Passive cloud
By introducing data valves and temporary storage areas during data transmission and utilizing the NOC system to manage data flow, the problem of protocol and legal differences in cross-sovereign territory data transmission is resolved, thus ensuring the security and legality of data.
Patent Information
- Application Number
- CN202480032561.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-03
- Filing Date
- 2024-05-13
- Publication Date
- 2025-12-12
AI Technical Summary
Data transmission across sovereign territories faces differences in security protocols and legal requirements, making it difficult for data recipients to determine the legality and security of the data.
Data valves and temporary storage areas are introduced during data transmission. Data valves verify and isolate data at intermediate points, while NOC systems manage data flow to ensure that data complies with the legal and security requirements of the receiving party's sovereign territory. Further verification and processing are then performed in the temporary storage area.
It ensures the security and legality of data during cross-sovereignty regional data transmission, guarantees that data complies with legal requirements at the receiving end, and reduces the risk of data leakage and unauthorized access.
Smart Images

Figure CN121128137A_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims the benefits of U.S. Provisional Application No. 63 / 466,599, filed May 15, 2023; U.S. Non-Provisional Application No. 18 / 654,267, filed May 3, 2024; and U.S. Non-Provisional Application No. 18 / 654,448, filed May 3, 2024, each of which is incorporated in its entirety by reference for all purposes. Technical Field
[0003] This disclosure relates to the field of computing networks, and more particularly, to techniques for verifying data transmitted from one region of the computing network to another region. Background Technology
[0004] Cloud service providers (CSPs) can offer multiple cloud services to subscribers. These services are offered under different models, including Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS), and so on. Summary of the Invention
[0005] This disclosure generally relates to verifying data received from a second sovereign region within a first sovereign region. More specifically, techniques for storing data received from a foreign jurisdiction in an isolated environment are described. The data can be verified while stored in the isolated environment. Verified data can be approved for transfer from the isolated environment to a data center in the first sovereign region. Various embodiments are described herein, including computer-implemented methods, systems, non-transitory computer-readable media storing programs, code, or instructions executable by one or more processors. Some embodiments can be implemented using a computer program product comprising programs / instructions that, when executed by a processor, cause the processor to perform any of the methods described in this disclosure.
[0006] A computer-implemented method may include: detecting data from a second data center in a second region by a computing system in a first data center in a first region. The data may be stored in an isolated environment of the first data center.
[0007] The computer-implemented method may also include determining verification parameters by the computing system, at least in part, based on the first region.
[0008] The computer-implemented method may also include verifying the data by the computing system, at least in part, based on verification parameters.
[0009] The computer-implemented method may also include processing by a computing system a first message instructing the release of data from the isolated environment.
[0010] The computer-implemented method may further include processing by a computing system a second message indicating that the first message originates from a computing device located in the first region.
[0011] The computer-implemented method may also include the release of data from the isolated environment by a computing system based at least in part on a first message that verifies and releases data, and a second message originating from the first region. Attached Figure Description
[0012] Figure 1 This is an illustration of an example data verification system based on one or more embodiments.
[0013] Figure 2 This is an illustration of an example data verification system based on one or more embodiments.
[0014] Figure 3 This is an illustration of an example data valve according to one or more embodiments.
[0015] Figure 4 This is an illustration of an example verification technology database based on one or more embodiments.
[0016] Figure 5 This is an illustration of an example staging area according to one or more embodiments.
[0017] Figure 6 This is a signaling diagram of an example process for data verification according to one or more embodiments.
[0018] Figure 7 This is an example process flow for data verification according to one or more embodiments.
[0019] Figure 8 This is an example process flow for data verification according to one or more embodiments.
[0020] Figure 9 This is a block diagram illustrating a pattern for implementing a cloud infrastructure-as-a-service system according to at least one embodiment.
[0021] Figure 10 This is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system according to at least one embodiment.
[0022] Figure 11 This is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system according to at least one embodiment.
[0023] Figure 12 This is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system according to at least one embodiment.
[0024] Figure 13 This is a block diagram illustrating an example computer system according to at least one embodiment. Detailed Implementation
[0025] In the following description, various embodiments will be described. Specific configurations and details are set forth for illustrative purposes to provide a thorough understanding of the embodiments. However, it will be apparent to those skilled in the art that the embodiments can be practiced without these specific details. Furthermore, well-known features may be omitted or simplified so as not to obscure the described embodiments.
[0026] An entity may control more than one data center and may wish to transfer or receive data from a data center in one region to a data center in another region. For example, an entity (e.g., a cloud service provider) may have a data center in a first region (e.g., the United States) and expect to transfer data to another data center in a second region (e.g., Europe). One potential issue is that the protocols used for the data center receiving the data may differ from those used for transferring the data. For example, the security protocols at the receiving data center may differ from those at the transmitting data center. This can raise questions about whether the data should be received by the receiving data center.
[0027] This document describes an embodiment of a secure conduit for transferring data across sovereign boundaries from one data center to another. A secure conduit for enhanced data flow regulation can be established between two data centers, which may be operated by the same service provider. The secure conduit may include a data valve positioned at an intermediate point between the two data centers. The data valve can regulate data flow in a predetermined format and pattern in a specific direction, and specify validation rules that must be applied to any data payload to determine whether the payload is allowed to pass. The data valve can log all payloads and their processing results. Such logs can be fed into a Security and Information Event Management (SIEM) system for further processing and auditing.
[0028] A data valve can include software, hardware, or a combination thereof for verifying data. For example, in some cases, a data valve may be a bare-metal server, and in others, it may be a network interface controller (NIC) that controls traffic to and from a host. Verification performed by the data valve can include reviewing any changes to the data, including manual, automatic, or semi-automatic changes. Verification can include verifying any change signatures to determine if the signature corresponds to someone authorized to make the change. Verification can include checking the data for malware. Malware detection can be performed without or without the assistance of a machine learning model. Verification can include hermetic rebuilding from the source. For example, the receiving data center may request instructions for building an object instead of accepting the object. For example, the object can be rebuilt using any necessary libraries, code, or other data at the data valve. This process can include the receiving data center building the object in a secure environment (e.g., a hermetic environment) at the data valve, where the data cannot interact with other data outside the secure environment. Verification can also include hermetic rebuilding from the source. Verification can also include hermetic rebuilding using alternative dependencies. The receiving data center can determine whether data transmitted by the sending data center is valid or invalid based on the verification process described above.
[0029] Data can pass through a data valve and reach the receiving data center, where it is stored in a staging area. The staging area can be a secure region separating the data from the rest of the receiving data center. The staging area can include software, hardware, or a combination thereof for verifying the data and isolating it from the rest of the receiving data center. The staging area can also be used to perform verifications other than those performed at the data valve to validate the data. The receiving data center can determine whether data is allowed to leave the staging area and enter the receiving data center.
[0030] Figure 1 This is a diagram 100 illustrating an example data verification system according to one or more embodiments. A Network Operations Center (NOC) 102 can communicate with a first data center 104 and a second data center 106. NOC 102 can be one or more virtual or physical interfaces of the data centers used to operate the various data center systems. For example, NOC 102 can be a computer in a designated room within the first data center 104 or the second data center 106, or NOC 102 can be a computer used by authorized personnel to operate the various data center systems. In other words, NOC 102 can be a computing device, such as a laptop computer located outside the first data center 104 and the second data center 106.
[0031] NOC 102 may have its use restricted by Operational Access Lease (OAT) 108, which may be an authorized person to use NOC 102 to operate various data center systems. In some cases, these persons are residents of the same area as the data center. For example, if the data center is located in India, the person is also a resident of India and physically resides in the same area as the data center. NOC 102 may include one or more security mechanisms to restrict NOC use to OAT 108. For example, access to use of NOC 102 may be protected by passwords, biometrics, or other appropriate security measures. In other cases, access to NOC 102 may be protected by additional security measures, such as storing NOC 102 in a secure room that requires authorization from security personnel and / or passwords, biometrics, or other appropriate access security measures. In any case, access to NOC 102 may be restricted to OAT 108.
[0032] First data center 104 and second data center 106 can be part of a network of data centers operated by a cloud service provider (CSP) 110. The data center network can be regionally distributed, with each region potentially including one or more data centers. Each data center within a region can include physically distinct infrastructure, including servers, computing systems, intranetting systems, internal climate control systems, and internal power systems. Therefore, if a failure or anticipated failure occurs at one data center, it is unlikely to affect another data center, given that each data center is physically distinct and has its own internal systems. Data centers within a region (e.g., first data center 104 and second data center 106) can be connected via a low-latency, high-bandwidth network. Therefore, even if a failure or anticipated failure occurs at one data center, other data centers within the region can continue to provide service to the CSP's customers.
[0033] Each data center can manage data on behalf of the CSP's customers and suppliers. This data includes any data provided by the CSP's customers or suppliers, as well as any data or metadata derived from the interaction between the customers or suppliers and the cloud service. This data and metadata may include customer-provided data, customer identity, compute name, IP address, data address, metrics, usage data, and other data.
[0034] Data stored in data centers may be subject to the legal requirements of the sovereign territory in which the data center is located. For example, depending on the sovereign territory, data may be subject to different privacy regulations. Data stored in California is subject to the California Consumer Privacy Act (CCPA), while data stored in the European Union is subject to the General Data Protection Regulation (GDPR). Although each of the CCPA and GDPR may have some overlapping requirements, other differences between the CCPA and GDPR necessitate managing data stored in California differently than data stored in Europe. It should be understood that data privacy is just one example of a legal area where different sovereign territories may impose different legal requirements on data.
[0035] As illustrated, the first data center 104 and the second data center 106 can be located in the same first sovereign territory 112. In this scenario, data stored in the first data center 104 and data stored in the second data center 106 are subject to the same legal requirements. In some other cases, a data center in one sovereign territory may wish to transfer data from another sovereign territory. In these cases, the differences in the legal requirements of one jurisdiction and the other can be considered before transferring data from one data center to another.
[0036] For example, CSP 110 can operate first data center 104 and second data center 106, both located in first sovereign zone 112. CSP 110 can also operate third data center 114 in second sovereign zone 116. If CSP 110 wants to transmit data from third data center 114 to first data center 104, CSP 110 may need to consider whether the payload from third data center 114 complies with the legal requirements of first sovereign zone 112.
[0037] NOC 102 can be used to manage data received or transmitted from or through a secure conduit 118 to a first data center 104. In some embodiments, the secure conduit 118 can be unidirectional. In other words, CSP 110 can transmit data from one or more data centers to the first data center 104 through the secure conduit 118. However, the first data center 104 cannot receive data from one or more data centers through the secure conduit 118. In other embodiments, the secure conduit 118 can be bidirectional, where the first data center 104 and one or more data centers can transmit data to each other through the secure conduit 118.
[0038] The security conduit 118 may include a data valve 120 located at an intermediate point between the first data center 104 and the third data center 114. In some embodiments, the data valve 120 may be located within the boundary of a first sovereign territory 112. For example, if the first sovereign territory 112 is France, then both the first data center 104 and the data valve 120 are located in France. The data valve 120 may include software, hardware, or a combination thereof for temporarily storing data transferred from the data center (e.g., the third data center). Data stored at the data valve 120 may be isolated and inaccessible to users at the third data center 114 and the first data center 104.
[0039] Data transmitted from the third data center 114 can be intercepted by data valve 120. Data valve 140 can transmit a message to NOC 102 that the data has been received by security conduit 118. NOC 102 can transmit a response including control commands for data valve 120 to isolate the data, making the data inaccessible to the third data center 114, and verifying the data received from the third data center 114.
[0040] Data valve 120 can verify data according to control instructions including verification requirements. Each sovereign region can implement its own data verification requirements. Data valve 120 can verify data according to the requirements of the sovereign region. Since the data is neither located in the third data center 114 nor in the first data center 104, the data valve can replicate the data and has the flexibility to perform various operations to verify it without interference from the third data center 114. The verification results can be transmitted to NOC 102. The results may include, for example, a description of any changes, checksums, and other relevant data.
[0041] As indicated above, NOC 102 can be used by personnel, including one or more persons authorized to operate one or more systems in each of the first data center 104 and the second data center 106. In addition to being authorized to operate one or more systems, personnel may also satisfy additional time conditions to authorize the release of data from data valves. Personnel may be required to be physically present in the sovereign area in which the data center is located. For example, personnel may be required to be located in the first sovereign area 112. Another requirement may be that these personnel must be residents of the sovereign area in which the data center is located. Similarly, as illustrated, personnel may be required to be residents of the first sovereign area 112.
[0042] NOC 102 can communicate with the human resources system at the first data center 104. The human resources system may include employee data indicating which employees are currently employed by CSP 110 and authorized to use NOC 102. Users may be required to enter a password, use multi-factor authentication, or submit biometric information to verify their identity. In response to verifying the user's identity and authorization to use NOC 102, the first data center computing system can access the human resources system to confirm that the user is a resident of the first sovereign area 112. The first data center computing system can also determine whether the user is physically located within the first sovereign area. For example, if NOC 102 is a laptop, the user may have taken their laptop out of the first sovereign area 112. The first data center computing system can use various methods to determine whether the user is physically located within the first sovereign area 112. For example, the first data center computing system can determine whether NOC 102 is connected to a local network. In another example, the first data center computing system can access location services (e.g., Global Positioning System services) to determine the location of NOC 102. If a user enters a password, uses multi-factor authentication, or submits biometric information in NOC 102, and NOC 102 is located within the first sovereign zone 112, it can be inferred that the user is also located within the first sovereign zone 112.
[0043] If NOC 102 verifies the user's identity, authorization level, and location, NOC 102 can authorize the user to determine whether to permit data valve 120 to release data. The user can review the data and verification results with the assistance of the computing system from the first data center and determine whether to permit data valve 120 to release data. If the user chooses not to permit data valve 120 to release data, the data valve can process the data. For example, data valve 120 can delete data, perform any copying of data, and perform any transformation of data. The computing system in the first data center can also send a message to the third data center 114 indicating that data is not permitted to enter the first data center 104.
[0044] If the user grants permission for data valve 120 to release data, the data can be received at a staging area. First data center 104 can store data at the staging area, which can be an isolated environment of first data center 104, similar to data valve 120. Data can undergo a second verification while in the staging area. As described above, one or more verification processes can be performed at the staging area. Additional processes can also be performed to verify data at the staging area. In some cases, the staging area can have different capabilities than data valve 120. For example, the staging area can have more capabilities than data valve 120. In these cases, the staging area can be able to verify additional sovereign territory requirements compared to data valve 120. The staging area can also transmit verification results to NOC 102.
