Quorum-Based Authorization
Patent Information
- Application Number
- JP2024540879
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-01-07
- Filing Date
- 2022-11-10
- Publication Date
- 2025-11-11
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Non-provisional Application No. 17 / 571,346, entitled "Quorum-based Authorization," filed on January 7, 2022, the entire disclosure of which is incorporated herein by reference for all purposes.
[0002] Field The present disclosure relates to a framework for determining authorization for access to infrastructure services of a cloud service provider. [Background technology]
[0003] background Cloud service providers (CSPs) use different systems and infrastructure services to provide various services to users or clients on demand. CSPs provide infrastructure services that can be used by clients to create their own networks and deploy customer resources. To ensure security and continued availability of the CSP's infrastructure services, authorization for users and / or clients to use and perform actions on the infrastructure services may be required to prevent malicious parties from accessing unauthorized data and / or attacking portions of the infrastructure services. Summary of the Invention [Problem to be solved by the invention]
[0004] Legacy approaches for users and / or clients to obtain authorization to use and perform actions on a CSP's infrastructure services often resulted in unauthorized access of the system by third parties and / or sharing of sensitive information about the users and / or clients that could be used to perform unauthorized actions. Legacy approaches also required pre-approved authorization to perform an action, with users and / or clients needing authorization to perform an action prior to requesting the action to be allowed to be performed.
[0005] overview The present disclosure generally relates to a framework for managing authorization for the execution of actions on a computing system, such as a cloud infrastructure service. Various embodiments are described herein, including methods, systems, non-transitory computer-readable storage media that store programs, codes, or instructions executable by one or more processors, and the like. These exemplary embodiments are set forth not to limit or define the present disclosure, but to provide examples to aid in the understanding of the present disclosure. Additional embodiments are discussed in the Detailed Description section, and further descriptions are provided in the Detailed Description section. [Means for solving the problem]
[0006] An aspect of the disclosure includes one or more non-transitory computer-readable media having instructions stored thereon that, when executed by a computing system, may cause the computing system to receive a request for an action to be performed by the computing system, the request being directed to the one or more non-transitory computer-readable media received from a client device. The instructions, when executed by the computing system, may further cause the computing system to identify one or more authorizers, where an authorization for the action is to be received from the one or more authorizers, where the authorization corresponds to performing the action on the client device. The instructions, when executed by the computing system, may further cause the computing system to serialize one or more operations corresponding to the action and sign the serialized one or more operations with an elliptic curve digital signature algorithm. Additionally, the instructions, when executed by the computing system, may cause the computing system to initiate a query procedure for authorization of the action from each of the one or more authorizers to determine whether the one or more operations are authorized to be performed.
[0007] Aspects of the disclosure are directed to a method of determining authorization of an action for a cloud infrastructure service, the method including a security element receiving a request for an action to be performed by the cloud infrastructure service, the security element identifying one or more authorizers, where authorization for the action is to be received from the one or more authorizers, the authorization corresponding to execution of the action. The method may further include the security element determining one or more operations to be performed by the cloud infrastructure service to complete the action, the security element signing the one or more operations with an elliptic curve digital signature algorithm, and the security element storing the signed one or more operations. The method may further include the security element initiating a query procedure for authorization of the action based at least in part on a response received from the one or more authorizers.
[0008] An aspect of the disclosure includes a computing system, the computing system including a memory for storing operations for execution by the computing system, and one or more processors coupled to the memory, the one or more processors identifying a request for an action to be performed by the computing system, the request being received from a client device, the one or more processors identifying one or more authorizers, and authorization for the action being received from the one or more authorizers, the authorization being directed to the computing system corresponding to the execution of the action on the client device. The one or more processors may further determine one or more operations to be performed by the computing system to complete the action, serialize the one or more operations, and sign the serialized one or more operations by an elliptic curve digital signature algorithm. Furthermore, the one or more processors may store the signed serialized one or more operations in the memory, and initiate a query procedure for authorization of the action from the one or more authorizers.
[0009] The foregoing, together with other features and embodiments, will become more apparent upon reference to the following specification, claims, and accompanying drawings.
