Handshake for service authorization

The authorization service with an authorization agent and pseudo-unique ID system addresses the challenge of managing access and authorization for customer resources, enhancing security and efficiency by preventing unauthorized access from cloned systems and managing credentials effectively.

DE112016006123B4Active Publication Date: 2025-07-03AMAZON TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE112016006123
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2015-12-30
Filing Date
2016-12-21
Publication Date
2025-07-03
Estimated Expiration
2036-12-21

AI Technical Summary

Technical Problem

Existing systems face challenges in efficiently managing access and authorization of customer resources to online services, particularly when multiple credentials are required and resources are cloned or replicated, leading to inefficiencies and security vulnerabilities.

Method used

A method and system that utilizes an authorization service to generate and manage authorization tokens for customer resources, including the installation of an authorization agent that generates a pseudo-unique ID and uses public-private key pairs for secure access, ensuring that cloned resources are detected and managed effectively.

Benefits of technology

Enables secure, efficient access management for customer resources by preventing unauthorized access from cloned systems and reducing the need for multiple credentials, while ensuring continuous authorization through token refresh and detection of cloned resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Computer-implemented method comprising: Receiving a registration request from a customer, the registration request specifying a security role to be granted to a customer resource by an online service, the customer resource comprising a virtual machine; Determine that credentials submitted with the registration request are valid; Authorize the registration request; Generating an activation code for the registration request; Generate a resource ID for the customer resource; Storing sufficient information to identify the activation code and sufficient information to identify the resource ID; Issuing the activation code to the customer; Cause an authorization agent to be installed on the customer resource that contains the virtual machine; Receiving an activation request from the authorization agent, the activation request including the resource ID, a pseudo-unique resource ID, and the activation code, the pseudo-unique resource ID generated by the authorization agent as unique for the customer resource; Determining, based at least in part on the pseudo-unique resource ID, that the customer resource is a cloned resource; Acquiring an authorization token that enables the customer resource, including the virtual machine, to use the online service in accordance with the security role from an authorization token service associated with the online service; and Providing the authorization token to the authorization agent.
Need to check novelty before this filing date? Find Prior Art

Description

GENERAL STATE OF THE ART

[0001] Online services are an important part of modern computing. Online services provide storage and backup services, data processing services, key management services, virtual computing services, financial services, shopping services, and many other computing and data access services. Access to online services is generally controlled by a variety of authentication and authorization techniques, such as username / password pairs, digital certificates, network address filters, and biometric identification. When accessing an online service, a customer provides the online service with the correct authentication information, and the online service grants access. In some environments, customers operate a variety of customer resources, such as customer computers, servers, virtual machines, and other network-connected computing devices that would benefit from access to online services.However, providing access to online services for customer resources can be a significant challenge.

[0002] Customer resources may require different levels of access to online services than those that would be provided by simply providing the customer with credentials to the customer resource. Furthermore, multiple sets of customer credentials may be required if a customer resource requires access to multiple online services. If specific customer credentials change, customer resources that use those specific credentials must be updated with the new credentials. For these and other reasons, controlling the authorization of customer resources to use online services can be very problematic.

[0003] US 8,577,334 B1 provides a method for providing privileged access to an electronic device. The method includes receiving a first request for an activation code, wherein the first request includes an identifier of the electronic device. An expiration time for the activation is determined by a computer system. An activation code is determined based on the identifier of the electronic device, and the activation code is transmitted. A second request for a token to unlock privileged access to the electronic device is received, wherein the second request includes the activation code and the identifier of the electronic device.If the activation code received in the second request matches the electronic device identifier specified in the second request and if the second request is received before the activation expiration time, the token is transferred to enable privileged access to the electronic device.

[0004] US 2009 / 0089866 A1 provides an access control system that can reduce the user's waiting time until a user-requested service is provided. The access control system of the present invention specifies the next service to be provided to a UT (a client-side communication device) after the service currently being provided to the UT, and then executes a process to make an authorization decision regarding the next service with respect to the user of the UT in advance before the UT requests the next service.

[0005] The present invention is based on the object of improving the provision of access to online services for customer resources and controlling the authorization of customer resources to use online services.

[0006] This problem is solved by a computer-implemented method according to independent claim 1, a system according to independent claim 4, and a non-transitory computer-readable storage medium according to independent claim 9. Specific embodiments of the invention are claimed in the dependent claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Various techniques are described with reference to the drawings in which: Fig. 1 shows an illustrative example of an environment in which various embodiments may be performed; Fig. 2 shows an illustrative example of a customer resource accessing a set of online services with a common authorization token according to one embodiment; Fig. 3 shows an illustrative example of a cloned customer resource accessing an online service according to one embodiment; Fig. 4 shows an illustrative example of an authorization service that authorizes access to an online service by a customer resource, according to one embodiment; Fig. 5 shows an illustrative example of a process that authorizes access to an online service by a customer resource as a result of being performed by a service management console, an authorization service, and an authorization agent, according to one embodiment; Fig. 6 shows an illustrative example of a process that, as a result of being performed by an authorization service, an authorization agent, and an online service, satisfies an online service request submitted by a customer resource, according to one embodiment; Fig. 7 shows an illustrative example of a process that updates an authorization token used by a customer resource as a result of being performed by an authorization service, an authorization agent, and an online service, according to one embodiment; Fig. 8 shows an illustrative example of a process that registers a customer resource to use an online service as a result of being performed by an authorization service, according to one embodiment; Fig. 9 shows an illustrative example of a process that, as a result of being performed by an authorization agent on a customer resource, enables a customer resource to use an online service, according to one embodiment; Fig. 10 shows an illustrative example of a process that satisfies a resource activation request as a result of being performed by an authorization service, according to one embodiment; Fig. 11 shows an illustrative example of a process that updates an activation token as a result of being performed by an authorization service, according to one embodiment; and Fig. Figure 12 illustrates an environment in which various embodiments may be implemented. DETAILED DESCRIPTION

[0008] This document describes an authorization service that enables on-premises customer resources, such as servers, computing devices, and virtual machines, to register with an online service provider and receive an authorization token that can be used to access online services provided by the online service provider. This may, for example, enable the on-premises customer resources to communicate with the online service provider, including receiving commands from it. A customer, such as an administrator or other authorized user, accesses the authorization service using a customer computer system via an application programming interface ("API"), command-line interface, or other user interface.The customer registers a customer resource with the Authorization Service by providing a resource identifier ("Resource ID") and a security role or set of privileges to be granted to the customer resource. The Authorization Service records the Resource ID and the granted role or privileges in a resource registry database and generates a one-time activation code, which is issued to the customer. The one-time activation code expires after a period of time.

[0009] The customer authorizes the customer resource by installing an authorization agent on the customer resource and activating the authorization agent with the authorization service. The customer is provided with installation instructions for the authorization agent along with a one-time activation code. In some environments, the customer is prompted to download and run an installer on the customer resource. The installer can be in the form of an MSI, PKG, ZIP, or setup.exe file.

[0010] Once the authorization agent has been installed, the customer activates the authorization agent by submitting an activation command to the authorization agent. In some implementations, the activation command is passed to the installer as a parameter. The customer provides the resource ID and activation code as parameters with the activation command. In response to receiving the activation command, the authorization agent generates and stores a public-private key pair for signing requests sent to the authorization service. The authorization agent generates an activation request that includes the resource ID, the activation code, and the public key of the public-private key pair. In some implementations, the activation request includes a pseudo-unique resource ID.The pseudo-unique resource ID is generated by the customer resource such that it has a value that is typically unique for each instance of a customer resource, even if the customer resource is mapped or cloned from another customer resource. For example, the pseudo-unique resource ID may be based at least in part on a processor ID, a hardware serial number, or a network address associated with the customer resource. The pseudo-unique resource ID may be used to track customer resources that have been cloned or replicated. The authorization agent signs the activation request with the private key of the public-private key pair and submits the activation request to the authorization service.

[0011] The authorization service receives the activation request from the authorization agent and verifies the signature on the activation request using the included public key. The activation request is validated by confirming that the activation code for the provided resource ID is valid, has not expired, or is not already in use. If the activation request is valid, the authorization service records that the activation code is no longer valid in a database maintained by the activation service and records the customer resource information in a database of authorized customer resources. The activation code can be invalidated by the authorization service itself or by causing another entity to invalidate the activation code.The authorization service retrieves the requested role or privileges from the resource registry database based at least in part on the resource ID provided with the activation command. The activation service contacts the online service provider and acquires an authorization token that provides the requested role or privileges. The authorization service issues the authorization token to the authorization agent running on the customer resource. Information related to the issued authorization token is stored in a resource authorization database for later use.

[0012] The authorization agent uses the authorization token to access online services provided by the online service provider. When the customer resource sends a request to an online service, the customer resource provides the authorization token with the request. The online service receives the request and grants or denies the request according to the role or privileges associated with the authorization token. When the authorization token expires, the authorization token can be refreshed by the authorization agent. To refresh an authorization token, the authorization agent sends a signed request to the authorization service. The authorization service validates the digital signature on the request, acquires a new authorization token from the online service provider, and issues the new authorization token to the authorization agent.

[0013] In some environments, the customer resources may be cloned or replicated. Cloned resources may be acquired by the authorization service during activation or during requests for a service. In some implementations, the authorization agent generates a pseudo-unique resource identifier, which is provided to the authorization service during registration of the customer resource. The pseudo-unique resource identifier is provided to the authorization service during registration and distinguishes a cloned customer resource from its related parent customer resource. In another implementation, the authorization agent includes a sequence number with each request to the authorization service.When the authorization service receives a request from a customer resource that includes a previously received resource ID and sequence number, a cloned resource is recorded.

