Multi-Realm Login
Patent Information
- Application Number
- JP2024525481
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-27
- Filing Date
- 2022-10-28
- Publication Date
- 2025-10-03
AI Technical Summary
Cloud service providers face challenges in securely managing multi-region login systems, where traditional methods limit login attempts to a single entity, leading to potential security vulnerabilities and inconsistencies across different regions.
A framework for multi-region login that allows login credentials to be obtained from multiple regions, combining authentication information across data centers to determine access rights, ensuring secure and consistent access management across different geographic areas.
Enables secure and efficient login across multiple regions by synchronizing authentication data, reducing the risk of unauthorized access and maintaining consistent security protocols.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Application No. 63 / 273,806, entitled "MULTI-REGION LOGIN," filed on October 29, 2021, and U.S. Patent Application No. 18 / 050,453, entitled "MULTI-REGION LOGIN," filed on October 27, 2022, the disclosures of which are incorporated by reference in their entireties herein for all purposes.
[0002] Field The present disclosure relates to a cloud service provider infrastructure that enables login across data centers in different regions. [Background technology]
[0003] background Cloud service providers (CSPs) use one or more networks to provide a variety of services to their customers on demand. CSPs often require customers to sign in to access the network in order to use the services. Customers provide the CSP with login credentials that the CSP uses to determine whether to provide access to the network.
[0004] Login credentials often include a disposable password, such as a time-based one-time password (TOTP). If a customer attempts to log back into the network using a previously used disposable password, the CSP can deny access to the network for security reasons. Additionally, the CSP can choose to retain the number of failed login attempts and prohibit logins to accounts associated with failed login attempts. To achieve these security protections, the entity used to log in must be able to determine which disposable password was previously used to log in and the number of failed login attempts. Traditional CSPs address this issue by storing previously used disposable passwords and the number of failed login attempts in a single entity and directing all login attempts for the customer to that specific entity. Summary of the Invention
[0005] overview The present disclosure generally relates to a framework for multi-domain login to a cloud service provider's network. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media storing programs, codes, or instructions executable by one or more processors, and the like. These exemplary embodiments are mentioned to provide examples to aid in understanding, not to limit or define the disclosure. Additional embodiments are described in the detailed description section and are described in more detail therein. [Means for solving the problem]
[0006] One aspect of the present disclosure relates to a method for facilitating multi-domain login, including receiving a request to login to a network of a cloud service provider (CSP) and identifying login credentials received in the request. The method may further include obtaining authentication information associated with the request from two or more domains of the cloud service provider and determining whether to provide access to the network based at least in part on the login credentials and the authentication information. Additionally, the method may include providing access to the network according to a decision to provide access to the network or denying access to the network according to a decision not to provide access to the network.
[0007] One aspect of the disclosure relates to one or more computer-readable media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including receiving a request to log into a network of a cloud service provider (CSP) and identifying login credentials received in the request. The operations may further include obtaining authentication information associated with the request from two or more domains of the cloud service provider and determining whether to provide access to the network based at least in part on the login credentials and the authentication information. Further, the operations may include providing access to the network in accordance with the decision to provide access to the network or denying access to the network in accordance with the decision not to provide access to the network.
[0008] One aspect of the disclosure relates to a server device, which may include a memory that stores login credentials received in a request, and one or more processors coupled to the memory. The one or more processors may receive a request to log into a network of a cloud service provider (CSP) and identify the login credentials received in the request. The one or more processors may further store the login credentials in the memory, obtain authentication information associated with the request from two or more domains of the cloud service provider, and determine whether to provide access to the network based at least in part on the login credentials and the authentication information. Furthermore, the one or more processors may provide access to the network according to a decision to provide access to the network or deny access to the network according to a decision not to provide access to the network.
[0009] One aspect of the disclosure is directed to a method including a computing device receiving a request to log into a network of a cloud service provider (CSP), and the computing device identifying login credentials (including a passcode) received in the request, which may further include the computing device querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network responsive to the first region being available, and the method may further include the computing device querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or cloned from the first set of passcodes responsive to the second region being available. The method may further include the computing device determining whether a passcode has been previously used based at least in part on one or more responses received in response to the first data center's query or the second data center's query, the computing device determining whether to provide access to the network based at least in part on whether the passcode has been previously used, and the computing device providing access to the network in accordance with the determination to provide access to the network.
[0010] One aspect of the disclosure is directed to one or more non-transitory computer-readable media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform a plurality of operations including receiving a request to log into a network of a cloud service provider (CSP) and identifying login credentials received in the request, the login credentials including a passcode, the plurality of operations including querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network according to the first available region, and the plurality of operations further including querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or replicated from the first set of passcodes according to the second available region. The operations may further include determining whether the passcode has been previously used based at least in part on one or more responses received in response to the query of the first data center or the query to the second data center, determining whether to provide access to the network based at least in part on whether the passcode has been previously used, and providing access to the network in accordance with the decision to provide access to the network.
[0011] One aspect of the disclosure is directed to a server device including a memory that stores login credentials received in a request and one or more processors coupled to the memory, the one or more processors being capable of receiving a request to log into a network of a cloud service provider (CSP), identifying the login credentials received in the request, the login credentials including a passcode, and storing the login credentials in the memory. The one or more processors are further capable of querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network in response to the first region being available, and querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or replicated from the first set of passcodes in response to the second region being available. The one or more processors may further determine whether the passcode has been previously used based at least in part on the one or more responses received in response to the query of the first data center or the query to the second data center, determine whether to provide access to the network based at least in part on whether the passcode has been previously used, and provide access to the network in accordance with the decision to provide access to the network.
[0012] The foregoing, as well as other features and embodiments, will become more apparent with reference to the following specification, claims, and accompanying drawings. [Brief description of the drawings]
[0013] [Figure 1] FIG. 1 illustrates an exemplary system configuration according to at least one embodiment. [Diagram 2]FIG. 1 illustrates another exemplary system configuration according to at least one embodiment. [Diagram 3] FIG. 1 illustrates an exemplary credential combining scenario in accordance with at least one embodiment. [Figure 4] FIG. 1 illustrates another exemplary system configuration according to at least one embodiment. [Diagram 5] FIG. 1 illustrates an exemplary sign-on interface in accordance with at least one embodiment. [Figure 6] FIG. 1 illustrates an example procedure associated with signing in to a cloud service provider (CSP) in accordance with at least one embodiment. [Figure 7] FIG. 7 illustrates a second portion of the example procedure of FIG. 6 according to at least one embodiment. [Figure 8] FIG. 1 is a block diagram illustrating one pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 9] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 10] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 11] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure as a service system, according to at least one embodiment. [Figure 12] FIG. 1 is a block diagram illustrating an example computer system in accordance with at least one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] Detailed Description Various embodiments are described below. For purposes of explanation, specific configurations and details are set forth to provide a thorough understanding of the embodiments. However, it will be apparent to one skilled in the art that the embodiments may be practiced without the specific details. Furthermore, well-known features may be omitted or simplified so as not to obscure the embodiments being described.
[0015] A cloud service provider (CSP) may offer multiple cloud services to subscribing customers. These services may be offered in various models, such as Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) models. A CSP may offer multiple cloud services over one or more networks. Each network may include computers and software capable of offering the services.
[0016] In a cloud environment, an identity management system is typically provided by a CSP to control user access to resources provided or used by the cloud service. Typical services or functions provided by an identity management system include, but are not limited to, single sign-on capabilities for users, authentication and authorization services, and other identity-based services.
[0017] The resources protected by the identity management system can be of various types, such as computing instances, block storage volumes, virtual cloud networks (VCNs), subnets, route tables, various callable APIs, internal or traditional applications, etc. These resources include resources stored in the cloud and / or customer on-premise resources. Typically, each resource is identified by a unique identifier (e.g., ID) that is assigned to the resource when the resource is created.
[0018] Described herein are techniques that allow customers and / or clients (collectively referred to in this disclosure as customers) to log into a replication region and / or a portion of a CSP. In particular, a CSP may be organized into one or more regions (e.g., datacenters within a particular geographic region), with each region being defined by datacenters within a different geographic area served by the CSP. For example, a first region may correspond to a first datacenter located in a first geographic area served by the CSP, and a second region may correspond to a second datacenter located in a second geographic area served by the CSP. In this case, the second geographic area is different from the first geographic area. Each region may be comprised of one or more datacenters. Throughout this disclosure, an operation may be described as being performed by a region, but it should be understood that one or more datacenters in the region may perform the operation. For example, when a first region is described as performing an operation, it should be understood that one or more services provided by one or more datacenters in the first region perform the operation.
[0019] In some embodiments, the CSP may provide subscription services for the CSP's territories. For example, the CSP may allow customers to subscribe to one or more of the CSP's territories. The CSP may enable customers who subscribe to a territories to use the services offered in that territories and may prevent customers / users who do not subscribe to a territories from using the services offered in that territories. The CSP may maintain an account for each customer, and the customer's account may indicate the territories to which the customer subscribes. The account may further include other information about the customer associated with the account, as further described throughout this disclosure.
[0020] The regions to which a customer subscribes may be assigned different roles for the customer. For example, a region may be assigned as a home region or a subscription region. There may be only one home region assigned to a customer. In a region assigned as a home region, the customer may perform write and read operations on data stored in the region. A subscriber may be assigned multiple subscription regions. A region assigned as a subscription region prevents write operations on at least a portion of the data stored by the region, thereby allowing only read operations to be performed on the portion of the data. Subscription regions may be assigned a rank, such as a first subscription region, a second subscription region, a third subscription region, etc. Depending on the ranking of the subscription region, the behavior of the subscription region may differ. For example, a first subscription region may store customer authentication information that may be used to authenticate the customer, as described further throughout this disclosure. Roles may be assigned by the customer and / or the CSP. For example, the CSP may assign roles based on the order in which customers subscribe to the regions in some cases. In some of these cases, the first region that a customer joins may be assigned as the home region, the second region that the customer joins may be assigned as the first subscribing region, etc. In some cases, a customer may assign the home region, subscribing regions, and / or the rank of the subscribing regions.
[0021] One or more domains may be stored in a data center, and a domain may include a container that can store information and use resources of the data center. Each domain may be assigned a domain home area, which may be referred to as a domain home area. Typically, a customer is directed to a corresponding area (which may be referred to as a tenancy home area) to log in to a CSP. The tenancy home area may be an area where infrastructure identity and access management (IAM) related information is allowed to be updated for the customer. However, during operation, one or more areas of a CSP may become unavailable (e.g., the area may go down or the services in the area may become inaccessible). In a traditional approach, if a customer attempts to log in and the tenancy home area corresponding to the customer is unavailable, the tenancy home area cannot be accessed and the customer is left in a broken state.
[0022] The techniques described herein may include having one or more replication domains in different regions. For example, a tenant's Identity Cloud Services (IDCS) stripe may be located in a home region associated with the customer. The IDCS stripe may be replicated to one or more other regions in addition to the home region. The IDCS stripe may be replicated within a region via synchronized backchannel communication. A login selection may provide the customer with one or more domains available for login that the customer can select. The list of available domains may be obtained from the home region and / or the first replication region corresponding to the customer. The available domains displayed may be in the region available at the time of login. Upon selecting a domain from the list of available domains, the CSP may direct the customer to the IDCS stripe of the region corresponding to the selected domain for the customer to log in. The IDCS stripe used for login may read and / or write some data to and from one or more other regions during authentication to reconcile the IDCS stripes between regions. In some cases, the regions from which data is read and / or written may include the domain home region and the first replication region corresponding to the customer.
[0023] In some cases, the customer is directed to or can select a domain for login in the realm that is down. In these cases, the CSP can update the information so that the customer is not directed to or can not select the domain for login until it is determined that the realm is working properly again. The CSP may also provide other available domains that the customer can use to log in. The customer can then select one of the other available domains to log in with.
[0024] In some cases, the domain home region and / or the first replicated region may become unavailable while the customer is logged in to another region. Because the region into which the customer logs in cannot write to the domain home region and / or the first replicated region, the region may coordinate with the domain home region and / or the first replicated region to merge conflicts between the regions. For example, the region may coordinate with the domain home region and / or the first replicated region to update storage information associated with the login to the latest updated storage information.
[0025] 1 illustrates an exemplary system configuration 100 according to at least one embodiment. System configuration 100 illustrates an example of a system with an IDCS stripe, or portions thereof, that is replicated across multiple domains of a CSP. For example, the system may have credentials that are replicated across multiple domains. The replicated credentials reside within the IDCS stripe, and the credentials may be used to determine whether one or more users are customers that are authorized to access the CSP.
[0026] The system configuration 100 may include a CSP 102. The CSP 102 may include a network of computer hardware implementing software that can provide services to customers. The computer hardware and / or software of the CSP 102 may be referred to as resources, which customers may use or request to perform operations. The CSP 102 may include an IAM, which may control user access to the CSP 102.
[0027] The CSPs 102 may be organized into one or more regions, with each region forming a portion of the network of the CSPs 102. For example, the illustrated CSP 102 may include a login region 104, a first region 106, and a second region 108. Each region may include a portion of the computer hardware of the CSPs 102. For example, the login region 104 may include a first portion of the computer hardware of the CSPs 102, the first region 106 may include a second portion of the computer hardware of the CSPs 102, and the second region 108 may include a third portion of the computer hardware of the CSPs 102. In some embodiments, each region corresponds to a particular geographic area, and the computer hardware within a region may be located within the corresponding geographic area. The computer hardware within a region may correspond to one or more routers and / or switches that connect the region to one or more other regions. For example, the computer hardware in the login realm 104, in the illustrated embodiment, may correspond to one or more routers and / or switches connecting the login realm 104 to one or more routers and / or switches corresponding to the first realm 106 and one or more routers and / or switches corresponding to the second realm 108. The routers and / or switches corresponding to the realm serve as access points to the realm such that electronic communication traffic to and from the realm passes through at least one of the routers and / or switches. The corresponding routers and / or switches may, in some embodiments, further connect the realm to one or more other external devices, such as the Internet and / or user devices associated with the user.
[0028] In some embodiments, one or more regions of the CSP 102 may be connected to one or more other regions within the CSP 102 by one or more backchannels. For example, in the illustrated embodiment, the login region 104 is connected to the first region 106 and the second region 108 by a backchannel 110. The backchannel may connect to routers and / or switches of the region, which may serve as an access point to the region for the backchannel. The routers and / or switches to which the backchannel is connected may be separate from the routers and / or switches that connect the region to external devices. The backchannel may provide a connection between two or more regions within the CSP 102. For example, the backchannel may provide a direct connection between two regions within the CSP 102 or may provide a shared connection between two or more regions within the CSP 102. For example, the backchannel 110 of the illustrated embodiment may provide a shared connection between the login region 104, the first region 106, and the second region 108. In some embodiments, the backchannel 110 may not be accessible to elements outside of the CSP 102, such as user devices outside of the CSP 102. The backchannel allows synchronous or asynchronous messages to be sent between the domains, which allows data to be exchanged between the domains.
[0029] The system configuration 100 may include one or more user devices connectable to the CSP 102. For example, in the illustrated embodiment, the system configuration 100 includes a user device 112. The user device is external to the CSP 102 and may be connected to the CSP 102 by one or more wired or wireless connections, such as a connection via the Internet. For clarity, the description herein refers to the user device 112, but it should be understood that one or more operations performed by and / or in relation to the user device 112 may be performed by or in relation to one or more other user devices.
[0030] The system configuration 100 may show elements related to logging in the user device 112. In particular, the system configuration 100 may show elements exchanged between the user device 112 and elements of the CSP 102 so that the user device 112 can use the services of the CSP 102, and these elements may be used for the user device 112 to log in to the CSP 102.
