Data transmission of encryption keys for protecting communication between computing devices
By using encrypted tokens for authentication and key delivery during initial connection between the client and the server, the problem of inefficient processing and security vulnerabilities in the prior art is solved, and efficient and secure communication is achieved.
Patent Information
- Application Number
- CN202080050794.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-12
- Filing Date
- 2020-05-21
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-05-21
AI Technical Summary
The prior art requires frequent authentication and cryptography operations in the interaction between the client and the application/service, resulting in low processing efficiency and long waiting time, and the long validity period of the digital certificate may cause security vulnerabilities.
By using encrypted tokens for authentication and key delivery during initial connection between the client and the server, the server decrypts the token with the pre-shared decryption and signature verification key, thereby directly initiating secure communications, avoiding the search for client identity and additional authentication service intervention.
Improves communication processing efficiency between clients and servers, reduces waiting time, and enhances security, avoiding security vulnerabilities caused by long validity of digital certificates.
Smart Images

Figure CN114175579B_ABST
Abstract
Description
Background Art
[0001] The interaction between a client and an application / service is typically protected using authentication, cryptography, or a combination thereof. Generally, the client must be authenticated to access application / service domain-specific data. In today's world, time is of the essence, and processing efficiency and reduced latency are crucial when authenticating users and performing operations during the runtime of an application / service that may include encrypted data. This is especially true when the client interacts with an application / service such as a video game platform configured to provide, for example, an online multiplayer game. In such an environment, a large amount of data is transferred and needs to be processed instantaneously to provide the best possible experience to the user.
[0002] If a client is communicating with an application / service, the application / service needs to know the client with which it is interacting. The client logs in to the application / service by providing a client identifier. Traditionally, once the client is authenticated, the application / service not only needs to perform processing to initiate a connection with the client but also needs to perform a lookup operation on the client identifier and correlate that client identifier with cryptographic data. This process is cumbersome from a processing efficiency perspective, causes latency in the execution of the application / service, and typically requires the identity provider and / or software platform to allocate additional computing resources and bandwidth for managing the interaction between the client and the application / service, as well as the interaction with a certificate authority (CA). For example, digital certificates are typically issued to enable a client to interact with an application / service after authentication, which not only requires management by a trusted CA but also a significant amount of computing resources such as dedicated storage.
[0003] There may be additional security vulnerabilities in instances where digital certificates are used. For example, the validity period of a digital certificate is typically longer than the time preferably used in a game application / service scenario. Users generally do not remain logged in for long periods. If the validity period of a digital certificate is longer than the duration of the user's current session, this may expose the network to vulnerabilities including spoofing. Continuously reissuing digital certificates can be cumbersome and requires more dedicated storage and computing resources for continuous management. Summary of the Invention
[0004] In view of the above technical challenges, the present disclosure relates to processing operations configured to efficiently enable a client and a server to establish secure communication at the time of an initial connection between the client and the server. At the time of an initial connection with the server, the client provides an encrypted token to the server, the encrypted token serving as proof of authentication / identity and providing an encryption key within the encrypted token that the server can use to initiate secure communication with the client. The server can trust the encrypted token and the encryption key because the encrypted token can be encrypted and signed by an authentication service that has a trust relationship with the server, and because the authentication service and the server pre-share decryption and signature verification keys. The server uses the encrypted key to protect communication with the client without the need for additional processing to look up the client identity or any further intervention from the authentication service.
[0005] The present invention content is provided to introduce a selected collection of concepts described below in the detailed description in a simplified form. The present invention content is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. Additional aspects, features, and / or advantages of the examples will be set forth in the following description and will be partially apparent from the description, or may be learned by practicing the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Non-limiting and non-exhaustive examples are described with reference to the following drawings.
[0007] Figure 1 An exemplary process flow illustrating the interaction between components implementing secure transmission of communication between computing devices, which can be used to practice aspects of the present disclosure.
[0008] Figure 2 An exemplary method related to processing operations for initiating and managing a secure communication session between a client and a server, which can be used to practice aspects of the present disclosure.
[0009] Figure 3 A computing system suitable for implementing the processing operations described herein related to initiating and managing a secure communication session between computing devices, which can be used to practice aspects of the present disclosure. DETAILED DESCRIPTION
[0010] The present disclosure relates to processing operations configured to efficiently enable a client and a server to establish secure communication at the time of an initial connection between the client and the server. At the time of an initial connection with the server, the client provides an encrypted token to the server, the encrypted token serving as proof of the client's authentication / identity and providing an encryption key within the encrypted token that the server can use to initiate secure communication with the client. The server can trust the encrypted token and the encryption key because the encrypted token can be encrypted and signed by an authentication service having a trust relationship with the server and because the authentication service and the server pre-share decryption and signature verification keys. The server then uses the encrypted key to secure communication with the client without the need for additional processing to look up the client's identity or any further intervention from the authentication service. The present disclosure relates to interactions between a client, a server, an authentication service, or any combination thereof, where claims can be written from the perspective of any one of the client, the server, the authentication service, or a system including one or more of them without departing from the spirit of the present disclosure.
[0011] Some examples described herein relate to a client / server relationship where the client connects to a distributed gaming platform via a game console, which provides applications / services to enable the client to connect to a game server(s). For example, encryption key data may relate to an encrypted game server key used to establish a connection between a client and a server that wish to communicate to perform a game application / service. However, the present disclosure is not limited to this. The processing described herein applies to any type of client / server relationship operating in any type of application / service scenario. Additionally, the technical examples described herein can relate to client logins for a single application / service and single sign-on (SSO) examples where the login is used to access multiple different applications / services. Further, the examples of the present disclosure apply to both symmetric key and asymmetric key cryptography.