[0014] Various authentication mechanisms used by a customer can be used to acquire authorization tokens for customer resources. For example, if a customer uses a username and password to authenticate to an online service, the username and password can be provided by the customer during registration of a customer resource with the authentication service. If the customer uses a digital certificate to authenticate to the online service, the digital certificate can be provided by the customer during registration of the customer resource with the authorization service.

[0015] Customer resources may be located on a local customer computer system, a customer-controlled network environment, an on-site data center, a remote network, or a network controlled by the online service provider. On-site customer resources refer to customer resources that are physically located at the customer's place of business and subject to the customer's physical control. The authorization service may be a separate service offered by the online service provider or may be a service associated with a specific online service offered by the online service provider. In some implementations, the authorization service is offered by a third party, and the authorization service interacts with the online service provider or the specific online services for which the authorization service provides authorization tokens.By distributing authorization tokens to customer resources, the customer resources are able to access a range of online services under the supervision of the customer who owns the customer resources, without having to distribute customer credentials to the customer resources or issue new credentials for each customer resource.

[0016] Fig. 1 shows an illustrative example of an environment in which various embodiments may be practiced. An online service provider 102 provides a set of online services and an authorization service 104. A customer 106 of the online service provider 102 accesses the services provided by the online service provider over a computer network. The customer 106 manages access to the online service provider from a customer computer system 108 that provides a service management console 110. The customer 106 owns and operates a number of customer resources, such as servers, virtual machines, or other computing devices, on the network.

[0017] When the customer 106 wishes to provide access to the services provided by the online service provider at a customer resource 112, the customer generates a registration request using the service management console 110 and sends the registration request to the authorization service 104. The registration request includes a resource ID for the customer resource 112, a security role to be granted to the customer resource, and any credentials associated with the customer 106 required to authorize the request, such as a username / password combination or a customer digital certificate.

[0018] The authorization service 104 generates an activation code and stores the activation code, the resource ID, and a timestamp in a resource registry database located within the authorization service 104. Storing the activation code in the resource registry database may include storing a record containing the activation code itself or information enabling verification of access to the activation code, such as a hash function or other information derived at least in part from the activation code. The resource ID may be stored as a hash function enabling verification of a matching resource ID represented by the authorization agent.The activation code is issued to the customer by the service management console 110, and instructions are provided to the customer 106 for downloading and installing an authorization agent 114 on the customer resource 112. In some embodiments, the authorization service causes the authorization agent 114 to be stored on the customer resource 112 without intervention from the customer 106. The authorization service 104 commands the service management console 110 to contact the customer resource 112 and install the authorization agent 114. In another embodiment, the customer 106 has received instructions from the authorization service 104 and downloads an authorization agent installer compatible with the customer resource 112.The installation program may be transferred to the customer resource 112 over the computer network or through the use of computer-readable media, such as a CD-ROM, USB memory stick, flash drive, or other media. The customer 106 executes the installation program on the customer resource 112 to install the authorization agent 114. Parameters may be provided to the installation program specifying the activation code and resource ID. In some implementations, the customer 106 issues an activation command to the authorization agent that includes the resource ID and activation code as parameters.

[0019] The authorization agent 114 is activated by sending an activation request to the authorization service 104 that includes the activation code. In some implementations, the authorization agent 114 generates a public-private key pair, such as a 2048-bit RSA key pair, for use in signing requests sent to the authorization service 104. The authorization agent 114 may also generate a pseudo-unique resource ID, which is provided to the authorization service 104 with the resource ID. The pseudo-unique resource ID helps ensure that customer resources generated by cloning or replicating other customer resources have unique identifiers with the authorization service 104.The authorization agent 114 generates an activation request that includes the resource ID, the activation code, and, if applicable, a pseudo-unique resource ID and the public key of the public-private key pair. The activation request is signed using the private key of the public-private key pair and sent to the authorization service 104.

[0020] The authorization service 104 receives the activation request and verifies the signature on the request using the public key provided with the request. If the activation request is not properly signed, the request is denied. If the activation request is properly signed, the authorization service 104 accesses the resource registry database and retrieves the activation code associated with the provided resource ID. If the activation code cannot be found, or if the activation code has expired, or if the activation code is not associated with the provided resource ID, or if the activation code has already been used, the activation code is invalid and the activation request is denied.If the activation code is valid, the activation code is removed from the resource registry database so that the activation code can no longer be used, and the roles and / or privileges assigned to the customer resource 112 are retrieved from the registry database. The authorization service 104 requests an authorization token from the online service provider 102, which provides the roles and / or privileges assigned to the customer resource 112. The authorization token, the resource ID, the pseudo-unique resource ID, the public key of the public-private key pair, and a current timestamp are stored in a resource authorization database in the authorization service 104. The authorization service 104 issues the authorization token to the authorization agent 114.

[0021] The authorization agent 114 receives the authorization token, which can be used to access online services provided by the online service provider 102. In some implementations, the authorization agent 114 provides a service API to applications running on the customer resource 112. Service requests received through the service API are forwarded to a service provided along with the authorization token by the online service provider 102. The online service uses the authorization token to identify the requester and to identify the role or permissions granted to the requester. If the role or permissions granted to the requester allow the service request to be fulfilled, the service fulfills the request and provides a response to the authorization agent 114.In another implementation, the authorization agent 114 provides the authorization token to applications executing on the customer resource 112, and by providing the authorization token with the service requests, the applications submit requests to a service provided by the online service provider 102. The service uses the authorization token to identify and authorize the requestor, fulfills the service requests if applicable, and provides the application with associated responses for the service requests.

[0022] In various implementations, the authorization token may be configured to expire after a period of time. For example, the authorization token may expire one hour after the authorization token is issued to the authorization agent 114. The authorization service 104 may issue an updated token to the authorization agent 114 in response to an update command from the authorization agent 114 or in response to receiving a request from the authorization agent 114 (or an application executing on the customer resource) with an expired authorization token and in anticipation of the authorization token expiring.

[0023] Fig. 2 shows an illustrative example of a customer resource accessing a set of online services with a common authorization token, according to one embodiment. An environment 200 includes a customer resource 202 accessing a set of online services provided by an online service provider 204. An authorization agent 206 is installed on the customer resource 202 and receives an authorization token from an authorization service 208 in response to an activation request including an activation code. The authorization service 208 is associated with the online service provider 204. The online service provider 204 provides a set of online services, including a computing service 210, a storage service 212, and an encryption service 214.In additional implementations, the online service provider 204 may provide other online services, such as key management services, virtual computing services, email services, messaging services, video conferencing services, or Internet search services. The authorization token provided by the authorization service 208 is associated with one or more roles and / or one or more permissions that grant access to one or more online services provided by the online service provider 204. The authorization token may be used by the authorization agent 206 based at least in part on the roles and permissions associated with the authorization token to access one or more of the services provided by the online service provider 204.

[0024] For example, if a customer registers the customer resource 202 with the authorization service 208 and indicates that the customer resource 202 should be granted a role that allows access to a set of services provided by the online service provider 204, the authorization token provided to the authorization agent 206 by the authorization service 208 at the customer resource 202 can be used by the customer resource 202 to access any service at the online service provider 204. For example, in Fig. 2, the authorization token provided by the authorization service 208 may be used by the authorization agent 206 to access the computing service 210, the storage service 212, or the encryption service 214. The customer may request access to one, all, or a subset of the services provided by the online service provider upon authorizing the customer resource. In another example, the authorization agent 206 receives a restricted token from the authorization service 208. The restricted token may be used by the authorization agent 206 to access the computing service 210 and the storage service 212, but not the encryption service 214.

[0025] In some implementations, customer resource 202 receives commands from a service provided by online service provider 204. For example, the token provided by authorization agent 206 may provide access to an execution command service. The execution command service sends commands to customer resource 202 for execution. In another example, a security service provided by online service provider 204 may determine that customer resource 202 has been compromised and send a command through authorization agent 206 that causes customer resource 202 to delete sensitive data stored on customer resource 202.

[0026] Fig. 3 shows an illustrative example of a cloned customer resource accessing an online service according to one embodiment. A system 300 includes an online service provider 302 providing an authorization service 304 and a computing service 306. In additional embodiments, the online service provider 302 may provide web hosting services, storage services, or other services in place of the computing service 306. A customer resource 308, such as a virtual computer instance, a web device, or other computing device, hosts an authorization agent 310. The authorization agent 310 has been registered with the authorization service 304 and has been provided by the authorization service 304 with an authorization token. The customer resource 308 generates and sends requests to the computing service 306 using the authorization token.The computing service 306 determines whether the request is authorized based at least in part on the authorization token and fulfills the request.

[0027] When the customer resource 308 is cloned, copied, or otherwise replicated, a cloned customer resource 312 is created. The cloned customer resource 312 includes a duplicate authorization agent 314. In some implementations, the cloned customer resource 312 and the duplicate authorization agent 314 have a configuration that matches the configuration of the customer resource 308 and the authorization agent 310. When the duplicate authorization agent 314 generates and forwards to the computing service 306 a service request that includes an authorization token that matches the authorization token used by the authorization agent 310, the computing service 306 detects that matching authorization tokens are being used by two different customer resources and denies the service request submitted by the cloned customer resource.