[0031] A user may request access to a CSP 102 using a user device 112. For example, the user may enter an Internet Protocol (IP) address corresponding to the CSP 102 (or a portion thereof) into a browser on the user device 112, and the CSP 102 (or a portion thereof) may instruct the user device 112 to display a user interface for accessing the CSP 102. The user interface may include an input field for login credentials 114 that are used to determine whether the user is authorized to access the CSP 102. In some embodiments, the login credentials 114 may include a passcode. In some embodiments, the passcode may be a one-time password. In some embodiments, the CSP 102 may request, as part of the login credentials 114, a display of characteristic information of the user device 112 and / or results of previous login attempts.
[0032] The user device 112 can obtain login credentials 114 for login of a user using the user device 112. For example, the user device 112 can receive the login credentials 114 from a user using the user device 112 and / or obtain information indicative of characteristics of the user device 112 (e.g., an identifier, a key, and / or other value associated with the user device 112). The login credentials 114 can include input from the user, such as a passcode and / or a one-time password. In some embodiments, the one-time password can be a time-based one-time password (TOTP). The one-time password can be generated by a program associated with the CSP 102. In particular, the program can generate the one-time password and provide the one-time password to the user and the CSP 102. The program can provide the one-time password to the user via an email account associated with the user, a phone number associated with the user (e.g., a text message and / or a voice message), software running on the user device 112 that can receive the one-time password from a program associated with the CSP 102, and / or other methods known in the art for providing the one-time password to a user. During the login process, the CSP 102 may request input of a one-time password from a user of the user device 112, for example, in a displayed login interface. The user may enter the one-time password into the user device 112 along with other user authentication information (e.g., passwords associated with the user). During the login process, the user device 112 provides login credentials 114 to the CSP 102, which the CSP 102 uses to determine whether the user can log in to the CSP 102.
[0033] In some embodiments, the login credentials 114 received from the user device 112 may further include information related to previous login attempts and / or previous logins initiated by the user device 112. For example, the user device 112 may maintain a count of the number of consecutive times that a user of the user device 112 has attempted to log into the CSP 102 unsuccessfully. The user device 112 may include in the login credentials 114 an indication of the number of consecutive times that the user has unsuccessfully attempted to log into the CSP 102. In other embodiments, the CSP 102 may maintain a count of the number of consecutive unsuccessful login attempts and / or access to a particular customer's account by the user device 112. The CSP 102 may determine whether the number of consecutive unsuccessful login attempts exceeds a threshold number of attempts and may determine not to provide the user with access to the CSP 102 based on the number of consecutive unsuccessful login attempts exceeding the threshold number of attempts.
[0034] In the illustrated embodiment, the user device 112 may be directed to the login area 104 during a login process to the CSP 102. The user device 112 may be directed to the login area 104 based on the user device 112 being geographically closest to the login area 104 compared to other areas of the CSP 102, the login area 104 being the area of the CSP 102 that is geographically closest to the available user device 112, the IP address used by the user device 112 as part of the login process that corresponds to the login area 104, the user device 112 indicating a selection of the login area 104 to be used for the login process, or a combination thereof. As a result of being directed to the login area 104, the user device 112 provides the login credentials 114 to the login area 104 as part of the login process.
[0035] The login area 104 can use the login credentials 114 provided by the user device 112 to determine whether the user of the user device 112 is authorized to access the CSP 102. For example, the login area 104 can use authentication information in combination with the login credentials 114 to determine whether the user is authorized to access the CSP 102. The authentication information for determining whether the user is authorized to access the CSP 102 can be stored in two or more areas of the CSP 102. However, there may be areas in the CSP 102 where authentication information corresponding to the user is not stored, in which case the user may be able to log in to the CSP 102 even in areas where authentication information corresponding to the user is not stored.
[0036] In some embodiments, the credentials corresponding to the user may be stored in a home domain corresponding to the user and a first subscription domain corresponding to the user. In the illustrated embodiment, the first domain 106 stores a first credential 116 corresponding to the user, and the second domain 108 stores a second credential 118 corresponding to the user. The first credential 116 may be or be part of an IDCS stripe maintained in the first domain 106, and the second credential 118 may be or be part of an IDCS stripe replicated in the second domain 108. In some embodiments, the first domain 106 may be the home domain of the user, and the second domain 108 may be the first subscription domain. The user, or an entity associated with the user, may be able to define the home domain and / or the first subscription domain corresponding to the user. In the illustrated embodiment, the login domain 104 does not store credentials corresponding to the user.
[0037] The authentication information may include information for determining whether the user is authorized to access the CSP 102 and / or information related to the user's previous logins. For example, the authentication information may include one or more passcodes corresponding to the user, an indication of one or more devices used by the user to log into the CSP 102, a single-use password previously used by the user to access the CSP 102, a single-use password still valid to access the CSP 102, or a combination thereof. The authentication information may be updated based on the user logging into the CSP 102. For example, the CSP 102 may update the authentication information using the single-use password used to access the CSP 102, thereby updating the single-use password previously used by the user to access the CSP 102 to include an additional single-use password used to access the CSP 102. In some embodiments, updating the previously used single-use password may include transmitting a copy of the single-use password used for access from the domain used for login to the other domain via back-channel communication using the back channel 110. In some embodiments, the back-channel communication is a synchronous back-channel communication.
[0038] In some cases, the copies of the authentication information stored in the regions may be different. For example, the first authentication information 116 stored in the first region 106 may be different from the second authentication information 118 stored in the second region 108. There may be delays in replicating and / or updating the authentication information between the regions, and the authentication data stored in the different regions may be different. For example, the second authentication information 118 in the second region 108 may be replicated and / or updated at a time that is delayed after the first authentication information 116 in the first region 106. If a region attempts to retrieve the first authentication information 116 and the second authentication information 118 between the time the first authentication information 116 is updated and / or replicated and the time the second authentication information 118 is updated and / or replicated, the first authentication information 116 that is retrieved may be different from the second authentication information 118. Furthermore, when updating and / or replicating authentication information, if one or more areas for which authentication information is to be updated and / or replicated are unavailable, the authentication information for those one or more areas may differ from other areas.
[0039] The login realm 104 can obtain authentication information corresponding to the user to determine whether to provide the user with access to the CSP 102. For example, the login realm 104 can obtain authentication information from one or more realms to determine whether to provide access to the user. In some embodiments, the login realm 104 can determine from which realm to obtain authentication information based on the login credentials 114 and / or a request for access to the CSP 102 received from the user device 112. For example, the login credentials 114 and / or the request can indicate a home realm and / or a first joining realm corresponding to the user. The login realm 104 can query the home realm and / or the first joining realm for a realm from which to obtain authentication information. For example, the login credentials 114 and / or the request can indicate that the first realm 106 is the home realm and / or the second realm 108 is the first joining realm in the illustrated embodiment. The login area 104 can query the first area 106 and / or the second area 108 based on the indication to determine from which area to obtain the authentication information. In some embodiments, the query to the first area 106 and / or the second area 108 can be made by a backchannel call, such as a call made on the backchannel 110. The first area 106 and / or the second area 108 can indicate the area from which to obtain the authentication information using the backchannel 110. In other embodiments, the login area 104 can store an indication of the area from which to obtain the user's authentication information, and the login area 104 can determine from which area to obtain the authentication information based on the stored indication.
[0040] The login realm 104 may make a backchannel call to the realm to obtain authentication information that is used to determine whether a user of the user device 112 is authorized to access the CSP 102. In the illustrated embodiment, the login realm 104 may have determined to obtain authentication information from the first realm 106 and the second realm 108. The login realm 104 may send a backchannel call to the first realm 106 and the second realm 108 over the backchannel 110. The backchannel call may request that the first realm 106 provide the first authentication information 116 and that the second realm 108 provide the second authentication information 118 to the login realm 104. In response to the backchannel call, the first realm 106 may provide the first authentication information 116 to the login realm 104 and the second realm 108 may provide the second authentication information 118 to the login realm 104. The first area 106 and the second area 108 can provide information to the login area 104 via a back channel 110 .
[0041] The login area 104 may receive the first credential 116 from the first area 106 and the second credential 118 from the second area 108. The login area 104 may combine the first credential 116 and the second credential 118, or portions thereof, to generate a credential for determining whether to provide the user access to the CSP 102. For example, the login area 104 may compare the first credential 116 and the second credential 118 to identify overlapping information in the first credential 116 and the second credential 118. The login area 104 may generate a combined credential that includes the first credential 116 and the second credential 118 without overlapping information. The combined credential may be used as a credential for determining whether the user is allowed access to the CSP 102.
[0042] The login area 104 can receive the login credential 114 from the user device 112 and generate authentication information based on the first authentication information 116 from the first area 106 and the second authentication information 118 from the second area 108. The login area 104 can determine whether to provide access to the user based on the login credential 114 and the authentication information. The login area 104 can compare a passcode from the authentication information corresponding to the user with the passcode received in the login credential 114. Additionally, the login area 104 can compare a one-time password received in the login credential 114 with a previously used one-time password from the authentication information and / or a still valid one-time password from the authentication information. In some embodiments, the login area 104 can further determine whether the user device 112 is a known user device used by the user based on the login credential 114 and / or the authentication information and can request further verification if the user device 112 is not a known user device used by the user.
[0043] The login area 104 can determine to provide access to the CSP 102 based on: the passcode provided in the login credentials 114 matches the passcode from the authentication information, the one-time password from the login credentials 114 is not included among the previously used one-time passwords from the authentication information, the one-time password from the login credentials 114 matches one of the still valid one-time passwords from the authentication information, the user device 112 is a known user device used by the user, further verification is received based on the user device 112 not being a known user device used by the user, or a combination thereof. The login area 104 can determine to deny access to the CSP 102 based on: the passcode provided in the login credentials 114 does not match the passcode from the authentication information, the one-time password of the login credentials 114 is included among the previously used one-time passwords of the authentication information, the one-time password of the login credentials 114 does not match one of the still valid one-time passwords of the authentication information, or a combination thereof.
[0044] As described in connection with system configuration 100, the credentials may be replicated across multiple realms and retrievable via a backchannel, allowing a user to log into CSP 102 from multiple realms within CSP 102. For example, credentials obtained from multiple realms may allow a user to log into CSP 102 while mitigating the risk of a user logging into multiple realms using the same disposable password. Thus, this approach may have the advantage of ease of use of being able to log into any realm within CSP 102 while still providing security.
[0045] 2 illustrates another exemplary system configuration 200 in accordance with at least one embodiment. System configuration 200 illustrates an example of a system with an IDCS stripe, or portions thereof, that is replicated across multiple domains of a CSP. System configuration 200 as illustrated illustrates an example of a user logging in via a domain with a replicated IDCS stripe.
[0046] The system configuration 200 may include a CSP 202. The CSP 202 may include one or more functions of the CSP 102 (FIG. 1). For example, the CSP 202 may include one or more regions, such as a first region 204 and a second region 206. The first region 204 may include one or more of the functions of the first region 106 (FIG. 1), and the second region 206 may include one or more of the functions of the second region 108 (FIG. 1). The first region 204 may store a first authentication information 208, which may include one or more of the functions of the first authentication information 116 (FIG. 1). The second region 206 may store a second authentication information 210, which may include one or more of the functions of the second authentication information 118 (FIG. 1).
[0047] The system configuration 200 may further include a user device 212. The user device 212 may include one or more features of the user device 112 (FIG. 1). A user may attempt to access a CSP 202 using the user device 212. In the illustrated embodiment, the user device 212 may be directed to a first region 204 to log into the CSP 202. The user device 212 may be directed to the first region 204 based on the user device 212 being geographically closest to the first region 204 of the regions of the CSP 202, the user requesting access to the CSP 202 using an IP address on the user device 212 corresponding to the first region 204, or a combination thereof. The CSP 202 may instruct the user device 212, via the first region 204, to display an interface for accessing the CSP 202. The user interface may include an input field for login credentials 214 used to determine whether the user is authorized to access the CSP 202. In some embodiments, the CSP 202 may further request an indication of user device 212 characteristic information and / or results of previous login attempts as part of the login credentials 214. The login credentials 214 may include one or more features of the login credentials 114 (FIG. 1).
[0048] The first domain 204 can receive user login credentials 214 from the user device 212. The first domain 204 can use the login credentials 214 provided by the user device 212 to determine whether the user of the user device 212 is permitted to access the CSP 202. In particular, the first domain 204 can use the login credentials 214 and the authentication information to determine whether the user is authorized to access the CSP 202.
[0049] The first domain 204 can obtain the first authentication information 208 of the first domain 204 and the second authentication information 210 from the second domain 206. The first domain 204 can make a backchannel call to the second domain 206 via the backchannel 216 to obtain the second authentication information 210 from the second domain 206. The backchannel 216 can include one or more functions of the backchannel 110 (FIG. 1). The second domain 206 can provide the second authentication information 210 to the first domain 204 via the backchannel 216. For example, the second domain 206 can provide the second authentication information 210 in response to a backchannel call from the first domain 204.
[0050] The first domain 204 can combine the first authentication information 208 and the second authentication information 210 to generate an authentication information used to determine whether a user is authorized to access the CSP 202. The combination of the first authentication information 208 and the second authentication information 210 can be performed similarly to the combination of the first authentication information 116 and the second authentication information 118. For example, the first domain 204 can identify duplicate information in the first authentication information 208 and the second authentication information 210. The first domain 204 can generate a combined authentication information including the first authentication information 208 and the second authentication information 210 without the duplicate information, and the combined authentication information can be used as an authentication information to determine whether a user is authorized to access the CSP 202.
[0051] The first area 204 may determine whether to provide access to the CSP 202 based on the login credentials 214 and the authentication information. The determination by the first area 204 of whether to provide access to the CSP 202 may include one or more of the functions of the determination of whether to provide access to the CSP 102 performed by the login area 104 (FIG. 1). For example, the first area 204 may compare a passcode corresponding to the user from the authentication information with a passcode received in the login credentials 214. Furthermore, the first area 204 may compare a one-time password received in the login credentials 214 with a previously used one-time password from the authentication information and / or a still valid one-time password from the authentication information. In some embodiments, the first area 204 may further determine whether the user device 212 is a known user device used by the user based on the login credentials 214 and / or the authentication information, and may request further verification if the user device 212 is not a known user device used by the user.
[0052] The first region 204 may determine to provide access to the CSP 202 based on the passcode provided in the login credential 214 matching a passcode from the authentication information, the one-time password from the login credential 214 not being included among the previously used one-time passwords from the authentication information, the one-time password from the login credential 214 matching one of the still valid one-time passwords from the authentication information, the user device 212 being a known user device used by the user, further other verification being received based on the user device 212 not being a known user device used by the user, or a combination thereof. The first region 204 may determine to deny access to the CSP 202 based on the passcode provided in the login credential 214 not matching a passcode from the authentication information, the one-time password from the login credential 214 being included among the previously used one-time passwords from the authentication information, the one-time password from the login credential 214 not matching one of the still valid one-time passwords from the authentication information, or a combination thereof.
[0053] 3 illustrates an example credential binding scenario 300 according to at least one embodiment. In particular, binding scenario 300 illustrates an example of a binding of a first credential 302 and a second credential 304 according to some embodiments. The binding illustrated in binding scenario 300 may be an example of a credential binding that may be performed by login domain 104 (FIG. 1) and / or first domain 204 (FIG. 2).
[0054] The binding scenario 300 illustrates an exemplary first credential 302 and an exemplary second credential 304. For the sake of brevity and clarity, the information included in the first credential 302 and the second credential 304 is limited to a previously used one-time password. It should be understood that the first credential 302 and the second credential 304 may include additional information in embodiments, and may be bound in accordance with the binding approach described in connection with the binding scenario 300. For example, the first credential 302 and the second credential 304 may include, in embodiments, one or more passcodes corresponding to the user, an indication of one or more devices known to be associated with the user, one or more previously used one-time passwords associated with the user, one or more still-valid one-time passwords, or a combination thereof.