[0012] In one example, a client device may transmit user authentication information for logging in to an application or service. The login of the client device may be directed to an authentication service. The exemplary authentication service is configured to implement one or more protocols for managing the security of the client / server relationship, where the authentication service is an intermediary for authenticating the client's access to the application / service. The authentication service may determine whether to authenticate the client device based on an evaluation of the user authentication information. In response to authenticating the user authentication information, the authentication service is configured to dynamically generate an encryption key for communication between the client / server, and dynamically generate (and sign) an encrypted token associated with the client's access to the application or service. The encrypted token includes the dynamically generated encryption key in the payload. The authentication service transmits the encryption key and the encrypted (and signed) token to the client device. Subsequently, the client device receives the encryption key and the encrypted token, and then forwards the encrypted token to the application or service (e.g., the server component of the application / service) to initiate a connection with the application or service. The authentication service is further configured to pre-share with the server a decryption key for decrypting the encrypted token received from the client device. In an example where the encrypted token is also signed by the authentication service, the signature verification key is pre-shared from the authentication service with the server. The server of the application or service is configured to use the decryption key (and signature verification key) to decrypt the encrypted (and signed) token. The server is then configured to parse the content of the decrypted token and extract the encryption key. The server may utilize the encryption key to initiate secure communication directly with the client device, where the client device already has the encryption key (which was pre-shared by the authentication service).
[0013] As cited above, the present disclosure relates to a cryptographic scenario that includes symmetric key encryption / decryption and asymmetric key encryption / decryption. In the symmetric key example, the authentication service pre-shares an encryption key with the client device, which is the same as the encryption key included in the payload of the encrypted token. In the asymmetric key example, one or more key pairs are pre-shared between the authentication and the client component and the server component.
[0014] Further examples relate to interactions with one or more servers of an application / service. For example, a server component (e.g., a server device) receives a pre-shared decryption key from an authentication service for decrypting an encrypted token forwarded from a client device. In an example where the encrypted token is also signed by the authentication service, a signature verification key is pre-shared between the authentication service and the server component. Subsequently, the server component receives an encrypted (and signed) token from the client device, which token includes an encryption key (or key pair) that can be used to secure direct communication with the client device. The server component is then configured to use the pre-shared decryption key (and the pre-shared signature verification key) to decrypt the encrypted (and signed) token and extract the encryption key from the payload of the decrypted token. The server component then initiates a connection with the client device and uses the extracted encryption key to transmit secure communication to the client device. For example, the server component is configured to encrypt communication destined for the client device using the extracted encryption key and transmit the secure communication to the client device. The client device is pre-shared with the encryption key (or key pair) to enable secure communication with the server component. In some examples, the server device may be configured to initiate a communication channel that varies based on the interaction with an authenticated client device for the transmission of secure communication.
[0015] Additional examples relate to interactions of the authentication service with the client and / or server components. For example, the authentication service may pre-share with the server component decryption and signature verification keys for decrypting subsequently received encrypted and signed tokens. The authentication service authenticates client credentials for logging into the application / service and dynamically generates an encryption key (or keys, key pairs, etc.) as well as an encrypted and signed token for client authentication of the application / service. In one example, a new encryption key and / or encrypted token are generated when client authentication information is received and authenticated by the authentication service. For example, this may occur when the client has logged out of the application / service and needs to re-authenticate. Thus, the authentication of the client identity is a trigger for dynamically generating an encryption key, such as an encryption key that can be used to secure communication between the client component and the server component. This process enables the authentication service to remove itself from the process of creating secure communication that directly occurs between the client component and the server component by creating a trusted relationship with each entity. For example, the server can trust an encrypted token received from the client device because it has pre-shared decryption and signature verification keys.
[0016] In non-limiting examples, an encryption key and / or an encrypted token may last for the duration of a client login session. For example, a client device may log in to a distributed gaming service and participate in an online multiplayer session of a game, where the client / server may communicate via secure messaging to enable the execution of an online multiplayer game, including the private messaging capabilities of the client devices participating in the online multiplayer session. The client device may disconnect from the distributed gaming service actively or may automatically log out after a predetermined idle period. In some alternative examples, the associated encryption key and / or encrypted token may also be pre-determined to expire at a specified point in time to avoid unauthorized access to the client account and server interactions. In any case, when the client device disconnects from the server component, it may be required to re-authenticate. This is a trigger for dynamically generating a new encryption key and / or an encrypted token, enabling the server to communicate securely with the client in a new session.
[0017] Exemplary technical advantages provided by the processes described in this disclosure include, but are not limited to: dynamically generating and providing an encryption key and an encrypted token based on client authentication for the purpose of protecting communications between a client and a server; pre-sharing an encryption key that can be used to establish secure communications between a client and a server; pre-sharing decryption and signature verification keys via an authentication service to enable the server to decrypt encrypted and signed tokens; generating and propagating a customized encrypted (and signed) token that can be configured to include customized claims, where the customized claims include an encryption key and other types of data included as claims in the payload of the token; improving processing efficiency during the initiation of a connection between a client and a server for the execution of an application / service; improving the processing efficiency of a computing device (e.g., reducing processing cycles, saving resources / bandwidth) when initiating a connection between a client and a server and establishing secure communications therebetween; reducing latency when secure communications are implemented between a client and a server; being able to send secure communications directly between a client and a server and selectively highlighting that the communication is secure via the graphical user interface of the application / service; achieving interoperability of the described technical security scenarios across multiple applications / services (e.g., applications / services of a software application platform); and improving the usability of the application / service for users and other technical advantages.