[0045] Based on the verification performed at the staging area, the person using NOC 102 can determine whether to release data from the staging area and to the first data center 104. If the same NOC 102 is used to release data from data valve 120, the user may or may not be required to re-verify their identity, authorization level, location, and place of residence. However, if a different NOC 102 is used to release data from the staging area, the user may be required to verify their identity, authorization level, location, and place of residence.
[0046] In some embodiments, data from a data center (e.g., a third data center 114) can be verified at the data valve 120 and the staging area. In some other embodiments, a security conduit 118 is included within the staging area, such that data is verified by the data valve 120 at the staging area.
[0047] After the data is released from the buffer, it can be converted for storage at the first data center 104. It should be understood that the data is transmitted from data valve 120 in the same format as the data received by data valve 120. In other words, the data is transmitted from the data valve in the same format as the data transmitted from the third data center 114. For example, the data can be organized into raw data, metadata, and summary data in a format compatible with the first data center 104. The data can then be stored at the first data center 104 and made available to the user.
[0048] Figure 2 This is an illustration of an example data verification system according to one or more embodiments. First data center 202 and second data center 204 may be part of a network of data centers operated by the same CSP. First data center 202 may be located in a first sovereign region 206 (e.g., the United States), and second data center 204 may be located in a second sovereign region 208 (e.g., Spain). First data center 202 and second data center 204 may also utilize [the following information is missing from the original text]. Figures 9-13 The infrastructure and computing systems described herein are used to perform the functions described herein.
[0049] First data center 202 can transmit data to second data center 204 via secure conduit 210. Secure conduit 210 may include one or more security measures to prevent unauthorized access to data transmitted through the conduit. For example, data transmitted across secure conduit 210 may be encrypted at first data center 202 and decrypted at second data center 204.
[0050] Security conduit 210 may include a data valve 212 positioned at an intermediate point between the first data center 202 and the second data center 204, and within the second sovereign zone 208. For example, data valve 212 may be located within the sovereign boundary 228 of the second sovereign zone 208. Data valve 212 may include a combination of hardware (e.g., a server or network interface controller) and software for regulating data in a unidirectional path from one or more data centers (including the first data center 202) to the second data center 204. Data valve 212 may also create an isolation environment in which data intercepted at data valve 212 cannot be accessed by either the first data center 202 or the second data center 204 until data valve 212 releases the data. Generally, an isolation environment can be one in which neither the source system nor the target system can access the data within the isolation environment before data verification. Data in the isolation environment must be verified and authorized for release before the source and target systems can access the data. In the event that data valve 212 intercepts data routed to the second data center 204, data valve 212 can store the data in an isolated environment and implement access control that prevents both the first data center 202 and the second data center 204 from accessing the data. The data can be stored in a format provided by the first data center 202 (e.g., JSON). After the data has been isolated, data valve 212 can send a message to the second data center 204 indicating that the data transmitted through security pipe 210 has been received at data valve 212. For example, the second data center 204 may include a NOC for operating one or more systems capable of receiving messages. The message may include indications of the characteristics of the received data. For example, the message may indicate the data structure type, data class, and other appropriate data categories. The NOC sends a response message along with instructions to verify the data. In some cases, the message may include instructions to use a specific verification technique for a specific data category. In other cases, data valve 212 may be configured to select a specific verification technique based on the data category or sovereignty requirements. Data valve 212 can verify the data and send the verification result to the NOC.
[0051] The user operating the NOC can determine whether to permit the release of data from data valve 212 based on the verification result. For example, the user can view the verification result and enter an input indicating whether data should be released from data valve 212. However, before executing a command to permit or deny the release of data from data valve 212, the NOC can determine whether the user meets the requirements for making that determination. The NOC can access the identifier associated with the user. For example, the NOC can be assigned to the user, who may have entered a user identifier or password, or the NOC can use biometric data (such as facial features) to identify the user. The NOC can transmit the user's identity along with the instruction to the permission parser 214 to determine whether the user meets the requirements for determining whether to permit the release of data from data valve 212.
[0052] The license parser 214 may include software for applying a set of rules and determining whether a user meets the requirements for making that determination. Requirements may include whether the user is currently an employee of the CSP, whether the user has a license level to determine whether to allow or deny the release of data from the data valve 212, whether the user is a resident of a second sovereign zone, and whether the user is currently located within a second sovereign zone.
[0053] The permission resolver can access a second human resources system 216 in the second sovereign region 208. The second human resources system 216 may include employee information of employees working in the second sovereign region. For example, the second human resources system may include employee information for each employee working in each data center within the second sovereign region 208. Employee information stored in the second human resources system 216 may include personally identifiable information such as name, employee identifier, address, and place of residence. In some cases, the second human resources system 216 may include a subset of employees working for the CSP. The CSP may include a global human resources system that includes employee information for all employees of the CSP. For example, in some cases, the first sovereign region 206 may be the headquarters of the CSP and include a first human resources system 218 as the global human resources system. In other cases, the global human resources system may be located in a data center other than the data center that transmits data to the second data center 204. In any case, the permission resolver 214 may be configured to determine employee information from the local human resources system, rather than accessing employee information from the global human resources system.
[0054] The license resolver 214 can transmit the employee identifier along with instructions for verifying that the user is currently working for the CSP, the user's license level, and the user's place of residence to the second human resources system 216. The second human resources system 216 can access the employee database and access the user's files based on the received employee identifier. The second human resources system 216 can also determine whether the user is currently an employee of the CSP and whether they have been assigned to the second data center 204. In other words, the license resolver 214 can locally resolve whether the user is currently working for the CSP, whether they have been assigned to the second data center 204, and whether they are a resident of the second sovereign zone 208.
[0055] In some embodiments, the second human resources system 216 may also access the global human resources system (e.g., the first human resources system 218) and re-verify that the user is currently working for a CSP, that the user has been assigned to the second data center 204, and that the user is a resident of the second sovereign region 208. In some cases, the global human resources system may have already been updated with changes to the user's employment status, location assignment, and place of residence; and the global human resources system may not have pushed the updates to the local human resources system (e.g., the second human resources system 216).
[0056] The second human resources system 216 can also determine whether a user has permission to authorize the release of data. The second human resources system 216 can also access a second licensing service 220, which is configured to manage employee access rights to prevent employees from engaging in unauthorized activities on the CSP's computing systems. The second licensing service 220 may include information for managing roles, licenses, and access control rules assigned to employees in the second data center 204. For example, the CSP may assign licenses to employees based on predefined rules. These licenses may include whether a user can authorize or deny the release of data from data valve 212.
[0057] The second human resources system 216 can send a message to the second licensing service 220, providing the user's identity and a request for information regarding whether the user has the necessary permissions to determine whether data can be released from the data valve 212. In response to receiving the identity and request, the second licensing service 220 can determine whether the user has the necessary permissions. For example, the user may be part of a group already designated by the CSP that has the necessary permissions to determine whether data can be released from the data valve. The second human resources system 216 can check the group to verify the user's status as a group member.
[0058] In some embodiments, the second human resources system 216 may also access a global human resources system (e.g., the first human resources system 218) and transmit user identity and requests to verify the user's license level. The global human resources system may access a global licensing service. For example, the first licensing service 222 of the first data center 202 may be a global licensing service. The first licensing service 222 may access its records and determine whether a user has the necessary license level. Similar to the human resources system, the global licensing service may have been updated with changes to the user's license level; and the global licensing service may not have pushed the updates to the local licensing service (e.g., the second licensing service 220).
[0059] The license resolver 214 can also determine whether the user is located in the second sovereign zone 208. To do this, the license resolver 214 can determine whether the NOC is located in the second sovereign zone 208. If the NOC is in the second sovereign zone 208, the license resolver 214 can infer that the user is also in the second sovereign zone 208. The license resolver 214 can use various methods to determine whether the NOC is in the second sovereign zone 208. The license resolver 214 can determine that the NOC is physically located within the second data center 204. For example, the license resolver 214 can access the mainframe in the second data center 204 and determine that the NOC is communicating with the mainframe using a wired communication interface. The license resolver 214 can also infer the user's presence in the second sovereign zone 208 based on the wired communication with the mainframe. In another example, the license resolver can access the local area network (LAN) (such as a Wi-Fi network) of the second data center 204 and communicate with the NOC using a wireless interface. Based on the communication, the license resolver can determine that the NOC is connected to the LAN. The license resolver 214 can also determine that the NOC is located within the second sovereign zone 208 based on the fact that the NOC is connected to the LAN.
[0060] In yet another example, the NOC may be equipped with circuitry for accessing location services, such as Global Positioning System (GPS) services. The license resolver 214 may transmit messages to the NOC via a wired or wireless interface to provide the NOC's location via the location service. If the NOC provides a location within the second sovereign area 208, the license resolver 214 can determine that the NOC is located within the second sovereign area 208. If the license resolver 214 determines that the NOC is within the second sovereign area 208, it can also determine that the user is within the second sovereign area 208.
[0061] However, sometimes the license resolver 214 may initially determine that the NOC is not located within the second sovereign zone 208. For example, if the NOC does not communicate with the mainframe via a wired connection, or if the NOC is not connected to the LAN, the license resolver may send a message to the NOC requesting its location via a location service. If the NOC can provide a location within the second sovereign zone 208, the NOC can determine that it is within the second sovereign zone 208. If the NOC cannot provide a location within the second sovereign zone 208, the license resolver 214 can determine that the NOC is not within the second sovereign zone 208.
[0062] The license resolver 214 can use one or more of the methods described above to determine the NOC and, by inference, whether the user is located in the second sovereign zone 208. It should be understood that the license resolver 214 can also use the methods in various sequences. For example, as noted above, if the license resolver 214 determines that the NOC is not connected to the mainframe via a wired interface or to the LAN via a wireless interface, the license resolver 214 can send a request for location information from the location service to the NOC. In another case, the license resolver 214 can send a request for location information from the location service to the NOC. Then, if the NOC cannot provide location information indicating that the NOC is in the second sovereign zone 208, the license resolver 214 can determine whether the NOC is connected to the mainframe via a wired interface or to the LAN via a wireless interface.
[0063] In order to determine whether a user's data should be released from data valve 212, the user can be required to meet all requirements. Therefore, in order to make a decision on whether a user's data should be released from data valve 212, the user can be required to currently work for a CSP, be assigned to a second data center 204, be a resident of a second sovereign territory 208, and be assigned a permission level, thereby making a determination.
[0064] If the user decides to refuse the release of data from data valve 212, the data and any permutations thereof (e.g., copies, transformations) can be deleted. However, if the user decides to release the data from data valve 212, the data can be received in the staging area.
[0065] After passing through data valve 212, data can be received at staging area 226 in the second data center 204. Staging area 226 can be an intermediate storage area that the second data center can use for data processing. Similar to data valve 212, staging area 226 can provide an isolated environment for verifying data before it is reformatted and introduced into the data storage of the second data center 204. Staging area 226 may include storage devices of a network interface controller or a bare-metal storage server. Furthermore, as described above, one or more verification processes can be performed at staging area 226.
[0066] Data can be received by the staging area 226 in the same format as that transmitted by data valve 212. Furthermore, data can also be received by the staging area 226 in the same format as that transmitted by the first data center 202. When data is stored in the staging area 226, the second data center 204 can instruct the staging area 226 to perform one or more verification operations. For example, after data is received in the staging area 226, the permission parser 214 can notify the NOC that the data has been received at the staging area. The permission parser 214 can also verify that the data is inaccessible to any system of the second data center 204 other than the first data center 202, data valve 212, or the staging area system. The NOC can transmit a response message to perform one or more verification procedures on the data and return a result report to the NOC. In some cases, the NOC can transmit instructions for a specific verification procedure to be performed, and in other cases, the NOC can transmit instructions to select a verification procedure based on the nature of the data. The permission parser 214 can transmit control instructions to the staging area 226 to perform one or more verification procedures based on instructions from the NOC.
[0067] Staging area 226 allows data to be verified in a single location, rather than being distributed throughout second data center 204 for verification by different processes. Verification can be performed in a single area, and the results can be transmitted to the NOC, including each step in the verification process. In this sense, because the staging area is aware of each step in the verification process being performed, one or more verification steps are not omitted from the final verification test report. Furthermore, if the data does contain viruses, malware, or other code that may be harmful to second data center 204 (including any stored data), the isolated environment of staging area 226 prevents harmful data from interacting with any data stored in second data center 204.
[0068] The temporary storage area 226 can perform one or more verification processes on the data based on instructions from the license parser 214. (Regarding...) Figure 4 An example of one or more verification processes is described in more detail. The temporary storage area 226 can also transmit the verification result to the license resolver 214. The license resolver 214 can then transmit the verification result to the NOC. The NOC can transmit a response message indicating whether the data can be released from the temporary storage area.
[0069] As illustrated, data valve 212 and buffer zone 226 are indicated as separate points where verification can be performed. It should be understood that in some cases, the security conduit 210 from the first data center 202 to the second data center 204 may include either data valve 212 or buffer zone 226, rather than both. For example, if data valve 212 is present, buffer zone 226 may not exist. Alternatively, if buffer zone 226 is present, data valve 212 may not exist.
[0070] If data is released from the staging area, the deployment of the data to its intended destination in the second data center 204 can be managed by the service manager 224.
[0071] Figure 3 The illustration 300 illustrates an example data valve according to one or more embodiments. Data valve 302 may include a data analysis unit 304, a mapping unit 306, a verification technology database 308, and a verification unit 310. Data valve 302 may be gated from an external environment via a first access control unit 312 and a second access control unit 314. The first access control unit 312 may include a combination of software and hardware configured to manage data going to and from data valve 302. The first access control unit 312 may permit data transmission via a secure conduit (e.g., secure conduit 210) through entry into data valve 302. For example, data may be transmitted from a first data center (e.g., first data center 202).
[0072] The first access control unit 312 can regulate the data flow, allowing data to pass through a secure conduit 316 from a source system (e.g., a first data center) into a data valve 302. However, data from the data valve 302 cannot be passed back through the first access control unit 312 to the secure conduit 316 from the source system. For example, the first access control unit 312 can be implemented by a network interface card (NIC) configured to receive data from a source system (e.g., the first data center 202) via the secure conduit 316, and also not allow data to be transmitted back to the source. For example, the NIC can be configured to filter communication, allowing communication to flow only in one direction. For example, the NIC can be configured to read the header associated with data packets received using the secure conduit 316 from the source system. The NIC can also determine the source address (e.g., Internet Protocol (IP) address, Media Access Control (MAC) address) of the source system transmitting the data packets based on the header. The NIC can also determine the destination address (e.g., IP address, MAC address) of the data packets based on the header. The NIC can be configured to only allow data packets received from a specific source system and destined for a specific destination system to pass through. For example, the first NIC can be configured to only allow data packets received from the first data center 202 that are to be transmitted to the second data center 204. The second NIC can be configured to only allow data packets received from the second data center 204 that are to be transmitted to the first data center 202.