[0055] The first credential 302 may be stored in a first area, such as the first area 106 (FIG. 1) and / or the first area 204 (FIG. 2). The second credential 304 may be stored in a second area, such as the second area 108 (FIG. 1) and / or the second area 206 (FIG. 2). For example, the first credential 302 may be stored in a memory in the first area, and the second credential 304 may be stored in a memory in the second area. In some embodiments, the memory includes one or more caches, and the information stored in the caches may be deleted and / or purged after a period of time since it was stored. The first credential 302 and the second credential 304 may include a replicated IDCS stripe or a portion thereof. For example, the first credential 302 and the second credential 304 may be a copy of an IDCS stripe (or a portion thereof) that includes information related to the user.
[0056] In the illustrated embodiment, the first credential 302 may include a first set of previously used one-time passwords 306 and the second credential 304 may include a second set of previously used one-time passwords 308. The first set of previously used one-time passwords 306 and the second set of previously used one-time passwords 308 may include one-time passwords that a user previously used to sign in to a CSP (e.g., CSP 102 (FIG. 1) and / or CSP 202 (FIG. 2)). The first set of one-time passwords 306 and the second set of one-time passwords 308 may be copies of a set of previously used one-time passwords included in an IDCS stripe that is replicated to areas corresponding to the first credential 302 and the second credential 304.
[0057] In the illustrated embodiment, the first set of one-time passwords 306 and the second set of one-time passwords 308 include different one-time passwords. The difference in the one-time passwords between the first set of one-time passwords 306 and the second set of one-time passwords 308 may be due to different times when the first credential 302 and the second credential 304 were updated. For example, the update of either the first credential 302 or the second credential 304 may have been delayed compared to the other due to a delay in the CSP updating the corresponding field and / or the unavailability of one of the fields at the time of the update. In the illustrated embodiment, the update of the second credential 304 may have been delayed, resulting in the second set of one-time passwords 308 having one less one-time password than the first set of one-time passwords 306 (shown in the illustrated embodiment as password "241972").
[0058] A realm of the CSP, which determines whether to provide access to a user, may obtain first authentication information 302 and second authentication information 304. The realm may combine first authentication information 302 and second authentication information 304 to generate combined authentication information 310. The realm may combine first authentication information 302 and second authentication information 304 to generate combined authentication information 310.
[0059] As part of the merging, the region may identify duplicate information and / or differences in information in the first credential 302 and the second credential 304. If the region identifies duplicate information in the first credential 302 and the second credential 304, the region may remove the duplicate information when generating the combined credential 310. If the region identifies differences in information, the region may determine whether to include or exclude the different information to generate the combined credential 310. Whether the different information is included or excluded may be determined based on the type of information.
[0060] In the illustrated embodiment, the combined credential 310 is shown with a copy of a first set of previously used one-time passwords 312 and a copy of a second set of previously used one-time passwords 314. The field may identify duplicate one-time passwords within the copy of the first set of previously used one-time passwords 312 and the copy of the second set of previously used one-time passwords 314. In the illustrated example, the field may determine that the values "561232", "243852", "792163", and "555292" are duplicated within the copy of the first set of previously used one-time passwords 312 and the copy of the second set of previously used one-time passwords 314. The field may remove the duplicate one-time passwords from one of the copies of the previously used one-time passwords to generate the combined credential 310. In the depicted example, the realm has determined to remove duplicate one-time passwords from the copy of the second set of previously used one-time passwords 314 to generate the combined credential 310, as indicated by the duplicate one-time passwords being crossed out in the copy of the second set of previously used one-time passwords 314. In some cases, the realm may determine whether to allow the user access to the CSP using the remaining previously used one-time passwords in the combined credential 310.
[0061] In some embodiments, the realm may additionally or alternatively define differences between the first credential 302 and the second credential 304. In the illustrated embodiment, the realm may identify differences between the copy of the first set of previously used one-time passwords 312 and the copy of the second set of previously used one-time passwords 314. In particular, the realm may determine that a value of "241972" is present in the copy of the first set of previously used one-time passwords 312 but is not included in the copy of the second set of previously used one-time passwords 314. The realm may determine to remove or maintain the difference based on the different types of information. For example, the realm may determine to maintain the value "241972" based on the difference in the type of information of the previously used one-time passwords. For other types of information, the difference may be removed or maintained. Thus, the combined credential 310 includes the value "241972".
[0062] Once the binding credential 310 is generated, the binding credential 310 may be used to determine whether or not to allow the user to access the CSP. In particular, the realm may use the binding credential 310 as a credential for determining whether or not the user is allowed to access the CSP. For example, the realm may compare the binding credential 310 with the login credential received from the user (e.g., login credential 114 (FIG. 1) and / or login credential 214 (FIG. 2)) to determine whether or not to allow the user to access the CSP. In the illustrated embodiment, the realm may compare a one-time password provided by the user in the login credential with the first set 312 of previously used one-time passwords included in the binding credential 310. If the realm determines that the one-time password provided by the user matches any of the one-time passwords in the first set 312 of previously used one-time passwords, the realm may determine not to allow the user to access the CSP based at least in part on the one-time password provided by the user.
[0063] 4 illustrates another exemplary system configuration 400 according to at least one embodiment. System configuration 400 illustrates an example of a system with an IDCS stripe, or portions thereof, that is replicated to multiple regions of a CSP. The illustrated system configuration 400 illustrates an example of a user logging in via a login region. System configuration 400 may have one or more regions that are unavailable.
[0064] The system configuration 400 may include a CSP 402. The CSP 402 may include one or more functions of the CSP 102 (FIG. 1) and / or the CSP 202 (FIG. 2). The CSP 402 may include a login area 404. The login area 404 may include one or more functions of the login area 104 (FIG. 1). The login area 104 may be used to log in to the CSP 402 and may determine whether a user is authorized to log in to the CSP 402. The CSP 402 may further include a first area 406 and a second area 408. The first area 406 may include one or more of the functions of the first area 106 (FIG. 1) and / or the first area 204 (FIG. 2). The second area 408 may include one or more of the functions of the second area 108 (FIG. 1) and / or the second area 206 (FIG. 2).
[0065] The login area 404 may be coupled to the first area 406 and the second area 408. For example, the login area 404 may be coupled to the first area 406 and the second area 408 via a back channel 410. The back channel 410 may include one or more functions of the back channel 110 (FIG. 1) and / or the back channel 216 (FIG. 2). The back channel 410 may connect the login area 404, the first area 406, and / or the second area 408. The back channel 410 may provide a direct connection between the areas or a shared connection between the areas. For example, the back channel 410 may provide a direct connection between the login area 404 and the first area 406, another direct connection between the login area 404 and the second area 408, and / or another direct connection between the first area 406 and the second area 408 in some embodiments. In other embodiments, the back channel 410 may provide a shared connection between the login domain 404 , the first domain 406 , and the second domain 408 .
[0066] The system configuration 400 may include one or more user devices that connect to the CSP 402. For example, in the illustrated embodiment, the system configuration 400 includes a user device 412. The user device 412 may include one or more features of the user device 112 (FIG. 1) and / or the user device 212 (FIG. 2). A user may request access to the CSP 402 using the user device 412. For example, the user may request access to the CSP 402 by entering an IP address corresponding to the CSP 402 (or a portion thereof) into a browser of the user device 412. The CSP 402 (or a portion thereof) may instruct the user device 412 to display a user interface for accessing the CSP 402. The user interface may include an input field for login credentials 414 that are used to determine whether the user is authorized to access the CSP 402. In some embodiments, the CSP 402 may request a display of characteristic information of the user device 412 and / or results of previous login attempts as part of the login credentials 414.
[0067] The user device 412 can obtain login credentials 414 for login of a user using the user device 412. For example, the user device 412 can receive the login credentials 414 from a user using the user device 412 and / or obtain information indicative of characteristics of the user device 412 (e.g., an identifier, a key, and / or other value associated with the user device 412). The login credentials 414 can include input from the user, such as a passcode and / or a one-time password. In some embodiments, the one-time password can be a TOTP. The one-time password can be generated by a program associated with the CSP 402. In particular, the program can generate a one-time password and provide the one-time password to the user and to the CSP 402. The program can provide the one-time password to the user via an email account associated with the user, a phone number associated with the user (e.g., via a text message and / or a voice message), software running on the user device 412 that can receive the one-time password from a program associated with the CSP 402, and / or other methods known in the art for providing a one-time password to a user. During the login process, the CSP 402 may request input of a one-time password from a user of the user device 412, for example, in a displayed login interface. The user may enter the one-time password along with other user authentication information (e.g., passwords associated with the user) into the user device 412, which may generate login credentials that include the one-time password and the other user authentication information. During the login process, the user device 412 provides the login credentials 414 to the CSP 402, which the CSP 402 may use to determine whether the user is allowed to log in to the CSP 402.
[0068] In some embodiments, the login credentials 414 received from the user device 412 may further include information related to previous login attempts and / or previous logins initiated by the user device 412. For example, the user device 412 may maintain a count of the number of consecutive times that a user of the user device 412 has attempted and failed to log into the CSP 402. The user device 412 may include in the login credentials 414 an indication of the number of consecutive times that the user has failed to log into the CSP 402. In other embodiments, the CSP 402 may maintain a count of the number of consecutive unsuccessful login attempts and / or access to a particular customer's account by the user device 412. The CSP 402 may determine whether the number of consecutive unsuccessful login attempts exceeds a threshold number of attempts and may decide not to provide the user with access to the CSP 402 based on the number of consecutive unsuccessful login attempts exceeding the threshold number of attempts.
[0069] In the illustrated embodiment, the user device 412 may be directed to the login area 404 during a login process to the CSP 402. The user device 412 may be directed to the login area 404 based on the user device 412 being geographically closest to the login area 404 compared to other areas of the CSP 402, the login area 404 being the area of the CSP 402 that is geographically closest to the available user device 412, the IP address used by the user device 412 as part of the login process corresponding to the login area 404, the user device 412 indicating a selection of the login area 404 to be used for the login process, or a combination thereof. As a result of being directed to the login area 404, the user device 412 provides the login credentials 414 to the login area 404 as part of the login process.
[0070] The login area 404 may use the login credentials 414 provided by the user device 412 to determine whether the user of the user device 412 is authorized to access the CSP 402. For example, the login area 404 may use authentication information in combination with the login credentials 414 to determine whether the user is authorized to access the CSP 402. The authentication information for determining whether the user is authorized to access the CSP 402 may be stored in two or more areas of the CSP 402. However, there may be areas in the CSP 402 where authentication information corresponding to the user is not stored, in which case the user may be able to log in to the CSP 402 even in areas where authentication information corresponding to the user is not stored.
[0071] In some embodiments, the credentials corresponding to the user may be stored in a home domain corresponding to the user and a first subscription domain corresponding to the user. In the illustrated embodiment, the first domain 406 may store a first credential 416 corresponding to the user, and the second domain 408 may store a second credential 418 corresponding to the user. The first credential 416 may be or be part of an IDCS stripe maintained in the first domain 406, and the second credential 418 may be or be part of an IDCS stripe replicated in the second domain 408. In some embodiments, the first domain 406 may be the home domain of the user, and the second domain 408 may be the first subscription domain. The user, or an entity associated with the user, may define the home domain and / or the first subscription domain corresponding to the user. In the illustrated embodiment, the login domain 404 does not store credentials corresponding to the user.
[0072] The authentication information may include information for determining whether the user is authorized to access the CSP 402 and / or information related to the user's previous logins. For example, the authentication information may include a passcode corresponding to the user, an indication of one or more devices used by the user to log into the CSP 402, a one-time password previously used by the user to access the CSP 402, a one-time password still valid to access the CSP 402, or a combination thereof. The authentication information may be updated based on a user login to the CSP 402. For example, the CSP 402 may update the authentication information with the one-time password used to access the CSP 402, thereby updating the one-time password previously used by the user to access the CSP 402 to include an additional one-time password used to access the CSP 402. Updating to include the one-time password may include providing a copy of the one-time password over the back channel 410 to one or more areas that did not receive the one-time password upon login. In some embodiments, the one-time password may be provided by synchronous communication on the back channel 410. For example, if the first domain 406 receives a one-time password as part of a login, the first domain 406 provides a copy of the one-time password to the second domain 408 via synchronous communication on the back channel 410 and updates the second authentication information 418 with the one-time password.
[0073] Upon receiving a request to access the CSP 402 using the login credentials 414, the login area 404 may query two or more areas of the CSP 402 where the user's credentials are stored for the credentials. For example, in the illustrated embodiment, the login area 404 may query the first area 406 for the first credentials 416 and query the second area 408 for the second credentials 418. In the illustrated example, the first area 406 is unavailable. Because the first area 406 is unavailable, the first area 406 may not be able to receive a query for the first credentials 416 and / or may not be able to provide the first credentials 416 to the login area 404 in response to a query for the first credentials 416. The second area 408 may still be able to receive a query for the second credentials 418 and provide the second credentials 418 to the login area 404.
[0074] After sending a query for the first credential 416 to the first region 406 and a query for the second credential 418 to the second region 408, the login region 404 may wait for responses from the first region 406 and the second region 408. The login region 404 may determine that the first region 406 is unavailable based on not receiving a response from the first region 406. In some embodiments, the login region 404 may determine that the first region 406 is unavailable based on not receiving a response from the first region 406 within a defined time period.
[0075] In other embodiments, the login area 404 may recognize that the first area 406 is unavailable. In these embodiments, the login area 404 may query the second area 408 for the second credential 418 and skip querying the first area 406 for the first credential 416 based on receiving a request to access the CSP 402. The login area 404 may avoid querying the first area 406 because it is aware that the first area 406 is unavailable. In these embodiments, the login area 404 may not wait a period of time to determine if the first area 406 is unresponsive. Thus, there may be less delay in obtaining credentials used to determine if the user of the user device 412 is authorized to access the CSP 402 because there is no need to wait to determine if the first area 406 is unresponsive to a query for the first credential 416.
[0076] The login area 404 may determine to use the second authentication information 418 received from the second area 408 to determine whether the user can access the CSP 402 based on the determination that the first area 406 is unavailable. For example, the login area 404 may determine whether the user is authorized to access the CSP 402 based on the login credentials 414 and the second authentication information 418. The login area 404 may compare a passcode from the second authentication information 418 corresponding to the user with the passcode received in the login credentials 414. Additionally, the login area 404 may compare the one-time password received in the login credentials 414 with a previously used one-time password from the second authentication information 418 and / or a still valid one-time password from the second authentication information 418. In some embodiments, the login area 404 may further determine whether the user device 412 is a known user device used by the user based on the login credentials 414 and / or the second authentication information 418, and may request further verification if the user device 412 is not a known user device used by the user.
[0077] The login area 404 may determine to provide access to the CSP 402 based on the passcode provided in the login credentials 414 matching the passcode of the second authentication information 418, the one-time password of the login credentials 414 not being included among the previously used one-time passwords of the second authentication information 418, the one-time password of the login credentials 414 matching one of the still valid one-time passwords of the second authentication information 418, the user device 412 being a known user device used by the user, further verification being received based on the user device 412 not being a known user device used by the user, or a combination thereof. The login area 404 can determine to deny access to the CSP 402 based on the passcode provided in the login credentials 414 not matching the passcode in the second credential 418, the one-time password in the login credentials 414 being included among the previously used one-time passwords in the second credential 418, the one-time password in the login credentials 414 not matching one of the still-valid one-time passwords in the second credential 418, or a combination thereof.
[0078] If the user's home realm is unavailable or if the user chooses to log in to a realm other than the home realm corresponding to the user, the user may be provided with access to CSP402 via one of the available realms used to determine whether access to CSP402 is authorized. For example, the user may be authenticated via a first subscription realm, which may determine whether the user is authorized to access CSP402, and the first subscription realm may provide the user with access to CSP402 if the home realm is unavailable or if the user chooses to log in to the first subscription realm. If one of the realms other than the home realm provides the user with access to CSP402, the operations the user can perform may be limited in some way. For example, if a realm other than the home realm provides access to CSP402, the user may be limited to read-only access to CSP402. In contrast, if the home realm provides access to CSP402, the user may have both read and write access to CSP402.