[0028] In some embodiments, the computing service 306 detects that matching authorization tokens are being used by using a pseudo-unique resource identifier provided by the customer resources. The authorization agents generate pseudo-unique resource identifiers based at least in part on a processor ID, the network address of network interfaces associated with the customer resources, or a serial number of a machine. The authorization agents provide the pseudo-unique resource identifier when submitting requests to the computing service 306. In another embodiment, the computing service 306 detects that matching authorization tokens are being used by examining sequence numbers included in requests sent by the authorization agents.Requests generated by an authorization agent are assigned a sequence number by the authorization agent. The sequence number is incremented for each subsequent request, and the computing service 306 compares the sequence number of each request received by a given authorization agent with a sequence number of the previous request received by the given authorization agent. If the computing service 306 receives a request from a duplicate authorization agent with a resource ID and sequence number that match another request sent by the customer resource 308, the computing service 306 determines that the request originated from a cloned resource from the cloned customer resource 312. The computing service 306 notifies the authorization service 304, and the authorization service 304 issues a new authorization token to the cloned customer resource 312.In some implementations, if the computing service determines that the request originated from the cloned customer resource 312, the service request is denied and no new token is issued to the cloned customer resource.

[0029] In another embodiment, the duplicate authorization agent 314 detects that the cloned customer resource 312 is a cloned resource by comparing the pseudo-unique resource identifier with a newly generated pseudo-unique resource identifier. Before sending a request to the computing service 306, the duplicate authorization agent 314 generates a new pseudo-unique resource identifier and compares the new pseudo-unique resource identifier with the stored pseudo-unique resource identifier copied from the customer resource 308 when the customer resource 308 was cloned to create the cloned customer resource 312. If the stored pseudo-unique resource identifier does not match the new pseudo-unique resource identifier, the service request submitted by the cloned customer request is denied.In some implementations, if the stored pseudo-unique resource identifier does not match the new pseudo-unique resource identifier, the duplicate authorization agent 314 contacts the authorization service 304 and requests a new authorization token. The new authorization token is used by the duplicate authorization agent 314 to request services from the computing service 306.

[0030] Fig. Figure 4 shows an illustrative example of an authorization service that authorizes access to an online service by a customer resource, according to one embodiment. A system diagram 400 includes an online service provider 402 associated with an authorization service 404. A customer resource 406 has been registered with the authorization service 404 by a customer 407 operating a customer computer 408. In the Fig. In the example shown in Figure 4, the online service provider 402 includes a computing service 410; however, the computing service 410 may be replaced with a virtual computing service, a storage service, an encryption service, or another online service, as appropriate. The online service provider 402 provides an authorization token service 412. The authorization token service issues tokens to the authorization service 404, which can be used by online devices to authorize service requests submitted to the computing service 410.

[0031] The authorization service 404 includes a resource authorization manager 414. The resource authorization manager 414 is an operational module that exposes an activation API and a registration API over the network. The registration API provides functions that enable the customer 407 to register customer resources authorized to access the online service provider 402. The activation API provides functions that enable an authorization agent to receive an authorization token in exchange for an activation code provided by the customer 407. The authorization service 404 includes a resource registration database 418 in which registration information for customer resources is stored.The registration information may include a resource ID, an activation code, a security role, security permissions, a registration timestamp, and a resource label. The authorization service 404 includes a resource authorization database 420. Information related to activated customer resources, such as customer resource 406, is stored in the resource authorization database 420. The information related to the activated customer resources may include a resource ID, a pseudo-unique resource ID, a public encryption key, security roles, security permissions, and a token validity period.

[0032] The customer resource 406 is authorized to access the computing service 410 using a process initiated by the customer 407. The customer 407 uses a service management console 422 hosted by the customer computer 408. The service management console 422 provides a command line interface, application programming interface, graphical user interface, or other interface with the resource authorization manager 414. The customer 407 submits a customer resource registration request to the resource authorization manager 414 to register the customer resource 406. The customer resource registration request specifies one or more security roles and / or one or more permissions to be granted to the customer resource 406. The customer resource registration request is authorized by the customer 407 using credentials of the customer 407.For example, the customer 407 may authorize the customer resource registration request using the customer's username and password, digital certificate, or biometric signature. The resource authorization manager 414 verifies the credentials provided by the customer 407 and generates an activation code if the credentials are sufficient. In some implementations, the activation code expires after a period of time. The period is set as a time period reasonable to complete the activation of the customer resource 406, such as one hour. The activation code and the validity period are stored in the resource registration database 418. The resource authorization manager 414 issues the activation code to the customer 407 through the service management console 422.

[0033] The resource authorization manager 414 causes an authorization agent 424 to be installed on the customer resource 406. In some implementations, the resource authorization manager 414 provides the customer 407 with instructions for downloading and installing the authorization agent 424 on the customer resource 406. In another implementation, the resource authorization manager 414 sends commands to the service management console 422 to cause the service management console 422 to install the authorization agent 424 on the customer resource 406. In yet another implementation, the resource authorization manager 414 sends commands to the customer resource 406 that cause the customer resource 406 to install the authorization agent 424.The authorization agent 424 can be installed by copying executable images to the customer resource 406 or by executing an installation program or installation script for the authorization agent 424 on the customer resource 406. In some implementations, the customer 407 provides the resource ID and activation code as parameters to the installation program or script that installs the authorization agent 424. In another implementation, the customer 407 sends the resource ID and activation code to the authorization agent 424 as part of an activation command.

[0034] The authorization agent 424 operates as a service on the customer resource 406 and is activated with the resource authorization manager 414 to acquire an authorization token that allows access to the computing service 410. The authorization agent 424 generates a public-private key pair and stores the public-private key pair on the customer resource 406. In some implementations, the authorization agent 424 generates a pseudo-unique resource ID that can be used to detect whether customer resources are cloned or replicated. The authorization agent 424 sends an activation request to the authorization service that includes the resource ID for the customer resource, the pseudo-unique resource ID generated by the authorization agent 424, the public key of the public-private key pair, and a timestamp.The activation request is signed using the private key of the public-private key pair and sent to the authorization service 404. The authorization service 404 accesses the resource registry database 418 and determines whether the activation code is valid for the provided resource ID and whether the activation code has expired or been previously used. If the activation code has not been previously used, has not expired, and is valid for the provided resource ID, the resource authorization manager 414 accepts the activation from the authorization agent 424 and records the resource ID, the pseudo-unique resource ID, the roles and permissions granted to the customer resource 406, and the public key of the public-private key pair in the resource authorization database 420.The resource authorization manager 414 requests authorization from the authorization token service 412, which grants the roles and permissions requested during the registration of the customer resource 406, and issues the authorization token to the authorization agent 424.

[0035] The customer resource 406 may use the authorization token to authorize requests sent to the computing service 410. In some implementations, the authorization token expires after a period of time, such as one hour. When the authorization token expires, the authorization agent 424 may request an updated token from the resource authorization manager 414. Requests from the authorization agent 424 are signed with the private key of the public-private key pair, and the resource authorization manager 414 verifies the source of the request by confirming the signature on the request with public keys stored in the resource authorization database 420. The customer 407 may manage roles and permissions granted to the customer resources through the service management console 422.For example, if a particular customer resource has been compromised or is decommissioned, the customer 407 can access the resource authorization manager 414 via the service management console 422 and remove the compromised customer resource from the registry. The resource authorization manager 414 contacts the authorization token service 412 and invalidates the tokens stored in the compromised resource. Consequently, the compromised resource is no longer able to access the computing service 410.

[0036] Fig. 5 shows an illustrative example of a process that authorizes access to an online service by a customer resource as a result of being performed by a service management console, an authorization service, and an authorization agent, according to one embodiment. A swimlane diagram 500 illustrates operations performed by the service management console, the authorization service, and the authorization agent. The service management console is an interface program used by a customer to communicate with the authorization service. The service management console may be a command-line interface, a graphical interface, or an API. The process begins at block 502, where a customer submits a request to register a customer resource with the authorization service via the service management console.The request includes several parameters, including a name for the customer resource and a security role and / or security permissions to be granted to the customer resource. The security role and / or security permissions specify the rights the customer resource will have when accessing the online service.

[0037] At block 504, the authorization service receives the request from the service management console. The authorization service examines the customer credentials included in the request to determine whether the customer resource should be registered for the requested security role(s) and / or security authorizations. For example, the customer may provide a username and password, a digital certificate, or a biometric signature to identify the customer and enable the authorization service to authorize the request. If the request is authorized, execution continues with block 508. The authorization service generates an activation code and resource ID for the customer resource, and the activation code, resource ID, and registration timestamp are added to the resource registry database.In some implementations, the activation code is a one-time-use alphanumeric code that expires after a period of time or as a result of a first use. The validity period can be configured by the authorization service once per customer resource or globally for customer services authorized by the authorization service. The validity period can be recorded as a timestamp representing the current time along with an offset period, or as a timestamp representing a future time at which the validity period ends. The customer can specify a validity period for the activation code with a registration request. If the customer specifies a validity period with the registration request, the validity period is recorded in the resource registry database on the authorization service.The authorization service returns the activation code and resource ID to the service management console.

[0038] At block 510, the service management console receives the activation code and the resource ID from the authorization service. In response to receiving the registration information from the authorization service, the service management console initiates the installation 512 of the authorization agent on the customer resource. In some implementations, the authorization service provides instructions with the activation code instructing the customer to install an authorization agent on the customer resource. The instructions may include an installation program or script for the authorization agent or instructions for downloading an installation program or script for the authorization agent. The installation program or script uses the registration information provided by the authorization service as parameters.In another implementation, the authorization service causes the service management console to invoke a script that copies an executable image of the authorization agent to the customer resource and invokes the authorization agent on the customer resource. In yet another implementation, the authorization service causes the service management console to invoke an installer on the customer resource that installs and runs the authorization agent.