[0018] Figure 1Exemplary process flow 100 illustrates the interaction between components that implement secure transmission of communication between computing devices, which can be used to practice aspects of the present disclosure. The exemplary components described in process flow 100 can be hardware and / or software components programmed to perform the processing operations described herein. In some examples, the components of process flow 100 can each be one or more computing devices associated with the execution of a particular service. The exemplary service can be managed by an application platform that also provides the components with access to and knowledge of other components associated with the application / service. In one instance, the processing operations described in process flow 100 can be implemented by one or more components connected via a distributed network. The operations performed in process flow 100 can correspond to operations performed by systems and / or services that execute computer programs, application programming interfaces (APIs), neural network or machine learning processing, language understanding processing, search and filtering processing, and generating content for presentation via the user interface of an application / service, etc. In the exemplary illustration of process flow 100, there are process flow steps (1-5) that are non-limiting examples of the interaction between the components shown in Figure 1 . Process flow steps 1-5 are non-limiting examples of the interaction between client component(s) 102, authentication component(s) 104, and server component(s) 106. Process flow 100 includes: one or more client components 102; one or more authentication components 104; and one or more server components 106. The exemplary components of process flow 100 can be connected via a network connection, where data (including protected data) is transmitted via a network connection known to those skilled in the art. Additionally, process flow 100 between the components can be changed without departing from the spirit of the present disclosure. Additionally, process flow 100 describes what can be used to execute method 200 ( Figure 2 ) and the components described in the accompanying description.
[0019] One or more client components 102 (hereinafter referred to as "client components") can include any one of software components, hardware components, or a combination thereof. For example, client component 102 is a collection of computer programs and / or computing devices that enables a user to access one or more applications / services, which become available via one or more server components 106 (hereinafter referred to as "server components"). Client configurations and operations of client components for implementing the functions described herein are known to those skilled in the art. Client component 102 can include client devices that a user can use to communicate with server component 106. The client device can be a single device, system, or apparatus, or can be implemented in a distributed manner as multiple devices, systems, or apparatuses. Non-limiting examples of client devices include, but are not limited to: smart phones, laptop computers, tablets, PDAs, desktop computers, servers, smart computing devices, including television devices and wearable computing devices, e-reader devices, gaming consoles, and conferencing systems, and other non-limiting examples. As mentioned above, the client device can be a gaming console that a user uses to connect to a distributed gaming platform (e.g., ). For example, the client device can connect to a server to initiate an online multiplayer session for a game, where data transmission between the client device and the service can be protected to enable the online multiplayer session. The client device can connect to the distributed gaming platform via a network connection, where the distributed gaming platform can be configured to connect the user not only to game-related applications / services, but also to any other type of application / service (e.g., accessible via the network connection). Client component 102 interfaces with server component 106 and one or more authentication components 104 (hereinafter referred to as "authentication components") for secure data transmission, which can initiate a connection between the client device and the server and subsequent secure communication transmissions during the operation of one or more applications / services.
[0020] Authentication component 104 can include any software component, hardware component, or a combination thereof. For example, authentication component 104 is a collection of computer programs and / or computing devices that provide functions including, but not limited to: authenticating client component 102 for access to one or more applications / services provided by server component 106; managing the sharing of security data (e.g., encryption keys, decryption keys, and signature verification keys), including pre-sharing security data with client component 102 and server component 106; managing the creation, encryption, and signing of tokens that include data to be transmitted over the network connection; the dynamic generation and applicability of encryption and decryption keys for initiating connections and secure communications between the client and the server; and managing the valid state of encryption keys and / or encrypted tokens, and other examples. Authentication service configurations and operations of authentication components for implementing the functions described herein are known to those skilled in the art.
[0021] The server component 106 can include any software component, hardware component, or a combination thereof. For example, the server component 106 is a collection of computer programs and / or computing devices that provide functionality for a client to access one or more applications / services via the server component 106. Server configurations and operations of server components for implementing the functionality described herein are known to those skilled in the art. As identified above, the server component 106 interfaces with the client component 102 and the authentication component 104 for secure data transmission, which is capable of initiating a connection between the client device and the server and subsequent secure communication transmissions during the operation of one or more applications / services. For example, the server component 106 is configured to interface with the authentication component 104 to receive pre-shared decryption and signature verification keys for decrypting the encrypted and signed tokens created by the authentication component 104. The server component 106 is further configured to receive an encrypted token from the client component 102 that desires access to the applications / services managed by the server component 106. The server component 106 can decrypt and parse the transmitted token to obtain the necessary data to enable the client device to connect to the server (e.g., a game server) and access the encryption keys available for securing the communication. Additionally, the server component 106 is further responsible for initiating a connection to the application / service for an authenticated client and managing the transmission of secure communication with the authenticated client. In some examples, the transmission of secure communication between the client and the server can be implemented over a communication channel created by the server component 106 to manage communication with one or more specific client devices. For example, secure communication can be sent to one or more client devices via a communication channel dedicated to two-way communication with the client device. In some instances, the secure communication channel can further be used to enable authenticated client devices to communicate with each other (e.g., via the server component 106). For example, multiple client devices can participate in an online multiplayer game through a distributed game platform, where the messaging functionality of the online multiplayer game can be enabled through the secure communication channel.
[0022] The process flow steps of the steering process flow 100 (at Figure 1Marked as 1-5) in the figure, the process is initiated at process flow step 1, where the authentication component 104 is configured to pre-share with the server component 106 a decryption and signature verification key for decrypting the encrypted and signed token. During subsequent processing of process flow 100, the server component 106 is configured to use the pre-shared decryption and signature verification key to decrypt the encrypted token and verify the signature on the encrypted token to ascertain that the token has not been modified since it was generated. In at least one example, the authentication component 104 is configured to dynamically generate the decryption and / or signature verification key prior to client authentication processing. Thus, the pre-shared decryption and signature verification key can be applicable to the verification of multiple connected clients. In some alternative examples, the authentication component 104 can be configured to generate a pre-shared key for a single client scenario. As an alternative example, when the client device is authenticated and an encryption key that can be used to secure communication between the client and the server is dynamically generated, the authentication component 104 can be configured to dynamically generate decryption and signature verification keys applicable to managing a specific client authentication scenario and pre-share these decryption and signature verification keys with the server component 106.