[0073] In other embodiments, the first access control unit 312 may include optical circuitry configured to receive optical signals from a source. For example, a secure conduit 316 from the source system may include an optical fiber for transmitting the optical signal to the first access control unit 312. In these embodiments, the first access control unit 312 may include an optical receiver comprising a photodiode for receiving the optical signal via the optical fiber and converting the optical signal into an electrical signal. The first access control unit 312 may also include converter circuitry for receiving the electrical signal from a photodetector and converting the current into a voltage signal. The first access control unit 312 may also include filters (e.g., high-pass filters, low-pass filters, band-pass filters) for receiving the voltage signal and filtering out noise. The first access control unit 312 may also include a driver for processing the signal to comply with downstream processing. In this embodiment, the first access control unit 312 may not include a light source, such as a laser. Therefore, the photodetector can collect the optical signal from the source, and the first access control unit 312 may not have a light source to transmit the optical signal back to the source via the optical fiber.
[0074] The first access control unit 312 can also prevent external sources from accessing data stored in the data valve 302. For example, after the first data center 202 has transmitted data to be received by the second data center 204, the first access control unit 312 can initialize security mechanisms, such as a firewall, to prevent the first data center 202 from accessing the data stored in the data valve 302, including adding new data, modifying data, or deleting data.
[0075] Data transmitted through the first access control unit 312 can be received by the data analysis unit 304. The data analysis unit 304 may include software for analyzing data to gather information for verification purposes. The data analysis unit 304 can perform various functions, such as gathering information to provide data visualization, statistical analysis of the data, mining data patterns, and performing predictive analysis. The information can be used by the data analysis unit 304 to determine one or more verification processes to be performed on the data. The data analysis unit 304 can gather information to provide visualizations (e.g., data type histograms, data relationship diagrams, metadata charts describing the data) to users on the NOC. The data analysis unit 304 can use this information to determine whether to grant permission to perform one or more verification processes on the data.
[0076] Data analysis unit 304 can perform statistical analyses on the data, such as descriptive and inferential statistics. Statistics can be used by data analysis unit 304 to determine patterns in the data. In some cases, these patterns can indicate data under a specific category in the second sovereign area 208. For example, statistical analysis can indicate that data (such as personally identifiable information) is mixed with another type of data. Furthermore, this specific data category, such as data with mixed types of data, may be prohibited from being received in the second sovereign area 208. Statistical analysis can be used by data analysis unit 304 to select one or more verification processes to be performed on the data.
[0077] Data analysis unit 304 can also perform data mining to extract and discover patterns and relationships in the data. Data analysis unit 304 can be configured to discover patterns and relationships related to the second sovereign zone 208. For example, one piece of data can be associated with another piece of data. For instance, a user's name can be associated with an account, and this association can be unencrypted. This association may be permitted in the first sovereign zone 206 but may not be permitted in the second sovereign zone 208. Data analysis unit 304 can also use predictive modeling to generate predictive analytics. For example, data analysis unit 304 can make predictions about the results of data transformation processes included in the data. Furthermore, data transformations can alter data in ways prohibited in the second sovereign zone 208, such as changes to certain financial information. These patterns and relationships can also provide information that can be used by data analysis unit 304 to select one or more verification processes.
[0078] Data analysis unit 304 can use information obtained from the analyzed data to determine the specific verification process to be used to verify data received from the source system. Data analysis unit 304 can use various criteria to determine one or more verification techniques to be used. Data analysis unit 304 can make decisions based on data type. For example, if the data is numerical, data analysis unit 304 can determine the scope of verification to be used. Data analysis unit 304 can determine verification techniques based on the regulations of a jurisdiction. For example, a second sovereign area 208 may require specific verification. As indicated above, first access control unit 312 can receive data from the source system via a secure conduit 316 from the source system. First access control unit 312 can decode the data into a bit stream. Then, first access control unit 312 can identify the header from the bit stream and determine the source and destination addresses of the data. Based on the source and destination systems, second sovereign area 208 may require one or more verification techniques. Therefore, data analysis unit 304 can use this information to determine the verification techniques. Data analysis unit 304 can use other criteria to determine one or more verification techniques to be used for data received from the target system.
[0079] Data analysis unit 304 can transmit information to mapping unit 306, which can map data or portions of data to various verification processes. Specifically, mapping unit 306 can communicate with verification technology database 308, which can store one or more verification processes. Mapping unit 306 can receive information from data analysis unit 304 or from user-based input. For example, the user may have previously used NOC to instruct data valve 302 to perform a specific verification process. Mapping unit 306 can ingest information from each source and map data or portions of data to memory addresses stored in verification technology database 308 for executing one or more instructions to perform the verification process. Mapping unit 306 can also transmit the mapping to verification unit 310. Verification unit 310 can use the mapping to retrieve one or more instructions for performing the verification process from verification technology database 308 and verify the data. Figure 4 The different verification techniques that the verification technology database 308 and verification unit 310 can perform are described in more detail. Verification unit 310 can perform one or more verification techniques on the data to determine whether the data can be received by a data center in a second sovereign area (e.g., second sovereign area 208). If verification unit 310 verifies the data, it can transmit the data to the second access control unit 314. However, if verification unit 310 is unable to verify the data, it can delete the data, isolate the data, or perform a second attempt to verify the data.
[0080] Data valve 302 can also be gated from the external environment via a second access control unit 314. In some embodiments, data valve 302 may include only the second access control unit 314 and may not include the first access control unit 312. In these embodiments, data that has been transmitted via the secure conduit 316 from the source system is received by the data analysis unit 304, rather than by the first access control unit 312. Similar to the first access control unit 312, the second access control unit 314 may be implemented by a NIC. The second access control unit 314 may also include logic circuitry for determining whether to allow data received via the second conduit 316 from the source system to be transmitted via the secure conduit 318 to the target system. The logic circuitry may receive control commands and data from the verification unit 310 to transmit data via the secure conduit 318 to the target system. The logic circuitry may also receive user information (e.g., identity, permission, authorization) from a permission parser. Based on the control commands and user information, the second access control unit 314 may transmit data to the target system. In some embodiments, the secure conduit 318 to the target system may include an optical fiber, and the second access control unit 314 may include an optical transmitter. The optical transmitter may include a light source (e.g., a laser) for generating optical signals, a modulator for receiving electrical signals representing data and encoding the data into optical signals, and an optical isolator for preventing optical signals from the secure conduit 318 to the target system from being transmitted back to the second access control unit 314. The secure conduit 318 to the target system may include an optical receiver unit for receiving signals from the optical transmitter unit. Similar to the optical system of the first access control unit 312 described above, a physical gap may be created between the second access control unit 314 and the secure conduit to the target system through which the optical signals pass. Since the optical receiver at the secure conduit to the target system may not include a light source, and the second access control unit 314 may not include a photodiode, communication may be unidirectional.
[0081] Users operating the NOC can communicate with the second access control unit 314 via the NOC interface 320. Users can determine whether to permit the release of data from the data valve 302 based on the verification result. However, before executing a command to permit or deny the release of data from the data valve 302, the NOC can determine whether the user meets the requirements for making that determination. The NOC can access identifiers associated with the user. For example, the NOC can be assigned to a user who may have entered a user identifier or password, or the NOC can use biometric data (such as facial features) to identify the user.
[0082] Figure 4This is a diagram 400 illustrating an example verification technology database according to one or more embodiments. A data valve (e.g., data valve 302) may include a verification technology database 402 (e.g., verification technology database 308). A mapping unit (e.g., mapping unit 306) may access the verification technology database 402 to map verification technologies to instructions for performing the verification technologies. The verification technology database 402 may store one or more instructions for verification. The verification technology to be used may be determined by a data analysis unit (e.g., data analysis unit 304) using data received via a security conduit and the requirements of a second sovereign jurisdiction where the data valve is located. The verification technology database 402 may include instructions for various verification technologies. For example, verification technology instructions may be used for format verification 404 to determine whether data or portions of data conform to a specific format. For example, whether data including an account database includes values formatted for a specific account. Values in one jurisdiction may be formatted differently from values in another jurisdiction. For example, in one jurisdiction, a date may be formatted as month-day-year, while in another jurisdiction, a date may be formatted as year-month-day. Therefore, format verification 404 can determine whether these values are properly formatted for the jurisdiction in which the data is received. Furthermore, if the value format is inappropriate, this could be an indication that the data is malicious. Verification instructions may include length and size verification 406 to determine whether the length of the data string in the data is less than a threshold length. If the string is longer than the threshold length, this could be an indication that malicious data has been added to the data. Verification instructions may include range verification 408 to determine whether the value of a numerical value falls within a threshold range. If the data includes values outside the threshold range, this could be an indication that the value of the numerical value has been tampered with. Verification instructions may include whitelist and blacklist verification. Whitelist verification may include configuring a data valve with a list of approved source systems. For example, the data valve may be configured with the IP addresses or Media Access Control (MAC) addresses of approved source systems. IP addresses or MAC addresses may also be used for approved source systems within a specific jurisdiction. The IP addresses or MAC addresses of the approved source systems can be compared with the IP addresses or MAC addresses of the source systems. If the IP addresses or MAC addresses do not match, this could be an indication that data was sent from a malicious source. Blacklist verification can include configuring a data valve with a list of unapproved source systems. For example, the data valve can be configured with the IP addresses or MAC addresses of unapproved source systems. IP addresses or MAC addresses can also be used for unapproved source systems within a specific jurisdiction. The IP addresses or MAC addresses of approved source systems can be compared with those of the source system. If the IP addresses or MAC addresses match, there may be an indication that data was sent from a malicious source.
[0083] Verification techniques may include cross-field verification 412 to determine whether the relationship between data fields is logical. For example, if the first and second fields are to include consecutive ranges of data, cross-field verification can be used to determine whether the end date of the first field is earlier than the start date of the second field. If the relationship between the fields is illogical (e.g., the end date of the first field is later than the start date of the second field), it may be an indication that malicious data has been introduced into the data. Verification techniques may include checksum and hash verification 414. The verification unit may determine the checksum or hash of the data and compare the checksum or hash with a checksum or hash received with the data. Some jurisdictions may require checksum and hash verification 414 to be performed for specific types of data. Therefore, in these jurisdictions, if the checksum or hash does not match, the data may not be delivered through the second access control unit (e.g., second access control unit 314). Verification techniques may include data integrity verification 416. Data integrity verification 416 may include determining whether the data includes the correct number of tables, and whether each table has the correct number of columns and rows. In some cases, the data may include instructions for assembling data structures such as tables. The data valve can assemble data structures and determine whether malicious code is included. Verification technology instructions may include virus and malware detection 418, where virus and malware detection software runs against the data to determine whether any virus or malware is included.
[0084] It should be understood that Figure 4 A set of example verification techniques is illustrated, and other embodiments may include a different set of verification techniques. A verification unit (e.g., verification unit 310) may execute one or more verification techniques included in the verification technique database 402. Verification unit 310 may also include logic circuitry for determining whether to permit data passage when data is determined to be invalid based on one or more of the verification techniques. The verification techniques provide information to verification unit 310 for determining whether data can be released from the data valve to a data center in the sovereign area.
[0085] Figure 5This is a diagram 500 of an example buffer area according to one or more embodiments. The buffer area 502 may be located at a data center (e.g., second data center 204) receiving data within a sovereign region (e.g., second sovereign region 208), which is different from the sovereign region (e.g., first sovereign region 206) of a data center (e.g., first data center 202) transmitting data. It should be understood that in some embodiments, the data verification system may include only a data valve; in other embodiments, the data verification system may include only a buffer area; and in still other embodiments, the data verification system may include both a data valve and a buffer area. The buffer area 502 may function similarly to a data valve (e.g., data valve 302) and includes a data analysis unit 504, a mapping unit 506, a verification technology database 508, and a verification unit 510. The buffer area 502 may be gated from an external environment via a third access control unit 512 and a fourth access control unit 514. The third access control unit 512 may include a combination of software and hardware configured to manage data going to and from the data valve 302. The third access control unit 512 may permit data transfer via a secure conduit (e.g., via secure conduit 210 and from data valve 212) to enter the temporary storage area 502.
[0086] The third access control unit 512 can regulate the data flow, allowing data to be passed through into the buffer 502. For example, the third access control unit 512 can be implemented by a NIC configured to receive data from 316 via a secure channel from the source system and also prevent data from being transmitted back to the secure channel. In other embodiments, the third access control unit 512 may include optical circuitry configured to receive optical signals from a source. In these embodiments, the third access control unit 512 may include an optical receiver comprising a photodiode for receiving optical signals via an optical fiber and converting the optical signals into electrical signals. The third access control unit 512 may also include converter circuitry for receiving electrical signals from a photodetector and converting current into voltage signals. The third access control unit 512 may also include a filter for receiving voltage signals and filtering out noise. The third access control unit 512 may also include a driver for processing signals to comply with downstream processing. Similar to the first access control unit 312, the third access control unit 512 may also prevent external sources from accessing the data stored in the buffer 502.
[0087] Data transmitted through the third access control unit 512 can be received by the data analysis unit 504, which may include software for analyzing the data to gather information for verification purposes. The data analysis unit 504 can perform various functions, such as gathering information to provide data visualization, statistical analysis of the data, mining data patterns, and performing predictive analysis. The information can be used by the data analysis unit 504 to determine one or more verification processes to be performed on the data. The data analysis unit 504 can gather information to provide visualizations (e.g., data type histograms, data relationship graphs, metadata graphs describing the data) to users on the NOC. The data analysis unit 504 can use this information to determine whether to grant permission to perform one or more verification processes on the data.
[0088] Data analysis unit 504 can perform statistical analyses on the data, such as descriptive statistics and inferential statistics. Statistics can be used by data analysis unit 504 to determine patterns in the data. In some cases, these patterns can indicate data under a specific class in a second sovereign region. Furthermore, this specific data class may be prohibited from being received in the second sovereign region, such as data with a mixture of two data types. Statistical analysis can be used by data analysis unit 504 to select one or more verification processes to be performed on the data.
[0089] Data analysis unit 504 can also perform data mining to extract and discover patterns and relationships in the data. Data analysis unit 504 can be configured to discover patterns and relationships related to the second sovereign region. Data analysis unit 504 can also use predictive modeling to generate predictive analytics. For example, data analysis unit 504 can make predictions about the results of data transformation processes included in the data. These patterns and relationships can also provide information that can be used by data analysis unit 504 to select one or more validation processes.