[0039] At block 514, the authorization agent is installed on the customer resource. The registration information provided to the service management console by the authorization service is passed to the authorization agent as part of the installation. The authorization agent stores the resource ID and activation code for use in activation with the authorization service. The authorization agent generates 515 an encrypted public-private key pair. The public-private key pair is stored by the authorization agent on the customer resource, and the public key of the public-private key pair is provided to the authorization service. The authorization agent signs future requests sent to the authorization service using the private key of the public-private key pair.At block 516, the authorization agent is activated with the authorization service by providing the resource ID, public key, and activation code to the authorization service. The activation request may be signed with the private key of the public-private key pair. In some implementations, the authorization agent generates a pseudo-unique resource ID based at least in part on a processor ID, a hardware serial number, a network address, an IP address, or a media access code ("MAC") of a network interface associated with the customer resource. The pseudo-unique resource ID is provided to the authorization service during activation and may be used to distinguish between resources that were cloned or replicated during a mapping or snapshot process.

[0040] At block 518, the authorization service receives the activation request and validates the signature on the request using the public key provided with the request. The authorization service validates the activation code and resource ID using information in the resource registry database. Activation of the customer resource is granted if the activation token has not expired, has not been previously used, and is registered with the provided resource ID. If activation is granted, the authorization service registers 519 the customer resource with the online service by acquiring an authorization token from an authorization token service associated with the online service.The authorization token grants the security roles and / or security permissions for which the customer resource is registered when provided to an online service with a service request. At block 520, the authorization token is provided to the authorization agent. The authorization agent receives the authorization token from the authorization service and stores 522 the authorization token for use with service requests submitted to the online service.

[0041] In some implementations, the authorization agent generates a public-private key pair at block 516. The public-private key pair is stored by the authorization agent for use in signing messages exchanged between the authorization agent and the authorization service. The public key of the public-private key pair is provided to the authorization service with the activation code and the resource ID in a message signed with the private key of the public-private key pair. At block 518, the authorization service confirms the signature using the provided public key and stores the public key in a resource authorization database maintained by the authorization service.Messages sent from the authorization service to the authorization agent may be signed with the public key. For example, at block 520, when the authorization service sends the authorization token to the authorization agent, the authorization token may be encrypted using the public key, and the authorization service may decrypt the message using the private key of the public-private key pair.

[0042] Fig. Figure 6 shows an illustrative example of a process that, as a result of being performed by an authorization service, an authorization agent, and an online service, fulfills an online service request submitted by a customer resource, according to one embodiment. A swimlane diagram 700 illustrates operations performed by the authorization service, the authorization agent, and the online service. The authorization service issues, in response to the Fig. 5, the authorization agent transmits an authorization token to the authorization agent 602 executing on the customer resource. The authorization agent stores 604 the authorization token for use with service requests submitted to the online service. At block 606, the authorization agent generates a service request for the online service. The service request is transmitted 608 to the online service along with the authorization token.

[0043] The online service authenticates 610 the requestor in response to receiving the service request based at least in part on a determination that the token is valid and not expired. If the resource ID is provided by the authorization agent, the authorization agent determines that the authorization token is associated with the resource ID. At block 612, the online service retrieves the security role and / or security permissions associated with the authorization token. If the security role and / or security permissions are sufficient to satisfy the request, execution continues to block 614 and the online service satisfies the request submitted by the customer resource. If the authorization token is not valid or if the security role or security permissions are insufficient, the service request is denied.

[0044] At block 616, the authorization agent receives the results of the service request. If the service request was satisfied, the results may be forwarded to the sender of the service request, such as an application program executing on the customer resource. If the service request was denied, the authorization agent may take further action, such as requesting a renewal of the authorization token or re-registering the customer resource with the authorization service.

[0045] Fig. 7 shows an illustrative example of a process that, as a result of being performed by an authorization service, an authorization agent, and an online service, updates an authorization token used by a customer resource, according to one embodiment. In many implementations, authorization tokens issued to authorization agents expire after a period of time and are updated by the authorization agent to ensure continued access to the online service. A swimlane diagram 700 illustrates operations performed by the authorization service, the authorization agent, and the online service. At block 702, the authorization agent generates a service request for the online service.The service request may originate from the authorization agent or may be generated in response to a request from an application program executing on the customer resource. The authorization agent transmits 704 the service request along with the authorization token to the online service.

[0046] The online service attempts to authenticate the service request by confirming that the token is properly registered with the customer resource and that any credentials or signatures associated with the service request are valid 708. At block 710, the online service determines that the authorization token has expired and notifies the authorization agent.

[0047] The authorization agent receives the notification that the authorization token has expired and requests a new authorization token from the authorization service 712. The authorization agent signs the request with a private key of a public-private key pair generated by the authorization agent and used during registration of the customer resource with the authorization agent.

[0048] In response to receiving the request for a new authorization token, the authorization service authenticates 713 the request by verifying the signature on the request using the public key of the public-private key pair maintained in the resource authorization database and acquires 714 a new authorization token. The new authorization token may be acquired by retrieving the security roles and / or security approvals from the resource registry and requesting an authorization token from an authorization token service associated with the online service used by the customer resource. At block 716, the authorization service provides the new authorization token to the authorization agent.The new authorization token can be signed or encrypted using the public key of the public-private key pair and decrypted upon receipt by the authorization agent.

[0049] The authorization agent receives the new authorization token from the authorization service and stores 718 the new authorization token for use in submitting service requests to the online service. The service request is resubmitted 720 by the authorization agent, along with the new authorization token, to the online service. Service requests may be submitted to the online service using a secure network protocol, such as TLS or SSL, on an IP port designated for receiving such requests.

[0050] The online service receives the resubmitted service request and authenticates 722 the resubmitted request using the new authorization token. If the new authorization token is associated with a security role and / or security permissions that allow / enable the request to be fulfilled, the online service 724 fulfills the service request and returns appropriate results to the authorization agent.

[0051] In some implementations, the authorization agent generates a pseudo-unique resource ID that is provided to the authorization service when requesting a new authorization token. The pseudo-unique resource ID can be used by the authorization service to detect whether the authorization agent is installed on a customer resource that was cloned from another customer resource that was previously registered with the authorization service. If a cloned customer resource is detected, the authorization service can register the cloned customer resource as a new customer resource instead of updating the one currently used by the cloned customer resource.In some implementations, the authorization service denies the request for a new authorization token when a cloned customer resource is detected, causing the authorization agent on the cloned customer resource to issue a request to be registered as a new customer resource.

[0052] In another implementation, at block 702, the authorization agent generates a service request sequence number for the service request. The service request sequence number is incremented for each subsequent request submitted to the online service. When the online service receives a service request containing a sequence number at block 708, the online service compares the received sequence number to the previously received sequence number. If the received sequence number is not greater than the previously received sequence number, the online service determines that the requester is a cloned customer resource and denies the service request.When the authorization agent receives a notification of an incorrect sequence number from the online service, the authorization agent can take various actions, including sending a request to the authorization service to invalidate the current authorization token, requesting a new authorization token from the authorization service, and reporting the cloned resource to the customer via the service management console.

[0053] Fig. 8 shows an illustrative example of a process that registers a customer resource for use with an online service as a result of being performed by an authorization service, according to one embodiment. A process diagram 800 shows a process beginning at block 802, in which an authorization service receives a registration request to register a customer resource from a customer. The registration request may originate from a customer computer hosting a service management console. The customer accesses the service management console from the customer computer to grant or deny access to online services from various customer resources. The registration request may include a resource label and specify one or more security roles and / or one or more security permissions.The security roles and permissions define rights and privileges to be granted to the customer resource with respect to the online service. For example, a security role may grant the customer resource administrative access rights to the online service, or it may specify privileges that grant the customer resource the ability to execute a read command from a storage service but deny the ability to issue a write command to the storage service. The registration request includes credentials provided by the customer. The credentials may take the form of a username and password, a digital certificate, a two-factor authentication sequence, biometric identification, or other credentials.At block 804, the authorization service verifies the customer's credentials to authenticate the customer's identity. The authorization service determines 806, based at least in part on the customer's credentials, whether the customer is authorized to register a customer device with the requested security roles and / or privileges. In some implementations, the customer credentials include a property (AssignRole) that indicates whether the customer may assign roles and privileges to customer resources. If the customer's credentials do not allow the customer to register a customer resource with the requested security roles and / or privileges, execution proceeds to block 808, and the registration request is denied.

[0054] If the customer's credentials allow the customer to register the customer resource, execution continues with block 810 and the authorization service generates a resource ID for the resource. The resource ID is an identifier issued to the customer and made available to the customer resource when the customer resource is activated. The resource ID can be an alphanumeric sequence, an integer, a generally unique identifier ("GUID"), a binary sequence, or a database index. At block 812, the authorization service generates an activation code for the resource. In some implementations, the activation code is an alphanumeric sequence, such as a group of four tuples, an integer, or a sequence of letters that forms a set of phonetically pronounceable syllables.For example, the activation code may be a base-64 encoded 128-bit (22-character) activation code generated using a random or pseudo-random number. The authorization service stores 814 the resource ID and activation code, along with the resource label and security roles, in a resource registry database maintained by the authorization service. In some implementations, the authorization service stores the timestamp that records the time the activation code was generated, and the activation code expires after a period of time, such as one hour.