[0010] The features, embodiments, and advantages of the present disclosure will be better understood when the following detailed description is read in conjunction with the accompanying drawings. [Brief description of the drawings]
[0011] [Figure 1] FIG. 2 illustrates an example infrastructure services deployment configuration according to some embodiments. [Diagram 2] FIG. 1 illustrates an example authorization arrangement according to some embodiments. [Diagram 3]FIG. 1 illustrates an example data migration flow that may be implemented for authorization according to some embodiments. [Figure 4] FIG. 1 illustrates another example authorization arrangement according to some embodiments. [Diagram 5] FIG. 2 illustrates an example procedure for client authorization to perform an action according to some embodiments. [Figure 6] FIG. 13 illustrates another example procedure for client authorization to perform an action according to some embodiments. [Figure 7] FIG. 13 illustrates a first portion of another example procedure for client authorization to perform an action in accordance with some embodiments. [Figure 8] 8 illustrates a second portion of the example procedure of FIG. 7 according to some embodiments. [Figure 9] FIG. 1 is a block diagram illustrating one pattern for implementing a cloud infrastructure as a service system in accordance with at least one embodiment. [Figure 10] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system in accordance with at least one embodiment. [Figure 11] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system in accordance with at least one embodiment. [Figure 12] FIG. 1 is a block diagram illustrating another pattern for implementing a cloud infrastructure-as-a-service system in accordance with at least one embodiment. [Figure 13] FIG. 1 is a block diagram illustrating an example computer system in accordance with at least one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Detailed Description In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of some embodiments. It will be apparent, however, that various embodiments may be practiced without these specific details. The figures and descriptions are not intended to be limiting. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" should not necessarily be construed as preferred or advantageous over other embodiments or designs.
[0013] This disclosure describes techniques for performing authorization of users and / or clients (collectively referred to throughout this disclosure as “clients”) for access to and / or performance of actions on infrastructure services (e.g., cloud infrastructures of FIG. 9, FIG. 10, FIG. 11, and / or FIG. 12, etc.) provided by a cloud servicer provider (CSP). More specifically, real-time authorization may be provided, and the infrastructure service may seek to obtain authorization for the client in response to receiving a request for performance of the action from the client, rather than authorization being sought prior to the request for authorization. The infrastructure service may serialize one or more operations for performance of the action and may sign the serialized operations with an Elliptic Curve Digital Signature Algorithm (ECDSA). The infrastructure service may store the serialized operations and may thaw and perform the operations once authorization for the action to be performed by the client has been received.
[0014] A CSP may provide various services to clients on demand using different systems and infrastructure services (referred to herein as cloud infrastructure services). In some embodiments, a CSP may provide services under an infrastructure as a service (IaaS) model, where the CSP provides infrastructure services that can be used by a client to create its own network and deploy customer resources. The infrastructure provided by a CSP may include interconnected high performance computing resources, including various host machines (further referred to as hosts), memory resources, and network resources that form a physical network called a substrate network or underlay network. The infrastructure provided by a CSP may span one or more data centers, which may span geographically across one or more regions.
[0015] The CSP's physical network, which may include various host machines, memory resources, and / or network resources, may provide an underlying foundation for creating one or more virtual or overlay networks on top of the physical network. These virtual or overlay networks (also called software-based or software-defined networks) may be realized using software virtualization techniques to create a layer of network abstraction that may be implemented on top of the physical network. Overlay networks may take many forms. Overlay networks may use Layer 3 IP addressing, with endpoints specified by their virtual IP addresses. This method of overlay networking is often referred to as virtual Layer 3 networking.
[0016] When a client subscribes to or registers for an IaaS service offered by a CSP, a tenancy may be created for the client; the tenancy is a secure and isolated partition within the CSP's infrastructure services where the client may create, organize, and manage the client's cloud resources. For example, the client may use the resources provided by the CSP to create one or more customizable and private virtual networks, called virtual cloud networks (VCNs), within the client's tenancy. One or more client resources, such as compute instances (e.g., virtual machines, bare metal instances, etc.), may be deployed on these client VCNs.
[0017] When a client attempts to access an infrastructure service to establish a tenancy or perform another action, the client may send a request to the infrastructure service requesting to establish a tenancy or perform that other action. The infrastructure service may receive the request and determine that the client is requesting the infrastructure service to perform the action. Based on the action and / or the client, the infrastructure service may determine that authorization is required from one or more authorizers to authorize the action to be performed for the client. The infrastructure service may identify one or more authorizers to provide authorization based on the client and / or action, if the authorizers may be predefined. The infrastructure service may provide one or more requests for authorization to perform the action for the client to each of the determined authorizers. The infrastructure service may monitor from the responses from the authorizers and determine whether the client is authorized to perform the action based on the responses from the authorizers.
[0018] Based on the action requested by the client, the infrastructure service may determine one or more operations to be performed by the infrastructure service to complete the action. In some embodiments, the client may be stateful, while the infrastructure service may be stateless. To facilitate this interfacing between stateful clients and stateless infrastructure services, the state associated with the action may be serialized and stored in a manner that may be unfrozen and validated once an authorization decision has been made by the infrastructure service. For example, the infrastructure service may serialize the operation associated with the action. The infrastructure service may sign the serialized operation with an Elliptic Curve Digital Signature Algorithm (ECDSA) and store the signed serialized operation. Using ECDSA for signing may use fewer clock cycles to cryptographically protect data compared to legacy approaches for the same level of cryptographic protection of the same data. Additionally, using ECDSA may result in the encrypted data being post-quantum secure.