[0090] Data analysis unit 504 can use information obtained from the analyzed data to determine the specific verification process to be used to verify data received from the source system. Data analysis unit 504 can use various criteria to determine one or more verification techniques to be used. Data analysis unit 504 can make decisions based on data type. Data analysis unit 504 can determine verification techniques based on the regulations of a jurisdiction. For example, a second sovereign region may require specific verification. Therefore, data analysis unit 504 can use this information to determine the verification techniques. Data analysis unit 504 can use other criteria to determine one or more verification techniques to be used for data received by the target system.
[0091] Data analysis unit 504 can transmit information to mapping unit 506, which can map data or portions of data to various verification processes. Specifically, mapping unit 506 can communicate with verification technology database 508, which can store one or more verification processes. Verification technology database 508 in temporary storage area 502 can be different from verification technology database 308 in data valve 302. Mapping unit 506 can receive information from data analysis unit 504 or from user-based input. For example, the user may have previously used NOC to execute a specific verification process via NOC interface 516 instruction temporary storage area 502. Mapping unit 506 can ingest information from each source and map data or portions of data to memory addresses stored in verification technology database 508 for executing one or more instructions to perform the verification process. Mapping unit 506 can also transmit the mapping to verification unit 510, which can use the mapping to retrieve one or more instructions from verification technology database 508 for executing the verification process and verify the data. Verification technology database 508 can store code for performing different verification techniques. Verification unit 510 may perform one or more verification techniques on the data to determine whether the data can be received by the data center in the second sovereign zone 208. If verification unit 510 verifies the data, it may transmit the data to the fourth access control unit 514. However, if verification unit 510 is unable to verify the data, it may delete the data, isolate the data, or perform a second attempt to verify the data.
[0092] In some embodiments, the temporary storage area 502 may include only the fourth access control unit 514 and may not include the third access control unit 512. In these embodiments, the transmitted data is received by the data analysis unit 504, rather than by the third access control unit 512. The fourth access control unit 514 may also include logic circuitry for determining whether to allow the received data to be transmitted via a secure pipeline to the target system.
[0093] Users operating the NOC can communicate with the fourth access control unit 514 via the NOC interface 516. Users can determine whether data should be released from the temporary storage area 502 based on the verification result. However, before executing a command to allow or deny the release of data from the temporary storage area 502, the NOC can determine whether the user meets the requirements for making that determination. The NOC can access identifiers associated with the user. For example, the NOC can be assigned to a user who may have entered a user identifier or password, or the NOC can use biometric data (such as facial features) to identify the user. The NOC can transmit the user's identity to the permission parser 518.
[0094] The license parser 518 may include software for applying a set of rules and determining whether a user meets the requirements for making those determinations. Requirements may include whether the user is currently an employee of the CSP, whether the user has a license level to determine whether to allow or deny the release of data from the staging area 502, whether the user is a resident of a second sovereign zone, and whether the user is currently located in a second sovereign zone.
[0095] The permission resolver 518 can access a second human resources system (e.g., second human resources system 216) in the second sovereign region. The second human resources system may include employee information of employees working in the second sovereign region.
[0096] The license parser 518 can transmit the employee identifier along with instructions for verifying that the user is currently working for the CSP, the user's license level, and the user's place of residence to the second human resources system 216. The second human resources system 216 can access the employee database and access the user's files based on the received employee identifier. The second human resources system can also determine whether the user is currently an employee of the CSP and whether they have been assigned to the second data center.
[0097] In some embodiments, the second human resources system may also access the global human resources system (e.g., the first human resources system 218) and re-verify that the user works for the CSP, the user is assigned to the second data center, and the user is a resident of the second sovereign region. In some cases, the global human resources system may have been updated with changes to the user's employment status, location assignment, and place of residence; and the global human resources system has not yet pushed the updates to the local human resources system (e.g., the second human resources system 216).
[0098] The second human resources system can also determine whether a user has the necessary permissions to allow data transfer through staging area 502. The second human resources system can also access a second licensing service (e.g., second licensing service 220), configured to manage employee access rights to prevent employees from engaging in unauthorized activities on the CSP's computing systems. The second licensing service may include information for managing roles, permissions, and access control rules assigned to employees in the second data center. These permissions may include whether a user can authorize or deny the release of data from staging area 502.
[0099] The second human resources system can send a message to the second licensing service, providing the user's identity and a request for information regarding whether the user has the necessary permissions to determine whether data can be released from the temporary storage area 502. In response to receiving the identity and request, the second licensing service can determine whether the user possesses the required permissions. Based on this information, the fourth access control unit 514 can grant permission for data transfer through the temporary storage area. In some embodiments, the data is stored in a database 520 at a second data center.
[0100] Figure 6 This is a signaling diagram of an example process 600 for data verification according to one or more embodiments. As illustrated, NOC 602 may communicate with a data valve 604 or a buffer. For simplicity, the data valve may include a data valve (e.g., data valve 302 or buffer 502). Although the operation of process 600 is described as being performed by a general-purpose computer, it should be understood that any suitable device may be used to perform one or more operations of this method. Process 600 (described below) is illustrated as a signaling diagram, where each operation represents a series of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, an operation represents computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the described operation. Typically, computer-executable instructions include routines, programs, objects, components, data structures, etc., that perform a particular function or implement a particular data type. The order in which the operations are described is not intended to be construed as limiting, and any number of the described operations may be combined and / or implemented in parallel in any order.
[0101] At 606, data valve 604 can transmit a message indicating that data has been received. For example, data can be received from a first data center (e.g., first data center 202) located in a first sovereign territory (e.g., first sovereign territory 206) via a secure conduit (e.g., secure conduit 210). NOC 602 can be located in a second sovereign territory (e.g., second sovereign territory 208) and associated with a second data center (e.g., second data center 204).
[0102] At 608, NOC 602 can generate a message instructing data valve 604 to verify data. NOC 602 can generate a message that includes specific verification techniques for data verification. NOC 602 can also transmit the message to data valve 604.
[0103] At 610, data valve 604 can verify the data. For example, data valve 604 may include verification units (e.g., verification unit 310, verification unit 510). The verification unit can access a verification technique database and use code to perform one or more verification techniques on the data. At 612, data valve 604 can generate a message indicating the verification result. Data valve 604 can also transmit the message to NOC 602.
[0104] At 614, NOC 602 can use the result from the verification unit to determine whether data has reached the second data center. In some embodiments, any decision made using the NOC can also be verified to determine whether the NOC user is authorized to make the decision. For example, in response to receiving a determination from the verification unit, the NOC can send a message to a permission resolver to determine whether the NOC user is authorized to make the determination. The permission resolver can access the human resources system to determine the user's permission. If the permission resolver determines that the user is authorized, the permission resolver can send an instruction to the control access unit to permit data transfer through the data valve.
[0105] At 616, NOC 602 can send a message to data valve 604 indicating whether data transmission through data valve 604 is permitted. If the message indicates that data should be transmitted and the permission resolver indicates that the user is authorized to make a confirmation, then data valve 604 can allow the data to pass. If the message indicates that data should be transmitted and the permission resolver indicates that the user is not authorized to make a confirmation, then data valve 604 can prevent data transmission. If the message indicates that data should not be transmitted and the permission resolver indicates that the user is authorized to make a confirmation, then data valve 604 can prevent data transmission. If the message indicates that data will not pass and the permission resolver indicates that the user is not authorized to make a confirmation, then data valve 604 can prevent data transmission.
[0106] Figure 7This is an example process flow 700 for data verification according to one or more embodiments. At 702, a computer-implemented method may include a computing system in a first data center (e.g., second data center 204) in a first region (e.g., second sovereign region 208) processing a first message indicating that an intermediate computing system (e.g., data valve 212) managed by the first data center has received data from a second data center (e.g., first data center 202) in a second region (e.g., first sovereign region 206). The computing system may be a data center mainframe or a NOC, wherein the NOC communicates with the mainframe. Data is stored in an isolated environment of the intermediate computing system. For example, the intermediate computing system may include a first access control unit (e.g., first access control unit 312) and a second access control unit (e.g., second access control unit 314) that can be configured to prevent data from entering or leaving the isolated environment. In some embodiments, the computing system may include computing devices distributed across various different locations.
[0107] At point 704, the computer-implemented method may include the computing system transmitting first control instructions to an intermediate computing system to verify data based on a first standard. The intermediate computing system may include a verification unit (e.g., verification unit 310) that can use various verification techniques to verify the data. The verification technique may be selected based on the requirements of the first region.
[0108] At 706, the computer-implemented method may include a computing system processing verification results from an intermediate computing system. The verification results may be output from the computing system using one or more verification techniques described above. The verification unit may process the verification results to determine whether the data should be verified.
[0109] At point 708, the computer implementation method may include a computing system processing a second message instructing the release of data from the isolated environment of an intermediate computing system. The computing system may be a National Office for Computing (NOC) or communicating with a NOC. The NOC user can analyze the verification results and determine whether to release the data from the intermediate computing system. The computing system can determine whether the NOC user is authorized to make the determination and whether they are located in a first area. For example, the computing system may send a request to a local human resources system to determine whether the user is authorized. The computing system may also use location technology to determine whether the NOC is located in a first area. If the NOC is located in a first area, it can be assumed that the user is in a first area.
[0110] At 710, the computer implementation may include a computing system processing a third message indicating that the second message originates from a computing device located in the first area. If at 708 it is assumed that the user is in the first area, then it can be assumed that the second message originates from the first area.
[0111] At point 712, the computer-implemented method may include a computing system releasing data from an isolated environment based at least in part on verification results, instructions to release data, and instructions from a second message source in the first area. The data may be released to a data center database or another isolated environment.
[0112] Figure 8 This is an example process flow 800 for data verification according to one or more embodiments. At 802, a computer-implemented method may include a computing system in a first data center (e.g., second data center 204) in a first region (e.g., second sovereign region 208) detecting data from a second data center (e.g., first data center 202) in a second region (e.g., first sovereign region 206). The data may be stored in an isolated environment (e.g., staging area 226) of the first data center. The computing system may be a data center mainframe or a NOC, wherein the NOC communicates with the mainframe. The data is stored in an isolated environment of an intermediate computing system. For example, the intermediate computing system may include a first access control unit (e.g., third access control unit 512) and a second access control unit (e.g., fourth access control unit 514) that may be configured to prevent data from entering or leaving the isolated environment. In some embodiments, the computing system may include computing devices distributed across various different locations.
[0113] At 804, the computer-implemented method may include determining verification parameters by the computing system based at least in part on a first region. The first region may have one or more requirements for data to be stored in the region. Furthermore, based on one or more requirements, the verification parameters for the first region may not be applicable to another region. Verification parameters may include, for example, targets of verification techniques, such as format, length and size, range, whitelists and blacklists, cross-field, checksums and hashes, data integrity, and viruses and malware. Verification parameters can be selected based on the requirements of the region. For example, in one region, checksums and hashes may be legally required (or by a data center in the region) for some data to be verified. In another region, checksums and hashes may not be legally required (or by a data center in the region) for the same data. Therefore, verification parameters can be selected based on the requirements of the region and the data to be received. Verification parameters can be used to determine verification techniques. Furthermore, different verification techniques can be used for different requirements. Therefore, the computing system can select verification techniques that can be used to determine whether the requirements have been met.
[0114] At 806, the computer-implemented method may include a computing system verifying data at least in part based on verification parameters. The isolated environment may include a verification unit (e.g., verification unit 510) that can use various verification techniques to verify the data. The verification technique may be selected based on the requirements of the first region.
[0115] At point 808, the computer implementation method may include a computing system processing a first message instructing the release of data from an isolated environment within an isolated environment. The computing system may be a NOC or communicate with a NOC. The NOC user may analyze the verification results and determine whether to release the data from the intermediate computing system. The verification results may include, for example, format identifiers, length and size values, range values, whether the data originated from a whitelisted source, whether the data originated from a blacklisted source, whether cross-field relationships are logical, checksum and hash values, determinations regarding data integrity, and determinations regarding the presence of any viruses or malware. The computing system may determine whether the NOC user is authorized to make these determinations and whether they are located in a first zone. For example, the computing system may send a request to a local human resources system to determine whether the user is authorized. The computing system may also use location technology to determine whether the NOC is located in a first zone. If the NOC is located in a first zone, it can be assumed that the user is in a first zone.
[0116] At 810, the computer implementation may include a computing system processing a second message indicating that the first message originates from a computing device located in the first area. If at 808 it is assumed that the user is in the first area, then it can be assumed that the second message originates from the first area.
[0117] At point 812, the computer-implemented method may include a computing system releasing data from an isolated environment based at least in part on a first message that verifies and releases data, and a second message originating from a first region. The data can then be released into a data center database.
[0118] As shown above, Infrastructure as a Service (IaaS) is a specific type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, cloud providers can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), or the like). In some cases, IaaS providers can also provision a wide variety of services to accompany those infrastructure components (example services include billing software, monitoring software, logging software, load balancing software, clustering software, etc.). Therefore, because these services can be policy-driven, IaaS users can implement policies to drive load balancing to maintain application availability and performance.
[0119] In some cases, IaaS customers can access resources and services over a wide area network (WAN) (such as the Internet) and can use the cloud provider's services to install the remaining elements of the application stack. For example, a user can log in to the IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as databases, create buckets for workloads and backups, and even install enterprise software into the VM. The customer can then use the provider's services to perform various functions, including balancing network traffic, troubleshooting application problems, monitoring performance, and managing disaster recovery.
[0120] In most cases, cloud computing models will require the involvement of a cloud provider. However, a cloud provider may not need to be a third-party service provider specializing in (e.g., provisioning, renting, or selling) IaaS. Entities can also choose to deploy a private cloud and become providers of their own infrastructure services.
[0121] In some examples, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server or similar. It may also include the process of preparing the server (e.g., installing libraries, daemons, etc.). This is typically managed by the cloud provider under a hypervisor layer (e.g., servers, storage, network hardware, and virtualization). Therefore, the customer may be responsible for handling (OS), middleware, and / or application deployment (e.g., on self-service virtual machines that can be started on demand) or the like.
[0122] In some examples, IaaS provisioning can refer to acquiring a computer or virtual host for use, and even installing the necessary libraries or services on it. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.
[0123] In some cases, there are two distinct challenges to IaaS provisioning. First, there's the initial challenge of provisioning the initial set of infrastructure before anything can run. Second, there's the challenge of evolving the existing infrastructure after everything has been provisioned (e.g., adding new services, changing services, removing services, etc.). In some cases, both challenges can be addressed by enabling the configuration of the infrastructure to be declaratively defined. In other words, the infrastructure (e.g., what components are needed and how they interact) can be defined by one or more configuration files. Therefore, the overall topology of the infrastructure can be declaratively described (e.g., which resources depend on which resources and how each works together). In some cases, after the topology is defined, workflows for creating and / or managing the different components described in the configuration files can be generated.