[0023] The process can proceed to process flow step 2, where a client authentication call is initiated by the client component 102. The client authentication call can be a request to authenticate the client device to log in to an application / service (e.g., a distributed gaming platform or a distributed gaming service). For example, a user can access the graphical user interface of the application / service via their client device (e.g., a gaming console). The user can enter their login credentials (e.g., client authentication information) through the graphical user interface to access the application / service (or a software application platform that provides access to multiple applications / services). When the user submits their credentials for authentication, the client authentication call can be propagated to the authentication component 104 that performs the authentication service to manage secure data transfer on behalf of the client component 102 and the server component 106.
[0024] At this time, the authentication component 104 evaluates the client authentication information and determines whether to authenticate the user for accessing the application / service. In an example where the client authentication information is found to be valid (i.e., the user is authenticated), the authentication component 104 is configured to dynamically generate an encryption key (or key pair) that can be used to protect data transmission between the client and the server. That is, the authentication of the client authentication information is the trigger for generating the encryption key. As cited above, the present disclosure relates to cryptographic scenarios including symmetric key encryption / decryption and cryptographic scenarios using asymmetric key encryption / decryption. In the symmetric key example, the authentication component 104 can generate a single encryption key used by the client component 102 and the server component 106 to protect their communication. In the asymmetric key example, the authentication component 104 can generate one or more keys for use by a specific entity (e.g., a key pair) that is propagated to the server component 106. The processing operations for generating the encryption key are known to those skilled in the art.
[0025] In addition, the authentication component 104 is further configured to dynamically generate a data token to represent the authenticated client. The data token is a container for data to be transmitted between components, applications / services, etc. over a network connection. As a non-limiting example, due to its integrated scalability, the data token can be a JavaScript Object Notation (JSON) token. However, it should be understood that the present disclosure is configured to work with any type of data token, which can be generated in any format known to those skilled in the art without departing from the spirit of the present disclosure. In one example, the JSON token is a JSON Web Encryption (JWE) token (e.g., an encrypted token). The encrypted token (e.g., JWE token) is used to encrypt the transmitted data and protect its integrity. For example, a man-in-the-middle attack cannot view or modify the data of the JWE token in case of verification failure. This helps the client component 102 and the server component 106 to trust the JWE issued by the authentication component 104.
[0026] In some examples, an additional layer of security is added by digitally signing the JWE token when it is created. When the server component 106 receives an encrypted and signed token corresponding to client authentication, the server component 106 can verify the digital signature. The encrypted token can be encrypted and signed by the authentication component 104 to protect the data of the data token from being tampered with and to make the data (such as sensitive data that cannot be viewed by the client or other unintended parties) opaque to the client. The processes for generating, signing, and encrypting tokens such as JWE tokens (e.g., JSON Web Signature and JSON Web Encryption) are known to those skilled in the art and are not specifically limited herein. In this scenario, the encrypted token is used for: 1) verifying that the client is authenticated to access the application / service associated with the server component 106, including an indication that the data token is valid, and 2) providing a container for the transmitted data including the data (e.g., client identifier and encryption key) such that the server component 106 can securely interface with the client component 102.
[0027] The data fields populated in the encrypted (and signed) token are referred to as data claims. The data claims can be included in the payload of the data token. In non-limiting examples, the data claims can include registered claims, public claims, and private claims. In addition to the data fields necessary for data transmission, developers can customize the data fields included in the encrypted token without departing from the spirit of the present disclosure. Among other types of data fields, the registered claims can include data, which can include but are not limited to: token issuance; the subject of the token; the token's lifetime, including expiration information; and the creation time, as well as other non-limiting examples known to those skilled in the art. The public claims define data fields related to defined names, domains, namespaces, etc., as well as other non-limiting examples known to those skilled in the art. The private claim fields can be custom-defined by the parties transmitting the data. For example, where the developers of the application / service can incorporate application- or service-specific data for transmission to assist in operations. In one example, the private claims can include data such as customer identification information (e.g., user ID, user role, and other relevant information), data for initiating a connection between the client component 102 and the server component 106, and game-server-specific data for performing an application / service related to a distributed gaming platform, and so on. In one example, the encryption key that can be used to protect data transmission between the client and the server is included in the private claims of the payload of the encrypted token. However, the examples of the present disclosure are not limited to the encryption key being included in any type of claim of the encrypted data token.
[0028] The process flow of process flow 100 can proceed to processing step 3, where the generated encryption key and the encrypted and signed token are transmitted from the authentication component 104 to the client component 102. The client component 102 can be configured to present the encrypted and signed token to the server component 106 when the client component 104 accesses an exemplary application / service. In a practical implementation, the possession of the encrypted (and signed) token may not be obvious to the client because the possession of the data token and the forwarding to the server component 106 may be the result of back-end processing.
[0029] The process flow of process flow 100 can proceed to processing step 4, where the client component 102 forwards the encrypted and signed token to the server component 106. This indicates that the client component 102 is initiating a connection to the application / service provided via the server component 106. As referenced in the previous description, the server component 106 is configured to decrypt the encrypted and signed token using a pre-shared decryption and signature verification key. The server can trust the encrypted and signed token received from the client device and, if the encrypted token has not been modified and the signature is verified, establish a secure direct communication with the client using the encrypted token. The server component 106 is then configured to parse the content of the decrypted token and extract the encryption key from the payload (e.g., claims) of the decrypted token.
[0030] The process flow of process flow 100 can proceed to processing step 5, where the server component 106 uses the encryption key to initiate a secure communication directly with the client component 102. As identified in the previous description, the client component 102 already has the encryption key (pre-shared by the authentication service) at process flow step 3. Processing operations for initiating a connection between a client / server, including generating a secure communication, are known to those skilled in the art. In some examples, the server component 106 can be configured to initiate a communication channel that varies based on the interaction with the authenticated client device for the transmission of secure communication between the client and the server. In this way, the client component 102 can communicate directly with the server component 106 in a secure manner that greatly increases the difficulty for a hacker to gain unauthorized access within a secure environment created by interacting with a trusted source.