[0019] If the infrastructure service determines that the action is authorized to be performed for the client, the infrastructure service may retrieve the signed serialized operation. The infrastructure service may verify that the serialized operation has not been tampered with based on the signature produced by signing the serialized operation. For example, the infrastructure service may verify that the signature corresponding to the signed serialized operation retrieved from storage matches the signature produced at the time the serialized operation was signed. If the infrastructure service verifies that the serialized operation has not been tampered with, the infrastructure service may perform the serialized operation. For example, the infrastructure service may perform the operation with a state specified by a stateful client.
[0020] FIG. 1 illustrates an example infrastructure service deployment 100 according to some embodiments. In particular, the infrastructure service deployment 100 illustrates a portion of an infrastructure service that may implement one or more of the approaches for determining authorization described throughout this disclosure. In some embodiments, the infrastructure service may include one or more features of the cloud infrastructure of FIG. 9, the cloud infrastructure of FIG. 10, the cloud infrastructure of FIG. 11, and / or the cloud infrastructure of FIG. 12. The infrastructure service may include a computing system. In some embodiments, the infrastructure service may include a cloud computing system. The infrastructure service may include infrastructure hardware and / or software that may provide services to clients.
[0021] An infrastructure service may include one or more devices 102 communicatively coupled to provide a portion of the infrastructure service. For example, the infrastructure service arrangement 100, in the illustrated embodiment, includes a first device 102a, a second device 102b, and a third device 102c. The devices 102 may include computing devices such as computer terminals, servers, other computing devices, or some combination thereof. The devices 102 may communicate with each other to form a portion of the infrastructure service, which may provide an infrastructure service such as a cloud infrastructure service.
[0022] The devices 102 may be grouped into different enclaves. For example, the first device 102a, the second device 102b, and the third device 102c may form part of an enclave 104 of an infrastructure service. The enclave 104 may perform specific operations. For example, the enclave 104 may include a management enclave that provides management operations, a service enclave that provides service operations, or a customer enclave that provides customer operations to clients. The enclave 104 may implement a software-defined perimeter (SDP) security model to create a protected IaaS instance. The enclave 104 may have a unique communication profile that may differ from other communication profiles of different enclaves in the infrastructure service. Access into and out of the enclave 104 may be controlled, monitored, and / or policy driven. For example, access to the enclave 104 may be based on authorization, and access to the enclave 104 may be restricted to authorized clients. The enclave 104 may require a client to receive authorization from one or more authorizers in order to provide access to the enclave 104. The enclave 104 may have an SDP defined that includes one or more devices (such as a first device 102a, a second device 102b, and a third device 102c) and / or certain software, and the edges of the enclave 104 are defined by the isolation of the devices and / or software from elements outside the enclave 104.
[0023] The enclave 104 may have a firewall 106 that protects against malicious network traffic. For example, the enclave 104 may have a software-based firewall 106 that monitors and protects against network traffic for the enclave 104. The firewall 106 may be located within the edge of the enclave 104 and may protect at least a portion of the devices and / or software of the enclave 104.
[0024] The infrastructure service may include one or more security elements, such as security element 108. Security element 108 may include a device, software, or some combination thereof. Security element 108 may be located at the edge of enclave 104. Additionally, security element 108 may be located outside firewall 106 of enclave 104. For example, security element 108 may be located at the edge of enclave 104 and / or outside firewall 106 to enable communication with security element 108 without accessing a secured portion of enclave 104.
[0025] The security element 108 may determine whether a client attempting to access the enclave 104 and / or infrastructure service is authorized to access the enclave 104 and / or infrastructure service. For example, the client may send a request for the enclave 104 and / or infrastructure service to perform one or more actions. The security element 108 may receive the request and determine whether the client has already received authorization to perform the one or more actions. If the security element 108 determines that the client already has authorization to access the enclave 104 and / or infrastructure service, the security element 108 may cause the enclave 104 and / or infrastructure service to perform the one or more actions requested by the client.
[0026] If the security element 108 determines that the client has not previously been provided with authorization to perform one or more actions, the security element 108 may initiate a procedure to determine whether the client should be granted authorization to perform one or more actions. For example, the security element 108 may identify one or more authorizers that may provide the client with authorization to perform one or more actions. An authorizer may include one or more individuals and / or one or more devices that may grant authorization to the client for one or more actions. An authorizer may be capable of granting authorization to the client to the infrastructure service and / or the enclave 104, to perform one or more actions, or some combination thereof. An authorizer may be predefined or may be defined at the time of the request.
[0027] Based on the security element 108 determining that the client has not previously been provided with authorization to perform the one or more actions, the security element 108 may not initially perform the one or more actions. In particular, the security element 108 may store the one or more actions until authorization is received from the authorizer, a predetermined amount of time for receiving authorization from the authorizer has expired, or the authorizer indicates that the client is not authorized to perform the one or more actions. The security element 108 may convert the one or more actions into one or more operations for storage, and the one or more operations will be executed to complete the one or more actions. The operations may be in a format that can be executed by the infrastructure service, whereas the actions may be in a different format.