[0055] At block 816, the authorization service issues the activation code and resource ID to the customer. In some implementations, the authorization service issues the activation code and resource ID to the customer via the service management console. The authorization service may cause the service management console to install an authorization agent on the customer resource. Alternatively, the authorization service may provide the customer with instructions for downloading and installing an authorization agent on the customer resource.

[0056] Fig. 9 shows an illustrative example of a process that, as a result of being performed by an authorization agent on a customer resource, activates a customer resource to use an online service, according to one embodiment. A process diagram 900 illustrates a process beginning at block 902, in which an authorization agent requests, for example, by command from a customer, to activate a customer resource. The authorization agent may be commanded to activate the customer resource in the process by which the authorization agent is installed on the customer resource. For example, the installation program or installation script that installs the authorization agent may use parameters including an activation code and a resource ID. Once the agent is installed, the installation script or installation program initiates the Fig. 9. In another example, the customer installs the authorization agent and then executes an activation command through an interface provided by the authorization agent, providing the activation code and resource ID as parameters.

[0057] In response to receiving the command to activate a customer resource, the authorization agent generates 904 a pseudo-unique resource ID. The pseudo-unique resource ID may be generated based at least in part on a serial number associated with the customer resource, a processor ID, a network address of a network interface associated with the customer resource, a media access control ("MAC") address of a network interface associated with the customer resource, or a system configuration of the customer resource. The pseudo-unique resource ID may be used to distinguish customer resources that have been cloned from their parent customer resources using image files or snapshots, or other cloned customer resources. At block 906, the authorization client generates and stores a public-private key pair, such as a 2048-bit RSA key pair.The public-private key pair is used to communicate with an authorization service.

[0058] The authorization agent generates 908 an activation command to be transmitted to an authorization service. The activation command may include, for example, the resource ID, the pseudo-unique resource ID, the activation code, and the public key of the public-private key pair. The activation command is signed 910 using the private key of the public-private key pair. At block 912, the activation command is transmitted to the authorization service. The activation command may be transmitted to the authorization service over the network using a secure protocol, such as TLS or SSL.

[0059] The authorization service outputs the results of the activation command to the authorization agent. If the authorization service indicates 914 that the activation was unsuccessful, access to the online service is denied 916. If the authorization service indicates 914 that the activation command was successful, the authorization agent receives 918 an authorization token from the authorization service, which can be used to access the online service according to the security roles and security permissions specified by the customer during registration of the customer resource. The authorization token is stored 920 by the authorization agent for use with subsequent service requests.

[0060] Fig. 10 shows an illustrative example of a process that satisfies a resource activation request as a result of being performed by an authorization service, according to one embodiment. A process diagram 1000 shows a process beginning at block 1002, in which an authorization service receives an activation request from an authorization agent executing on a customer resource. The activation request includes an activation code, a resource ID, a pseudo-unique resource ID, a public key of a public-private key pair associated with the authorization agent, and a timestamp. The activation request is signed with a private key of the public-private key pair. The authorization service makes a series of determinations to determine whether the activation request is permissible or not.

[0061] At block 1003, the authorization service determines whether the activation request has expired. The activation request has expired if the timestamp included in the activation code is more than five minutes old. This can prevent an activation request from being reused in a replay attack. If the activation request has not expired, execution continues to block 1004, and the authorization service determines whether the signature on the activation request is correct using the public key provided with the activation request. If the signature is valid, the authorization service queries the resource registry to determine 1006 whether the activation code has expired.The activation code may have expired if a period of time above a validity threshold has elapsed since the activation code was issued by the authorization service, or if the activation code was previously used to activate a customer resource with the authorization service. If the activation code has not expired, the authorization service determines 1008 whether the activation code is valid. The activation code is valid if the information in the resource registration database indicates that the activation code has been appropriately registered with the customer resource hosting the authorization agent. If the conditions described above are not met, execution continues to block 1012 and the authorization service denies the activation request. If the conditions described above are met, execution continues to block 1014.

[0062] At block 1014, the authorization service records the activation information in a resource authorization database. The activation information may include: a timestamp indicating when the activation request was granted, a validity period for an authorization token associated with the activation, the resource ID and pseudo-unique resource ID for the customer resource, and the public key of the public-private key pair. At block 1016, the authorization service acquires the authorization token for the online service. An authorization token for the online service may be acquired from an authorization token service associated with the online service. In some implementations, the authorization token service is associated with an online service provider that provides a variety of online services.In such implementations, a single authorization token can be used for the multitude of online services.

[0063] At block 1018, the authorization service provides the authorization token to the authorization agent. The authorization token may be signed or encrypted with the public key provided by the authorization agent as part of the request. The authorization token may be used by the authorization agent and the associated customer resource to make service requests to the online service.

[0064] Fig. 11 shows an illustrative example of a process that updates an activation token as a result of being performed by an authorization service, according to one embodiment. A process diagram 1100 illustrates a process for updating an activation token, beginning at block 1102, where an authorization service receives an update request from an authorization agent. The update request includes a timestamp for the request, a resource ID for the customer resource, and, in some embodiments, a pseudo-unique resource ID for the customer resource. The update request is signed with a private key of a public-private key pair possessed by the authorization agent.

[0065] The authorization service receives the update request and queries a resource authorization database 1104 to retrieve the public key for the authorization agent. The authorization service determines 1106, using the public key, whether the update request has expired. The authorization service determines whether the update request has expired by determining whether the difference between the timestamp and the current time exceeds a threshold. In some implementations, the threshold is five minutes. If the update request has expired, execution continues to block 1108, and the update request is denied.If the authorization service determines that the update request has not expired, execution proceeds to decision block 1110, where the authorization service determines whether the signature on the update request is valid. If the authorization service determines that the signature on the update request is not valid, the authorization service 1108 denies the update request. If the authorization service determines that the signature on the update request is valid, execution proceeds to decision block 1114, where the authorization service queries the resource authorization database to determine whether the authorization agent is hosted by a cloned customer resource. A cloned resource can be detected by examining the pseudo-unique resource ID.If the resource authorization database includes an entry for the resource ID specified in the update request, but the pseudo-unique resource ID provided with the request does not match the pseudo-unique resource ID in the resource authorization database, the authorization service determines that the customer resource hosting the authorization agent may be cloned. If the authorization service determines that the customer resource may be cloned, execution proceeds to block 1116, and the authorization service denies the update request and indicates to the authorization agent that a cloned resource has been detected.In some implementations, the authorization service creates a new entry in the resource authorization database and authorizes the cloned resource with the resource ID that was distinguished from the parent customer resource using the pseudo-unique resource ID.

[0066] If no cloned resource has been detected by the authorization service, execution continues with block 1118, where the authorization service obtains a new authorization token for the role requested during the registration process for the customer resource. The new authorization token may be acquired from an authorization token service associated with an online service provider or the online service. The authorization token and timestamps for managing a validity period of the authorization token may be stored in the resource authorization database. At block 1120, the new authorization token is provided to the authorization agent. The authorization token may be signed or encrypted with the public key of the public-private key pair associated with the authorization agent.

[0067] Fig. 12 illustrates aspects of an example environment 1200 for implementation aspects according to various embodiments. Although a web-based environment is used for purposes of explanation, it should be understood that other environments may be used to implement various embodiments, if appropriate. The environment includes a client electronic device 1202, which may include any suitable device operable to send and receive requests, messages, or information over a suitable network 1204, and in some embodiments, to transmit information back to a user of the device. Examples of such client devices include PCs, mobile phones, portable messaging devices, laptop computers, tablet computers, set-top boxes, personal data assistants, embedded computer systems, e-book readers, and the like.The network may include any suitable network, including an intranet, the Internet, a cellular network, a local area network, a satellite network, or any other such network, and / or a combination thereof. Components used for such a system may depend, at least in part, on the type of network and / or environment selected. Many protocols and components for communicating over such a network are well known and will not be discussed in detail here. Communication over the network may be enabled via wired or wireless connections, and combinations thereof.In this example, the network includes the Internet and / or other publicly available communications networks, as the environment includes a web server 1206 for receiving requests and presenting content in response thereto, although for other networks, an alternative device serving a similar purpose could be used, as would be apparent to one of ordinary skill in the art.

[0068] The illustrative environment includes at least one application server 1208 and a data store 1210. It should be understood that there may be multiple application servers, layers, or other elements, processes, or components that may be chained or otherwise configured and that may interact to perform tasks such as obtaining data from a suitable data store. Servers, as used herein, may be implemented in a variety of ways, such as as hardware devices or virtual computer systems. In some contexts, "server" may refer to a programming module executing on a computer system.Unless otherwise specified or clear from the context, the term "data store" as used herein refers to any device or combination of devices capable of storing, accessing, and retrieving data, which may include any combination and number of data servers, databases, data storage devices, and data storage media in any standard, distributed, virtual, or clustered environment. The application server may include any suitable hardware, software, and firmware for integration with the data store, if desired, to execute aspects of one or more applications for the customer device and to handle some or all of the data access and business logic for an application.The application server, in conjunction with the data store, may provide access control services and is capable of generating content, including, but not limited to, text, graphics, audio, video, and / or other content that may be used for delivery to the user, which may be made available to the customer using the web server in the form of HyperText Markup Language ("HTML"), Extensible Markup Language ("XML"), JavaScript, Cascading Style Sheets ("CSS"), JavaScript Object Notation (JSON), and / or any other convenient client-side structured language. Content transmitted to a customer device may be processed by the customer device to deliver the content in one or more forms, including, but not limited to, forms that are perceivable by the user audibly, visually, and / or through other senses.The handling of all requests and responses, as well as the delivery of content between the client device 1202 and the application server 1208, may be handled by the web server using PHP: Hypertext Preprocessor ("PHP"), Python, Ruby, Perl, Java, HTML, XML, JSON, and / or, in this example, another suitable server-side structured language. Furthermore, operations described herein as being performed by a single device, unless the context indicates otherwise, may be performed jointly by multiple devices, which may form a distributed and / or virtual system.