[0079] In the illustrated embodiment, the first realm 406 may be defined as a home realm for a user of the user device 412, and the second realm 408 may be defined as a first affiliation realm for the user. In the illustrated embodiment, when the user signs in to the second realm 408, the second realm 408 may limit the actions the user can perform using the CSP 402. For example, the second realm 408 may provide read-only access to the CSP 402.
[0080] If the second domain 408 provides access to the CSP 402, the second domain 408 may update the second authentication information 418 to include at least a portion of the information from the login credential 414. For example, the second domain 408 may store the one-time password received in the login credential 414. In some embodiments, the second domain 408 may store the one-time password along with other previously used one-time passwords in the second authentication information 418. Because the first domain 406 is unavailable, the first domain 406 may not update the first authentication information 416 with some of the information from the login credential 414. For example, the first domain 406 may not update the first authentication information 416 with the one-time password from the login credential 414. Thus, there may be differences between the first authentication information 416 and the second authentication information 418 based on the second domain 408 updating the second authentication information 418 and the first domain 406 not updating the first authentication information 416.
[0081] When the first region 406 becomes available again, in some embodiments, one or more actions may be performed on the first region 406 based on the first region 406 being unavailable. For example, in embodiments in which the login region 404 knows that the first region 406 is unavailable, an action may be performed to indicate to the login region 404 that the first region 406 is available again. In some embodiments, the login region 404 may query the first region 406 for a response at an interval and / or upon performance of an action to determine whether the first region 406 is available again. In these embodiments, the first region 406 may return a response indicating that the first region 406 is available again when the first region 406 becomes available. In some embodiments, the first region 406 may send an indication to the login region 404 that the first region 406 is available in response to the first region 406 being available again.
[0082] In some embodiments, the first region 406 can update the first authentication information 416 in response to the first region 406 becoming available again. For example, the first region 406 can send a query to one or more other regions to determine whether the other region has updated its authentication since the first region 406 became unavailable. In the illustrated embodiment, the first region 406 can send a query to the second region 408 over the back channel 410 in response to the first region 406 becoming available again. The second region 408 can send the second authentication information 418 to the first region 406 in response to the query. In some embodiments, the first region 406 can compare the first authentication information 416 to the second authentication information 418 to determine whether any updates were made to the second authentication information 418 while the first region 406 was unavailable. In some embodiments, the first region 406 may recognize a time when the first region 406 is unavailable and determine an update to be applied to the second credential 418 after the time when the first region 406 is unavailable and before the time when the first region 406 is available again. The first region 406 may update the first credential 416 based on the determined update. In other embodiments, a query sent by the first region 406 to the second region 408 may indicate a time when the first region 406 is unavailable. In these embodiments, the second region 408 may provide a portion of the second credential 418 that is updated after the specified time. The first region 406 may update the first credential 416 using a portion of the second credential 418 that is updated after the specified time provided by the second region 408.
[0083] 5 illustrates an example of a sign-on interface 500, according to at least one embodiment. For example, sign-on interface 500 may be displayed on a user device (e.g., user device 112 (FIG. 1), user device 212 (FIG. 2), and / or user device 412 (FIG. 4)) for signing in to a CSP (e.g., CSP 102 (FIG. 1), CSP 202 (FIG. 2), and / or CSP 402 (FIG. 4)). The sign-on interface 500 may be provided to the user device for each area of the CSP, such as a login area (e.g., login area 104 (FIG. 1) and / or login area 404 (FIG. 4)), a first area (e.g., first area 106 (FIG. 1), first area 204 (FIG. 2), and / or first area 406 (FIG. 4)), a second area (e.g., second area 108 (FIG. 1), second area 206 (FIG. 2), and / or second area 408 (FIG. 4)), or a combination thereof.
[0084] The sign-on interface 500 may include a user interface displayed on a user device. The sign-on interface 500 may include a representation of one or more entities at which a user of the user device may attempt to sign into a UE. The entities may include domains, areas, or combinations thereof. In some embodiments, the user interface may further indicate one or more characteristics of the entities. For example, the user interface may indicate whether the entity provides read and / or write capabilities or provides read-only capabilities.
[0085] In the illustrated embodiment, the sign-on interface 500 indicates that a user may attempt to sign in to Domain 1, Domain 2, Domain 3, and Domain 4 of the CSP. For example, a first representation 502 indicates that a user may attempt to sign in to Domain 1. A second representation 504 and a third representation 506 indicate that a user may attempt to sign in to Domain 2. A fourth representation 508 indicates that a user may attempt to sign in to Domain 3. A fifth representation 510 and a sixth representation 512 indicate that a user may attempt to sign in to Domain 4.
[0086] Additionally, sign-on interface 500 indicates which areas can be used to access the domains in the illustrated embodiment. For example, first representation 502 indicates that area 1 can be used to sign in to domain 1. Second representation 504 indicates that area 1 can be used to sign in to domain 2. Third representation 506 indicates that area 2 can be used to sign in to domain 2. Fourth representation 508 indicates that area 2 can be used to sign in to domain 3. Fifth representation 510 indicates that area 1 can be used to sign in to domain 4. Sixth representation 512 indicates that area 2 can be used to sign in to domain 4.
[0087] In the illustrated embodiment, the sign-on interface 500 indicates characteristics of several views. For example, the third view 506 indicates that the sign-in option corresponding to the third view 506 provides read-only access. Additionally, the sixth view 512 indicates that the sign-in option corresponding to the sixth view 512 provides read-only access.
[0088] A user of the user device may select one of the views to attempt to sign in to the CSP via the entity. For example, the user may select the first view 502 to attempt to sign in to the CSP via domain 1 and region 1. Based on the selection of the view, a login request may be provided to the selected entity. For example, if the user selects the first view 502, a login request may be sent to region 1 requesting to log in to domain 1 of the CSP. If region 1 is unavailable, the list of views may be updated without the first view 502 being displayed. The user may then select another view to attempt to sign in to another entity. If region 1 is available, region 1 may respond to the login request.
[0089] When the available region responds to the login request, a request for at least a portion of the login credentials (e.g., login credentials 114 (FIG. 1), login credentials 214 (FIG. 2), and / or login credentials 414 (FIG. 4)) may be displayed on the user device. The user may enter at least a portion of the login credentials, and the login procedure may proceed as described throughout this disclosure.
[0090] FIG. 6 illustrates a first portion of an example procedure 600 related to signing in to a CSP, according to at least one embodiment. FIG. 7 illustrates a second portion of the example procedure 600 of FIG. 6, according to at least one embodiment. The procedure 600 may be performed by a CSP or a portion thereof. For example, the procedure 600 may be performed by a login area (e.g., login area 104 (FIG. 1) and / or login area 404 (FIG. 4)), a first area (e.g., first area 106 (FIG. 1), first area 204 (FIG. 2), and / or first area 406 (FIG. 4)), a second area (e.g., second area 108 (FIG. 1), second area 206 (FIG. 2), and / or second area 408 (FIG. 4)), or a combination thereof.
[0091] At 602, the CSP may determine one or more areas available for login. For example, the CSP may store an indication of one or more available areas available for login. The CSP may determine the one or more available areas based on the stored indication. In other embodiments, the CSP may query one or more areas to determine which areas are available for login. The CSP may determine the available areas for login based on the response to the query. In some embodiments, 602 may be omitted.
[0092] At 604, the CSP may present a user interface indicating one or more available areas for selection. For example, the CSP may present a user interface indicating one or more available areas for selecting a login area from the one or more available areas. In some embodiments, the user interface may include a sign-on interface, such as sign-on interface 500 (FIG. 5). In some embodiments, 604 may be omitted.
[0093] At 606, the CSP may identify a selection of a login area from one or more available areas. For example, the CSP may identify that a user has selected one of the areas to be used as a login area from one or more available areas displayed within the user interface. In some embodiments, the selected area may be a first area (e.g., first area 106 (FIG. 1), first area 204 (FIG. 2), and / or first area 406 (FIG. 4)) or a second area (e.g., second area 108 (FIG. 1), second area 206 (FIG. 2), and / or second area 408 (FIG. 4)). In some embodiments, 606 may be omitted.
[0094] At 608, the CSP may receive a request to log into the network. For example, the CSP may receive a request to log into the CSP's network. In some embodiments, the request may be received at a login realm at 606 based at least in part on an identification of a selection of the login realm. In some embodiments, the request may be received at a first realm of the CSP that is separate from two or more realms from which authentication information associated with the request is obtained.
[0095] At 610, the CSP may identify the login credentials received in the request. For example, the CSP may identify the login credentials received in the request received at 608. In some embodiments, the login credentials may include a one-time password provided in the request received at 608.
[0096] At 612, the CSP may obtain authentication information associated with the request. For example, the CSP may obtain authentication information associated with the request received at 608 from two or more realms of the CSP. The authentication information may include first authentication information (e.g., first authentication information 116 (FIG. 1), first authentication information 208 (FIG. 2), and / or first authentication information 416 (FIG. 4)), second authentication information (e.g., second authentication information 118 (FIG. 1), second authentication information 210 (FIG. 2), and / or second authentication information 418 (FIG. 4)), or a combination thereof. In some embodiments, the authentication information may include one or more previously used disposable passwords corresponding to an account associated with the request received at 608. In some embodiments, obtaining the authentication information includes making a backchannel call to the two or more realms.
[0097] In some embodiments, obtaining the authentication information may include obtaining authentication information from a home domain of an account associated with the request and a first subscribed domain of the account. In some embodiments, obtaining the authentication information includes obtaining the first authentication information from the home domain and obtaining the second authentication information from the first subscribed domain.
[0098] The CSP may combine the first authentication information and the second authentication information to generate the authentication information. For example, the CSP may combine the first authentication information and the second authentication information according to the description of the combining of information described in connection with FIG. 3. In some embodiments, combining the first authentication information and the second authentication information may include generating a combined authentication information including the first authentication information and the second authentication information. The CSP may identify a first copy of the particular authentication information in the combined authentication information, the first copy of the particular authentication information being from the first authentication information. The CSP may further identify a second copy of the particular authentication information in the combined authentication information, the second copy of the particular authentication information being from the second authentication information. The CSP may remove either the first copy or the second copy of the particular authentication information from the combined authentication information to generate the authentication information.
[0099] At 614, the CSP may determine that the first realm is unavailable. For example, the two or more realms from which authentication information is obtained may include a first realm and a second realm. The CSP may determine that the first realm is unavailable. In these cases, obtaining the authentication information may include bypassing the first backchannel call to the first realm to obtain the authentication information based at least in part on the determination that the first realm is unavailable. Obtaining the authentication information may include making a second backchannel call to the second realm to obtain the authentication information. In some cases, 614 may be omitted.
[0100] Procedure 600 may proceed from 614 to 616. 616 in Figure 6 and 616 in Figure 7 indicate that procedure 600 continues from Figure 6 to Figure 7. When 616 in Figure 7 proceeds to 702, procedure 600 may proceed from 614 in Figure 6 to 702 in Figure 7.
[0101] At 702, the CSP may determine whether to provide access to the network. For example, the CSP may determine whether to provide access to the network based at least in part on the login credentials and the authentication information. In some embodiments, determining whether to provide access to the network includes determining to provide access to the network based at least in part on a one-time password from the login credentials not being present in one or more previously used one-time passwords included in the authentication information obtained at 612.
[0102] Based on the outcome of the decision at 702, procedure 700 may proceed from 702 to 704 or 706. In particular, if the CSP decides not to provide access to the network, procedure 700 may proceed from 702 to 704. If the CSP decides to provide access to the network, procedure 700 may proceed from 702 to 706.
[0103] At 704, the CSP may deny access to the network. For example, the CSP may deny access to the network pursuant to a decision not to provide access to the network at 702. If 704 is executed, procedure 700 may end after 704.
[0104] At 706, the CSP may provide access to the network. For example, the CSP may provide access to the network according to a decision to provide access to the network. If 706 is executed, the procedure 700 may proceed from 706 to 708.
[0105] At 708, the CSP may identify authentication data included in the login credentials. In some embodiments, the authentication data may include the login credentials identified at 610 or a portion thereof. In some embodiments, 708 may be omitted.
[0106] At 710, the CSP can store the authentication data in a first region. For example, the CSP can store the authentication data in a first region of two or more regions for which authentication is obtained. The stored authentication data can be used for future login attempts. In some embodiments, 710 can be omitted.
[0107] At 712, the CSP can store the authentication data in a second region. For example, the CSP may store the authentication data in a second region of two or more regions from which authentication information is obtained. The stored authentication data may be used for future login attempts. In some embodiments, storing the authentication data in the second region may include replicating the authentication data from the first region to the second region via synchronized backchannel communication between the first region and the second region. In some embodiments, 712 may be omitted.
[0108] 7 may be interpreted as implying an order for procedure 700, it should be understood that the operations of procedure 700 may be applied in a different order in other embodiments and / or one or more of the operations of procedure 700 may be performed simultaneously. Additionally, it should be understood that in other embodiments, one or more operations of procedure 700 may be omitted and / or one or more additional operations may be included in procedure 700 in other embodiments.
[0109] The approaches and procedures described throughout this disclosure allow a user to log in from multiple realms. For example, conventional approaches may limit login to a single realm, such as a home realm. Conventional approaches may limit login to a single realm to limit the ability of credentials to be improperly obtained by a third party and to prevent possible differences in credentials between different realms. The approaches and procedures described herein address these issues and can provide login via multiple realms and handle possible differences between credentials for different realms, while still providing adequate protection for the credentials.
[0110] Example Infrastructure as a Service Architecture As mentioned above, Infrastructure as a Service (IaaS) is a specific type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In the IaaS model, a cloud computing provider can host the infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, an IaaS provider can also provide various services (e.g., billing, monitoring, logging, load balancing, clustering, etc.) that accompany these infrastructure components. Thus, these services can be policy-driven, so that IaaS users may be able to implement policies that facilitate load balancing to maintain application availability and performance.
[0111] In some cases, IaaS customers can access resources and services over a wide area network (WAN) such as the Internet and use the cloud provider's services to install the remaining elements of their application stack. For example, a user can log into an IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as databases, create storage buckets for workloads and backups, and even install enterprise software on the VMs. Customers can use the provider's services to perform a variety of functions, such as distributing network traffic, troubleshooting application issues, monitoring performance, and managing disaster recovery.
[0112] In most cases, cloud computing models require the participation of a cloud provider, which may be, but does not have to be, a third-party service that specializes in providing (e.g., providing, renting, selling) IaaS. An entity may also choose to deploy a private cloud and become a provider of its own infrastructure services.
[0113] In some examples, IaaS deployment is the process of placing a new application, or a new version of an application, onto a prepared application server, etc. It may also include the server preparation process (e.g., installing libraries, daemons, etc.). This is often managed by the cloud provider below the hypervisor layer (e.g., server, storage, network hardware, virtualization). The customer may then be responsible for handling things like OS, middleware, and / or application deployment (e.g., self-service virtual machines (e.g., that can be started on demand)).
[0114] In some examples, IaaS provisioning may refer to obtaining computers or virtual hosts for use and installing the necessary libraries or services on them. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.
[0115] In some cases, there are two distinct challenges with IaaS provisioning. First, there is the initial challenge of provisioning the initial set of infrastructure before anything can be done. Second, there is the challenge of evolving the existing infrastructure (e.g. adding new services, modifying services, removing services, etc.) after everything has been provisioned. In some cases, these two challenges can be addressed by allowing the configuration of the infrastructure to be defined declaratively. That is, the infrastructure (e.g. what components are needed and how they interact) can be defined by one or more configuration files. Thus, the overall topology of the infrastructure (e.g. which resources depend on which resources and how each coordinates) can be described declaratively. In some cases, once the topology is defined, workflows can be generated that create and / or manage the various components described in the configuration files.