[0028] A client may be stateful, while an infrastructure service may be stateless. To properly execute an operation, the infrastructure service may take into account the state of the operation when executing the operation. To ensure that the state is taken into account when the operation is executed, the operation may be stored by the infrastructure service in a format to maintain the state of the operation. For example, security element 108 may serialize the operation for storage. For example, security element 108 may convert the operation into a format that can be stored and subsequently reconstructed. Serialization of the operation may enable the infrastructure service to maintain the state of the operation while it is being executed by the stateless infrastructure service.
[0029] The security element 108 may further sign the operation. For example, the security element 108 may sign the serialized operation. The security element 108 may sign the operation with an Elliptic Curve Digital Signature Algorithm (ECDSA). For example, the security element 108 may utilize ECDSA with a key to generate a signature for signing the operation. The security element 108 may generate a signature based on the key, and the signature is associated with the signed operation. The security element 108 may maintain the key within the enclave 104, while the security element 108 may share the signature with a client requesting the action. The security element 108 may then store the signed serialized operation, such as in a memory of the infrastructure service. Using ECDSA for signing the operation may provide post-quantum security. For example, the cost of resources that it would take for a quantum computer to crack ECDSA would be more expensive than the data that ECDSA is protecting for post-quantum security. Additionally, using ECDSA may be faster than legacy approaches, such as in that ECDSA uses fewer clock cycles to protect the same level of data compared to legacy approaches.
[0030] The security element 108 may initiate a query procedure for authorization of an action from each of one or more authorizers to determine whether one or more operations are authorized to be performed. For example, the security element 108 may send one or more authorization requests to each of the authorizers, which may request a response from each of the authorizers as to whether the client is authorized for one or more actions requested by the client. The security element 108 may send the authorization request as a text message, email, push message, and / or other message that provides for a response by the authorizer. The authorization request may allow each of the authorizers to respond to indicate that the client is authorized or not authorized to perform the action. The security element 108 may monitor for a response to the authorization request from each of the one or more authorizers.
[0031] The security element 108 may determine whether the client has authorization to perform one or more actions based on responses, or lack thereof, received from the authorizers. For example, the security element 108 may receive responses from the authorizers in response to an authorization request previously provided by the security element 108. In some embodiments, the security element 108 may wait until responses are received from all authorizers before performing a determination of whether the client has authorization to perform one or more actions. The security element 108 may determine whether each of the responses from the authorizers indicates that the client is authorized to perform one or more actions or indicates that the client is not authorized to perform one or more actions. The security element 108 may determine that the client has authorization to perform one or more actions based on each of the responses indicating that the client has authorization to perform one or more actions. In contrast, the security element 108 may determine that the client does not have authorization to perform based on any of the responses indicating that the client is not authorized to perform one or more actions.
[0032] In other cases, the security element 108 may determine that the client has authorization based on a particular percentage of responses indicating that the client has authorization to perform one or more actions, or responses corresponding to a particular authorizer indicating that the client has authorization to perform one or more actions. For example, the security element 108 may determine that the client has authorization in some cases based on a greater number of responses indicating that the client has authorization to perform one or more actions than a number of responses indicating that the client is not authorized to perform one or more actions. In some cases, there may be certain authorizers and / or certain groups of authorizers that may provide authorization to perform one or more actions for a client regardless of the responses of other authorizers. For example, for any authorization request, regardless of the authorizer, the security element 108 may determine that a predefined authorizer or a predefined group of authorizers has indicated that the client has authorization to perform one or more actions, and may determine that the client has authorization for one or more actions based on an indication of the predefined authorizer or a predefined group of authorizers indicating that the client is authorized to perform one or more actions. In some cases, one or more of the authorizers may grant authorization in an alternative manner, such that if any one of a group of authorizers indicates that the client has authorization to perform one or more actions, the security element 108 may determine that the client has authorization to perform one or more actions.
[0033] In some cases, the security element 108 may implement a timer for a response from an authorizer to determine whether the client has authorization to perform one or more actions. For example, if the security element 108 determines that a corresponding response from an authorizer to provide authorization to the client for one or more actions is not received within a time period defined by the timer, the security element 108 may determine that the client does not have authorization to perform the one or more actions.
[0034] If the security element 108 determines, based on the response from the authorizer, that the client does not have authorization to perform the one or more actions, the security element 108 may not perform the operations associated with the one or more actions. The security element 108 may further remove stored operations from memory based on a determination that the client does not have authorization to perform the one or more actions.