[0069] The data store 1210 may include multiple separate data tables, databases, data documents, dynamic data storage schemes, and / or other data storage mechanisms and media for storing data related to a particular aspect of the present disclosure. For example, the illustrated data store may include mechanisms for storing production data 1212 and user information 1216, which may be used to present content to the production site. The data store is also shown to include a mechanism for storing log data 1214, which may be used for reporting, analytics, or other such purposes.It should be understood that there may be many other aspects that need to be stored in the data store, such as page image information and access rights information, which may be stored in any of the mechanisms listed above or in additional mechanisms in the data store 1210, as appropriate. The data store 1210 may be operable, through logic associated therewith, to receive instructions from the application server 1208 and to obtain, update, or otherwise process data in response thereto. The application server 1208 may provide static, dynamic, or a combination of static and dynamic data in response to the received instructions.Dynamic data, such as data used in weblogs (blogs), shopping applications, news services, and other such applications, may be generated by server-side structured languages, as described herein, or may be provided by a content management system ("CMS") running on or controlled by the application server. In one example, a user may submit a search request for a certain type of object through a device operated by the user. In this case, the data store may access the user information to verify the user's identity and may access the catalog detail information to obtain information about objects of that type. The information may then be output to the user, such as in a results listing on a web page that the user may view via a browser on client device 1202.Information for a particular object of interest may be viewed on a dedicated page or in a dedicated browser window. However, it should be noted that embodiments of the present disclosure are not necessarily limited to the context of web pages, but may be more generally applicable to the processing of requests in general, where the requests are not necessarily content requests.

[0070] Each server typically includes an operating system that provides executable program instructions for the general administration and operation of that server, and typically includes a computer-readable storage medium (e.g., a hard disk, random access memory, read-only memory, etc.) on which are stored instructions that, when executed (i.e., in response to execution) by a processor of the server, enable the server to perform its intended functions.

[0071] The environment, in one embodiment, is a distributed and / or virtual computing environment utilizing multiple computer systems and components interconnected via communication links using one or more computer networks or direct connections. However, it will be apparent to one of ordinary skill in the art that such a system may be implemented in a system with fewer or greater numbers of components than in Fig. 12 illustrates that the system 1200 could work equally well. Thus, the representation of the system 1200 in Fig. 12 should be considered illustrative and not limiting as to the scope of the disclosure.

[0072] Additionally, embodiments of the present disclosure may be described in terms of the following sentences: 1. A computer-implemented method comprising: under the control of one or more computer systems configured with executable instructions, Receiving a registration request from a customer, the registration request specifying a security role to be granted to a customer resource by an online service; Determine that credentials submitted with the registration request are valid; Authorize the registration request; Generating an activation code for the registration request; Generate a resource ID for the customer resource; Storing sufficient information to identify the activation code and sufficient information to identify the resource ID; Issuing the activation code to the customer; Causing an authorization agent to be installed on the customer resource; receiving an activation request from the authorization agent, the activation request including the resource ID and the activation code; acquiring an authorization token that enables the customer resource to use the online service in accordance with the security role from an authorization token service associated with the online service; and Providing the authorization token to the authorization agent. 2. Computer-implemented method according to sentence 1, further comprising: Determine that a validity period has expired or that the activation code was provided with a previous activation request; and Invalidating the activation code based at least in part on determining that the validity period has expired or that the activation code was provided with a prior activation request. 3. Computer-implemented method according to sentence 1 or 2, wherein: the activation request includes a public key of a public-private key pair; the activation request is digitally signed using a private key associated with the public-private key pair; and the public key is stored. 4. Computer-implemented method according to one of sentences 1-3, further comprising: Receiving a pseudo-unique resource ID with the activation request, wherein the pseudo-unique resource ID was generated by the authorization agent as unique for the customer resource; and Determining, based at least in part on the pseudo-unique resource ID, that the customer resource is a cloned resource. 5. A system comprising at least one computing device implementing an authorization service, the authorization service: receives a registration request to register a customer resource associated with a customer with an online service; authorizes the registration request at least in part based on credentials associated with the customer; provides the Customer with an activation code in response to the registration request; receives an activation request containing the activation code from the customer resource; acquires an authorization token that enables a service request to be fulfilled by the online service; and provides the authorization token to the authorization agent. 6. System according to sentence 5, wherein the authorization service further: receives a validity period with the registration request; stores the validity period; determines that the activation code has expired by comparing the validity period with a current point in time; and invalidates the activation code. 7. The system of sentence 5 or 6, wherein a service management interface installs an authorization agent on the customer resource. 8. System according to any one of sentences 5-7, wherein the authorization service further: receives a pseudo-unique resource ID with the activation request, wherein the pseudo-unique resource ID is based at least in part on a processor ID of the customer resource, a device serial number of the customer resource, or a network address of a network interface associated with the customer resource; and determines, at least in part, based on the pseudo-unique resource ID, that the customer resource was not replicated from a parent customer resource. 9. System according to any one of sentences 5-8, wherein the authorization service further: receives a public key of a public-private key pair with the activation request; and a digital signature on the activation request is verified using the public key. 10. System according to any one of sentences 5-9, wherein the authorization service further: determines that a difference between a timestamp at the activation request and a current time exceeds a timeout value; and determines that the activation request has expired and denies the activation request. 11. System according to any one of sentences 5-10, wherein the online service: receives a service request that includes a timestamp; and the service request is refused if the difference between the timestamp and the time at which the service request is received is greater than a time threshold. 12. A system according to any of the clauses 5-11, wherein: the authorization token is acquired from an authorization token service associated with an online service provider; the online service provider provides a variety of online services; and the authorization token can be used with more than one of the multitude of online services. 13. Non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by one or more processors of a customer resource, cause the customer resource to do at least the following: Acquiring an activation code and a resource identifier, wherein the activation code and the resource identifier are provided by an authorization service associated with an online service provider; Generating a public-private key pair containing a public key and a private key; Generating a pseudo-unique resource identifier for the customer resource; transmitting an activation command to the authorization service, the activation command including the public key, the pseudo-unique resource identifier, the resource identifier, the activation code, and a digital signature generated with the private key; and Receiving an authorization token in response to the activation command. 14. The non-transitory computer-readable storage medium of sentence 13, wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the customer resource to: Submitting a service request to an online service provided by the online service provider, wherein the service request includes the authorization token. 15. The non-transitory computer-readable storage medium of sentence 14, wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the customer resource to: Determine that the service request was denied by the online service; Submitting an update request to the authorization service that causes the authorization service to issue a new authorization token; and receiving a new authorization token from the authorization service. 16. The non-transitory computer-readable storage medium of sentence 15, wherein the instructions causing the customer resource to determine that the service request has been denied further include instructions causing the customer resource to: Determining that the customer resource is a cloned resource; and Register the customer resource using a new resource identifier. 17. Non-transitory computer-readable storage medium according to sentence 15 or 16, wherein the update request includes a digital signature generated using the private key. 18. The non-transitory computer-readable storage medium of any one of sentences 13-17, wherein the instructions further comprise instructions that, during execution by the one or more processors, cause the customer resource to: Receiving a service request from an online service provided by the online service provider; and Fulfill the service requirement. 19. The non-transitory computer-readable storage medium of any of clauses 14-18, wherein the service request is transmitted to the online service over a computer network via a Transport Layer Security (“TLS”) connection. 20. The non-transitory computer-readable storage medium of any one of sentences 14-19, wherein the instructions further comprise instructions that, during execution by the one or more processors, cause the customer resource to: Generating a sequence number associated with the service request; Transmitting the sequence number with the service request to the authorization service; and receiving an indication from the authorization service that the customer resource is a cloned resource, the indication based at least in part on the sequence number.

[0073] The various embodiments may further be implemented in a wide variety of operating environments, which in some cases may include one or more user computers, computing devices, or processing devices that may be used to run any of a variety of applications. User or customer devices may include any of a variety of computers, such as desktop, laptop, or tablet computers running a standard operating system, as well as cellular, wireless, and wearable devices running mobile software and capable of supporting a variety of networking and messaging protocols.Such a system may also include a number of workstations running any of a variety of commercially available operating systems and other known applications for purposes such as development and database management. These devices may also include other electronic devices, such as dummy terminals, thin clients, gaming systems, and other devices capable of communicating over a network. These devices may also include virtual devices, such as virtual machines, hypervisors, and other virtual devices capable of communicating over a network.