[0116] In some examples, the infrastructure may have many elements that are interconnected. For example, there may be one or more virtual private clouds (VPCs) (e.g., a pool of potentially on-demand configurable and / or shared computing resources), also referred to as a core network. In some examples, there may also be one or more inbound / outbound traffic group rules that are provisioned to define how to configure inbound and / or outbound traffic for the network and one or more virtual machines (VMs). Other infrastructure elements such as load balancers, databases, etc. may also be provisioned. The infrastructure may evolve in stages as more infrastructure elements are required and / or added.
[0117] In some cases, continuous deployment techniques can be used to enable deployment of infrastructure code across different virtual computing environments. Additionally, the described techniques enable infrastructure management within these environments. In some examples, service teams can create code that needs to be deployed to one or more, and often many, different operating environments (e.g., different geographic locations, possibly across the globe). However, in some examples, the infrastructure onto which the code will be deployed must first be set up. In some cases, provisioning can be performed manually, provisioning tools can be used to provision resources, and / or deployment tools can be used to deploy the code once the infrastructure is provisioned.
[0118] FIG. 8 is a block diagram 800 illustrating an example pattern of an IaaS architecture according to at least one embodiment. A service operator 802 may be communicatively connected to a secure host tenancy 804, which may include a virtual cloud network (VCN) 806 and a secure host subnet 808. In some examples, the service operator 802 may be using one or more client computing devices. These devices may be portable handheld devices (e.g., iPhone, mobile phone, iPad, computing tablet, personal digital assistant (PDA)) or wearable devices (e.g., Google Glass head mounted display) running software such as Microsoft Windows Mobile, and / or various mobile operating systems such as iOS, Windows Phone, Android, BlackBerry 8, PalmOS, Internet, email, short message service (SMS), BlackBerry, or other enabled communication protocols. Alternatively, the client computing devices may be general purpose personal computers, including, for example, personal computers and / or laptop computers running various versions of Microsoft Windows, Apple Macintosh, and / or Linux operating systems. The client computing device may be a workstation computer running any of a variety of commercially available UNIX or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems such as Google Chrome OS).Alternatively, or in addition, the client computing devices may be other electronic devices capable of communicating over a network with access to the VCN 806 and / or the Internet, such as thin-client computers, Internet-enabled gaming systems (e.g., Microsoft Xbox game consoles with or without Kinect® gesture input devices), and / or personal messaging devices.
[0119] VCN 806 may include a local peering gateway (LPG) 810 that may be communicatively connected to a secure shell (SSH) VCN 812 via an LPG 810 that is included in SSH VCN 812. SSH VCN 812 may include an SSH subnet 814, which may be communicatively connected to a control plane VCN 816 via an LPG 810 that is included in control plane VCN 816. SSH VCN 812 may also be communicatively connected to a data plane VCN 818 via an LPG 810. The control plane VCN 816 and the data plane VCN 818 may be included in a service tenancy 819, which may be owned and / or operated by the IaaS provider.
[0120] The control plane VCN 816 may include a control plane demilitarized zone (DMZ) tier 820 that functions as a perimeter network (e.g., a portion of an enterprise network between an enterprise intranet and an external network). DMZ-based servers may have limited responsibility and aid in containment of breaches. Additionally, the DMZ tier 820 may include one or more load balancer (LB) subnets 822, a control plane app tier 824 that may include an app subnet 826, a control plane data tier 828 that may include a database (DB) subnet 830 (e.g., a front-end DB subnet and / or a back-end DB subnet). The LB subnet 822 included in the control plane DMZ tier 820 may be communicatively coupled to the app subnet 826 included in the control plane app tier 824 and an Internet gateway 834 that may be included in the control plane VCN 816, and the app subnet 826 may be communicatively coupled to the DB subnet 830 and a service gateway 836 and a network address translation (NAT) gateway 838 included in the control plane data tier 828. The control plane VCN 816 may include a service gateway 836 and a NAT gateway 838.
[0121] The control plane VCN 816 may include a data plane mirrored app layer 840 that may include an app subnet 826. The app subnet 826 included in the data plane mirrored app layer 840 may include a virtual network interface controller (VNIC) 842 on which a compute instance 844 can run. The compute instance 844 may be communicatively connected to the app subnet 826 of the data plane mirrored app layer 840, which may be included in the data plane app layer 846.
[0122] The data plane VCN 818 may include a data plane app layer 846, a data plane DMZ layer 848, and a data plane data layer 850. The data plane DMZ layer 848 may include a LB subnet 822 that may be communicatively connected to an app subnet 826 of the data plane app layer 846 and an Internet gateway 834 of the data plane VCN 818. The app subnet 826 may be communicatively connected to a service gateway 836 of the data plane VCN 818 and a NAT gateway 838 of the data plane VCN 818. The data plane data layer 850 may also include a DB subnet 830 that may be communicatively connected to the app subnet 826 of the data plane app layer 846.
[0123] The internet gateways 834 of the control plane VCNs 816 and data plane VCNs 818 may be communicatively connected to a metadata management service 852, which may be communicatively connected to the public internet 854. The public internet 854 may be communicatively connected to NAT gateways 838 of the control plane VCNs 816 and data plane VCNs 818. The service gateways 836 of the control plane VCNs 816 and data plane VCNs 818 may be communicatively connected to cloud services 856.
[0124] In some examples, a service gateway 836 in the control plane VCN 816 or the data plane VCN 818 can make application programming interface (API) calls to cloud services 856 without traversing the public Internet 854. API calls from the service gateway 836 to the cloud services 856 can be one-way; that is, the service gateway 836 can make an API call to the cloud services 856, and the cloud services 856 can send the requested data to the service gateway 836. However, the cloud services 856 may not be able to initiate an API call to the service gateway 836.
[0125] In some examples, secure host tenancy 804 can be directly connected to service tenancy 819, which may otherwise be separate. Secure host subnet 808 can communicate with SSH subnet 814 through LPG 810, which may allow bidirectional communication on otherwise separate systems. Connecting secure host subnet 808 to SSH subnet 814 allows secure host subnet 808 to access other entities in service tenancy 819.
[0126] The control plane VCN 816 can enable users of the service tenancy 819 to configure or provision desired resources. The necessary resources provisioned in the control plane VCN 816 can be deployed or used in the data plane VCN 818. In some examples, the control plane VCN 816 can be separate from the data plane VCN 818, and the data plane mirror app layer 840 of the control plane VCN 816 can communicate with the data plane app layer 846 of the data plane VCN 818 via a VNIC 842, which can be included in the data plane mirror app layer 840 and the data plane app layer 846.
[0127] In some examples, a user, or customer, of the system may make a request, for example, a create, read, update, or delete (CRUD) operation, via the public internet 854, which may communicate the request to a metadata management service 852. The metadata management service 852 may communicate the request to the control plane VCN 816 via an internet gateway 834. The request may be received by a LB subnet 822 included in the control plane DMZ layer 820. The LB subnet 822 may determine that the request is valid and, in response to this determination, may send the request to an app subnet 826 included in the control plane app layer 824. If the request is validated and a call to the public internet 854 is required, the call to the public internet 854 may be sent to a NAT gateway 838, which may make the call to the public internet 854. Metadata that may need to be stored by the request may be stored in the DB subnet 830.
[0128] In some examples, the data plane mirror app layer 840 can facilitate direct communication between the control plane VCN 816 and the data plane VCN 818. For example, it may be desired to apply a configuration change, update, or other appropriate modification to resources included in the data plane VCN 818. The control plane VCN 816 communicates directly with the resources included in the data plane VCN 818 via the VNIC 842, thereby allowing the configuration change, update, or other appropriate modification to be performed.
[0129] In some embodiments, the control plane VCN 816 and the data plane VCN 818 can be included within the service tenancy 819. In this case, a user or customer of the system may not own or operate either the control plane VCN 816 or the data plane VCN 818. Instead, an IaaS provider may own or operate the control plane VCN 816 and the data plane VCN 818, both of which may be included in the service tenancy 819. This embodiment may allow for network isolation that may prevent a user or customer from interacting with the resources of other users or other customers. This embodiment may also allow a user or customer of the system to store databases privately without relying on the public Internet 854, which may not have an adequate level of threat protection for storage.
[0130] In another embodiment, the LB subnet 822 included in the control plane VCN 816 can be configured to receive signals from the service gateway 836. In this embodiment, the control plane VCN 816 and the data plane VCN 818 can be configured to be called by the IaaS provider's customers without calling the public Internet 854. The IaaS provider's customers may desire this embodiment because databases used by the customers may be stored in the service tenancy 819, which may be controlled by the IaaS provider and isolated from the public Internet 854.
[0131] 9 is a block diagram 900 illustrating another example pattern of an IaaS architecture according to at least one embodiment. A service operator 902 (e.g., service operator 802 of FIG. 8 ) may be communicatively connected to a secure host tenancy 904 (e.g., secure host tenancy 804 of FIG. 8 ), which may include a virtual cloud network (VCN) 906 (e.g., VCN 806 of FIG. 8 ) and a secure host subnet 908 (e.g., secure host subnet 808 of FIG. 8 ). The VCN 906 may include a local peering gateway (LPG) 910 (e.g., LPG 810 of FIG. 8 ), which may be communicatively connected to a secure shell (SSH) VCN 912 (e.g., SSH VCN 812 of FIG. 8 ) via an LPG 810 included in the SSH VCN 912. The SSH VCN 912 can include an SSH subnet 914 (e.g., SSH subnet 814 in FIG. 8 ), which can be communicatively coupled to a control plane VCN 916 (e.g., control plane VCN 816 in FIG. 8 ) via an LPG 910 included in the control plane VCN 916. The control plane VCN 916 can be included in a service tenancy 919 (e.g., service tenancy 819 in FIG. 8 ), and the data plane VCN 918 (e.g., data plane VCN 818 in FIG. 8 ) can be included in a customer tenancy 921, which may be owned or operated by a user or customer of the system.
[0132] The control plane VCN 916 may include a control plane DMZ tier 920 (e.g., control plane DMZ tier 820 of FIG. 8 ) that may include a LB subnet 922 (e.g., LB subnet 822 of FIG. 8 ), a control plane app tier 924 (e.g., control plane app tier 824 of FIG. 8 ) that may include an app subnet 926 (e.g., app subnet 826 of FIG. 8 ), and a control plane data tier 928 (e.g., control plane data tier 828 of FIG. 8 ) that may include a database (DB) subnet 930 (e.g., similar to DB subnet 830 of FIG. 8 ). The LB subnet 922 included in the control plane DMZ layer 920 can be communicatively coupled to an app subnet 926 included in the control plane app layer 924 and an Internet gateway 934 (e.g., Internet gateway 834 in FIG. 8 ) that may be included in the control plane VCN 916, and the app subnet 926 can be communicatively coupled to a DB subnet 930 and a service gateway 936 (e.g., service gateway 836 in FIG. 8 ) and a network address translation (NAT) gateway 938 (e.g., NAT gateway 838 in FIG. 8 ) included in the control plane data layer 928. The control plane VCN 916 can include the service gateway 936 and the NAT gateway 938.
[0133] The control plane VCN 916 may include a data plane mirror app layer 940 (e.g., data plane mirror app layer 840 of FIG. 8 ), which may include an app subnet 926. The app subnet 926 included in the data plane mirror app layer 940 may include a virtual network interface controller (VNIC) 942 (e.g., VNIC 842) on which a compute instance 944 (e.g., similar to compute instance 844 of FIG. 8 ) can run. The compute instance 944 can facilitate communication between the app subnet 926 of the data plane mirror app layer 940 and the app subnet 926 that may be included in the data plane app layer 946 (e.g., data plane app layer 846 of FIG. 8 ) via the VNIC 942 included in the data plane mirror app layer 940 and the VNIC 942 included in the data plane app layer 946.
[0134] The internet gateway 934 included in the control plane VCN 916 may be communicatively connected to a metadata management service 952 (e.g., metadata management service 852 of FIG. 8), which may be communicatively connected to a public internet 954 (e.g., public internet 854 of FIG. 8). The public internet 954 may be communicatively connected to a NAT gateway 938 included in the control plane VCN 916. The service gateway 936 included in the control plane VCN 916 may be communicatively connected to cloud services 956 (e.g., cloud services 856 of FIG. 8).
[0135] In some examples, the data plane VCN 918 can be included in the customer tenancy 921. In this case, the IaaS provider can provide each customer with a control plane VCN 916, and the IaaS provider can configure a unique compute instance 944 included in the service tenancy 919 for each customer. Each compute instance 944 can enable communication between the control plane VCN 916 included in the service tenancy 919 and the data plane VCN 918 included in the customer tenancy 921. The compute instance 944 can enable resources provisioned in the control plane VCN 916 included in the service tenancy 919 to be deployed or otherwise used in the data plane VCN 918 included in the customer tenancy 921.
[0136] In another example, the IaaS provider's customer may have a database that resides in the customer tenancy 921. In this example, the control plane VCN 916 may include a data plane mirror app tier 940 that may include the app subnet 926. The data plane mirror app tier 940 may reside in the data plane VCN 918, but the data plane mirror app tier 940 may not reside in the data plane VCN 918. That is, the data plane mirror app tier 940 may have access to the customer tenancy 921, but the data plane mirror app tier 940 may not reside in the data plane VCN 918 or may not be owned or operated by the IaaS provider's customer. The data plane mirror app tier 940 may be configured to make calls to the data plane VCN 918, but may not be configured to make calls to entities contained in the control plane VCN 916. A customer may desire to deploy or otherwise use resources provisioned in the control plane VCN 916 in the data plane VCN 918, and the data plane mirror app layer 940 can facilitate the desired deployment or other use of the customer's resources.
[0137] In some embodiments, the IaaS provider's customer can apply filters to the data plane VCN 918. In this embodiment, the customer can determine what the data plane VCN 918 can access, and the customer can limit access from the data plane VCN 918 to the public internet 954. The IaaS provider may not be able to apply filters or control access from the data plane VCN 918 to external networks or databases. Applying customer filters and controls to the data plane VCN 918 contained in the customer tenancy 921 can help isolate the data plane VCN 918 from other customers and the public internet 954.
[0138] In some embodiments, cloud services 956 may be called by service gateway 936 to access services that may not reside on the public internet 954, the control plane VCN 916, or the data plane VCN 918. The connection between cloud services 956 and the control plane VCN 916 or the data plane VCN 918 may not be live or continuous. Cloud services 956 may reside on a separate network owned or operated by the IaaS provider. Cloud services 956 may be configured to receive calls from service gateway 936 and not receive calls from the public internet 954. Some cloud services 956 may be isolated from other cloud services 956, and the control plane VCN 916 may be isolated from cloud services 956 that may not be in the same region as the control plane VCN 916. For example, the control plane VCN 916 may be located in “Region 1” and cloud service “Deployment 8” may be located in Region 1 and Region 2. If a call is made to deployment 8 by a service gateway 936 included in a control plane VCN 916 located in region 1, the call may be sent to deployment 8 in region 1. In this example, control plane VCN 916, and thus deployment 8 in region 1, may not be communicatively coupled or in communication with deployment 8 in region 2.
[0139] 10 is a block diagram 1000 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 1002 (e.g., service operator 802 of FIG. 8 ) may be communicatively connected to a secure host tenancy 1004 (e.g., secure host tenancy 804 of FIG. 8 ), which may include a virtual cloud network (VCN) 1006 (e.g., VCN 806 of FIG. 8 ) and a secure host subnet 1008 (e.g., secure host subnet 808 of FIG. 8 ). The VCN 1006 may include an LPG 1010 (e.g., LPG 810 of FIG. 8 ), which may be communicatively connected to an SSH VCN 1012 (e.g., SSH VCN 812 of FIG. 8 ) via an LPG 1010 included in the SSH VCN 1012. The SSH VCN 1012 can include an SSH subnet 1014 (e.g., SSH subnet 814 in FIG. 8 ), which can be communicatively coupled to a control plane VCN 1016 (e.g., control plane VCN 816 in FIG. 8 ) via an LPG 1010 included in the control plane VCN 1016, and to a data plane VCN 1018 (e.g., data plane 818 in FIG. 8 ) via an LPG 1010 included in the data plane VCN 1018. The control plane VCN 1016 and the data plane VCN 1018 can be included in a service tenancy 1019 (e.g., service tenancy 819 in FIG. 8 ).