[0031] Figure 2 Illustrates an exemplary method 200 related to processing operations for initiating and managing a secure communication session between a client and a server, which can be used to practice aspects of the present disclosure. The processing operations described in method 200 can be performed by process flow 100 ( Figure 1) is performed by the components described therein, where the detailed description of process flow 100 supports and supplements the processing operations cited in method 200. Interfaces and communications between exemplary components, such as those described in process flow 100, are known to those skilled in the art. For example, data requests and responses can be transmitted between applications / services to enable a particular application / service to process data retrieved from other applications / services. This includes applying encryption / decryption protocols to protect and decrypt the data used for docking between the exemplary components. Without departing from the spirit of the present disclosure, the format of such communication can vary according to the programming protocols implemented by the developer.
[0032] The exemplary components described in method 200 can be hardware and / or software components that are programmed to perform the processing operations described herein. Each operation performed in method 200 can correspond to an operation performed by a system and / or service that executes a computer program, software agent, intelligent robot, application programming interface (API), neural network, and / or machine learning processing, etc. In some examples, the processing operations described in method 200 can be performed by one or more applications / services associated with a network service that can access multiple applications / services, devices, knowledge resources, etc. In one instance, the processing operations described in method 200 can be implemented by one or more components connected through a distributed network.
[0033] Method 200 begins with processing operation 202, where the authentication service pre-shares decryption and signature verification keys with the server. The pre-shared decryption and signature verification keys are used to decrypt the encrypted and signed token, which the server component subsequently receives when the client authenticates to the application / service hosted by the server component. In at least one example, the authentication service is configured to dynamically generate decryption and / or signature verification keys prior to the client authentication process. Thus, the pre-shared decryption and signature verification keys can be applicable to the verification of one or more connected clients. However, as cited in the foregoing description, some alternative examples can associate the dynamically generated decryption and signature verification keys with specific client authentication scenarios.
[0034] The flow of method 200 can proceed to processing operation 204, where client login data is received for logging in to the application / service. As identified in the foregoing description, including the description of process flow 100 ( Figure 1 ), for example, when the client logs in to the application / service and / or software application platform, the client authentication information can be propagated from the client component (e.g., a programmed client device) to the authentication component (e.g., the authentication service). As a non-limiting example, the user can be executed to perform a SSO login to multiple applications / services provided by the provider.
[0035] The process can proceed to processing operation 206, where the client credentials used for login are authenticated. The process for authenticating client credentials (e.g., client authentication information) has been previously referenced in the description of process flow 100 (authentication component 102) and is known to those skilled in the art. For example, an authentication service can authenticate a client for accessing an application / service hosted by one or more servers.
[0036] In processing operation 208, the authentication service dynamically generates security data for data transmission and publishes portions of the generated security data to the client component and the server component. Based on the result of the user being authenticated (e.g., the client authentication information is verified), the authentication service is configured to: 1) dynamically generate one or more encryption keys that can be used to protect data transmission between the client device and one or more server devices; and 2) dynamically generate an encrypted and signed token (e.g., a signed JWE token) for client authentication for an application / service associated with the server component. Such data items and the decryption and signature verification keys for decrypting the encrypted and signed token include the generated security data. In some examples, signing the token is an optional additional layer of security that may or may not be required to implement the processing described herein. In examples where signing is not required, pre-shared key data with the server component may only require the transmission of the decryption key for decrypting the encrypted token. In any case, processing operation 208 includes transmitting one or more encryption keys along with the encrypted and signed token to the client component (e.g., the client device). That is, one or more encryption keys are pre-shared with the client component, where the client component can directly communicate securely with the server component by decrypting secure communications received from the server component and encrypting communications transmitted to the server component using the one or more encryption keys.
[0037] The process of method 200 can proceed to processing operation 210, where a connection is initiated between the client component and the server component. Initiating the connection (processing operation 208) includes forwarding the encrypted and signed token in a data request to the server component. Since the encrypted token is signed and encrypted and the client component does not possess the decryption key, the content of the encrypted token (including the fact that the encryption key is provided in the claim) is opaque to the client.
[0038] In processing operation 212, the server component is configured to decrypt the encrypted and signed token using the pre-shared decryption and signature verification keys. Processing operation 212 includes parsing the decrypted token and extracting from the payload (e.g., from the claims in the payload) the encryption key that can be used to protect data transmission between the client device and one or more server devices.
[0039] The process can proceed to processing operation 214, where a secure communication is initiated between the client component and the server component using the encryption key extracted from the decrypted token. In a non-limiting example, a communication data channel specific to the communication between the authenticated client (or group of authenticated clients) and one or more servers can be started. As cited above, a non-limiting example is where the client device is a game console communicating with a server device of a distributed game service. In such examples, the secure communication can correspond to an online multiplayer game (e.g., a session) provided by the distributed game service, where the data channel can be dedicated to the interaction of a specific client device in the online multiplayer game or, alternatively, provide communication for multiple authenticated client devices participating in the online multiplayer game.
[0040] At processing operation 216, the server component directly transmits one or more secure communications to one or more clients using the encryption key for protecting the communication. The communication between the client and the server can be two-way, where the shared encryption key can be used to transmit secure communications and decrypt received secure communications. This type of processing can continue until the session of the authenticated client is no longer active.