[0074] Various embodiments of the present disclosure utilize at least one network known to one of ordinary skill in the art to support communication using any of a variety of commercially available protocols, such as the Transmission Control Protocol / Internet Protocol ("TCP / IP"), the User Datagram Protocol ("UDP"), protocols operating at various layers of the Open Systems Interconnection ("OSI") model, the File Transfer Protocol ("FTP"), Universal Plug and Play ("UPnP"), the Network File System ("NFS"), the Common Internet File System ("CIFS"), and AppleTalk. The network may be, for example, a local area network, a wide area network, a virtual private network, the Internet, an intranet, an extranet, a public switched telephone network, an infrared network, a wireless network, a satellite network, and any combination thereof.In some embodiments, connection-oriented protocols can be used to communicate between network endpoints. Connection-oriented protocols (sometimes referred to as connection-based protocols) are capable of transmitting data in an ordered stream. Connection-oriented protocols can be reliable or unreliable. For example, the TCP protocol is a reliable connection-oriented protocol. Asynchronous Transfer Mode ("ATM") and Frame Relay are unreliable connection-oriented protocols. Connection-oriented protocols contrast with packet-oriented protocols, such as UDP, which transmit packets without a guaranteed order.

[0075] In embodiments utilizing a web server, the web server may execute any of a variety of server or mid-tier applications, including Hypertext Transfer Protocol ("HTTP") servers, FTP servers, Common Gateway Interface ("CGI") servers, data servers, Java servers, Apache servers, and business application servers. The server(s) may also be capable of executing programs or scripts in response to requests from user devices, such as by executing one or more web applications, which may be implemented as one or more scripts or programs written in any programming language, such as Java. ®, C, C# or C++ or any scripting language such as Ruby, PHP, Perl, Python or TCL, and combinations thereof. The server(s) may also include database servers, including, but not limited to, those commercially available from Oracle®, Microsoft®, Sybase® and IBM®, as well as open source servers such as MySQL, Postgres, SQLite, MongoDB and any other servers capable of storing, retrieving and accessing structured or unstructured data. Database servers include table-based servers, document-based servers, unstructured servers, relational servers, non-relational servers, or combinations thereof and / or other database servers.

[0076] The environment may include a variety of data stores and other storage and other storage media, as discussed above. These may be located in a variety of locations, such as on a storage medium local to (and / or located within) one or more of the computers or remote from any or all of the computers across the network. In one particular set of embodiments, the information may be located in a Storage Area Network ("SAN"), which is known to those skilled in the art. Likewise, any files required to perform the functions associated with the computers, servers, or other network devices may be stored locally and / or remotely, as appropriate.When a system includes computer-based devices, each such device may include hardware elements that may be electrically coupled via a bus, where the elements include, for example, at least one central processing unit ("CPU" or "processor"), at least one input device (e.g., a mouse, a keyboard, a controller, a touchscreen, or a keypad), and at least one output device (e.g., a display device, a printer, or a speaker). Such a system may also include one or more storage devices, such as disk drives, optical storage devices, and solid-state storage devices such as random access memory ("RAM") or read-only memory ("ROM"), as well as removable media devices, memory cards, flash cards, etc.

[0077] Such devices may also include a computer-readable storage media reader, a communication device (e.g., a modem, a network card (wireless or wired), an infrared communication device, etc.), and memory, as described above. The computer-readable storage media reader may be connected to or configured to receive a computer-readable storage medium, which may include remote, local, fixed, and / or removable storage devices, as well as storage media for temporarily and / or permanently containing, storing, transmitting, and retrieving computer-readable information.The system and the various devices also typically include a number of software applications, modules, services, or other elements located within at least one memory device, including an operating system and application programs, such as a client application or a web browser. Furthermore, custom hardware may also be used and / or specialized elements may be implemented in hardware, software (including portable software such as applets), or both. Furthermore, a connection to other computing devices, such as network input / output devices, may be implemented.

[0078] Storage media and computer-readable media containing code or portions of code may include any convenient media known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media, implemented in any method or technique for storing and / or transmitting information, such as computer-readable instructions, data structures, program modules, or other data, including RAM, ROM, electrically erasable programmable read-only memory ("EEPROM"), flash memory or other storage technology, compact disc read-only memory ("CD-ROM"), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used toto store the desired information and which can be accessed by a system device. Based on the disclosure and teachings provided herein, one of ordinary skill in the art will understand that other ways and / or methods exist to implement the various embodiments.

[0079] It should be noted that the term "digital signature" includes any information that can be used to cryptographically verify the authenticity of a message, including information generated using an RSA-based digital scheme (such as RSA-PSS), the digital signature algorithm (DSA) and the elliptic curve algorithm of a digital signature, the ElGamal signature scheme, the Schnorr signature scheme, the Pointcheval-Stern signature algorithm, the Rabin signature algorithm, pairing-based digital signature schemes (such as the Boneh-Lynn-Schacham signature scheme), non-repudiable digital signature schemes, and others. Furthermore, message authentication codes (such as hash-based message authentication codes (HMACs)), encrypted cryptographic hash functions, and other types of information can also be used as digital signatures.

[0080] In various embodiments, data objects, such as digital signatures, may be cryptographically verifiable. In one example, cryptographically verifiable data objects are created to be cryptographically verifiable by the system to which the data object is to be provided or by another system that cooperates with the system to which the data object is provided. For example, the data object may be encrypted to be decrypted by the system that cryptographically verifies the data object, where the ability to decrypt the data object serves as cryptographic verification of the data object. As another example, the data object may be digitally signed (thereby creating a digital signature of the data object) such that the digital signature can be verified by the system that cryptographically verifies the data object.In other examples, both encryption and digital signatures are used for cryptographic verifiability and / or security. The key used to encrypt and / or digitally sign the data object may vary according to different embodiments, and the same key may not necessarily be used for encryption and digital signing. In some embodiments, a key used to encrypt the data object is a public key of a public-private key pair, wherein the private key of the key pair is securely held by the system to which the data object is to be deployed, thereby enabling the system to decrypt the data object using the private key of the key pair.Using the public key to encrypt the data object may include generating a symmetric key, using the symmetric key to encrypt the data object, and encrypting the symmetric key using the public key, wherein the encrypted symmetric key is provided to a system with the encrypted data object to enable the system to use the corresponding private key to decrypt the symmetric key and use the decrypted symmetric key to decrypt the data object. Further, in some embodiments, the data object is digitally signed using a private key of a public-private key pair corresponding to the computer system that encrypts and / or digitally signs the data object (e.g., a user device).For example, an application may be provided with the private key, and the data object may include a certificate for the private key for use by a system to verify the digital signature of the data object. Other variations, including variations in which a symmetric key is shared between the user computer and the system that cryptographically verifies the data object, may be used to encrypt and / or digitally sign the data object.

[0081] It should be noted that a system should be configured to trust a public encryption key if the logic with which the system is configured to operate depends on whether an attempt to verify a digital signature using the public encryption key is successful. Similarly, a system should be configured to trust a symmetric encryption key if the logic with which the system is configured to operate depends on whether an attempt to verify a digital signature using the symmetric encryption key is successful.

[0082] In general, embodiments of the present disclosure may use various protocols to establish encrypted communication sessions, such as an SSL or TLS protocol and extensions thereof, as defined in Request for Comments (RFC) 2246, RFC 2595, RFC 2712, RFC 2817, RFC 2818, RFC 3207, RFC 3268, RFC 3546, RFC 3749, RFC 3943, RFC 4132, RFC 4162, RFC 4217, RFC 4279, RFC 4347, RFC 4366, RFC 4492, RFC 4680, RFC 4681, RFC 4785, RFC 5054, RFC 5077, RFC 5081, RFC 5238, RFC 5246, RFC 5288, RFC 5289, RFC 5746, RFC 5764, RFC 5878, RFC 5932, RFC 6066, RFC 6083, RFC 6091, RFC 6176, RFC 6209, RFC 6347, RFC 6367, RFC 6460, RFC 6655, RFC 7027, and RFC 7366, which are incorporated herein by reference. Other protocols implemented below the application layer of the Open Systems Interconnect (OSI) model may also be used and / or adapted to utilize techniques described herein.It should be noted that the techniques described herein can be adapted to other protocols, such as the Real Time Messaging Protocol (RTMP), the Point-to-Point Tunneling Protocol (PPTP), the Layer 2 Tunneling Protocol, various virtual private network (VPN) protocols, Internet Protocol Security (e.g., as defined in RFC 1825 to 1829, RFC 2401, RFC 2412, RFC 4301, RFC 4303, and RFC 4309), and other protocols, such as secure communication protocols that involve a handshake.

[0083] In the foregoing and following descriptions, various techniques are described. For purposes of explanation, specific configurations and details are set forth in order to provide a thorough understanding of possible ways of implementing the techniques. However, it will also be appreciated that the techniques described below may be practiced in various configurations without the specific details. Furthermore, well-known features may be omitted or simplified to avoid obscuring the described techniques.

[0084] The specification and drawings are accordingly to be regarded in an illustrative rather than restrictive sense. However, it should be understood that various modifications and changes may be made therein without departing from the broader spirit and scope of the invention as set forth in the claims.

[0085] Other variations are within the scope of the present disclosure. Thus, while various modifications and alternative constructions may be made to the disclosed techniques, certain illustrative embodiments thereof are shown in the drawings and have been described in detail above. However, it is to be understood that there is no intention to limit the invention to the precise form or forms disclosed, but on the contrary, the intention is to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the invention as defined in the appended claims.