[0140] The control plane VCN 1016 may include a control plane DMZ tier 1020 (e.g., control plane DMZ tier 820 of FIG. 8 ) that may include a load balancer (LB) subnet 1022 (e.g., LB subnet 822 of FIG. 8 ), a control plane app tier 1024 (e.g., control plane app tier 824 of FIG. 8 ) that may include an app subnet 1026 (e.g., similar to app subnet 826 of FIG. 8 ), and a control plane data tier 1028 (e.g., control plane data tier 828 of FIG. 8 ) that may include a DB subnet 1030. The LB subnet 1022 included in the control plane DMZ layer 1020 can be communicatively coupled to an app subnet 1026 included in the control plane app layer 1024 and an Internet gateway 1034 (e.g., Internet gateway 834 in FIG. 8 ) that may be included in the control plane VCN 1016, and the app subnet 1026 can be communicatively coupled to a DB subnet 1030 and a service gateway 1036 (e.g., service gateway in FIG. 8 ) and a network address translation (NAT) gateway 1038 (e.g., NAT gateway 838 in FIG. 8 ) included in the control plane data layer 1028. The control plane VCN 1016 can include the service gateway 1036 and the NAT gateway 1038.
[0141] The data plane VCN 1018 may include a data plane app layer 1046 (e.g., data plane app layer 846 of FIG. 8 ), a data plane DMZ layer 1048 (e.g., data plane DMZ layer 848 of FIG. 8 ), and a data plane data layer 1050 (e.g., data plane data layer 850 of FIG. 8 ). The data plane DMZ layer 1048 may include a trusted app subnet 1060 and an untrusted app subnet 1062 of the data plane app layer 1046, and a LB subnet 1022 that may be communicatively connected to an Internet gateway 1034 included in the data plane VCN 1018. The trusted app subnet 1060 may be communicatively connected to a service gateway 1036 included in the data plane VCN 1018, a NAT gateway 1038 included in the data plane VCN 1018, and a DB subnet 1030 included in the data plane data layer 1050. The untrusted app subnet 1062 may be communicatively connected to a service gateway 1036 included in the data plane VCN 1018 and a DB subnet 1030 included in the data plane data layer 1050. The data plane data layer 1050 may include a DB subnet 1030 that may be communicatively connected to a service gateway 1036 included in the data plane VCN 1018.
[0142] The untrusted app subnet 1062 may include one or more primary VNICs 1064(1)-(N) that may be communicatively connected to tenant virtual machines (VMs) 1066(1)-(N). Each tenant VM 1066(1)-(N) may be communicatively coupled to a respective app subnet 1067(1)-(N) that may be included in a respective container egress VCN 1068(1)-(N) that may be included in a respective customer tenancy 1070(1)-(N). Each secondary VNIC 1072(1)-(N) may facilitate communication between the untrusted app subnet 1062 included in the data plane VCN 1018 and the app subnet included in the container egress VCN 1068(1)-(N). Each container egress VCN 1068(1)-(N) may include a NAT gateway 1038 that may be communicatively connected to the public Internet 1054 (e.g., public Internet 854 of FIG. 8 ).
[0143] An Internet gateway 1034 included in the control plane VCN 1016 and included in the data plane VCN 1018 may be communicatively connected to a metadata management service 1052 (e.g., metadata management system 852 of FIG. 8 ), which may be communicatively connected to the public Internet 1054. The public Internet 1054 may be communicatively connected to a NAT gateway 1038 included in the control plane VCN 1016 and included in the data plane VCN 1018. A service gateway 1036 included in the control plane VCN 1016 and included in the data plane VCN 1018 may be communicatively connected to cloud services 1056.
[0144] In some embodiments, the data plane VCN 1018 can be integrated with a customer tenancy 1070. This integration may be useful or desirable for the IaaS provider's customer, such as when support is needed when running code. A customer may provide code to be executed that may be disruptive, communicate with other customer resources, or cause other undesirable effects. In response, the IaaS provider can decide whether or not to execute code provided by the customer to the IaaS provider.
[0145] In some examples, an IaaS provider's customer may request that the IaaS provider grant temporary network access and the ability to connect to the data plane app layer 1046. The code that performs the function may run in the VMs 1066(1)-(N), and the code may not be configured to run elsewhere on the data plane VCN 1018. Each VM 1066(1)-(N) may be connected to one customer tenancy 1070. Each container 1071(1)-(N) contained in a VM 1066(1)-(N) may be configured to run code. In this case, there may be double isolation (e.g., container 1071(1)-(N) may run code, and container 1071(1)-(N) may be contained in a VM 1066(1)-(N) that is at least in an untrusted app subnet 1062), which may prevent erroneous or unwanted code from damaging the IaaS provider's network or damaging another customer's network. The containers 1071(1)-(N) may be communicatively coupled to the customer tenancy 1070 and configured to send or receive data from the customer tenancy 1070. The containers 1071(1)-(N) may not be configured to send or receive data from other entities in the data plane VCN 1018. Once the code execution is complete, the IaaS provider may kill or otherwise dispose of the containers 1071(1)-(N).
[0146] In some embodiments, the trusted app subnet 1060 may execute code that may be owned or operated by the IaaS provider. In this embodiment, the trusted app subnet 1060 may be communicatively coupled to the DB subnet 1030 and configured to perform CRUD operations on the DB subnet 1030. The untrusted app subnet 1062 may be communicatively coupled to the DB subnet 1030, but in this embodiment, the untrusted app subnet may be configured to perform read operations on the DB subnet 1030. The containers 1071(1)-(N) included in each customer's VMs 1066(1)-(N) that may execute code from the customer may not be communicatively coupled to the DB subnet 1030.
[0147] In other embodiments, the control plane VCN 1016 and the data plane VCN 1018 may not be directly communicatively coupled. In this embodiment, there may be no direct communication between the control plane VCN 1016 and the data plane VCN 1018. However, communication may occur indirectly through at least one method. An LPG 1010 may be established by an IaaS provider that may facilitate communication between the control plane VCN 1016 and the data plane VCN 1018. In another example, the control plane VCN 1016 or the data plane VCN 1018 may call a cloud service 1056 through a service gateway 1036. For example, a call from the control plane VCN 1016 to the cloud service 1056 may include a request for a service that may communicate with the data plane VCN 1018.
[0148] 11 is a block diagram 1100 illustrating another example pattern of an IaaS architecture, according to at least one embodiment. A service operator 1102 (e.g., service operator 802 of FIG. 8 ) may be communicatively connected to a secure host tenancy 1104 (e.g., secure host tenancy 804 of FIG. 8 ), which may include a virtual cloud network (VCN) 1106 (e.g., VCN 806 of FIG. 8 ) and a secure host subnet 1108 (e.g., secure host subnet 808 of FIG. 8 ). VCN 1106 may include an LPG 1110 (e.g., LPG 810 of FIG. 8 ), which may be communicatively connected to an SSH VCN 1112 (e.g., SSH VCN 812 of FIG. 8 ) via an LPG 1110 included in SSH VCN 1112. SSH VCN 1112 can include an SSH subnet 1114 (e.g., SSH subnet 814 in FIG. 8 ), which can be communicatively coupled to a control plane VCN 1116 (e.g., control plane VCN 816 in FIG. 8 ) via an LPG 1110 included in the control plane VCN 1116, and to a data plane VCN 1118 (e.g., data plane 818 in FIG. 8 ) via an LPG 1110 included in the data plane VCN 1118. The control plane VCN 1116 and the data plane VCN 1118 can be included in a service tenancy 1119 (e.g., service tenancy 819 in FIG. 8 ).
[0149] The control plane VCN 1116 may include a control plane DMZ layer 1120 (e.g., control plane DMZ layer 820 of FIG. 8 ) that may include a LB subnet 1122 (e.g., LB subnet 822 of FIG. 8 ), a control plane app layer 1124 (e.g., control plane app layer 824 of FIG. 8 ) that may include an app subnet 1126 (e.g., app subnet 826 of FIG. 8 ), and a control plane data layer 1128 (e.g., control plane data layer 828 of FIG. 8 ) that may include a DB subnet 1130 (e.g., DB subnet 1030 of FIG. 10 ). The LB subnet 1122 included in the control plane DMZ layer 1120 can be communicatively coupled to an app subnet 1126 included in the control plane app layer 1124 and an Internet gateway 1134 (e.g., Internet gateway 834 in FIG. 8 ) that may be included in the control plane VCN 1116, and the app subnet 1126 can be communicatively coupled to a DB subnet 1130 and a service gateway 1136 (e.g., service gateway in FIG. 8 ) and a network address translation (NAT) gateway 1138 (e.g., NAT gateway 838 in FIG. 8 ) included in the control plane data layer 1128. The control plane VCN 1116 can include the service gateway 1136 and the NAT gateway 1138.
[0150] The data plane VCN 1118 may include a data plane app layer 1146 (e.g., data plane app layer 846 in FIG. 8 ), a data plane DMZ layer 1148 (e.g., data plane DMZ layer 848 in FIG. 8 ), and a data plane data layer 1150 (e.g., data plane data layer 850 in FIG. 8 ). The data plane DMZ layer 1148 may include a trusted app subnet 1160 (e.g., trusted app subnet 1060 in FIG. 10 ) and an untrusted app subnet 1162 (e.g., untrusted app subnet 1062 in FIG. 10 ) of the data plane app layer 1146, and a LB subnet 1122 that may be communicatively connected to an Internet gateway 1134 included in the data plane VCN 1118. The trusted app subnet 1160 may be communicatively connected to a service gateway 1136 included in the data plane VCN 1118, a NAT gateway 1138 included in the data plane VCN 1118, and a DB subnet 1130 included in the data plane data layer 1150. The untrusted app subnet 1162 may be communicatively connected to a service gateway 1136 included in the data plane VCN 1118 and a DB subnet 1130 included in the data plane data layer 1150. The data plane data layer 1150 may include a DB subnet 1130 that may be communicatively connected to a service gateway 1136 included in the data plane VCN 1118.
[0151] The untrusted app subnet 1162 may include primary VNICs 1164(1)-(N) that may be communicatively connected to tenant virtual machines (VMs) 1166(1)-(N) that reside in the untrusted app subnet 1162. Each tenant VM 1166(1)-(N) may execute code within a respective container 1167(1)-(N) and be communicatively coupled to an app subnet 1126 that may be included within a data plane app layer 1146 that may be included within a container egress VCN 1168. Each secondary VNIC 1172(1)-(N) may facilitate communication between the untrusted app subnet 1162 included in the data plane VCN 1118 and the app subnet included in the container egress VCN 1168. The container egress VCN may include a NAT gateway 1138 that may be communicatively connected to the public Internet 1154 (e.g., public Internet 854 of FIG. 8 ).
[0152] An Internet gateway 1134 included in the control plane VCN 1116 and included in the data plane VCN 1118 may be communicatively connected to a metadata management service 1152 (e.g., metadata management system 852 of FIG. 8 ), which may be communicatively connected to the public Internet 1154. The public Internet 1154 may be communicatively connected to a NAT gateway 1138 included in the control plane VCN 1116 and included in the data plane VCN 1118. A service gateway 1136 included in the control plane VCN 1116 and included in the data plane VCN 1118 may be communicatively connected to cloud services 1156.
[0153] In some examples, the pattern illustrated by the architecture of block diagram 1100 of FIG. 11 may be considered an exception to the pattern illustrated by the architecture of block diagram 1000 of FIG. 10 and may be desirable for an IaaS provider's customer when the IaaS provider cannot communicate directly with the customer (e.g., in a disconnected area). Each container 1167(1)-(N) included in each customer's VM 1166(1)-(N) can be accessed by the customer in real time. The containers 1167(1)-(N) can be configured to call a respective secondary VNIC 1172(1)-(N) included in the app subnet 1126 of the data plane app tier 1146 that can be included in the container egress VCN 1168. The secondary VNIC 1172(1)-(N) can send the call to the NAT gateway 1138, which can send the call to the public Internet 1154. In this example, containers 1167(1)-(N) that a customer can access in real time can be isolated from control plane VCN 1116 and can be isolated from other entities included in data plane VCN 1118. Containers 1167(1)-(N) can also be isolated from resources of other customers.
[0154] In another example, a customer can invoke cloud service 1156 using container 1167(1)-(N). In this example, the customer can execute code in container 1167(1)-(N) that requests a service from cloud service 1156. Container 1167(1)-(N) can send the request to secondary VNIC 1172(1)-(N), which can send the request to a NAT gateway, which can send the request to public Internet 1154. Public Internet 1154 can send the request to LB subnet 1122 included in control plane VCN 1116 via Internet gateway 1134. In response to the request being determined to be valid, LB subnet can send the request to app subnet 1126, which can send the request to cloud service 1156 via service gateway 1136.
[0155] It should be understood that the IaaS architectures 800, 900, 1000, 1100 depicted in the figures may have components other than those depicted. Additionally, the embodiments depicted in the figures are only some examples of cloud infrastructure systems that may incorporate embodiments of the present disclosure. In some other embodiments, the IaaS systems may have more or fewer components than depicted in the figures, may combine two or more components, or may have a different configuration or arrangement of components.
[0156] In certain embodiments, the IaaS systems described herein may include a suite of application, middleware, and database service offerings that are delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. One example of such an IaaS system is Oracle Cloud Infrastructure (OCI), offered by the Assignee.
[0157] 12 illustrates an exemplary computer system 1200 upon which various embodiments may be implemented. System 1200 may be used to implement any of the computer systems described above. As shown, computer system 1200 includes a processing unit 1204 that communicates with a number of peripheral subsystems via a bus subsystem 1202. These peripheral subsystems may include a processing accelerator 1206, an I / O subsystem 1208, a storage subsystem 1218, and a communication subsystem 1224. The storage subsystem 1218 includes a tangible computer readable storage medium 1222 and a system memory 1210.
[0158] Bus subsystem 1202 provides mechanisms that allow the various components and subsystems of computer system 1200 to communicate with each other as intended. Although bus subsystem 1202 is shown diagrammatically as a single bus, alternative embodiments of the bus subsystem may use multiple buses. Bus subsystem 1202 may be any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures may include an Industry Standard Architecture (ISA) bus, a MicroChannel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus, which may be implemented as a mezzanine bus manufactured in accordance with the IEEE P1386.1 standard.
[0159] The processing unit 1204 may be implemented as one or more integrated circuits (e.g., conventional microprocessors or microcontrollers) and controls the operation of the computer system 1200. The processing unit 1204 may include one or more processors. These processors may include single-core processors or multi-core processors. In particular embodiments, the processing unit 1204 may be implemented as one or more independent processing units 1232 and / or 1234, with each processing unit including a single or multi-core processor. In other embodiments, the processing unit 1204 may be implemented as a quad-core processing unit formed by integrating two dual-core processors into one chip.
[0160] In various embodiments, the processing unit 1204 may execute various programs in response to program code and may maintain multiple simultaneously executing programs or processes. At any given time, some or all of the program code being executed may reside in the processor 1204 and / or in the storage subsystem 1218. With appropriate programming, the processor 1204 may provide the various functions described above. The computer system 1200 may further include a processing accelerator 1206, which may include a digital signal processor (DSP), special purpose processor, etc.