[0041] The process of method 200 can proceed to decision operation 218, where it is determined whether the client connection to the application / service is terminated. As cited above, the client component can actively disconnect from the distributed game service or automatically log out after a predetermined idle period. In some alternative examples, the associated encryption key and / or encrypted token can also be pre-determined to expire at a specified point in time to avoid unauthorized access to the client account and server interactions. In any case, when the client component disconnects from the server component, it may need to re-authenticate. This is the trigger for dynamically generating a new encryption key and / or encrypted token, enabling the server to communicate securely with the client in a new session. In an example where it is determined that the connection is not terminated, the flow of decision operation 218 branches to NO, and the processing of method 200 returns to processing operation 216, where additional secure communications can be transmitted between the client and the server. In an example where it is determined that the connection between the client and the application / service (e.g., via the server component) has terminated, the flow of decision operation 218 branches to YES, and the processing of method 200 proceeds to processing operation 220.
[0042] In processing operation 220, the client session with the application / service ends and the client needs to re-authenticate to regain access to the application / service. Processing operation 220 may further include terminating the secure communication between the client and the server and / or terminating the data channel for the secure communication. As referenced in the previous description, encryption keys and tokens may be dynamically generated, for example, in response to the authentication of the client authentication information. In the case where the user logs back into the application / service and the client is authenticated, the authentication service is configured to dynamically generate a new encryption key and a new encrypted (and signed) token. This helps to minimize the risk of unauthorized access that could compromise the client device and / or the server.
[0043] Figure 3 Illustrated is a computing system 301 suitable for implementing processing operations related to initiating and managing secure communication sessions between various computing devices, which may be used to practice aspects of the present disclosure. Computing system 301 may be implemented as a single device, system, or apparatus, or may be implemented in a distributed manner as multiple devices, systems, or apparatuses. For example, computing system 301 may include one or more computing devices that perform processing of applications and / or services over a distributed network to enable the processing operations described herein to be performed via one or more services. Computing system 301 may include a collection of devices that perform processing of front-end applications / services, back-end applications / services, or a combination thereof. Computing system 301 includes, but is not limited to, a processing system 302, a storage system 303, software 305, a communication interface system 307, and a user interface system 309. Processing system 302 is operatively coupled to storage system 303, communication interface system 307, and user interface system 309. Non-limiting examples of computer system 301 include, but are not limited to: smart phones, laptop computers, tablets, PDAs, desktop computers, servers, intelligent computing devices, including television devices and wearable computing devices, e-reader devices, gaming consoles, and conferencing systems, and other non-limiting examples.
[0044] Processing system 302 loads and executes software 305 from storage system 303. Software 305 includes one or more software components 306 configured to initiate and manage a communication channel for secure communication between a client and a server, thereby performing processing operations as described herein to achieve this purpose. In some examples, computing system 301 may be a game console for accessing video games, which may be accessed via a network connection or without a network connection. When executed by processing system 302, software 305 causes processing system 302 to operate at least as described herein for the various processes, operation scenarios, and sequences discussed in the foregoing implementations. Computing system 301 may optionally include additional devices, features, or functions not discussed for purposes of simplicity. Computing system 301 may further be used to execute exemplary processing flow 100( Figure 1 ) and method 200( Figure 2 ), where processing operations may be specifically performed to initiate and manage a communication channel for secure communication between a client and a server.
[0045] Still referring Figure 3 , processing system 302 may include a processor, a microprocessor, and other circuitry that retrieves and executes software 305 from storage system 303. Processing system 302 may be implemented in a single processing device, but may also be distributed across multiple processing devices or subsystems that cooperate when executing program instructions. Examples of processing system 302 include general-purpose central processing units, microprocessors, graphics processing units, dedicated processors, sound cards, speakers and logic devices, gaming devices, and any other type of processing device, combination, or variations thereof.
[0046] Storage system 303 may include any computer-readable storage medium that can be read by processing system 302 and capable of storing software 305. Storage system 303 may include volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, cache memories, or other data. Examples of storage media include random access memory, read-only memory, magnetic disks, optical disks, flash memory, virtual and non-virtual memories, magnetic tape cartridges, tapes, magnetic disk storage, or other magnetic storage devices, or other suitable storage media, excluding propagated signals. In any case, a computer-readable storage medium is not a propagated signal.
[0047] In addition to the computer-readable storage medium, in some implementations, the storage system 303 may further include a computer-readable communication medium through which at least some of the software 305 can communicate internally and externally. The storage system 303 can be implemented as a single storage device, but can also be implemented across multiple storage devices or subsystems that are co-located or distributed relative to each other. The storage system 403 may include additional elements, such as controllers, that are capable of communicating with the processing system 302 or possibly other systems.
[0048] The software 305 can be implemented with program instructions and, when executed by the processing system 302, together with other functions, direct the processing system 302 to operate as described in various operation scenarios, sequences, and processes as described herein. For example, the software 305 may include program instructions for the data security component(s) 306a, which may include: client component(s); server component(s), authentication component(s); or any combination thereof. The software 305 may further include application / service component(s) 306b (e.g., of a software application platform) and other service-based components including interactions with third-party applications / services, as described in the foregoing description. For example, the software may include programming instructions that enable specific components of the computer system 301 to perform the processing operations described herein, which may include, but are not limited to: the dynamic generation of encrypted tokens; the dynamic generation of encryption / decryption keys; the transmission of data between clients, authentication, servers, or any combination thereof; the decryption of encrypted tokens; the establishment of a secure communication channel between the client and the server; the encryption / decryption of secure communication between the client / server; the management of the authentication status of users, including the lifetime of tokens and / or encryption keys; and the management of interactions between the client and the service, including graphical user interface representations, etc.
[0049] Specifically, the program instructions may include various components or modules that cooperate or otherwise interact to perform the various processes and operation scenarios described herein. The various components or modules may be embodied in compiled or interpreted instructions, or in some other variant or combination of instructions. The various components or modules can be executed in a synchronous or asynchronous manner, serially or in parallel, in a single-threaded environment or a multi-threaded environment, or according to any other suitable execution paradigm, variant, or combination thereof. The software 305 may include additional processes, programs, or components, such as operating system software, virtual machine software, or other application software. The software 305 may also include firmware or some other form of machine-readable processing instructions that can be executed by the processing system 302.