[0035] If the security element 108 determines, based on the response from the authorizer, that the client has authorization to perform one or more actions, the security element 108 may perform the operation. For example, the security element 108 may retrieve the signed serialized operation from memory. The security element 108 may check the signature of the signed serialized operation to determine whether the operation has been tampered with. For example, the security element 108 may compare the signature of the signed serialized operation at the time of retrieval with the signature that was generated when the serialized operation was signed. If the signatures match, the security element 108 may determine that the operation has not been tampered with. If the signatures do not match, the security element 108 may determine that the operation has been tampered with.
[0036] If the security element 108 determines that the operation has been tampered with, the security element 108 may prevent the operation from being executed even if the security element 108 determines that the client has authorization to perform one or more actions. If the security element 108 determines that the operation has not been tampered with, the security element 108 may continue to cause the serialized operation to be executed. For example, the security element 108 may cause the serialized operation to be executed by an infrastructure service, where serialization of the operation ensures that the state is taken into account when executing the operation.
[0037] While infrastructure service arrangement 100 illustrates an embodiment of a portion of an infrastructure service, it should be understood that other embodiments of infrastructure services having features of infrastructure service arrangement 100 are to be encompassed by this disclosure. For example, an enclave (such as enclave 104) may be formed by one or more devices and / or one or more devices may be included in multiple enclaves. Additionally, an infrastructure service may include multiple enclaves rather than the single enclave illustrated. Each enclave may further include multiple security elements, each of which may be accessed by any of the clients, each of which may be dedicated to a corresponding client such that the corresponding client may have access to the corresponding security element, or some combination thereof.
[0038] 2 illustrates an example authorization arrangement 200 according to some embodiments. For example, the authorization arrangement 200 illustrates an example layout of devices for illustrating a quorum-based authorization technique according to some embodiments. It should be understood that the authorization arrangement 200 is a single embodiment used to illustrate the technique, and that implementation of the technique is not limited to the example layout illustrated.
[0039] Authorization arrangement 200 may include an enclave 202. Enclave 202 may include one or more of the features of enclave 104 (FIG. 1). Enclave 202 may include an infrastructure service, such as the infrastructure service described in connection with FIG. 1, or a portion thereof. The infrastructure service may, in some embodiments, include a computing system, such as a cloud computing system. Enclave 202 may include one or more security elements, such as illustrated security element 204. Security element 204 may include one or more of the features of security element 108 (FIG. 1).
[0040] The authorization arrangement 200 may include a client device 206. The client device 206 may include a single device, another infrastructure service, or a cloud computing system. In some embodiments, the client device 206 may be maintained by an operator separate from the enclave 202. The client device 206 may communicate with the enclave 202 over a network, such as over the Internet. In some embodiments, the client device 206, or a user utilizing the client device 206 (the client device 206 and the user may be referred to as a client), may be associated with a subscriber to an interface service (or an infrastructure service that includes the enclave 202) provided by the enclave 202, which may provide the service to the client device 206. In some embodiments, the subscriber may include an organization that may include multiple users and / or multiple client devices. The interface service may include a cloud computing service in some embodiments. The client device 206 may be able to request a service to be provided by the enclave 202. A user may utilize the client device 206 to access and request services from the enclave 202. For example, a user may be an individual who may sign in to the client device 206, and the user signing in to the client device 206 may verify the user's identity.
[0041] When a client device 206 requests an action and / or service from the enclave 202, the enclave 202 may perform an authorization procedure to determine whether the client device 206 and / or a user utilizing the client device 206 is authorized for the performance of the action and / or service. For example, the client device 206 may send a request to the enclave 202 for performance of one or more actions by the enclave 202 or an infrastructure service that includes the enclave 202. The security element 204 may receive the request from the client device 206 and may determine that the client device 206 is requesting one or more actions to be performed by the enclave 202 or an infrastructure service that includes the enclave 202.
[0042] Based on the request received from the client device 206, the security element 204 may determine the identity of the client device 206 sending the request and / or the user utilizing the client device 206. For example, the request received from the client device 206 may include an identifier corresponding to the client device 206, an identifier corresponding to the user utilizing the client device 206, or both. The security element 204 may determine whether the client device 206 and / or the user utilizing the client device 206 has previously been granted authorization for the performance of the action being requested. For example, the client device 206 may have previously provided for authorization for future performance of the type of action. The security element 204 may determine whether the action requested in the request falls into any of the types of actions for which the client device 206 and / or the user utilizing the client device 206 has previously received authorization to perform. If the security element 204 determines that authorization for the action has previously been presented to the client device 206 and / or a user utilizing the client device 206, the security element 204 may cause the enclave 202 and / or the infrastructure service to perform the action.