[0161] The I / O subsystem 1208 may include user interface input devices and user interface output devices. User interface input devices may include keyboards, pointing devices such as mice or trackballs, touch pads or touch screens integrated into displays, scroll wheels, click wheels, dials, buttons, switches, keypads, audio input devices with voice command recognition systems, microphones, and other types of input devices. User interface input devices may include motion sensing devices and / or gesture recognizers, such as, for example, a Microsoft Kinect® motion sensor. The Microsoft Kinect® motion sensor allows users to control and interact with input devices, such as a Microsoft Xbox® 360 game controller, through a natural user interface using gestures and voice commands. User interface input devices may also include eye gesture recognizers, such as a Google Glass® blink detector, that detects the user's eye movements (e.g., "blinking" when taking a picture and / or selecting a menu) and translates the eye gestures as input to an input device (e.g., Google Glass®). Additionally, the user interface input devices may include voice recognition sensing devices that allow a user to interact with a voice recognition system (e.g., the Siri® navigator) through voice commands.
[0162] User interface input devices may also include, but are not limited to, three-dimensional (3D) mice, joysticks or pointing sticks, game pads and graphic tablets, as well as audio / visual devices such as speakers, digital cameras, digital video cameras, portable media players, webcams, image scanners, fingerprint scanners, barcode readers 3D scanners, 3D printers, laser range finders, eye-tracking devices, etc. Additionally, user interface input devices may include medical imaging input devices such as, for example, computed tomography, magnetic resonance imaging, position emission tomography, medical ultrasound devices, etc. User interface input devices may also include audio input devices such as, for example, MIDI keyboards, digital musical instruments, etc.
[0163] User interface output devices may include display subsystems, indicator lights, or non-visual displays such as audio output devices. Display subsystems may be flat panel devices using cathode ray tubes (CRTs), liquid crystal displays (LCDs) or plasma displays, projection devices, touch screens, etc. In general, use of the term "output device" is intended to include any type of device or mechanism for outputting information from computer system 1200 to a user or to another computer. For example, user interface output devices may include, but are not limited to, a variety of display devices that visually convey text, graphics, or audio / video information, such as monitors, printers, speakers, headphones, automobile navigation systems, plotters, voice output devices, modems, etc.
[0164] Computer system 1200 may include a storage subsystem 1218 that includes software elements shown as currently located in system memory 1210. System memory 1210 may store program instructions that can be loaded and executed by processing unit 1204, as well as data generated during the execution of these programs.
[0165] Depending on the configuration and type of computer system 1200, the system memory 1210 may be volatile (e.g., random access memory (RAM)) and / or non-volatile (e.g., read only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that are immediately accessible by and / or currently being operated on and executed by the processing unit 1204. In some implementations, the system memory 1210 may include a number of different types of memory, such as static random access memory (SRAM) and dynamic random access memory (DRAM). In some implementations, a basic input / output system (BIOS), containing the basic routines that help to transfer information between elements within the computer system 1200, such as during start-up, may typically be stored in ROM. By way of example and not limitation, the system memory 1210 may also illustrate application programs 1212, program data 1214, and an operating system 1216, which may include client applications, a web browser, a mid-tier application, a relational database management system (RDBMS), etc. As an example, operating system 1216 may include various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems, various commercially available UNIX® or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, Google Chrome® OS, etc.), and / or mobile operating systems such as iOS, Windows® Phone, Android® OS, BlackBerry® OS, and Palm® OS operating systems.
[0166] The storage subsystem 1218 may also provide a tangible computer-readable storage medium for storing the basic programming and data structures that provide the functionality of some embodiments. Software (programs, code modules, instructions) that, when executed by the processor, provide the above-described functionality may be stored in the storage subsystem 1218. These software modules or instructions may be executed by the processing unit 1204. The storage subsystem 1218 may also provide a repository for storing data used in accordance with the present disclosure.
[0167] Storage subsystem 1200 may also include a computer readable storage medium reader 1220 that may be further connected to a computer readable storage medium 1222. Computer readable storage medium 1222, together with and optionally coupled to system memory 1210, may comprehensively represent remote, local, fixed, and / or removable storage devices as well as storage media for temporarily and / or more permanently containing, storing, transmitting, and retrieving computer readable information.
[0168] The computer readable storage medium 1222 containing the code or portions of code may include any suitable medium known or used in the art, including storage media and communication media, such as, but not limited to, volatile and non-volatile, removable and non-removable media implemented in any manner or technology for storing and / or transmitting information. This may include tangible computer readable storage media, such as RAM, ROM, Electronically Erasable Programmable ROM (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage, or other tangible computer readable medium. This may also include intangible computer readable media, such as data signals, data transmissions, or other media that can be used to transmit the required information and that can be accessed by the computing system 1200.
[0169] As an example, the computer readable storage medium 1222 may include hard disk drives that read from or write to non-removable non-volatile magnetic media, magnetic disk drives that read from or write to removable non-volatile magnetic disks, and optical disk drives that read from or write to removable non-volatile optical disks such as CD ROMs, DVDs, Blu-Ray® disks, or other optical media. The computer readable storage medium 1222 may include, but is not limited to, Zip® drives, flash memory cards, Universal Serial Bus (USB) flash drives, Secure Digital (SD) cards, DVD disks, digital video tapes, and the like. The computer readable storage medium 1222 may also include solid state drives (SSDs) based on non-volatile memory such as flash memory-based SSDs, enterprise flash drives, solid state ROMs, SSDs based on volatile memory such as solid state RAM, dynamic RAM, static RAM, DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs that use a combination of DRAM and flash memory-based SSDs. The disk drives and their associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for computer system 1200.
[0170] The communication subsystem 1224 provides an interface to other computer systems and networks. The communication subsystem 1224 serves as an interface for sending and receiving data from the computer system 1200 to and from other systems. For example, the communication subsystem 1224 allows the computer system 1200 to connect to one or more devices via the Internet. In some embodiments, the communication subsystem 1224 may include a wireless voice and / or data network (e.g., using radio frequency (RF) transceiver components for accessing cellular technology, advanced data network technologies such as 3G, 4G, EDGE (enhancing data rates as the world evolves), WiFi (IEEE 802.11 family standard, or other mobile communication technologies, or any combination thereof), global positioning system (GPS) receiver components, and / or other components). In some embodiments, the communication subsystem 1224 may provide a wired network connection (e.g., Ethernet) in addition to or instead of a wireless interface.
[0171] In some embodiments, the communications subsystem 1224 may also receive incoming communications in the form of structured and / or unstructured data feeds 1226, event streams 1228, event updates 1230, etc., on behalf of one or more users who may be using the computer system 1200.
[0172] As an example, the communications subsystem 1224 may be configured to receive data feeds 1226 in real time from users of social networks and / or other communications services, such as web feeds, such as Twitter® feeds, Facebook® updates, Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third party information sources.
[0173] Additionally, the communications subsystem 1224 may be configured to receive data in the form of a continuous data stream. The continuous data stream may include an event stream 1228 of real-time events and / or event updates 1230, and may be continuous or unlimited in nature without an explicit end. Examples of applications that generate continuous data may include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automobile traffic monitoring, and the like.
[0174] The communications subsystem 1224 may also be configured to output structured and / or unstructured data feeds 1226, event streams 1228, event updates 1230, etc. to one or more databases that can communicate with one or more streaming data source computers coupled to the computer system 1200.
[0175] The computer system 1200 may be any of a variety of types, including a handheld portable device (e.g., an iPhone® mobile phone, an iPad® computing tablet, a PDA), a wearable device (e.g., a Google Glass® head mounted display), a PC, a workstation, a mainframe, a kiosk, a server rack, or other data processing system.
[0176] Due to the ever-changing nature of computers and networks, the description of computer system 1200 shown in the figure is intended as a specific example only. Many other configurations are possible having more or fewer components than the system shown in the figure. For example, customized hardware may also be used, and / or particular elements may be implemented in hardware, firmware, software (including applets), or a combination thereof. Additionally, connections to other computing devices, such as network input / output devices, may also be used. Based on the disclosure and teachings provided herein, one of ordinary skill in the art will appreciate other ways and / or techniques for implementing various embodiments.
[0177] Although specific embodiments have been described, various modifications, variations, alternative configurations, and equivalents are within the scope of the present disclosure. The embodiments are not limited to operating in a particular data processing environment, but can freely operate in multiple data processing environments. For example, the embodiments can be implemented using a computer program product that includes computer programs / instructions that, when executed by a processor, cause the processor to perform any of the methods described in the present disclosure. Furthermore, while the embodiments are described using a particular sequence of transactions and steps, it should be apparent to one skilled in the art that the scope of the present disclosure is not limited to the sequence of transactions and steps described. Various features and aspects of the above-described embodiments can be used individually or in combination.
[0178] Additionally, while the embodiments are described using specific hardware and software combinations, it should be appreciated that other hardware and software combinations are within the scope of the present disclosure. The embodiments may be implemented using only hardware, only software, or a combination thereof. The various processes described herein may be implemented on any combination of the same or different processors. Thus, when a component or module is described as being configured to perform a certain operation, such configuration may be achieved, for example, by designing an electronic circuit to perform the operation, by programming a programmable electronic circuit (e.g., a microprocessor) to perform the operation, or any combination thereof. The processes may communicate using a variety of techniques, including, but not limited to, conventional techniques for inter-process communication, and different pairs of processes may use different techniques, or the same pair of processes may use different techniques at different times.
[0179] Accordingly, the specification and drawings are to be regarded in an illustrative, rather than a restrictive, sense. However, it will be apparent that additions, subtractions, deletions, and other modifications and alterations are possible without departing from the broader spirit and scope of the invention as defined in the claims. Thus, although certain disclosed embodiments have been described, they are not intended to be limiting. Various modifications and equivalents are within the scope of the following claims.
[0180] The use of the terms "a" and "an" and "the" and similar referents in the context of describing the disclosed embodiments (particularly in the context of the claims below) shall be interpreted to cover both the singular and the plural, unless otherwise stated herein or clearly contradicted by context. The terms "comprise", "have", "include", and "contain" shall be interpreted as open-ended terms (i.e., meaning "including, but not limited to"), unless otherwise stated. The term "connected" shall be interpreted as being partially or wholly contained, connected, or coupled, even if there is something intervening. The recitation of ranges of values herein is intended only to serve as a shorthand method of individually referring to each individual value contained within the range, unless otherwise stated herein, and each individual value is incorporated into the specification as if it were individually set forth herein. All methods described herein may be performed in any suitable order, unless otherwise stated herein or clearly contradicted by context. Any examples provided herein, or the use of exemplary language (e.g., "etc.") are intended only to more clearly illustrate the embodiments, and do not limit the scope of the disclosure, unless specifically claimed. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0181] Disjunctions such as the phrase "at least one of X, Y, or Z," unless otherwise noted, are generally intended to be understood within the context in which they are used to indicate that an item, term, etc. can be either X, Y, Z, or any combination thereof (e.g., X, Y, and / or Z). Thus, such disjunctions are generally not intended to, and should not, imply that an embodiment requires that at least one of X, at least one of Y, or at least one of Z, respectively, be present.
[0182] Preferred embodiments of the present disclosure are described herein, including the best mode known for carrying out the present disclosure. Variations of these preferred embodiments will become apparent to those skilled in the art upon reading the foregoing description. Those skilled in the art will be able to adopt such variations as necessary, and the disclosure may be carried out in a manner other than as specifically described herein. Accordingly, the present disclosure includes all modifications and equivalents of the subject matter described in the claims appended hereto as permitted by applicable law. Moreover, unless otherwise stated herein, any combination of any possible variations of the above elements is encompassed in the present disclosure.
[0183] All references cited in this specification, including publications, patent applications, and patents, are herein incorporated by reference to the same extent as if each reference was individually and specifically indicated to be incorporated by reference and was set forth in its entirety herein.
[0184] example In the following sections, further exemplary embodiments are provided.
[0185] Example 1 may include a method for facilitating multi-domain login, the method including receiving a request to log in to a network of a cloud service provider (CSP), identifying login credentials received in the request, obtaining authentication information associated with the request from two or more domains of the cloud service provider, determining whether to provide access to the network based at least in part on the login credentials and the authentication information, and providing access to the network in accordance with a decision to provide access to the network or denying access to the network in accordance with a decision not to provide access to the network.
[0186] Example 2 may include the method of example 1, in which obtaining authentication information includes obtaining authentication information from a home domain of an account associated with the request and a first affiliation domain of the account.
[0187] Example 3 may include the method of Example 2, where obtaining the authentication information includes obtaining first authentication information from a home domain, obtaining second authentication information from a first subscription domain, and combining the first authentication information and the second authentication information to generate the authentication information.
[0188] Example 4 may include the method of Example 3, where combining the first credential and the second credential includes generating a combined credential including the first credential and the second credential, identifying a first copy of the particular credential in the combined credential (wherein the first copy of the particular credential is from the first credential), identifying a second copy of the particular credential in the combined credential (wherein the second copy of the particular credential is from the second credential), and removing either the first copy or the second copy of the particular credential from the combined credential to generate the credential.
[0189] Example 5 may include the method of example 1, wherein the authentication information includes one or more previously used one-time passwords corresponding to an account associated with the request, and the login credentials include the one-time password provided in the request, and determining whether to provide access to the network includes determining to provide access to the network based at least in part on the one-time password being absent from the one or more previously used one-time passwords.
[0190] Example 6 may include the method of example 1, further including identifying authentication data included in the login credentials, storing the authentication data in a first area of the two or more areas used for future login attempts, and storing the authentication data in a second area of the two or more areas used for future login attempts.
[0191] Example 7 may include the method of Example 6, where storing the authentication data in the second domain includes replicating the authentication data from the first domain to the second domain via synchronized backchannel communication between the first domain and the second domain.
[0192] Example 8 may include the method of example 1, where the request is received at a first domain of the cloud service provider that is separate from the two or more domains, and obtaining the authentication information includes making a backchannel call to the two or more domains to obtain the authentication information.
[0193] Example 9 may include the method of Example 1, where the two or more domains include a first domain and a second domain, and the method further includes determining that the first domain is unavailable, and obtaining the authentication information includes, based at least in part on the determination that the first domain is unavailable, bypassing the first backchannel call to the first domain to obtain the authentication information and making a second backchannel call to the second domain to obtain the authentication information.
[0194] Example 10 may include the method of Example 1, further including determining one or more areas available for login; presenting a user interface indicating the one or more available areas to select the login area from the one or more available areas; and identifying a selection of the login area from the one or more available areas, wherein a request is received at the login area based at least in part on the identification of the selection of the login area.
[0195] Example 11 may include one or more computer-readable media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including receiving a request to log in to a network of a cloud service provider (CSP); identifying login credentials received in the request; obtaining authentication information associated with the request from two or more domains of the cloud service provider; determining whether to provide access to the network based at least in part on the login credentials and the authentication information; and providing access to the network in accordance with a decision to provide access to the network or denying access to the network in accordance with a decision not to provide access to the network.
[0196] Example 12 may include the one or more computer-readable media of Example 11, where obtaining the authentication information includes obtaining first authentication information from a home domain of an account associated with the request, obtaining second authentication information from a first affiliation domain of the account, and combining the first authentication information and the second authentication information to generate the authentication information.
[0197] Example 13 may include the one or more computer-readable media of Example 11, wherein the authentication information includes one or more previously used one-time passwords corresponding to an account associated with the request, the login credentials include the one-time password provided in the request, and determining whether to provide access to the network includes determining to provide access to the network based at least in part on the one-time password being absent from the one or more previously used one-time passwords.
[0198] Example 14 may include the one or more computer-readable media of Example 11, where the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including identifying authentication data included in the login credential; providing the authentication data to a first field of the two or more fields for storage for use in future login attempts; and providing the authentication data to a second field of the two or more fields for storage for use in future login attempts.
[0199] Example 15 may include the one or more computer-readable media of Example 11, where obtaining the authentication information includes making a backchannel call to the two or more realms to obtain the authentication information.
[0200] Example 16 may include the one or more computer-readable media of Example 11, where the two or more regions include a first region and a second region, and the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including determining that the first region is unavailable, and obtaining the authentication information includes, based at least in part on the determination that the first region is unavailable, bypassing a first backchannel call to the first region to obtain the authentication information and making a second backchannel call to the second region to obtain the authentication information.
