted endpoint are implemented within a single computing device, the method further comprising transmitting the first request via a connection local to the single computing device, and receiving the first request comprises receiving the first request via the connection.
[0085] Example 24 includes the subject matter of any of Examples 14-23, wherein loading the CIMA method comprises loading the CIMA method defined within at least one microservice class that implements at least one computing platform service.
[0086] Example 25 includes the subject matter of any of Examples 14-24, wherein initializing the at least one CIMA comprises initializing a plurality of different method areas.
[0087] Example 26 includes the subject matter of any of Examples 14-25, further comprising receiving source code defining a CIMA method, the source code including a language construct that identifies the CIMA method as software-definable; compiling the source code into intermediate code defining the CIMA method, the intermediate code executable by a process virtual machine; and storing the intermediate code in a memory at a location accessible by the process virtual machine.
[0088] Example 27 is a non-transitory computer-readable medium encoded with instructions that, when executed by one or more processors, result in execution of a process for managing one or more controlled immutable method areas (CIMA) methods. The process includes initializing at least one CIMA within a memory controlled by a process virtual machine; loading a CIMA method into the at least one CIMA; receiving a first request to update the CIMA method; determining whether the first request is received from a trusted endpoint; and suspending processing of the first request in response to determining that the first request is received from an endpoint other than a trusted endpoint.
[0089] Example 28 includes the subject matter of Example 27, wherein the process further comprises receiving a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; determining whether the second request is received from a trusted endpoint; and loading the updated version of the CIMA method into the at least one CIMA in response to determining that the second request is received from a trusted endpoint.
[0090] Example 29 includes the subject matter of Example 27 or Example 28, wherein the process further comprises receiving a challenge from a trusted endpoint; responding to the challenge; receiving a positive acknowledgement; and continuing execution in response to receiving the positive acknowledgement.
[0091] Example 30 includes the subject matter of Example 29, wherein in the process, responding to the challenge comprises generating authentication data comprising a measurement of the integrity of one or more components of the process virtual machine.
[0092] Example 31 includes the subject matter of Example 29 or Example 30, wherein the process further comprises establishing a trusted communication session with the trusted endpoint in response to receiving the positive acknowledgement; and receiving a second request from the trusted endpoint within the trusted communication session.
[0093] Example 32 includes the subject matter of any of Examples 27-31, wherein the process further comprises receiving a challenge from a trusted endpoint; responding to the challenge; failing to receive a positive acknowledgement within a predetermined time period; and terminating execution of the process virtual machine in response to failing to receive a positive acknowledgement within the predetermined time period.
[0094] Example 33 includes the subject matter of any of Examples 29-32, wherein in the process, responding to the challenge comprises responding to the challenge at a secure point.
[0095] Example 34 includes the subject matter of any of Examples 27-33, wherein the process further comprises initializing a process virtual machine, the process virtual machine being a Java virtual machine.
[0096] Example 35 includes the subject matter of example 34, wherein in the process, initializing the process virtual machine comprises initializing a Java virtual machine implemented in hardware.
[0097] Example 36 includes the subject matter of any of Examples 27-35, wherein the process virtual machine and the trusted endpoint are implemented within a single computing device, the process further comprising transmitting the first request via a connection local to the single computing device, and receiving the first request comprises receiving the first request via the connection.
[0098] Example 37 includes the subject matter of any of Examples 27-36, wherein in the process, loading the CIMA method comprises loading the CIMA method defined within at least one microservice class that implements at least one computing platform service.
[0099] Example 38 includes the subject matter of any of Examples 27-37, wherein in the process, initializing the at least one CIMA comprises initializing a plurality of different method areas.
[0100] Example 39 includes the subject matter of any of Examples 27-38, wherein the process further comprises receiving source code defining a CIMA method, the source code including a language construct that identifies the CIMA method as software definable; compiling the source code into intermediate code defining the CIMA method, the intermediate code executable by the process virtual machine; and storing the intermediate code in a memory at a location accessible by the process virtual machine.
[0101] The terms and expressions adopted in this article are used as terms of description rather than terms of limitation, and when such terms and expressions are used, it is not intended to exclude any equivalent schemes (or parts thereof) of the features shown and described, and it should be recognized that various modifications are possible within the scope of the claims. Accordingly, the claims are intended to cover all such equivalent schemes. Various features, aspects, and embodiments are described herein. As will be understood by those skilled in the art, the various features, aspects and embodiments are easy to combine with each other and to make changes and modifications. Therefore, the present disclosure should be considered to cover these combinations, changes and modifications. The scope of the present disclosure is not limited by this detailed description but by the appended claims. Applications filed in the future claiming priority to the present application may claim the disclosed subject matter in different ways and may generally include any collection of one or more limitations as disclosed herein in various aspects or otherwise shown.
Claims
1. A computing device comprising: Memory; at least one processor coupled to the memory; as well as a process virtual machine, the process virtual machine being executable by the at least one processor and being configured to: Initializing at least one controlled immutable method area CIMA within said memory; loading a CIMA method into the at least one CIMA; receiving a first request to update the CIMA method; determining whether the first request is received from a trusted endpoint; as well as Processing of the first request is aborted in response to determining that the first request was received from an endpoint other than the trusted endpoint.