[0043] If the security element 204 determines that authorization for the action has not been previously presented to the client device 206 and / or the user utilizing the client device 206, the security element 204 may perform a procedure to determine whether the client device 206 and / or the user utilizing the client device 206 should receive authorization for the action based on the request. For example, the security element 204 may identify one or more authorizers that the client device 206 and / or the user utilizing the client device 206 may provide authorization for the action to be performed. An authorizer may be an individual, a device, or some combination thereof that has the ability to grant authorization to the client device 206 and / or the user utilizing the client device 206 for the performance of the action. The authorizer may be predefined or may be defined at the time of the request. The authorizer may be associated with the same subscriber as the client device 206 and / or the user utilizing the client device 206 or may be assigned by the subscriber. If the security element 204 determines that an authorizer is not assigned to the client device 206 and / or a user utilizing the client device 206 for performance of the action, the security element 204 may determine that the enclave 202 and / or the infrastructure service should not perform the action. If the security element 204 identifies one or more authorizers assigned to the client device 206 and / or a user utilizing the client device 206 for performance of the action, the security element 204 may continue to determine whether the client device 206 and / or a user utilizing the client device 206 should receive authorization for the action.
[0044] Because there may be a delay between the time the request is received and the time authorization is received from the authorizer, the security element 204 may store the action for future execution. The client device 206 may be stateful, whereas the enclave 202 and / or infrastructure services may be stateless. To properly execute an action, the state for the action may need to be taken into account. Thus, the security element 204 may store the action in some manner to maintain a state corresponding to the action. For example, the security element 204 may determine one or more operations to be performed by the enclave 202 and / or infrastructure services to complete the requested action. The security element 204 may store the operation in some format to maintain a state corresponding to the operation. For example, the security element 204 may serialize the operation for storage. The security element 204 may convert the operation into a format that can be stored and subsequently reconstructed. Serialization of operations may enable an enclave 202 and / or infrastructure service to maintain the state of an operation as it is being executed by a stateless enclave 202 and / or infrastructure service.
[0045] The security element 204 may further sign the operation for storage. Signing the operation may be utilized to verify that the operation has not been tampered with prior to execution by the enclave 202 and / or infrastructure services. The security element 204 may sign the operation with ECDSA. For example, the security element 204 may utilize ECDSA with a key to sign the operation. The ECDSA-produced signature and key may be associated with the operation. The security element 204 may maintain the key within the enclave 202, while the security element 204 may share the signature with the client device 206 that sent the request. The security element 204 may then store the signed and serialized operation, such as in memory of the security element 204, the enclave 202, and / or the infrastructure service. Using ECDSA for signing may provide post-quantum security and may utilize fewer clock cycles compared to legacy approaches.
[0046] The security element 204 may initiate an inquiry procedure to determine whether the client device 206 and / or a user utilizing the client device 206 should receive authorization for the performance of the action. The security element 204 may identify an account (such as an email account, messaging account, social media account, or other account to which the authorizer may be provided messages), phone number, device, or some combination thereof, for the identified authorizer to provide authorization to the client device 206 and / or a user utilizing the client device 206. The security element 204 may send one or more requests to each of the authorizers requesting a response indicating whether the client device 206 and / or a user utilizing the client device 206 should be granted authorization for the action. The request may include an indication of the client device 206 and / or a user of the client device 206 that seeks to obtain authorization for the action. The security element 204 may send the request to one or more of the account, phone number, device, or some combination thereof, for each of the authorizers. The request may require the authorizer to respond with an indication that the client device 206 and / or a user utilizing the client device 206 should or should not be provided with authorization for the action. In some cases, the security element 204 may send one or more repeat requests after the initial request requesting an indication of whether the client device 206 and / or a user of the client device 206 should or should not be granted authorization for the action.
[0047] The authorization arrangement 200 may include one or more authorizer devices 208, such as a first authorizer device 208a and a second authorizer device 208b. The authorizer devices 208 may correspond to one or more of the authorizers. For example, each of the authorizer devices 208 may include a device, one or more of the authorizers may have access to an account, phone number, and / or device to which a request is sent by the security element 204. Based on the identified authorizer, the security element 204 may, in some cases, identify an authorizer device 208 associated with the identified authorizer and send the request to the authorizer device 208. In some cases, the authorizer device 208 may include an input device that allows the authorizer to input an indication of whether the client device 206 and / or a user utilizing the client device 206 should be provided with authorization for an action.
[0048] The security element 204 may provide the request to each of the authorizer devices 208. For example, the security element 204 may send the request directly to each of the authorizer devices 208, to an account that may be accessed via the authorizer device 208, to a phone number associated with the authorizer device 208, or some combination thereof. In the illustrated embodiment, the security element 204 may send one or more requests to the first authorizer device 208a to seek instructions from the first authorizer and may send one or more requests to the second authorizer device 208b to seek instructions from the second authorizer. In some cases, the first authorizer device 208a and / or the second authorizer device 208b may display a user interface on the device that requests authorization instructions from the corresponding authorizer for the client device 206 and / or a user utilizing the client device 206. Each of the authorizer devices 208 may detect an indication from a corresponding authorizer of whether the client device 206 and / or a user utilizing the client device 206 should be provided with authorization for an action. Based on the indication received from the authorizer, the authorizer device 208 may transmit an indication of whether the client device 206 and / or a user of the client device 206 should be granted authorization for an action. In some cases, one or more of the authorizer devices 208 may not be provided with an indication by an authorizer, in which case one or more of the authorizer devices that do not receive the indication may not provide a response to the security element 204.