[0201] Example 17 may include the one or more computer-readable media of Example 11, where the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including determining one or more areas available for login; presenting a user interface indicating the one or more available areas to select a login area from the one or more available areas; and identifying a selection of the login area from the one or more available areas, where the request is received at the login area based at least in part on the identification of the selection of the login area.
[0202] Example 18 may include a server device having a memory that stores login credentials received in the request and one or more processors coupled to the memory, where the one or more processors receive a request to log in to a network of a cloud service provider (CSP), identify the login credentials received in the request, store the login credentials in the memory, obtain authentication information associated with the request from two or more domains of the cloud service provider, determine whether to provide access to the network based at least in part on the login credentials and the authentication information, and provide access to the network in accordance with a decision to provide access to the network or deny access to the network in accordance with a decision not to provide access to the network.
[0203] Example 19 may include the server device of example 18, obtaining authentication information from a home domain of an account associated with the request and a first affiliation domain of the account.
[0204] Example 20 may include the server device of example 18, wherein the authentication information includes one or more previously used one-time passwords corresponding to an account associated with the request, and the login credentials include the one-time password provided in the request, and determining whether to provide access to the network includes determining to provide access to the network based at least in part on the one-time password being absent from the one or more previously used one-time passwords.
[0205] Example 21 illustrates a method for implementing a method for logging into a network of a cloud service provider (CSP), the method including: a computing device receiving a request to log into a network of a cloud service provider (CSP); the computing device identifying login credentials (including a passcode) received in the request; the computing device querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request (the first authentication information includes a first set of passcodes used to log into the network responsive to the first region being available); and the computing device querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request (the second authentication information includes a first set of passcodes used to log into the network responsive to the first region being available). the second set of passcodes used to log into the network or the second set of passcodes replicated from the first set of passcodes in response to the second domain being available; determining, by the computing device, whether or not the passcode has been used previously based at least in part on one or more responses received in response to the query to the first data center or the query to the second data center; determining, by the computing device, whether or not to provide access to the network based at least in part on whether the passcode has been used previously; and providing, by the computing device, access to the network in accordance with the determination to provide access to the network.
[0206] Example 22 may include the method of example 21, wherein the first domain includes a home domain of an account associated with the request and the second domain includes a first subscription domain associated with the account.
[0207] Example 23 may include the method of Example 22, further including: the computing device receiving one or more responses, the one or more responses including a first set of passcodes from the first data center and a second set of passcodes from the second data center; and combining the first set of passcodes and the second set of passcodes to generate a combined set of passcodes, wherein the determination of whether the passcode has been previously used is based at least in part on the combined set of passcodes.
[0208] Example 24 may include the method of Example 23, where combining the first set of passcodes and the second set of passcodes includes generating a passcode combination set including a first passcode from the first set of passcodes and a second passcode from the second set of passcodes, identifying a first copy of a particular passcode in the passcode combination set, where the first copy of the particular passcode is from the first set of passcodes, identifying a second copy of a particular passcode in the passcode combination set, where the second copy of the particular passcode is from the second set of passcodes, and removing either the first copy or the second copy of the particular passcode from the passcode combination set to generate the combined set of passcodes.
[0209] Example 25 may include the method of example 21, where the first set of passcodes includes a first set of one or more previously used one-time passwords corresponding to an account associated with the request, the second set of passcodes includes a second set of one or more previously used one-time passwords corresponding to the account, and the passcode includes a one-time password provided in the request, and determining whether the passcode has been previously used includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.
[0210] Example 26 may include the method of Example 21, further including identifying authentication data included in the login credentials, storing the authentication data in a first data center for use in future login attempts, and storing the authentication data in a second data center for use in future login attempts.
[0211] Example 27 may include the method of Example 26, wherein storing the authentication data at the second data center includes replicating the authentication data from the first data center to the second data center via synchronized backchannel communication between the first data center and the second data center.
[0212] Example 28 may include the method of Example 21, where the request is received at a third data center of the cloud service provider located in a third region separate from the first region and the second region, and the query to the first data center includes making a first backchannel call to the first data center to obtain a first set of passcodes, and the query to the second data center includes making a second backchannel call to the second data center to obtain a second set of passcodes.
[0213] Example 29 may include the method of Example 21, further including determining that the first data center is unavailable, where the querying the first data center includes bypassing a first backchannel call to the first data center to obtain a first set of passcodes based at least in part on the determination that the first data center is unavailable, and where the querying the second data center includes making a second backchannel call to the second data center to obtain a second set of passcodes.
[0214] Example 30 may include the method of Example 21, and further include determining one or more areas available for login; presenting a user interface indicating the one or more available areas to select a login area from the one or more available areas; and identifying a selection of a first area from the one or more available areas, where the request is received at the computing device in the first area based at least in part on the identification of the selection of the first area.
[0215] Example 31 may include one or more non-transitory computer-readable media having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to perform operations including receiving a request to log into a network of a cloud service provider (CSP); identifying login credentials received in the request, the login credentials including a passcode; querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network responsive to the first region being available; and querying a first data center of the cloud service provider located in a second region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network responsive to the first region being available. the second data center of the service provider for second authentication information associated with the request (the second authentication information including a second set of passcodes used to log into the network or replicated from the first set of passcodes responsive to the second domain being available); determining whether the passcode has been previously used based at least in part on one or more responses received in response to the query of the first data center or the query to the second data center; determining whether to provide access to the network based at least in part on whether the passcode has been previously used; and providing access to the network in accordance with the decision to provide access to the network.
[0216] Example 32 may include the non-transitory one or more computer-readable media of Example 31, where the first region includes a home region of an account associated with the request and the second region includes a first subscription region of the account, and the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including combining the first set of passcodes and the second set of passcodes to generate a combined set of passcodes.
[0217] Example 33 may include the non-transitory one or more computer-readable media of Example 31, where the first set of passcodes includes a first set of one or more previously used one-time passwords corresponding to an account associated with the request, and the second set of passcodes includes a second set of one or more previously used one-time passwords corresponding to the account, the passcodes including a one-time password provided in the request, and determining whether the passcode has been previously used includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.
[0218] Example 34 may include the non-transitory one or more computer-readable media of Example 31, where the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including identifying authentication data included in the login credentials; providing the authentication data to a first data center for storage and use in future login attempts; and providing the authentication data to a second data center for storage and use in future login attempts.
[0219] Example 35 may include the non-transitory one or more computer-readable media of Example 31, where the query to the first data center includes making a first backchannel call to the first data center and the query to the second data center includes making a second backchannel call to the second data center.
[0220] Example 36 may include the non-transitory one or more computer-readable media of Example 31, where the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including determining that the first datacenter is unavailable, where querying the first datacenter includes bypassing a first backchannel call to the first datacenter to obtain a first set of passcodes based at least in part on the determination that the first datacenter is unavailable, and where querying the second datacenter includes making a second backchannel call to the second datacenter to obtain a second set of passcodes.
[0221] Example 37 may include the non-transitory one or more computer-readable media of Example 31, where the instructions, when executed by the one or more processors, further cause the one or more processors to perform operations including determining one or more areas available for login; presenting a user interface indicating the one or more available areas for selecting a login area from the one or more available areas; and identifying a selection of a first area from the one or more available areas, where the request is received in the first area based at least in part on the identification of the selection of the first area.
[0222] Example 38 may include a server apparatus including a memory that stores login credentials received in a request and one or more processors coupled to the memory, the one or more processors receiving a request to log into a network of a cloud service provider (CSP), identifying the login credentials (including a passcode) received in the request, storing the login credentials in the memory, querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network responsive to the first region being available, and querying a cloud service provider located in a second region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network responsive to the first region being available, and and querying a second data center of the service provider for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or replicated from the first set of passcodes responsive to the second realm being available; determining whether the passcode has been previously used based at least in part on one or more responses received in response to the query to the first data center or the query to the second data center; determining whether to provide access to the network based at least in part on whether the passcode has been previously used; and providing access to the network in accordance with the decision to provide access to the network.
[0223] Example 39 may include the server device of example 38, wherein the first domain includes a home domain of an account associated with the request and the second domain includes a first affiliation domain of the account.
[0224] Example 40 may include the server device of example 38, wherein the first set of passcodes includes a first set of one or more previously used one-time passwords corresponding to an account associated with the request, the second set of passcodes includes a second set of one or more previously used one-time passwords corresponding to the account, and the passcode includes a one-time password provided in the request, and determining whether the passcode has been previously used includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.
[0225] In the foregoing specification, aspects of the disclosure have been described with reference to specific embodiments thereof, but those skilled in the art will appreciate that the disclosure is not limited thereto. Various features and aspects of the above disclosure may be used individually or in combination. Furthermore, various modifications and equivalents include relevant appropriate combinations of the features disclosed in the embodiments. The embodiments may be used in any number of environments and applications other than those described herein without departing from the broader spirit and scope of the specification. The specification and drawings should therefore be regarded as illustrative rather than restrictive.
Claims
1. 1. A method comprising: receiving, by a computing device, a request to log into a network of a cloud service provider (CSP); the computing device identifying login credentials received in the request, the login credentials including a passcode; the computing device querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network, the method further comprising: the computing device querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or cloned from the first set of passcodes, the method further comprising: determining, by the computing device, whether the passcode has been used before based at least in part on one or more responses received in response to the query to the first data center and / or the query to the second data center; determining whether to provide access to the network based at least in part on whether the passcode has been used before; the computing device providing access to the network in accordance with the determination to provide access to the network.
2. The method of claim 1 , wherein the first realm comprises a home realm of an account associated with the request, and the second realm comprises a first subscription realm associated with the account.
3. The method further includes the computing device receiving the one or more responses, the one or more responses including the first set of passcodes from the first data center and the second set of passcodes from the second data center, the method further including:
3. The method of claim 1 or claim 2, comprising combining the first set of passcodes and the second set of passcodes to generate a combined set of passcodes, and determining whether the passcode has been used previously is based at least in part on the combined set of passcodes.
4. Combining the first set of passcodes and the second set of passcodes may include: generating a combination set of passcodes including a first passcode from the first set of passcodes and a second passcode from the second set of passcodes; and identifying a first copy of a particular passcode within the combination set of passcodes, wherein the first copy of the particular passcode is from the first set of passcodes, and combining the first set of passcodes with the second set of passcodes further comprises: identifying a second copy of the particular passcode in the combination set of passcodes, the second copy of the particular passcode being from the second set of passcodes, and combining the first set of passcodes and the second set of passcodes further comprises: The method of claim 3 , comprising removing either the first copy or the second copy of the particular passcode from the combined set of passcodes to generate the combined set of passcodes.
5. 3. The method of claim 1 or 2, wherein the first set of passcodes includes a first set of one or more previously used one-time passwords corresponding to an account associated with the request, the second set of passcodes includes a second set of one or more previously used one-time passwords corresponding to the account, the passcodes including a one-time password provided in the request, and determining whether the passcode has been used before includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.
6. identifying authentication data included in the login credentials; storing the authentication data at the first data center for use in future login attempts; The method of claim 1 or 2, further comprising: storing the authentication data at the second data center for use in future login attempts.
7. 7. The method of claim 6, wherein storing the authentication data at the second data center comprises replicating the authentication data from the first data center to the second data center via synchronized back-channel communication between the first data center and the second data center.
8. 3. The method of claim 1, wherein the request is received at a third data center of the cloud service provider located in a third region separate from the first region and the second region, and wherein querying the first data center includes making a first backchannel call to the first data center to obtain the first set of passcodes, and querying the second data center includes making a second backchannel call to the second data center to obtain the second set of passcodes.
9. determining that the first data center is unavailable; querying the first data center includes, based at least in part on a determination that the first data center is unavailable, bypassing a first backchannel call to the first data center to obtain the first set of passcodes; The method of claim 1 or 2, wherein querying the second data center includes making a second backchannel call to the second data center to obtain the second set of passcodes.
10. determining one or more realms available for login; presenting a user interface showing the one or more available areas for selecting a login area from the one or more available areas; 3. The method of claim 1, further comprising: identifying a selection of the first region from the one or more available regions; and wherein the request is received at the computing device within the first region based at least in part on the identification of the selection of the first region.
11. 1. A computer program comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a plurality of operations, the plurality of operations comprising: receiving a login request to a cloud service provider (CSP) network; and identifying login credentials received in the request, the login credentials including a passcode, and the actions include: querying a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network, the plurality of operations comprising: querying a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or cloned from the first set of passcodes, the plurality of operations comprising: determining whether the passcode has been used before based at least in part on one or more responses received in response to the query to the first data center and / or the query to the second data center; determining whether to provide access to the network based at least in part on whether the passcode has been used before; providing access to the network in accordance with the decision to provide access to the network.
12. the first realm includes a home realm of an account associated with the request, and the second realm includes a first subscribed realm of the account, and the instructions, when executed by the one or more processors, further cause the one or more processors to:
12. The computer program product of claim 11, configured to perform operations including combining the first set of passcodes and the second set of passcodes to generate a combined set of passcodes.
13. 13. The computer program product of claim 11 or 12, wherein the first set of passcodes includes a first set of one or more previously used one-time passwords that correspond to an account associated with the request, the second set of passcodes includes a second set of one or more previously used one-time passwords that correspond to the account, the passcodes including a one-time password provided in the request, and determining whether the passcode has previously been used includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.
14. The computer program, when executed by the one or more processors, further causes the one or more processors to: identifying authentication data included in the login credentials; providing the authentication data to a first data center for storage and use in future login attempts; and providing the authentication data to the second data center for storage and use in future login attempts.
15. 13. The computer program product of claim 11 or 12, wherein querying the first data center includes making a first backchannel call to the first data center, and querying the second data center includes making a second backchannel call to the second data center.
16. The computer program, when executed by the one or more processors, further causes the one or more processors to: performing a plurality of operations including determining that the first data center is unavailable; querying the first data center includes, based at least in part on the determination that the first data center is unavailable, bypassing a first backchannel call to the first data center to obtain the first set of passcodes; 13. The computer program product of claim 11 or 12, wherein querying the second data center includes making a second backchannel call to the second data center to obtain the second set of passcodes.
17. The program, when executed by the one or more processors, further causes the one or more processors to: determining one or more realms available for login; presenting a user interface showing the one or more available areas for selecting a login area from the one or more available areas; and identifying a selection of the first region from the one or more available regions, wherein the request is received at the first region based at least in part on the identification of the selection of the first region.
18. A server device, a memory for storing the login credentials received in the request; one or more processors coupled to the memory, the one or more processors: configured to receive the login request to a cloud service provider (CSP) network; configured to identify the login credentials received in the request, including a passcode; configured to store the login credentials in the memory; configured to query a first data center of the cloud service provider located in a first region for first authentication information associated with the request, the first authentication information including a first set of passcodes used to log into the network, and the one or more processors further: configured to query a second data center of the cloud service provider located in a second region for second authentication information associated with the request, the second authentication information including a second set of passcodes used to log into the network or replicated from the first set of passcodes, and the one or more processors further: configured to determine whether the passcode has been used previously based at least in part on one or more responses received in response to the query to the first data center and / or the query to the second data center; configured to determine whether to provide access to the network based at least in part on whether the passcode has been used previously; a server device configured to provide access to the network in accordance with a decision to provide access to the network;
19. 20. The server device of claim 18, wherein the first realm includes a home realm of an account associated with the request, and the second realm includes a first affiliation realm of the account.
20. 19. The server device of claim 18, wherein the first set of passcodes includes a first set of one or more previously used one-time passwords corresponding to an account associated with the request, the second set of passcodes includes a second set of one or more previously used one-time passwords corresponding to the account, the passcodes including a one-time password provided in the request, and determining whether the passcode has previously been used includes determining whether the one-time password is included in the first set of one or more previously used one-time passwords or included in the second set of one or more previously used one-time passwords.