[0124] In some examples, the infrastructure can have many interconnected elements. For example, there may be one or more Virtual Private Clouds (VPCs) (e.g., potential on-demand pools of configurable and / or shared computing resources), also known as the core network. In some examples, there may also be one or more inbound / outbound traffic group rules, provisioned to define how inbound and / or outbound traffic will be structured, and one or more Virtual Machines (VMs). Other infrastructure elements, such as load balancers, databases, or the like, may also be provisioned. As more infrastructure elements are expected and / or added, the infrastructure can evolve incrementally.
[0125] In some cases, continuous deployment techniques can be employed to enable the deployment of infrastructure code across various virtual computing environments. Additionally, the described techniques can enable infrastructure management within these environments. In some examples, service teams may write code that they expect to deploy to one or more (but often multiple) different production environments (e.g., across various geographical locations, sometimes even across the world). However, in some examples, the infrastructure on which the code will be deployed must first be established. In some cases, provisioning can be done manually, provisioning tools can be used to provision resources, and / or, after the infrastructure is provisioned, deployment tools can be used to deploy the code.
[0126] Figure 9This is a block diagram 900 illustrating an example pattern of an IaaS architecture according to at least one embodiment. Service operator 902 may be communicatively coupled to a secure host lease 904, which may include a virtual cloud network (VCN) 906 and a secure host subnet 908. In some examples, service operator 902 may use one or more client computing devices, which may be portable handheld devices (e.g., iPhone®, cellular phone, iPad®, computing tablet, personal digital assistant (PDA)) or wearable devices (e.g., Google Glass® head-mounted display), running software (such as Microsoft Windows Mobile®) and / or a wide variety of mobile operating systems (such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, etc.), and enabled for the Internet, email, SMS, Blackberry®, or other communication protocols. Alternatively, client computing devices may be general-purpose personal computers, including, for example, personal computers and / or laptops running various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems. Client computing devices may be workstation computers running any wide variety of commercial UNIX® or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, such as, for example, Google Chrome OS). Alternatively or additionally, the client computing device may be any other electronic device capable of communicating via a network that can access the VCN 906 and / or the Internet, such as a thin client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox game console with or without Kinect® gesture input), and / or a personal messaging device.
[0127] VCN 906 may include a local peering gateway (LPG) 910, which may be communicatively coupled to a secure shell (SSH) VCN 912 via LPG 910 included in SSH VCN 912. SSH VCN 912 may include an SSH subnet 914, and SSH VCN 912 may be communicatively coupled to a control plane VCN 916 via LPG 910 included in control plane VCN 916. Furthermore, SSH VCN 912 may be communicatively coupled to a data plane VCN 918 via LPG 910. Control plane VCN 916 and data plane VCN 918 may be contained within a service lease 919 that may be owned and / or operated by an IaaS provider.
[0128] The control plane VCN 916 may include a control plane demilitarized zone (DMZ) layer 920, which acts as a perimeter network (e.g., a portion of a corporate network between an intranet and an external network). DMZ-based servers can have limited liability and help keep violations contained. Additionally, the DMZ layer 920 may include one or more load balancer (LB) subnets 922, a control plane application layer 924 that may include one or more application subnets 926, and a control plane data layer 928 that may include one or more database (DB) subnets 930 (e.g., one or more front-end DB subnets and / or one or more back-end DB subnets). One or more LB subnets 922 contained in the control plane DMZ layer 920 may be communicatively coupled to one or more application subnets 926 contained in the control plane application layer 924 and an Internet gateway 934 that may be contained in the control plane VCN 916, and one or more application subnets 926 may be communicatively coupled to one or more DB subnets 930 and a service gateway 936 and a Network Address Translation (NAT) gateway 938 contained in the control plane data layer 928. The control plane VCN 916 may include a service gateway 936 and a NAT gateway 938.
[0129] The control plane VCN 916 may include a data plane mirroring application layer 940, which may include one or more application subnets 926. The one or more application subnets 926 included in the data plane mirroring application layer 940 may include a virtual network interface controller (VNIC) 942, which can execute a compute instance 944. The compute instance 944 may communicatively couple the one or more application subnets 926 of the data plane mirroring application layer 940 to the one or more application subnets 926 that may be included in the data plane application layer 946.
[0130] Data plane VCN 918 may include a data plane application layer 946, a data plane DMZ layer 948, and a data plane data layer 950. Data plane DMZ layer 948 may include one or more application subnets 926 communicatively coupled to data plane application layer 946 and one or more LB subnets 922 of internet gateway 934 of data plane VCN 918. One or more application subnets 926 may be communicatively coupled to service gateway 936 and NAT gateway 938 of data plane VCN 918. Data plane data layer 950 may also include one or more DB subnets 930 communicatively coupled to one or more application subnets 926 of data plane application layer 946.
[0131] The Internet gateway 934 of the control plane VCN 916 and the data plane VCN 918 can be communicatively coupled to the metadata management service 952, which can be communicatively coupled to the public Internet 954. The public Internet 954 can be communicatively coupled to the NAT gateway 938 of the control plane VCN 916 and the data plane VCN 918. The service gateway 936 of the control plane VCN 916 and the data plane VCN 918 can be communicatively coupled to the cloud service 956.
[0132] In some examples, the service gateway 936 of the control plane VCN 916 or the data plane VCN 918 can make application programming interface (API) calls to the cloud service 956 without traversing the public internet 954. API calls from the service gateway 936 to the cloud service 956 can be unidirectional: the service gateway 936 can make API calls to the cloud service 956, and the cloud service 956 can send the requested data to the service gateway 936. However, the cloud service 956 may not initiate API calls to the service gateway 936.
[0133] In some examples, secure host lease 904 can connect directly to service lease 919, which would otherwise be isolated. Secure host subnet 908 can communicate with SSH subnet 914 via LPG 910, which enables bidirectional communication over otherwise isolated systems. Connecting secure host subnet 908 to SSH subnet 914 grants secure host subnet 908 access to other entities within service lease 919.
[0134] Control plane VCN 916 allows users of service lease 919 to establish or otherwise provision desired resources. Desired resources provisioned in control plane VCN 916 can be deployed or otherwise used in data plane VCN 918. In some examples, control plane VCN 916 can be isolated from data plane VCN 918, and the data plane mirror application layer 940 of control plane VCN 916 can communicate with the data plane application layer 946 of data plane VCN 918 via a VNIC 942 that can be included in both the data plane mirror application layer 940 and the data plane application layer 946.
[0135] In some examples, a user or client of the system may make a request (e.g., a Create, Read, Update, or Delete (CRUD) operation) via the public internet 954, which can then relay the request to the metadata management service 952. The metadata management service 952 can relay the request to the control plane VCN 916 via an internet gateway 934. The request can be received by one or more LB subnets 922 contained in the control plane DMZ layer 920. The LB subnets 922 can determine that the request is valid, and in response to this determination, they can forward the request to one or more application subnets 926 contained in the control plane application layer 924. If the request is authenticated and requires a call to the public internet 954, the call to the public internet 954 can be relayed to a NAT gateway 938 that can make the call to the public internet 954. The request may expect that the metadata to be stored can be stored in one or more DB subnets 930.
[0136] In some examples, the data plane mirroring application layer 940 can facilitate direct communication between the control plane VCN 916 and the data plane VCN 918. For example, it may be desirable to apply configuration changes, updates, or other suitable modifications to resources contained in the data plane VCN 918. Through VNIC 942, the control plane VCN 916 can communicate directly with the resources contained in the data plane VCN 918, thereby enabling the execution of configuration changes, updates, or other suitable modifications to the resources contained in the data plane VCN 918.
[0137] In some embodiments, control plane VCN 916 and data plane VCN 918 may be included in service lease 919. In this case, the system's users or customers may not own or operate control plane VCN 916 or data plane VCN 918. Instead, the IaaS provider may own or operate both control plane VCN 916 and data plane VCN 918, both of which may be included in service lease 919. This embodiment can enable network isolation that prevents users or customers from interacting with resources of other users or other customers. Similarly, this embodiment can allow the system's users or customers to privately store databases without relying on the public Internet 954, which may not have the desired level of threat prevention for storage.
[0138] In other embodiments, one or more LB subnets 922 included in the control plane VCN 916 may be configured to receive signals from the service gateway 936. In this embodiment, the control plane VCN 916 and the data plane VCN 918 may be configured to be invoked by the IaaS provider's customers without invoking the public internet 954. The IaaS provider's customers may expect this embodiment because the database(s) used by the customer can be controlled by the IaaS provider and can be stored on a service lease 919 that can be isolated from the public internet 954.
[0139] Figure 10 This is a block diagram 1000 illustrating another example pattern of an IaaS architecture according to at least one embodiment. Service operator 1002 (e.g., Figure 9 The service provider 902 can be communicatively coupled to the secure host lease 1004 (e.g., Figure 9 Secure hosting lease 904), the secure hosting lease may include a Virtual Cloud Network (VCN) 1006 (e.g., Figure 9 VCN906) and Security Host Subnet 1008 (e.g., Figure 9 The secure host subnet 908). VCN 1006 may include a local peering gateway (LPG) 1010 (e.g., Figure 9 The LPG 910 can be communicatively coupled to the Secure Shell (SSH) VCN 1012 (e.g., LPG 910 contained in the SSH VCN 1012) via the LPG 910 contained in the SSH VCN 1012. Figure 9 (SSH) VCN 912). SSH VCN 1012 can include SSH subnet 1014 (e.g., Figure 9 SSH subnet 914), and SSH VCN 1012 can be communicatively coupled to control plane VCN 1016 via LPG 1010 included in control plane VCN 1016 (e.g., Figure 9 Control plane VCN 916). Control plane VCN 1016 can be included in service lease 1019 (e.g., Figure 9 In the service lease 919), and the data plane VCN1018 (e.g., Figure 9 The data plane VCN 918 can be included in a customer lease 1021 that can be owned or operated by the system's users or customers.
[0140] The control plane VCN 1016 may include one or more LB subnets 1022 (e.g., Figure 9 The control plane DMZ layer 1020 of (one or more) LB subnets 922) (e.g., Figure 9The control plane DMZ layer 920), may include one or more application subnets 1026 (e.g., Figure 9 The control plane application layer 1024 of (one or more) application subnets 926 (e.g., Figure 9 The control plane application layer 924 may include one or more database (DB) subnets 1030 (e.g., similar to...). Figure 9 The control plane data layer 1028 of (one or more) DB subnets 930 (e.g., Figure 9 The control plane data layer 928). One or more LB subnets 1022 contained in the control plane DMZ layer 1020 can be communicatively coupled to one or more application subnets 1026 contained in the control plane application layer 1024 and an Internet gateway 1034 that can be contained in the control plane VCN 1016 (e.g., Figure 9 Internet gateway 934), and application subnet(s) 1026 can be communicatively coupled to DB subnet(s) 1030 and service gateway 1036 contained in control plane data layer 1028 (e.g., Figure 9 Service gateway 936) and Network Address Translation (NAT) gateway 1038 (e.g., Figure 9 (NAT gateway 938). The control plane VCN 1016 may include the service gateway 1036 and the NAT gateway 1038.
[0141] The control plane VCN 1016 may include a data plane mirror of the application layer 1040 (e.g., Figure 9 The data plane mirroring application layer 940 may include one or more application subnets 1026. The application subnets 1026 included in the data plane mirroring application layer 1040 may include instances 1044 capable of performing computations (e.g., similar to...). Figure 9 The virtual network interface controller (VNIC) 1042 (e.g., the VNIC of 942) of the computing instance 944. The computing instance 1044 may facilitate the mirroring of the application subnet(s) 1026 of the data plane application layer 1040 and may be included in the data plane application layer 1046 (e.g., Figure 9 Communication between one or more application subnets 1026 in the data plane application layer 946 via VNIC 1042 contained in the data plane mirror application layer 1040 and VNIC 1042 contained in the data plane application layer 1046.
[0142] The Internet gateway 1034, included in the control plane VCN 1016, can be communicatively coupled to the metadata management service 1052 (e.g., Figure 9 Metadata management service 952), which can be communicatively coupled to the public Internet 1054 (e.g., Figure 9 The public internet 1054 can be communicatively coupled to a NAT gateway 1038 contained in a control plane VCN 1016. The service gateway 1036 contained in the control plane VCN 1016 can be communicatively coupled to a cloud service 1056 (e.g., ...). Figure 9 Cloud services (956).
[0143] In some examples, data plane VCN 1018 may be included in customer lease 1021. In this case, the IaaS provider may provide control plane VCN 1016 for each customer, and the IaaS provider may establish a unique compute instance 1044 for each customer, included in service lease 1019. Each compute instance 1044 may allow communication between control plane VCN 1016 included in service lease 1019 and data plane VCN 1018 included in customer lease 1021. Compute instance 1044 may allow resources provisioned in control plane VCN 1016 included in service lease 1019 to be deployed or otherwise used in data plane VCN 1018 included in customer lease 1021.
[0144] In other examples, an IaaS provider's customer may have a database residing in customer lease 1021. In this example, control plane VCN 1016 may include a data plane mirroring application layer 1040, which may include one or more application subnets 1026. Data plane mirroring application layer 1040 may reside in data plane VCN 1018, but it may not reside in data plane VCN 1018. That is, data plane mirroring application layer 1040 may have access to customer lease 1021, but it may not reside in data plane VCN 1018 or be owned or operated by an IaaS provider's customer. Data plane mirroring application layer 1040 may be configured to make calls to data plane VCN 1018, but it may not be configured to make calls to any entity contained in control plane VCN 1016. Customers may expect to deploy or otherwise use resources provided in the control plane VCN 1016 in the data plane VCN 1018, and the data plane mirror application layer 1040 can facilitate the customer's expected deployment or other use of resources.
[0145] In some embodiments, an IaaS provider's customer can apply filters to data plane VCN 1018. In this embodiment, the customer can determine what data plane VCN 1018 can access, and the customer can restrict access from data plane VCN 1018 to the public internet 1054. The IaaS provider may not be able to apply filters or otherwise control data plane VCN 1018's access to any external networks or databases. Applying filters and controls to data plane VCN 1018, which is included in customer lease 1021, can help isolate data plane VCN 1018 from other customers and from the public internet 1054.