[0049] The security element 204 may monitor for responses from the authorizer devices 208 and may receive responses from the authorizer devices 208. For example, the security element 204 may receive a first response from a first authorizer device 208a corresponding to a first authorizer and a second response from a second authorizer device 208b corresponding to a second authorizer in the illustrated embodiment. The security element 204 may determine whether the client device 206 and / or a user of the client device 206 should be allowed authorization for the action. In some embodiments, the security element 204 may wait until responses are received from all authorizers to which a request was sent before determining whether the client device 206 and / or a user of the client device 206 should be allowed authorization for the action. If the security element 204 determines that all of the authorizers have indicated that the client device 206 and / or a user utilizing the client device 206 should be authorized for performing the action, the security element 204 may determine that the client device 206 and / or a user utilizing the client device 206 should be authorized for the action. If any of the authorizers have indicated that the client device 206 and / or a user utilizing the client device 206 should not be authorized for performing the action, the security element 204 may determine that the client device 206 and / or a user utilizing the client device 206 is not authorized to perform the action.
[0050] In some cases, the security element 204 may not require a unanimous indication from authorizers that the client device 206 and / or a user utilizing the client device 206 should be granted authorization to determine that the client device 206 and / or a user utilizing the client device 206 is authorized to perform an action. In these cases, the security element 204 may determine that the client has authorization based on a particular percentage of responses indicating that the client has authorization to perform the action, or a response corresponding to a particular authorizer indicates that the client has authorization to perform the action.
[0051] In some cases, the security element 204 may implement a timer for a response from an authorizer to determine whether the client has authorization to perform an action. For example, if the security element 204 determines that a corresponding response from an authorizer to provide authorization to the client device 206 and / or a user utilizing the client device 206 to perform an action is not received within a time period defined by a timer, the security element 204 may determine that the client device 206 and / or a user utilizing the client device 206 does not have authorization to perform the action.
[0052] If the security element 204 determines, based on the response from the authorizer, that the client does not have authorization to perform the action, the security element 204 may not perform the operation associated with the action. The security element 204 may further remove a stored operation from memory based on a determination that the client does not have authorization to perform the action.
[0053] If the security element 204 determines, based on the response from the authorizer, that the client has authorization to perform the action, the security element 204 may perform the operation. For example, the security element 204 may retrieve the signed serialized operation from memory. The security element 204 may check the signature of the signed serialized operation to determine whether the operation has been tampered with. For example, the security element 204 may compare the signature of the signed serialized operation at the time of retrieval with the signature that was generated when the serialized operation was signed. If the signatures match, the security element 204 may determine that the operation has not been tampered with. If the signatures do not match, the security element 204 may determine that the operation has been tampered with.
[0054] If the security element 204 determines that the operation has been tampered with, the security element 204 may prevent the operation from being executed. If the security element 204 determines that the operation has not been tampered with, the security element 204 may continue to cause the serialized operation to be executed. For example, the security element 204 may cause the serialized operation to be executed by the enclave 202 and / or infrastructure services, where serialization of the operation ensures that the state is taken into account when executing the operation.
[0055] 3 illustrates an example data migration flow 300 that may be implemented for authorization according to some embodiments. For example, a security element (such as security element 108 (FIG. 1) and / or security element 204 (FIG. 2)) may perform one or more of the migrations in some embodiments depending on an action received from a client device (such as client device 206 (FIG. 2)). The migrations and data structures shown in data migration flow 300 may facilitate storage of operations from a stateful system in a stateless system for later execution by the stateless system.
[0056] Data migration flow 300 may be initiated by an action 302. For example, the action 302 may be received by a security entity from a client device, where the action indicates an action on an enclave (such as enclave 104 (FIG. 1) and / or enclave 202 (FIG. 2)) and / or an interface corresponding to the security entity to perform on the client device. The security entity may determine that the action 302 should be stored for later execution.
[0057] The data migration flow 300 may include converting an action 302 into one or more operations 304. For example, a security element may convert an action 302 received from a client device into one or more operations 304. The one or more operations 304 may be performed by an enclave and / or an interface to complete the action 302. For example, the action 302 may be in a format that may not be performed by an enclave and / or infrastructure service, and the security element may convert the action 302 into one or more operations 304 that may be performed by an enclave and / or infrastructure service to complete the action 302. In other cases, the action 302 provided by a client device may be in a format that may be performed by an enclave and / or infrastructure service, and the action 302 may be utilized as one or more operations 304. In these cases, the conversion may be omitted.