[0050] In general, when loaded into and executed by processing system 302, software 305 can transform an entire suitable apparatus, system, or device (represented by computing system 301) from a general-purpose computing system into a special-purpose computing system customized for processing data and responding to queries. In fact, the encoded software 303 on storage system 305 can transform the physical structure of storage system 303. In different implementations of this specification, the specific transformation of the physical structure can depend on various factors. Examples of such factors can include, but are not limited to, the technology of the storage medium used to implement storage system 303 and whether the computer storage medium is characterized as primary storage or secondary storage, among other factors.
[0051] For example, if the computer-readable storage medium is implemented as a semiconductor-based memory, then when program instructions are encoded therein, software 305 can transform the physical state of the semiconductor memory, such as by transforming the states of transistors, capacitors, or other discrete circuit elements that make up the semiconductor memory. A similar transformation can occur with respect to magnetic or optical media. Without departing from the scope of this specification, other transformations of the physical media are possible, and the examples provided above are only for the purpose of facilitating this discussion.
[0052] Communication interface system 307 can include communication connections and devices that allow communication with other computing systems (not shown) via a communication network (not shown). Communication interface system 307 can also be used to cover the docking between the processing components described herein. Examples of the connections and devices that take into account inter-system communication include network interface cards or devices, antennas, satellites, power amplifiers, RF circuitry, transceivers, and other communication circuitry. The connections and devices can communicate via a communication medium to exchange communications with other computing systems or system networks, such as metal, glass, air, or any other suitable communication medium. The foregoing media, connections, and devices are well known and need not be discussed in detail herein.
[0053] User interface system 309 is optional and can include: a keyboard, a mouse, a voice input device, a touch input device for receiving touch gestures from a user, a motion input device for detecting non-contact gestures and other movements of the user, and other similar input devices and associated processing elements capable of receiving user input from the user. Output devices (such as a display, a speaker, a haptic device) and other types of output devices can also be included in user interface system 309. In some cases, the input device and the output device can be combined in a single device, such as a display capable of displaying images and receiving touch gestures. The foregoing user input and output devices are well known in the art and need not be discussed in detail herein.
[0054] The user interface system 309 may also include associated user interface software executable by the processing system 302 to support the various user input and output devices discussed above. For example, the user interface software and the user interface devices may, either alone or in combination with each other and with other hardware and software elements, support a graphical user interface, a natural user interface, or any other type of user interface that supports front-end processing of the exemplary applications / services described herein, including establishing a graphical user interface for secure communication channels that permit direct communication between two or more computing devices (e.g., a client and a server and / or other client devices authenticated to communicate in a secure communication channel). The user interface system 309 includes a graphical user interface that presents graphical user interface elements representative of any point in the processes described in the foregoing description, including the process flows 100( Figure 1 ) and the processing operations described in the method 200( Figure 2 ). The graphical user interface of the user interface system 1109 may further be configured to display graphical user interface elements (e.g., data fields, menus, links, graphics, charts, data correlation representations, and identifiers, etc.) that are representations generated from the processes described in the foregoing description. For example, the graphical user interface may enable a client device to log in to a game platform or an application / service and securely send / receive messages directly to a server or to other client devices authenticated and included in a secure communication session (e.g., via a secure data channel).
[0055] Communication between the computing system 301 and other computing systems (not shown) may occur over a communication network or networks and in accordance with various communication protocols, combinations of protocols, or variants thereof. Examples include intranets, the Internet, the Internet, local area networks, wide area networks, wireless networks, wired networks, virtual networks, software-defined networks, data center buses, computing backplanes, or any other type of network, combination of networks, or variant thereof. The communication networks and protocols mentioned above are well known and need not be discussed in detail herein. However, some communication protocols that may be used include, but are not limited to, Internet Protocol (IP, IPv4, IPv6, etc.), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP), as well as any other suitable communication protocol, variant, or combination thereof.
[0056] In any of the above examples of exchanging data, content, or any other type of information, the information exchange can be carried out according to any one of various protocols, including FTP (File Transfer Protocol), HTTP (Hypertext Transfer Protocol), REST (Representational State Transfer), WebSocket, DOM (Document Object Model), HTML (Hypertext Markup Language), CSS (Cascading Style Sheets), HTML5, XML (Extensible Markup Language), JavaScript, JSON (JavaScript Object Notation), and AJAX (Asynchronous JavaScript and XML), Bluetooth, infrared, RF, cellular networks, satellite networks, Global Positioning System, and any other suitable communication protocol, variant, or combination thereof.
[0057] The functional block diagrams, operational scenarios and sequences, and flowcharts provided in the various figures represent exemplary systems, environments, and methods for performing the novel aspects of the present disclosure. Although, for purposes of concise explanation, the methods included herein may be shown in the form of a functional diagram, operational scenario or sequence, or flowchart and may be described as a series of acts, it will be understood and appreciated that the methods are not limited by the order of these acts, since, in accordance with the present invention, certain acts may occur in a different order and / or concurrently with other acts than those shown and described herein. For example, those skilled in the art will understand and appreciate that the methods may alternatively be represented as a series of interrelated states or events, such as in the form of a state diagram. Additionally, not all acts illustrated in the methods are required for a novel implementation.
[0058] The descriptions and figures included herein depict specific implementations for teaching those skilled in the art how to make and use the best options. For purposes of teaching the principles of creativity, some conventional aspects have been simplified or omitted. Those skilled in the art will appreciate that variations from these implementations also fall within the scope of the present invention. Those skilled in the art will also appreciate that the features described above can be combined in various ways to form multiple implementations. As a result, the present invention is not limited to the specific implementations described above, but is defined only by the claims and their equivalents.
[0059] Throughout this specification, reference is made to "one example" or "an example", which means that a particular described feature, structure, or characteristic is included in at least one embodiment. Thus, the use of these phrases may refer to more than just one example. Moreover, the described features, structures, or characteristics may be combined in any suitable manner in one or more examples.