[0146] In some embodiments, cloud service 1056 can be invoked by service gateway 1036 to access services that may not exist on public internet 1054, control plane VCN 1016, or data plane VCN 1018. The connection between cloud service 1056 and control plane VCN 1016 or data plane VCN 1018 may not be active or continuous. Cloud service 1056 may reside on different networks owned or operated by an IaaS provider. Cloud service 1056 may be configured to receive invocations from service gateway 1036 and may be configured not to receive invocations from public internet 1054. Some cloud services 1056 may be isolated from other cloud services 1056, and control plane VCN 1016 may be isolated from cloud services 1056 that may not be in the same region as control plane VCN 1016. For example, control plane VCN 1016 may be located in "Region 1," while cloud service 1056 "Deployment 9" may be located in both "Region 1" and "Region 2." If a call to deployment 9 is made by a service gateway 1036 contained in a control plane VCN 1016 located in region 1, the call can be forwarded to deployment 9 in region 1. In this example, the control plane VCN 1016 or "deployment 9" in region 1 may be coupled to deployment 9 in region 2 without communication, or may otherwise communicate with deployment 9 in region 2.
[0147] Figure 11 This is a block diagram 1100 illustrating another example pattern of an IaaS architecture according to at least one embodiment. Service operator 1102 (e.g., Figure 9 The service provider 902 can be communicatively coupled to the secure host lease 1104 (e.g., Figure 9 Secure hosting lease 904), the secure hosting lease may include a Virtual Cloud Network (VCN) 1106 (e.g., Figure 9 VCN906) and Security Host Subnet 1108 (e.g., Figure 9The secure host subnet 908). VCN 1106 may include LPG 1110 (e.g., Figure 9 The LPG 910 can be communicatively coupled to the SSHVCN 1112 via the LPG 1110 contained in the SSH VCN 1112 (e.g., Figure 9 SSH VCN 912). SSH VCN 1112 can include SSH subnet 1114 (e.g., Figure 9 SSH subnet 914), and SSH VCN 1112 can be communicatively coupled to control plane VCN 1116 via LPG 1110 contained in control plane VCN 1116 (e.g., Figure 9 The control plane VCN 916) and the LPG 1110 communicatively coupled to the data plane VCN 1118 (e.g., via the control plane VCN 916) and the data plane VCN 1118 via the LPG 1110 contained in the data plane VCN 1118. Figure 9 Data plane 918). Control plane VCN 1116 and data plane VCN 1118 can be included in service lease 1119 (e.g., Figure 9 In the service rental (919).
[0148] The control plane VCN 1116 may include one or more load balancer (LB) subnets 1122 (e.g., Figure 9 The control plane DMZ layer 1120 of (one or more) LB subnets 922) (e.g., Figure 9 The control plane DMZ layer 920 may include one or more application subnets 1126 (e.g., similar to...). Figure 9 The control plane application layer 1124 of (one or more) application subnets 926 (e.g., Figure 9 The control plane application layer 924 may include (one or more) control plane data layers 1128 of the DB subnet 1130 (e.g., Figure 9 The control plane data layer 928). One or more LB subnets 1122 contained in the control plane DMZ layer 1120 can be communicatively coupled to one or more application subnets 1126 contained in the control plane application layer 1124 and to an Internet gateway 1134 that can be contained in the control plane VCN 1116 (e.g., Figure 9 Internet gateway 934), and application subnet(s) 1126 can be communicatively coupled to DB subnet(s) 1130 contained in control plane data layer 1128 and to service gateway 1136 (e.g., Figure 9 The service gateway) and Network Address Translation (NAT) gateway 1138 (e.g., Figure 9(NAT gateway 938). The control plane VCN 1116 may include the service gateway 1136 and the NAT gateway 1138.
[0149] Data plane VCN 1118 may include data plane application layer 1146 (e.g., Figure 9 Data plane application layer 946), data plane DMZ layer 1148 (e.g., Figure 9 Data plane DMZ layer 948), and data plane data layer 1150 (e.g., Figure 9 The data plane data layer 950). The data plane DMZ layer 1148 may include one or more LB subnets 1122, which may be communicatively coupled to one or more trusted application subnets 1160 and one or more untrusted application subnets 1162 of the data plane application layer 1146, and an Internet gateway 1134 contained in the data plane VCN 1118. One or more trusted application subnets 1160 may be communicatively coupled to the service gateway 1136 contained in the data plane VCN 1118, the NAT gateway 1138 contained in the data plane VCN 1118, and one or more DB subnets 1130 contained in the data plane data layer 1150. One or more untrusted application subnets 1162 may be communicatively coupled to the service gateway 1136 contained in the data plane VCN 1118 and the one or more DB subnets 1130 contained in the data plane data layer 1150. The data plane data layer 1150 may include one or more DB subnets 1130, which may be communicatively coupled to a service gateway 1136 contained in the data plane VCN 1118.
[0150] One or more untrusted application subnets 1162 may include one or more primary VNICs 1164(1)-(N) that may be communicatively coupled to tenant virtual machines (VMs) 1166(1)-(N). Each tenant VM 1166(1)-(N) may be communicatively coupled to a corresponding application subnet 1167(1)-(N) that may be contained in a corresponding container egress VCN 1168(1)-(N) that may be contained in a corresponding customer lease 1170(1)-(N). The corresponding secondary VNICs 1172(1)-(N) may facilitate communication between one or more untrusted application subnets 1162 contained in a data plane VCN 1118 and the application subnets contained in a container egress VCN 1168(1)-(N). Each container exit VCN 1168(1)-(N) may include a NAT gateway 1138, which may be communicatively coupled to the public Internet 1154 (e.g., Figure 9 (Public Internet 954).
[0151] Internet gateway 1134, contained in control plane VCN 1116 and data plane VCN 1118, can be communicatively coupled to metadata management service 1152 (e.g., Figure 9 The metadata management system 952 can be communicatively coupled to the public internet 1154. The public internet 1154 can be communicatively coupled to a NAT gateway 1138 contained in a control plane VCN 1116 and a data plane VCN 1118. The service gateway 1136 contained in the control plane VCN 1116 and the data plane VCN 1118 can be communicatively coupled to a cloud service 1156.
[0152] In some embodiments, the data plane VCN 1118 may be integrated with the customer lease 1170. This integration may be useful or desired by the IaaS provider's customer in certain situations, such as when support may be expected when executing code. The customer may provide code to run, which may be destructive, may communicate with other customer resources, or may otherwise cause adverse effects. In response, the IaaS provider may determine whether to run the code provided by the customer.
[0153] In some examples, an IaaS provider's customer may grant temporary network access to the IaaS provider and request functionality to be attached to the data plane application layer 1146. The code running this functionality may execute in VMs 1166(1)-(N) and may not be configured to run anywhere else on the data plane VCN 1118. Each VM 1166(1)-(N) may be connected to a customer lease 1170. A corresponding container 1171(1)-(N) contained in VM 1166(1)-(N) may be configured to run the code. In this case, dual isolation may exist (e.g., container 1171(1)-(N) runs the code, where container 1171(1)-(N) may be contained at least in VM 1166(1)-(N), which is contained in one or more untrusted application subnets 1162), which can help prevent incorrect or otherwise unintended code from corrupting the IaaS provider's network or the networks of different customers. Containers 1171(1)-(N) may be communicatively coupled to customer lease 1170 and may be configured to send or receive data from customer lease 1170. Containers 1171(1)-(N) may not be configured to send or receive data from any other entity in data plane VCN 1118. After the running code is complete, the IaaS provider may terminate or otherwise dispose of containers 1171(1)-(N).
[0154] In some embodiments, one or more trusted application subnets 1160 may run code that can be owned or operated by an IaaS provider. In this embodiment, one or more trusted application subnets 1160 may be communicatively coupled to one or more DB subnets 1130 and may be configured to perform CRUD operations in one or more DB subnets 1130. One or more untrusted application subnets 1162 may be communicatively coupled to one or more DB subnets 1130, but in this embodiment, one or more untrusted application subnets may be configured to perform read operations in one or more DB subnets 1130. Containers 1171(1)-(N) that may be contained in each customer's VM 1166(1)-(N) and may run code from the customer may not be communicatively coupled to one or more DB subnets 1130.
[0155] In other embodiments, the control plane VCN 1116 and the data plane VCN 1118 may be coupled without direct communication. In this embodiment, there may be no direct communication between the control plane VCN 1116 and the data plane VCN 1118. However, communication can occur indirectly through at least one method. An LPG 1110 may be established by an IaaS provider, which can facilitate communication between the control plane VCN 1116 and the data plane VCN 1118. In another example, either the control plane VCN 1116 or the data plane VCN 1118 may make a call to the cloud service 1156 via the service gateway 1136. For example, a call from the control plane VCN 1116 to the cloud service 1156 may include a request for a service that can communicate with the data plane VCN 1118.
[0156] Figure 12 This is a block diagram 1200 illustrating another example pattern of an IaaS architecture according to at least one embodiment. Service operator 1202 (e.g., Figure 9 The service provider 902 can be communicatively coupled to the secure host lease 1204 (e.g., Figure 9 Secure hosting lease 904), the secure hosting lease may include a Virtual Cloud Network (VCN) 1206 (e.g., Figure 9 VCN906) and Security Host Subnet 1208 (e.g., Figure 9 The secure host subnet 908). VCN 1206 can include LPG 1210 (e.g., Figure 9 The LPG 910 can be communicatively coupled to the SSHVCN 1212 via the LPG 1210 contained in the SSH VCN 1212 (e.g., LPG 910). Figure 9 SSH VCN 912). SSH VCN 1212 can include SSH subnet 1214 (e.g., Figure 9 SSH subnet 914), and SSH VCN 1212 can be communicatively coupled to control plane VCN 1216 via LPG 1210 included in control plane VCN 1216 (e.g., Figure 9 The control plane VCN 916) and are communicatively coupled to the data plane VCN 1218 via the LPG 1210 contained in the data plane VCN 1218 (e.g., Figure 9 Data plane 918). Control plane VCN 1216 and data plane VCN 1218 can be included in service lease 1219 (e.g., Figure 9 In the service rental (919).
[0157] The control plane VCN 1216 may include one or more LB subnets 1222 (e.g., Figure 9 The control plane DMZ layer 1220 of (one or more) LB subnets 922) (e.g., Figure 9 The control plane DMZ layer 920 may include one or more application subnets 1226 (e.g., Figure 9 The control plane application layer 1224 of (one or more) application subnets 926 (e.g., Figure 9 The control plane application layer 924 may include one or more DB subnets 1230 (e.g., Figure 11 The control plane data layer 1228 of (one or more) DB subnets 1130 (e.g., Figure 9 The control plane data layer 928). One or more LB subnets 1222 contained in the control plane DMZ layer 1220 can be communicatively coupled to one or more application subnets 1226 contained in the control plane application layer 1224 and an Internet gateway 1234 that can be contained in the control plane VCN 1216 (e.g., Figure 9 Internet gateway 934), and application subnet(s) 1226 can be communicatively coupled to DB subnet(s) 1230 contained in control plane data layer 1228 and to service gateway 1236 (e.g., Figure 9 The service gateway) and Network Address Translation (NAT) gateway 1238 (e.g., Figure 9 (NAT gateway 938). The control plane VCN 1216 may include the service gateway 1236 and the NAT gateway 1238.
[0158] Data plane VCN 1218 may include data plane application layer 1246 (e.g., Figure 9 Data plane application layer 946), data plane DMZ layer 1248 (e.g., Figure 9 Data plane DMZ layer 948), and data plane data layer 1250 (e.g., Figure 9 The data plane data layer 950). The data plane DMZ layer 1248 may include one or more LB subnets 1222, which may be communicatively coupled to one or more trusted application subnets 1260 of the data plane application layer 1246 (e.g., Figure 11 (one or more) trusted application subnets 1160 and (one or more) untrusted application subnets 1262 (e.g., Figure 11The data plane VCN 1250 may include one or more untrusted application subnets 1162 and an Internet gateway 1234 contained in the data plane VCN 1218. One or more trusted application subnets 1260 may be communicatively coupled to a service gateway 1236 contained in the data plane VCN 1218, a NAT gateway 1238 contained in the data plane VCN 1218, and one or more DB subnets 1230 contained in the data plane data layer 1250. One or more untrusted application subnets 1262 may be communicatively coupled to a service gateway 1236 contained in the data plane VCN 1218 and one or more DB subnets 1230 contained in the data plane data layer 1250. The data plane data layer 1250 may include one or more DB subnets 1230 that may be communicatively coupled to a service gateway 1236 contained in the data plane VCN 1218.
[0159] One or more untrusted application subnets 1262 may include a primary VNIC 1264(1)-(N) that may be communicatively coupled to tenant virtual machines (VMs) 1266(1)-(N) residing within one or more untrusted application subnets 1262. Each tenant VM 1266(1)-(N) may run code in a corresponding container 1267(1)-(N) and is communicatively coupled to an application subnet 1226 that may be contained in a data plane application layer 1246, which may be contained in a container egress VCN 1268. A corresponding secondary VNIC 1272(1)-(N) may facilitate communication between one or more untrusted application subnets 1262 contained in a data plane VCN 1218 and the application subnets contained in a container egress VCN 1268. The container egress VCN may include a NAT gateway 1238 that may be communicatively coupled to the public internet 1254 (e.g., Figure 9 (Public Internet 954).
[0160] Internet gateway 1234, contained in control plane VCN 1216 and data plane VCN 1218, can be communicatively coupled to metadata management service 1252 (e.g., Figure 9 The metadata management system 952 can be communicatively coupled to the public internet 1254. The public internet 1254 can be communicatively coupled to a NAT gateway 1238 contained in a control plane VCN 1216 and a data plane VCN 1218. The service gateway 1236 contained in the control plane VCN 1216 and the data plane VCN 1218 can be communicatively coupled to a cloud service 1256.
[0161] In some examples, by Figure 12 The architecture diagram of block diagram 1200 can be viewed as being composed of... Figure 11 The architecture illustrated in block diagram 1100 is an exception to the pattern, and may be what the IaaS provider's customers expect if the IaaS provider cannot communicate directly with the customer (e.g., in a disconnected region). The corresponding container 1267(1)-(N) contained in each customer's VM 1266(1)-(N) can be accessed by the customer in real time. Container 1267(1)-(N) can be configured to make calls to the corresponding secondary VNIC 1272(1)-(N) contained in one or more application subnets 1226 of the data plane application layer 1246, which may be contained in the container egress VCN 1268. The secondary VNIC 1272(1)-(N) can forward the calls to a NAT gateway 1238, which can forward the calls to the public internet 1254. In this example, containers 1267(1)-(N), which can be accessed by clients in real time, can be isolated from the control plane VCN 1216 and from other entities contained in the data plane VCN 1218. Containers 1267(1)-(N) can also be isolated from resources from other clients.