2. The computing device of claim 1, wherein: The process virtual machine is further configured to: receiving a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; determining whether the second request is received from the trusted endpoint; as well as The updated version of the CIMA method is loaded into the at least one CIMA in response to determining that the second request is received from the trusted endpoint.
3. The computing device of claim 1, wherein: The process virtual machine is further configured to: receiving a challenge from the trusted endpoint; responding to said inquiries; Receiving positive confirmation; and Execution continues in response to receiving the positive acknowledgement.
4. The computing device of claim 1, wherein: The process virtual machine is a Java virtual machine.
5. The computing device of claim 1, wherein: The process virtual machine is a hardware component. The computing device of claim 1 , further comprising the trusted endpoint.
7. The computing device according to any one of claims 1 to 6, wherein: The CIMA method is included within one or more microservice classes that implement one or more computing platform services.
8. The computing device according to any one of claims 1 to 6, wherein: The at least one CIMA includes a plurality of different method areas.
9. The computing device of any one of claims 1 to 6, further comprising a compiler executable by the at least one processor and configured to: receiving source code defining the CIMA method, the source code including a language construct identifying the CIMA method as software definable; Compiling the source code into an intermediate code defining the CIMA method, wherein the intermediate code can be executed by the process virtual machine; as well as The intermediate code is stored in the memory at a location accessible by the process virtual machine.
10. A method for managing one or more controlled immutable method areas (CIMA) methods executable by a process virtual machine, the method comprising: Initializing at least one CIMA in a memory controlled by the process virtual machine; loading a CIMA method into the at least one CIMA; receiving a first request to update the CIMA method; determining whether the first request is received from a trusted endpoint; as well as Processing of the first request is aborted in response to determining that the first request was received from an endpoint other than the trusted endpoint.
11. The method of claim 10, further comprising: receiving a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; determining whether the second request is received from the trusted endpoint; as well as The updated version of the CIMA method is loaded into the at least one CIMA in response to determining that the second request is received from the trusted endpoint.
12. The method of claim 10, further comprising initializing the process virtual machine, the process virtual machine being a Java virtual machine.
13. The method according to claim 12, wherein: Initializing the process virtual machine includes initializing a Java virtual machine implemented in hardware.
14. The method according to claim 10, wherein The process virtual machine and the trusted endpoint are implemented within a single computing device, the method further comprising transmitting the first request via a connection local to the single computing device, and receiving the first request comprises receiving the first request via the connection.
15. The method according to any one of claims 10 to 14, wherein: Loading the CIMA method includes loading a CIMA method defined within at least one microservice class that implements at least one computing platform service.
16. The method according to any one of claims 10 to 14, wherein: Initializing the at least one CIMA includes initializing a plurality of different method areas.
17. The method of any one of claims 10 to 14, further comprising: receiving source code defining the CIMA method, the source code including a language construct identifying the CIMA method as software definable; Compiling the source code into an intermediate code defining the CIMA method, wherein the intermediate code can be executed by the process virtual machine; as well as The intermediate code is stored in the memory at a location accessible by the process virtual machine.
18. A computing device comprising: means for initializing at least one CIMA within a memory controlled by the process virtual machine; means for loading a CIMA method into said at least one CIMA; means for receiving a first request to update said CIMA method; means for determining whether the first request is received from a trusted endpoint; as well as Means for aborting processing of the first request in response to determining that the first request was received from an endpoint other than the trusted endpoint.
19. The computing device of claim 18, further comprising: means for receiving a second request to update the CIMA method, the second request specifying an updated version of the CIMA method; means for determining whether the second request is received from the trusted endpoint; as well as Means for loading the updated version of the CIMA method into the at least one CIMA in response to determining that the second request was received from the trusted endpoint.
20. The computing device of claim 18, further comprising means for initializing the process virtual machine, the process virtual machine being a Java virtual machine.
21. The computing device of claim 20, wherein: The means for initializing the process virtual machine includes means for initializing a Java virtual machine implemented in hardware.
22. The computing device of claim 18, further comprising means for transmitting the first request via a connection local to the single computing device, and receiving the first request comprises receiving the first request via the connection.
23. The computing device of any one of claims 18 to 22, wherein: The means for loading the CIMA method includes means for loading the CIMA method defined within at least one microservice class that implements at least one computing platform service.
24. The computing device of any one of claims 18 to 22, wherein: The means for initializing the at least one CIMA includes means for initializing a plurality of different method areas.
25. The computing device of any one of claims 18 to 22, further comprising: means for receiving source code defining the CIMA method, the source code including a language construct identifying the CIMA method as software definable; means for compiling the source code into an intermediate code defining the CIMA method, the intermediate code being executable by the process virtual machine; as well as Means for storing the intermediate code in the memory at a location accessible to the process virtual machine.
Citation Information
Patent Citations
System and Method for Processor-Based Security
US20100281273A1
System and method for updating a trusted application (TA) on a device
US20150268952A1