[0060] However, those skilled in the relevant art can understand that each example can be implemented by omitting one or more specific details, or by other methods, resources, materials, etc. In other instances, well-known structures, resources, or operations have not been shown or described in detail so as to avoid only confusing certain aspects of each embodiment.
[0061] Although examples and applications have been shown and described, it should be understood that this embodiment is not limited to the above exact configurations and resources. Various modifications, changes, and variations that are obvious to those skilled in the art can be made to the arrangements, operations, and details of the methods and systems disclosed herein without departing from the scope of the present example claimed.
Claims
1. A method for establishing secure communication, comprising: transmitting user authentication information for logging in to an application or service from a client device to an authentication service; in response to authentication of the user authentication information by the authentication service, receiving an encrypted token associated with accessing the application or service at the client device, wherein the encrypted token includes an encryption key in a payload, and a server associated with the application or service and the authentication service pre-share a decryption key and a signature verification key, wherein the encrypted token is encrypted and signed by the authentication service; forwarding the encrypted token by the client device to the application or service to initiate a connection with the application or service; and receiving secure communication at the client device from the server, wherein the secure communication is protected using the encryption key without additional processing to look up the identity of the client device or any further intervention from the authentication service.
2. The method according to claim 1, wherein, further comprising: initiating a connection to the application or service via the client device, and wherein the secure communication is received at the client device by an instance of the application or service presented based on the initiated connection.
3. The method according to claim 1, wherein, the client device is a game console and wherein the application or service is a distributed game service.
4. The method according to claim 3, wherein, the secure communication corresponds to an online multiplayer game provided by the distributed game service, and wherein the secure communication further includes one or more additional authenticated client devices interacting in the online multiplayer game.
5. The method according to claim 1, wherein, the encryption key is dynamically generated in response to authentication of the user authentication information, and wherein the use of the encrypted token and the encryption key is available until the client device disconnects from the application or service.
6. The method according to claim 1, wherein, the encryption key is included as a claim in the payload of the encrypted token.
7. The method according to claim 1, wherein, the data within the encrypted token including the encryption key is opaque to the client device, and wherein the server accesses the encryption key by decrypting the encrypted token using the pre-shared decryption key, wherein the pre-shared decryption key is pre-shared by the authentication service with the server before generating the encrypted token.
8. The method according to claim 1, wherein, the authentication service pre-shares the encryption key with the client device.
9. A system for establishing secure communication, comprising: at least one processor; and a memory operably connected to the at least one processor, the memory storing computer-executable instructions that, when executed by the at least one processor, cause the at least one processor to perform a method, the method comprising: Transmit user authentication information for logging in to an application or service from the system to an authentication service; In response to authentication of the user authentication information by the authentication service, receive an encrypted token associated with accessing the application or service at the system, wherein the encrypted token includes an encryption key in a payload, and a server associated with the application or service and the authentication service pre-share a decryption key and a signature verification key, and wherein the encrypted token is encrypted and signed by the authentication service; Forward the encrypted token by the system to the application or service to initiate a connection with the application or service; and Receive secure communication at the system from a server associated with the application or service, wherein the secure communication is protected using the encryption key without additional processing to look up the identity of the system or any further intervention from the authentication service.
10. The system according to claim 9, wherein, the method performed by the at least one processor further includes: initiating a connection to the application or service via the system, and wherein the secure communication is received at the system by an instance of the application or service presented based on the initiated connection.
11. The system according to claim 9, wherein, the system is a game console and the application or service is a distributed game service, and wherein the secure communication corresponds to an online multiplayer game provided by the distributed game service.
12. The system according to claim 9, wherein, the encryption key is dynamically generated in response to authentication of the user authentication information, and wherein the use of the encrypted token and the encryption key is available until the system disconnects from the application or service.
13. The system according to claim 9, wherein, the encryption key is included as a claim in the payload of the encrypted token.
14. The system according to claim 9, wherein, the data within the encrypted token including the encryption key is opaque to the system, and wherein the server accesses the encryption key by decrypting the encrypted token using the pre-shared decryption key, and wherein the pre-shared decryption key is pre-shared by the authentication service with the server before generating the encrypted token.
15. The system according to claim 9, wherein, the authentication service pre-shares the encryption key with the system.
16. A method for establishing secure communication, comprising: receiving, at a server device, a pre-shared decryption key and a signature verification key from an authentication service for decrypting an encrypted token associated with accessing an application or service, wherein the encrypted token is encrypted and signed by the authentication service; receiving, at the server device, the encrypted token from a client device, wherein the encrypted token includes an encryption key in a payload that can be used to protect communication with the client device; decrypting the encrypted token using the pre-shared decryption key; Extract the encryption key from the payload of the decrypted token; and Use the extracted encryption key to transmit secure communication to the client device without additional processing to look up the identity of the client device or any further intervention from the authentication service.
17. The method according to claim 16, wherein, The encryption key is included as a claim in the payload of the encrypted token, and wherein the extraction extracts the encryption key from the claim.
18. The method according to claim 16, wherein, Further comprising: Initiate a connection from the application or service to the client device; Start a communication channel for communicating with the client device, and wherein the secure communication is transmitted over the secure communication channel by an instance of the application or service started on the client device based on the initiated connection.
19. The method according to claim 17, wherein, The client device is a game console, wherein the application or service is a distributed game service, and wherein the secure communication corresponds to an online multiplayer game provided by the distributed game service.
20. The method according to claim 17, wherein, The transmission is protected using an asymmetric encryption protocol, and the encryption key is the first asymmetric encryption key of the asymmetric encryption protocol, and wherein the client device uses the second asymmetric encryption key of the asymmetric encryption protocol to decrypt the secure communication.
Citation Information
Patent Citations
Method and system for hypertext transfer protocol digest authentication
EP2717539A1