[0162] In other examples, a client may use containers 1267(1)-(N) to invoke cloud service 1256. In this example, the client may run code within containers 1267(1)-(N) requesting services from cloud service 1256. Container 1267(1)-(N) may forward this request to a secondary VNIC 1272(1)-(N), which may forward the request to a NAT gateway, which may forward the request to the public internet 1254. The public internet 1254 may forward the request via internet gateway 1234 to one or more LB subnets 1222 contained in control plane VCN 1216. In response to determining that the request is valid, one or more LB subnets may forward the request to one or more application subnets 1226, which may forward the request to cloud service 1256 via service gateway 1236.
[0163] It should be understood that the IaaS architectures 900, 1000, 1100, and 1200 depicted in the accompanying drawings may have other components besides those depicted. Furthermore, the embodiments shown in the drawings are merely some examples of cloud infrastructure systems that can be incorporated into embodiments of this disclosure. In some other embodiments, the IaaS system may have more or fewer components than shown in the drawings, may combine two or more components, or may have different configurations or arrangements of components.
[0164] In some embodiments, the IaaS system described herein may include a suite of application, middleware, and database services delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such an IaaS system is the Oracle Cloud Infrastructure (OCI) provided by this assignee.
[0165] Figure 13 An example computer system 1300, in which various embodiments can be implemented, is illustrated. System 1300 can be used to implement any computer system described above. As shown, computer system 1300 includes a processing unit 1304 that communicates with a plurality of peripheral subsystems via a bus subsystem 1302. These peripheral subsystems may include a processing acceleration unit 1306, an I / O subsystem 1308, a storage subsystem 1318, and a communication subsystem 1324. Storage subsystem 1318 includes a tangible computer-readable storage medium 1322 and system memory 1310.
[0166] Bus subsystem 1302 provides a mechanism for enabling the various components and subsystems of computer system 1300 to communicate with each other as intended. Although bus subsystem 1302 is schematically shown as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. Bus subsystem 1302 can be any of several types of bus architectures, including memory buses or memory controllers, peripheral buses, and local buses using any of a wide variety of bus architectures. For example, such architectures may include Industry Standard Architecture (ISA) buses, Micro Channel Architecture (MCA) buses, Enhanced ISA (EISA) buses, Video Electronics Standards Association (VESA) local buses, and Peripheral Component Interconnect (PCI) buses that may be implemented as mezzanine buses manufactured according to the IEEE P1386.1 standard.
[0167] A processing unit 1304, which may be implemented as one or more integrated circuits (e.g., a conventional microprocessor or microcontroller), controls the operation of the computer system 1300. One or more processors may be included in the processing unit 1304. These processors may include single-core or multi-core processors. In some embodiments, the processing unit 1304 may be implemented as one or more independent processing units 1332 and / or 1334, wherein each processing unit includes a single-core or multi-core processor. In other embodiments, the processing unit 1304 may also be implemented as a quad-core processing unit formed by integrating two dual-core processors into a single chip.
[0168] In various embodiments, processing unit 1304 can execute a wide variety of programs in response to program code and can maintain multiple concurrently executing programs or processes. At any given time, some or all of the program code to be executed may reside in processor(s) 1304 and / or storage subsystem 1318. With appropriate programming, processor(s) 1304 can provide the various functions described above. Computer system 1300 may additionally include processing acceleration unit 1306, which may include a digital signal processor (DSP), a dedicated processor, and / or the like.
[0169] I / O subsystem 1308 may include user interface input devices and user interface output devices. User interface input devices may include keyboards, pointing devices such as mice or trackballs, touchpads or touchscreens integrated into the display, scroll wheels, click wheels, dial pads, buttons, switches, keypads, audio input devices with voice command recognition systems, microphones, and other types of input devices. User interface input devices may include, for example, motion sensing and / or gesture recognition devices, such as the Microsoft Kinect® motion sensor, which enables users to control and interact with input devices (such as the Microsoft Xbox® 360 game controller) using a natural user interface that employs gestures and verbal commands. User interface input devices may also include eye gesture recognition devices, such as the Google Glass® blink detector, which detects eye activity from the user (e.g., “blinking” when taking a photo and / or making menu selections) and translates the eye gesture into input on the input device (e.g., Google Glass®). Additionally, user interface input devices may include voice recognition sensing devices that enable users to interact with a voice recognition system (e.g., the Siri® navigator) via voice commands.
[0170] User interface input devices may also include, but are not limited to, 3D mice, joysticks or pointers, game controllers, and graphics tablets, as well as audio / video devices such as speakers, digital cameras, digital camcorders, portable media players, webcams, image scanners, fingerprint scanners, barcode readers, 3D scanners, 3D printers, laser rangefinders, and eye-tracking devices. Additionally, user interface input devices may include, for example, medical imaging input devices such as computed tomography (CT), magnetic resonance imaging (MRI), positron emission tomography (PET), and medical ultrasound equipment. User interface input devices may also include, for example, audio input devices such as MIDI keyboards and digital musical instruments.
[0171] User interface output devices may include display subsystems, indicator lights, or non-visual displays such as audio output devices. Display subsystems may be cathode ray tubes (CRTs), flat panel devices such as those using liquid crystal displays (LCDs) or plasma displays, projection devices, touchscreens, etc. Generally, the term "output device" is used to encompass all possible types of devices and mechanisms for outputting information from computer system 1300 to the user or other computers. For example, user interface output devices may include, but are not limited to, a wide variety of display devices that visually convey text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, car navigation systems, plotters, voice output devices, and modems.
[0172] Computer system 1300 may include storage subsystem 1318, which provides a tangible, non-transitory computer-readable storage medium for storing software and data constructs that provide the functionality of the embodiments described in this disclosure. The software may include programs, code modules, instructions, scripts, etc., which, when executed by one or more cores or processors of processing unit 1304, provide the aforementioned functionality. Storage subsystem 1318 may also provide a repository for storing data used according to this disclosure.
[0173] like Figure 13 As illustrated in the example, storage subsystem 1318 may include various components, including system memory 1310, computer-readable storage medium 1322, and computer-readable storage medium reader 1320. System memory 1310 may store program instructions that can be loaded and executed by processing unit 1304. System memory 1310 may also store data used during instruction execution and / or data generated during program instruction execution. Various types of programs may be loaded into system memory 1310, including but not limited to client applications, web browsers, middleware applications, relational database management systems (RDBMS), virtual machines, containers, etc.
[0174] System memory 1310 may also store operating system 1316. Examples of operating system 1316 may include various versions of Microsoft Windows®, Apple Macintosh® and / or Linux operating systems, a wide variety of commercial UNIX® or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, Google Chrome® OS, etc.) and / or mobile operating systems such as iOS, Windows® Phone, Android® OS, BlackBerry® OS, and Palm® OS. In some implementations of computer system 1300 that execute one or more virtual machines, the virtual machine, along with its guest operating system (GOS), may be loaded into system memory 1310 and executed by one or more processors or cores of processing unit 1304.
[0175] Depending on the type of computer system 1300, system memory 1310 can have different configurations. For example, system memory 1310 can be volatile memory (such as random access memory (RAM)) and / or non-volatile memory (such as read-only memory (ROM), flash memory, etc.). Different types of RAM configurations can be provided, including static random access memory (SRAM), dynamic random access memory (DRAM), etc. In some implementations, system memory 1310 may include a basic input / output system (BIOS) containing basic routines that facilitate the transfer of information between elements within computer system 1300 (such as during startup).
[0176] Computer-readable storage medium 1322 may represent remote, local, fixed and / or removable storage devices and storage media for temporarily and / or more permanently containing and storing computer-readable information used by computer system 1300, including instructions executable by processing unit 1304 of computer system 1300.
[0177] Computer-readable storage medium 1322 may include any suitable medium known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing and / or transmitting information. This may include tangible computer-readable storage media or other tangible computer-readable media such as RAM, ROM, electronically erasable programmable ROM (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic tape cassette, magnetic tape, disk storage or other magnetic storage devices.
[0178] For example, computer-readable storage medium 1322 may include a hard disk drive that reads from or writes to a non-removable non-volatile magnetic medium, a disk drive that reads from or writes to a removable non-volatile disk, and an optical disc drive that reads from or writes to a removable non-volatile optical disc (such as a CD-ROM, DVD, and Blu-ray® disc) or other optical medium. Computer-readable storage medium 1322 may include, but is not limited to, Zip® drives, flash memory cards, Universal Serial Bus (USB) flash memory drives, Secure Digital (SD) cards, DVD discs, digital video tapes, etc. Computer-readable storage medium 1322 may also include solid-state drives (SSDs) based on non-volatile memory (such as flash-based SSDs, enterprise flash drives, solid-state ROMs, etc.), volatile memory-based SSDs (such as SSDs based on solid-state RAM, dynamic RAM, static RAM, DRAM), magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs using a combination of DRAM and flash-based SSDs. Disk drives and their associated computer-readable media can provide non-volatile storage for computer-readable instructions, data structures, program modules and other data for computer system 1300.
[0179] Machine-readable instructions executable by one or more processors or cores of the processing unit 1304 may be stored on a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium may include physically tangible memory or storage devices that include volatile memory storage devices and / or non-volatile memory storage devices. Examples of non-transitory computer-readable storage media include magnetic storage media (e.g., magnetic disks or magnetic tapes), optical storage media (e.g., DVDs, CDs), various types of RAM, ROM, or flash memory, hard disk drives, floppy disk drives, removable memory drives (e.g., USB drives), or other types of storage devices.
[0180] The communication subsystem 1324 provides an interface to other computer systems and networks. The communication subsystem 1324 serves as an interface for receiving data from other systems and transmitting data to other systems from computer system 1300. For example, the communication subsystem 1324 may enable computer system 1300 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 1324 may include radio frequency (RF) transceiver components, global positioning system (GPS) receiver components, and / or other components for accessing wireless voice and / or data networks (e.g., using cellular telephone technology, advanced data network technologies such as 3G, 4G, or EDGE (Enhanced Data Rate Global Evolution), WiFi (IEEE 802.11 series standards, or other mobile communication technologies, or any combination thereof)). In some embodiments, in addition to or instead of a wireless interface, the communication subsystem 1324 may provide wired network connectivity (e.g., Ethernet).
[0181] In some embodiments, the communication subsystem 1324 may also receive input communications on behalf of one or more users who may use the computer system 1300 in the form of structured and / or unstructured data feeds 1326, event streams 1328, event updates 1330, etc.
[0182] For example, the communication subsystem 1324 can be configured to receive data feeds 1326 in real time from users of social networks and / or other communication services, such as Twitter® feeds, Facebook® updates, web feeds such as Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third-party information sources.
[0183] Additionally, the communication subsystem 1324 can also be configured to receive data in the form of a continuous data stream, which may include event streams 1328 and / or event updates 1330 of real-time events, and may be continuous or unbounded in nature without a definite end. Examples of applications that generate continuous data may include, for example, sensor data applications, financial stocks, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, vehicle traffic monitoring, etc.
[0184] The communication subsystem 1324 can also be configured to output structured and / or unstructured data feeds 1326, event streams 1328, event updates 1330, etc., to one or more databases that can communicate with one or more streaming data source computers coupled to the computer system 1300.
[0185] The computer system 1300 can be of a variety of types, including handheld portable devices (e.g., iPhone® cellular phones, iPad® computing tablets, PDAs), wearable devices (e.g., Google Glass® head-mounted displays), PCs, workstations, mainframes, kiosks, server racks, or any other data processing system.
[0186] Due to the constantly evolving nature of computers and networks, the description of the computer system 1300 depicted in the accompanying drawings is intended only as a particular example. Many other configurations with more or fewer components than the system depicted in the drawings are possible. For example, custom hardware may also be used and / or specific elements may be implemented in hardware, firmware, software (including applets), or a combination thereof. Furthermore, connections to other computing devices, such as network input / output devices, may be employed. Based on the disclosure and teachings provided herein, those skilled in the art will understand other ways and / or methods for implementing the various embodiments.
[0187] Example
[0188] Example 1 may include a computer-implemented method comprising: detecting data from a second data center in a second region, the data being stored in an isolated environment of the first data center, by a computing system in a first data center in a first region; determining verification parameters by the computing system at least in part based on the first region; verifying the data by the computing system at least in part based on the verification parameters; processing a first message by the computing system instructing the release of the data from the isolated environment; processing a second message by the computing system instructing the first message to originate from a computing device located in the first region; and causing the data to be released from the isolated environment by the computing system at least in part based on the first message verifying and releasing the data and the second message indicating that the first message originated from the first region.
[0189] Example 2 may include the computer-implemented method of Example 1, wherein the method further includes: selecting a verification technique to be used for verifying data based at least in part on a first region.
[0190] Example 3 may include a computer-implemented method of Example 1 or 2, wherein releasing data from the isolation environment includes: releasing data from the isolation environment to a database at a first data center.
[0191] Example 4 may include a computer-implemented method of Example 1, 2 or 3, wherein the method further includes receiving data from an intermediate computing system via a secure pipeline.
[0192] Example 5 may include the computer-implemented method of Example 4, wherein the method further includes: making the data inaccessible to the intermediate computing system and during data verification.
[0193] Example 6 may include a computer-implemented method of any of the foregoing examples, wherein the method further includes: transmitting a request to a human resources system in a second area to determine authorization to transmit the first message, wherein the release of data from the isolated environment is based at least in part on that authorization.
[0194] Example 7 may include a computer-implemented method of any of the foregoing examples, wherein verifying data based at least in part on verification parameters includes: mapping the data to a verification technique, wherein the data is verified using that verification technique.
[0195] Example 8 may include a computing system comprising: one or more processors; and one or more computer-readable media having a set of instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to perform the method of any of the examples 1-7.
[0196] Example 9 may include one or more non-transitory computer-readable media having a set of instructions stored thereon, which, when executed by one or more processors of a computing system, cause the one or more processors to perform the method of any of the examples 1-7.
[0197] Example 10 may include a computer-implemented method comprising: processing a first message by a computing system in a first data center in a first region, the first message indicating that an intermediate computing system managed by the first data center has received data from a second data center in a second region, the data being stored in an isolated environment of the intermediate computing system; transmitting a first control instruction from the computing system to the intermediate computing system to verify the data at least in part based on a first standard; processing a verification result from the intermediate computing system by the computing system; processing a second message by the computing system, the second message indicating that the data is released from the isolated environment of the intermediate computing system; processing a third message by the computing system indicating that the second message originated from a computing device located in the first region; and causing the data to be released from the isolated environment by the computing system at least in part based on the verification result, the second message, and the third message.
[0198] Example 11 may include the computer-implemented method of Example 10, wherein the intermediate computing system is located in the first region.
[0199] Example 12 may include a computer-implemented method of Example 10 or 11, wherein transmitting a first control instruction to an intermediate computing system to verify data at least in part based on a first criterion includes: selecting a verification technique to be used to verify the data at least in part based on a first region, wherein the first control instruction includes an indication of the verification technique.