[0086] The use of the terms "a" and "an" and "the" and similar referents in the context of describing the disclosed embodiments (particularly in the context of the following claims) is intended to be construed to cover both the singular and the plural, unless otherwise stated herein or clearly contradicted by the context. The terms "comprising," "having," "including," and "containing" are to be construed as open-ended terms (i.e., meaning "including, but not limited to") unless otherwise stated. The term "connected" is to be construed as partially or wholly contained, attached, or attached to one another when unmodified and refers to physical connections even when an element is interposed therebetween.The reference to ranges of values herein is intended merely as a quick way of referring individually to each separate value that falls within the range, unless otherwise noted herein, and each separate value is included in the description as if individually recited herein. Use of the term "set" (e.g., "a set of objects") or "subset" is to be construed as a non-empty collection comprising one or more elements, unless otherwise noted or contradicted by the context. Further, the term "subset" of a corresponding set does not necessarily denote an actual subset of the corresponding set; rather, the subset and the corresponding set may be the same, unless otherwise noted or contradicted by the context.

[0087] Linking language, such as expressions of the form 'at least one of A, B, and C' or 'at least one of A, B, and C', are otherwise to be understood in the context in which they are generally used to represent that an object, term, etc., can be either A, B, C, or any non-empty subclause of the set of A, B, and C, unless otherwise specified or unless otherwise clearly evident from the context. For example, in the illustrative example of a set having three elements, the linking expressions 'at least one of A, B, and C' and 'at least one of A, B, and C' refer to one of the following sets: {A}, {B}, {C}, {A, B}, {A, C}, {B, C}, {A, B, C}. Thus, such connecting language is generally not intended to express that certain embodiments require that at least one of A, at least one of B, and at least one of C be present.

[0088] Operations of processes described herein may be performed in any suitable order unless otherwise specified herein or the context otherwise clearly contradicts it. Processes described herein (or variations and / or combinations thereof) may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that together execute one or more processors, by hardware, or combinations thereof. The code may be stored on a computer-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable storage medium may be non-transitory.In some embodiments, the code is stored on a set of one or more non-transitory computer-readable storage media having executable instructions stored thereon that, when executed (i.e., as a result of execution or in the course of execution) by one or more processors of a computer system, cause the computer system to perform acts described herein. The set of non-transitory computer-readable storage media may comprise a plurality of non-transitory computer-readable storage media, and one or more individual non-transitory storage media of the plurality of non-transitory computer-readable storage media may not have all of the code stored thereon, while a total of all of the code is stored on the plurality of non-transitory computer-readable storage media.Furthermore, in some examples, the executable instructions are executed such that different instructions are executed by different processors. As an illustrative example, a non-transitory computer-readable storage medium may store instructions. A main CPU may execute some of the instructions, and a graphics processing unit may execute others of the instructions. In general, different components of a computer system may have separate processors, and different processors may execute different subsets of the instructions.

[0089] Accordingly, in some examples, computer systems are configured to implement one or more services that individually or collectively perform operations of processes described herein. Such computer systems may, for example, be configured with applicable hardware and / or software that enables the operations to be performed. Further, computer systems implementing various embodiments of the present disclosure may, in some examples, be single devices, and in other examples, may be distributed computer systems that include multiple devices that operate differently such that the distributed computer system performs the operations described herein, and such that a single device may not perform all of the operations.

[0090] The use of any examples or exemplary language (e.g., "such as") provided herein is intended merely to better illustrate embodiments of the invention and is not intended to limit the scope of the invention unless otherwise claimed. No language in the specification should be construed to identify any unclaimed element as essential to the implementation of the invention.

[0091] Embodiments of this disclosure are described herein, including the best mode known to the inventors for carrying out the invention. Those skilled in the art, upon reading the foregoing description, may recognize variations of these described embodiments. The inventors expect those skilled in the art to employ such variations as appropriate, and the inventors contemplate that the embodiments of the present disclosure may be implemented otherwise than as specifically described herein. Accordingly, the scope of the present disclosure includes all modifications and equivalents of the subject matter recited in the appended claims as permitted by applicable law.Furthermore, any combination of the elements described above in all possible variations thereof is covered by the scope of the present disclosure unless otherwise stated herein or the context otherwise clearly contradicts it.

[0092] Any references, including publications, patent applications, and patents mentioned herein are hereby incorporated by reference to the same extent as if each reference were individually and specifically indicated to be incorporated by reference and set forth in its entirety herein.

Claims

[1] Computer-implemented method comprising: Receiving a registration request from a customer, the registration request specifying a security role to be granted to a customer resource by an online service, the customer resource comprising a virtual machine; Determine that credentials submitted with the registration request are valid; Authorize the registration request; Generating an activation code for the registration request; Generate a resource ID for the customer resource; Storing sufficient information to identify the activation code and sufficient information to identify the resource ID; Issue the activation code to the customer; Cause an authorization agent to be installed on the customer resource that contains the virtual machine; Receiving an activation request from the authorization agent, the activation request including the resource ID, a pseudo-unique resource ID, and the activation code, the pseudo-unique resource ID generated by the authorization agent as unique for the customer resource; Determining, based at least in part on the pseudo-unique resource ID, that the customer resource is a cloned resource; Acquiring an authorization token that enables the customer resource, including the virtual machine, to use the online service in accordance with the security role from an authorization token service associated with the online service; and Providing the authorization token to the authorization agent. [2] The computer-implemented method of claim 1, further comprising: Determine that a validity period has expired or that the activation code was provided with a previous activation request; and Invalidating the activation code based at least in part on determining that the validity period has expired or that the activation code was provided with a prior activation request. [3] A computer-implemented method according to claim 1, wherein: the activation request includes a public key of a public-private key pair; the activation request is digitally signed using a private key associated with the public-private key pair; and the public key is stored. [4] A system comprising at least one computing device implementing an authorization service, the authorization service: receives a registration request, the registration request specifying a security role to be granted to a customer resource by an online service, the customer resource comprising a virtual machine; determines that credentials submitted with the registration request are valid; authorized the registration request; generates an activation code for the registration request; generates a resource ID for the customer resource; stores sufficient information to identify the activation code and sufficient information to identify the resource ID; issues the activation code to the customer; causes an authorization agent to be installed on the customer resource containing the virtual machine; receives an activation request from the authorization agent, the activation request including the resource ID, a pseudo-unique resource ID, and the activation code, the pseudo-unique resource ID generated by the authorization agent as unique for the customer resource; determines, at least in part, that the customer resource is a cloned resource based on the pseudo-unique resource ID; acquires an authorization token that enables the customer resource, including the virtual machine, to use the online service in accordance with the security role from an authorization token service associated with the online service; and provides the authorization token to the authorization agent. [5] The system of claim 4, wherein the authorization service further comprises: receives a validity period with the registration request; stores the validity period; by comparing the validity period with a current point in time, determines that the activation code has expired; and invalidates the activation code. [6] The system of claim 4, wherein the authorization service further comprises: receives a pseudo-unique resource ID with the activation request, wherein the pseudo-unique resource ID is based at least in part on a processor ID of the customer resource, a device serial number of the customer resource, or a network address of a network interface associated with the customer resource; and determines, at least in part, based on the pseudo-unique resource ID, that the customer resource was not replicated from a parent customer resource. [7] The system of claim 4, wherein the authorization service further comprises: determines that a difference between a timestamp at the activation request and a current time exceeds a timeout value; and determines that the activation request has expired and denies the activation request. [8] System according to claim 4, wherein: the authorization token is acquired from an authorization token service associated with an online service provider; the online service provider provides a variety of online services; and the authorization token can be used with more than one of the multitude of online services. [9] A non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by one or more processors of a customer resource, cause the customer resource to do at least the following: Receiving a registration request, the registration request specifying a security role to be granted to a customer resource by an online service, the customer resource comprising a virtual machine; Determine that credentials submitted with the registration request are valid; Authorize the registration request; Generating an activation code for the registration request; Generate a resource ID for the customer resource; Storing sufficient information to identify the activation code and sufficient information to identify the resource ID; Issue the activation code to the customer; Cause an authorization agent to be installed on the customer resource that contains the virtual machine; Receiving an activation request from the authorization agent, the activation request including the resource ID, a pseudo-unique resource ID, and the activation code, the pseudo-unique resource ID generated by the authorization agent as unique for the customer resource; Determining, based at least in part on the pseudo-unique resource ID, that the customer resource is a cloned resource; Acquiring an authorization token that enables the customer resource, including the virtual machine, to use the online service in accordance with the security role from an authorization token service associated with the online service; and Providing the authorization token to the authorization agent. [10] The non-transitory computer-readable storage medium of claim 9, wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the customer resource to: Submitting a service request to an online service provided by the online service provider, wherein the service request includes the authorization token. [11] The non-transitory computer-readable storage medium of claim 10, wherein the instructions further comprise instructions that, during execution by the one or more processors, cause the customer resource to: Determine that the service request was denied by the online service; Submitting an update request to the authorization service, which causes the authorization service to issue a new authorization token; and Receiving a new authorization token from the authorization service. [12] The non-transitory computer-readable storage medium of claim 9, wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the customer resource to: Receiving a service request from an online service provided by the online service provider; and Fulfill the service requirement. [13] The non-transitory computer-readable storage medium of claim 10, wherein the service request is transmitted to the online service over a computer network via a Transport Layer Security (“TLS”) connection. [14] The non-transitory computer-readable storage medium of claim 10, wherein the instructions further comprise instructions that, when executed by the one or more processors, cause the customer resource to: Generating a sequence number associated with the service request; Transmitting the sequence number with the service request to the authorization service; and Receiving an indication from the authorization service that the customer resource is a cloned resource, the indication based at least in part on the sequence number.

Citation Information

Patent Citations

  • Access authorization system, access control server, and business process execution system

    US20090089866A1

  • Restricted testing access for electronic device

    US8577334B1