[0200] Example 13 may include a computer-implemented method of Example 10, 11, or 12, wherein the isolation environment is a first isolation environment, and wherein releasing data from the isolation environment based at least in part on a verification result, an instruction to release data, and an instruction from a second message source in a first region includes: releasing data from the first isolation environment to a second isolation environment at a first data center.
[0201] Example 14 may include a computer-implemented method of any of Examples 10 to 13, wherein releasing data from an isolated environment based at least in part on a verification result, an instruction to release data, and an instruction from a second message source in a first region includes: releasing data from the isolated environment to a database in a first data center.
[0202] Example 15 may include a computer-implemented method of any of Examples 10 to 14, wherein the method further includes: making the data inaccessible to the first data center and the second data center during the verification process.
[0203] Example 16 may include a computer-implemented method of any of Examples 10 to 15, wherein the method further includes: transmitting a request to a human resources system in a second area to determine authorization for transmitting a second message, wherein data is released from the isolated environment at least in part based on authorization.
[0204] Example 17 may include a computing system comprising: one or more processors; and one or more computer-readable media having a set of instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to perform the method of any of the examples 10-16.
[0205] Example 18 may include one or more non-transitory computer-readable media having a set of instructions stored thereon, which, when executed by one or more processors of a computing system, cause the one or more processors to perform the method of any of the examples 10-16.
[0206] Example 19 may include a computer-implemented method comprising: processing a first message by a computing system in a first data center in a first region, the first message indicating that an intermediate computing system managed by the first data center has received data from a second data center in a second region, the data being stored in a first isolation environment of the intermediate computing system; transmitting a first control instruction from the computing system to the intermediate computing system to verify the data at least in part based on a first standard; processing a verification result from the intermediate computing system by the computing system; processing a second message by the computing system indicating that the data is being released from the first isolation environment of the intermediate computing system; processing a third message by the computing system indicating that the second message originated from a computing device located in the first region; and causing the data to be released from the first isolation environment by the computing system at least in part based on the verification result, the second message, and the third message.
[0207] Example 20 may include the computer-implemented method of Example 19, wherein the intermediate computing system is located in the first region.
[0208] Example 21 may include the computer-implemented method of Example 19 or 20, wherein transmitting a first control instruction to an intermediate computing system to verify data at least in part based on a first criterion includes: selecting a verification technique to be used to verify the data at least in part based on a first region, wherein the first control instruction includes an indication of the verification technique.
[0209] Example 22 may include a computer-implemented method of Example 19, 20 or 21, wherein releasing data from a first isolation environment based at least in part on a verification result, an instruction to release data, and an instruction from a second message source in a first area includes: releasing data from the first isolation environment to a second isolation environment at a first data center.
[0210] Example 23 may include a computer-implemented method of any of Examples 19-22, wherein releasing data from a first isolation environment based at least in part on a verification result, an instruction to release data, and an instruction from a second message source in a first region includes: releasing data from the first isolation environment to a database in a first data center.
[0211] Example 24 may include a computer-implemented method of any of the examples 19-23, wherein the computer-implemented method further includes: making the data inaccessible to the first data center and the second data center during the verification process.
[0212] Example 25 may include a computer-implemented method of any of the examples 19-24, wherein the computer-implemented method further includes: transmitting a request to a human resources system in a second area to determine authorization for transmitting a second message, wherein data is released from the isolation environment at least in part based on authorization.
[0213] Example 26 may include the computer-implemented method of Example 19, wherein the method further includes: detecting data from a second data center in a second region, the data being stored in a second isolation environment of a first data center; determining verification parameters by the computing system at least in part based on the first region; verifying the data by the computing system at least in part based on the verification parameters; processing a first message by the computing system instructing the release of data from the second isolation environment; processing a second message by the computing system instructing the first message to originate from a computing device located in the first region; and causing the data to be released from the second isolation environment by the computing system at least in part based on the verification, the first message releasing the data, and the second message indicating that the first message originates from the first region.
[0214] Example 27 may include the computer-implemented method of Example 26, wherein the computer-implemented method further includes: transmitting a request to a human resources system in a second area to determine authorization for transmitting the first message, wherein data is released from the second isolated environment at least in part based on authorization.
[0215] Example 28 may include a computing system comprising: one or more processors; and one or more computer-readable media having a set of instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to perform the methods of any of the examples 19-28.
[0216] Example 29 may include one or more non-transitory computer-readable media having a set of instructions stored thereon, which, when executed by one or more processors of a computing system, cause the one or more processors to perform the method of any of the examples 19-28.
[0217] Unless otherwise expressly stated, any example in any of the foregoing examples may be combined with any other example (or combination of examples). The foregoing description of one or more implementations provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise forms disclosed. Modifications and variations are possible in accordance with the foregoing teachings, or may be obtained from practice with various embodiments.
[0218] Although specific embodiments have been described, various modifications, alterations, alternative constructions, and equivalents are also included within the scope of this disclosure. The embodiments are not limited to operation within certain specific data processing environments, but can freely operate within multiple data processing environments. Additionally, although the embodiments have been described using a specific series of transactions and steps, it will be apparent to those skilled in the art that the scope of this disclosure is not limited to the described series of transactions and steps. Various features and aspects of the above embodiments can be used individually or in combination.
[0219] Furthermore, while embodiments have been described using specific combinations of hardware and software, it should be recognized that other combinations of hardware and software are also within the scope of this disclosure. Embodiments may be implemented using only hardware, or only software, or a combination thereof. The various processes described herein may be implemented on the same or different processors in any combination. Thus, where a component or service is described as being configured to perform certain operations, such a configuration may be implemented, for example, by designing electronic circuits to perform operations, by programming programmable electronic circuits (such as microprocessors), or any combination thereof. Processes may communicate using a wide variety of techniques, including but not limited to conventional techniques for inter-process communication, and different pairs of processes may use different techniques, or the same pair of processes may use different techniques at different times.
[0220] Therefore, the specification and drawings are to be considered illustrative rather than restrictive. However, it will be apparent that additions, deletions, omissions, and other modifications and alterations may be made thereto without departing from the broader spirit and scope set forth in the claims. Thus, although specific disclosed embodiments have been described, they are not intended to be limiting. Various modifications and equivalents are within the scope of the following claims.
[0221] In the context of describing the disclosed embodiments (particularly in the context of the following claims), the terms “a,” “an,” and “the,” as well as similar pronouns, should be interpreted as encompassing both the singular and plural, unless otherwise stated herein or obviously contradicted by the context. Unless otherwise stated, the terms “comprising,” “having,” “containing,” and “including” should be interpreted as open-ended terms (i.e., meaning “including, but not limited to”). The term “connected to” should be interpreted as partially or wholly included, attached to, or combined with, even if something else is involved. Unless otherwise stated herein, the enumeration of numerical ranges herein is intended only as a concise way of expressing each separate value falling within that range, and each separate value is incorporated into the specification as if it were individually enumerated herein. Unless otherwise stated herein or obviously contradicted by the context, all methods described herein can be performed in any suitable order. Unless otherwise claimed, the use of any and all examples or exemplary language (e.g., “such as”) provided herein is intended only to better illustrate the embodiments and does not limit the scope of this disclosure. Nothing in the specification should be construed as indicating that any unclaimed element is essential to the practice of this disclosure.
[0222] Unless otherwise expressly stated, disjunctive language such as the phrase “at least one of X, Y, or Z” is intended to be understood in context as generally used to refer to items, terms, etc., and can be X, Y, or Z or any combination thereof (e.g., X, Y, and / or Z). Therefore, such disjunctive language is generally not intended and should not imply that certain embodiments require the presence of at least one of X, at least one of Y, or at least one of Z.
[0223] This document describes preferred embodiments of the present disclosure, including known best modes for carrying out the present disclosure. Variations of those preferred embodiments will become apparent to those skilled in the art upon reading the foregoing description. Those skilled in the art should be able to appropriately employ such variations, and the present disclosure can be practiced in addition to those specifically described herein. Therefore, the present disclosure includes all modifications and equivalents of the subject matter set forth in the appended claims as permitted by applicable law. Furthermore, unless otherwise stated herein, any combination of the foregoing elements in all possible variations is included in this disclosure.
[0224] All references cited herein, including publications, patent applications and patents, are incorporated herein by reference to the extent that each reference is individually and specifically indicated as being incorporated and set forth herein by reference in its entirety.
[0225] In the foregoing description, aspects of this disclosure have been described with reference to specific embodiments thereof; however, those skilled in the art will recognize that this disclosure is not limited thereto. The various features and aspects of the foregoing disclosure may be used alone or in combination. Furthermore, embodiments may be utilized in any number of environments and applications beyond those described herein without departing from the broader spirit and scope of this specification. Therefore, the description and drawings are to be considered illustrative rather than restrictive.
Claims
1. A computer-implemented method, comprising: A first message is processed by a computing system in a first data center in a first region. The first message indicates that an intermediate computing system managed by the first data center has received data from a second data center in a second region, and the data is stored in a first isolation environment of the intermediate computing system. The computing system transmits a first control command to the intermediate computing system to verify the data based at least in part on a first standard; The verification results from the intermediate computing system are processed by the computing system. The computing system processes a second message, which instructs the data to be released from the first isolated environment of the intermediate computing system. The computing system processes the third message, which indicates that the second message originated from a computing device located in the first area; as well as The computing system releases the data from the first isolation environment, at least in part based on the verification result, the second message, and the third message.
2. The computer-implemented method according to claim 1, wherein the intermediate computing system is located in the first region.
3. The computer-implemented method according to claim 1 or 2, wherein transmitting a first control instruction to the intermediate computing system to verify the data at least in part based on a first standard comprises: The verification technique to be used to verify the data is selected at least in part based on a first region, wherein the first control command includes an instruction for the verification technique.
4. The computer-implemented method of claim 1, 2, or 3, wherein releasing the data from the first isolation environment based at least in part on the verification result, the instruction to release the data, and the instruction originating from the second message in the first region comprises: This allows the data to be released from the first isolation environment to the second isolation environment at the first data center.
5. The computer-implemented method according to any one of claims 1-4, wherein the data is released from the first isolation environment based at least in part on the verification result, the instruction to release the data, and the instruction originating from the second message in the first region, comprising: This allows the data to be released from the first isolated environment to the database in the first data center.
6. The computer-implemented method according to any one of claims 1-5, wherein the computer-implemented method further comprises: This prevents the data from being accessed by the first and second data centers during the verification process.
7. The computer-implemented method according to any one of claims 1-6, wherein the computer-implemented method further comprises: A request is sent to the human resources system in the second region to determine authorization to transmit a second message, wherein the data is released from the first isolation environment at least in part based on the authorization.
8. The computer-implemented method according to claim 1, wherein the method further comprises: The computing system detects data from a second data center in a second region, the data being stored in a second isolated environment within the first data center; The verification parameters are determined by the computing system based at least in part on the first region; The data is verified by the computing system, at least in part, based on the verification parameters; The computing system processes a first message, which instructs the data to be released from the second isolated environment. The computing system processes the second message, which indicates that the first message originated from a computing device located in the first region; as well as The computing system releases the data from the second isolation environment based at least in part on the verification, the first message releasing the data, and the second message originating from the first region.
9. The computer-implemented method according to claim 8, wherein the computer-implemented method further comprises: A request is sent to the human resources system in the second region to determine authorization to transmit the first message, wherein the data is released from the second isolation environment at least in part based on the authorization.
10. A computing system for a first data center in a first region, the computing system comprising: One or more processors; as well as One or more computer-readable media storing a set of instructions that, when executed by the one or more processors, cause the one or more processors to: Process a first message indicating that the intermediate computing system managed by the first data center has received data from the second data center in the second region, and the data is stored in the first isolation environment of the intermediate computing system; The first control command is transmitted to the intermediate computing system to verify the data at least in part based on a first standard; Process the verification results from the intermediate computing system; Process a second message, which instructs the data to be released from the first isolated environment of the intermediate computing system; Process the third message, which indicates that the second message originated from a computing device located in the first area; as well as The data is released from the first isolation environment based at least in part on the verification result, the second message, and the third message.
11. The computing system of claim 10, wherein the intermediate computing system is located in the first region.
12. The computing system of claim 10 or 11, wherein transmitting the first control instruction to the intermediate computing system to verify the data at least in part based on the first criterion comprises: The verification technique to be used to verify the data is selected at least in part based on a first region, wherein the first control command includes an instruction for the verification technique.
13. The computing system of claim 10, 11, or 12, wherein releasing the data from the first isolation environment based at least in part on the verification result, the instruction to release the data, and the instruction originating from the second message in the first region comprises: This allows the data to be released from the first isolation environment to the second isolation environment at the first data center.
14. The computing system according to any one of claims 10-13, wherein releasing the data from the first isolation environment is based at least in part on the verification result, the instruction to release the data, and the instruction originating from the second message source in the first region, comprising: This allows the data to be released from the first isolated environment to the database in the first data center.
15. The computing system according to any one of claims 10-14, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to: This prevents the data from being accessed by the first and second data centers during the verification process.
16. The computing system according to any one of claims 10-15, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to: A request is sent to the human resources system in the second region to determine authorization to transmit a second message, wherein the data is released from the first isolation environment at least in part based on the authorization.
17. The computing system of claim 10, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to: The data originating from a second data center in a second region is detected, and the data is stored in a second isolated environment within the first data center; The verification parameters are determined at least in part based on the first region; The data is verified by the computing system, at least in part, based on the verification parameters; Process the first message, which instructs the data to be released from the second isolation environment; Process the second message, which indicates that the first message originated from a computing device located in the first area; as well as The data is released from the second isolation environment based at least in part on the verification, the first message releasing the data, and the second message originating from the first region.
18. The computing system of claim 10, wherein the set of instructions, when executed by the one or more processors, further causes the one or more processors to: A request is sent to the human resources system in the second region to determine authorization to transmit the first message, wherein the data is released from the second isolation environment at least in part based on the authorization.
19. One or more non-transitory computer-readable media storing a set of instructions, which, when executed by one or more processors of a computing system in a first data center in a first region, cause the one or more processors to: Process a first message indicating that the intermediate computing system managed by the first data center has received data from the second data center in the second region, and the data is stored in the first isolation environment of the intermediate computing system; The first control command is transmitted to the intermediate computing system to verify the data at least in part based on a first standard; Process the verification results from the intermediate computing system; Process a second message, which instructs the data to be released from the first isolated environment of the intermediate computing system; Process the third message, which indicates that the second message originated from a computing device located in the first area; as well as The data is released from the first isolation environment based at least in part on the verification result, the second message, and the third message.
20. One or more non-transitory computer-readable media according to claim 19, wherein the intermediate computing system is located in the first region.