[0058] The data migration flow 300 may include serializing one or more operations 304. For example, a security element may serialize one or more operations 304 to produce serialized operations 306. The security element may convert the operations into serialized operations 306 that may be stored and later reconstructed. The serialization of the operations may maintain a state corresponding to the operations. Thus, the enclave and / or infrastructure service may take the state of the operations into account when subsequently executing the operations. In some cases, serialization may be omitted.
[0059] The data migration flow 300 may include signing the serialized operation 306. For example, the security element may sign the serialized operation with ECDSA. The security element may have a key and generate a signature 308 with ECDSA and the key. The security element may sign the serialized operation 306 with the signature 308 to generate a signed serialized operation 310. In some cases, the security element may provide the signature 308 to a client device.
[0060] The data migration flow 300 may include unfreezing the signed serialized operation. For example, the security element may unfreeze the signed serialized operation for execution by the enclave and / or infrastructure service. Unfreezing the signed serialized operation may include verifying the signature 308 of the signed serialized operation to verify that the operation has not been tampered with between the time the serialized operation was signed and the time the signed serialized operation is unfrozen. Unfreezing the signed serialized operation may further include deserializing the operation to produce one or more operations 312 that may be executed by the enclave and / or infrastructure service. For example, the security element may convert the serialized operation into a format that may be executed by the enclave and / or infrastructure service. The security element may then cause the enclave and / or infrastructure service to execute the one or more operations 312.
[0061] 4 illustrates another example authorization arrangement 400 in accordance with some embodiments. For example, the authorization arrangement 400 shows an example in which a client device 402 requests that a load balancer 404 be created. A quorum-based authorization approach may be implemented in the authorization arrangement 400.
[0062] The authorization arrangement 400 may include a client device 402. The client device 402 may include one or more of the features of the client device 206 (FIG. 2). In the illustrated embodiment, the client device 402 may request that a load balancer 404 be generated by an enclave 406 and / or an infrastructure service (such as the infrastructure service described in connection with FIG. 1, the cloud infrastructure of FIG. 9, the cloud infrastructure of FIG. 10, the cloud infrastructure of FIG. 11, and / or the cloud infrastructure of FIG. 12, etc.). The load balancer 404 may be utilized to direct data transmitted by the client device 402 to the enclave 406 and / or the infrastructure service. For example, the load balancer 404 may be utilized to direct actions requested by the client device 402 or other devices among the enclave 406 and / or the infrastructure service.
[0063] Authorization arrangement 400 may include enclave 406. Enclave 406 may include one or more of the features of enclave 104 (FIG. 1) and / or enclave 202 (FIG. 2). Enclave 406 may include an infrastructure service, such as the infrastructure service described in connection with FIG. 1, or a portion thereof. The infrastructure service may, in some embodiments, include a computing system, such as a cloud computing system. Enclave 406 may include security element 408. Security element 408 may include one or more of the features of security element 108 (FIG. 1) and / or security element 204 (FIG. 2). Client device 402 may be coupled to and may communicate with enclave 406 over a network, such as over the Internet. In the illustrated embodiment, a client device 402, or a user utilizing the client device 402, may send a request to the enclave 406 requesting the creation of a load balancer 404 or another action including the creation of a load balancer 404. A security element 408 of the enclave 406 may receive the request and may determine whether the client device 402, and / or the user utilizing the client device 402, has authorization to have the load balancer 404 created or to have another action performed, including the creation of a load balancer 404. If the security element 408 determines that the client device 402, and / or the user utilizing the client device 402, has previously been granted authorization to have the load balancer 404 created or to have the action performed, the security element 408 may cause the enclave 406 and / or the infrastructure service to create the load balancer 404.
[0064] If the security element 408 determines that the client device 402 and / or the user utilizing the client device 402 has not previously been authorized to have the load balancer 404 created or the action performed, the security element 408 may perform a procedure to determine whether the client device 402 and / or the user utilizing the client device 402 should receive authorization to create the load balancer 404 and / or perform the action to create the load balancer 404. For example, the security element 408 may identify one or more authorizers that may provide authorization for the client device 402 and / or the user utilizing the client device 402 to create the load balancer 404 and / or perform the action to create the load balancer 404. The authorizers may be predefined or may be defined at the time of the request. The authorizers may be associated with the same subscriber as the client device 402 and / or the user utilizing the client device 402 or may be assigned by the subscriber.
[0065] The security element 408 may store the operation for the creation of the load balancer 404 and / or the action of creating the load balancer 404 for future execution. The operation may correspond to the creation of the load balancer 404 and / or the action that the enclave 406 and / or infrastructure service performing the operation will result in the creation of the load balancer 404 and / or the execution of the action. Because the client device 402 may be stateful and the enclave 406 and / or infrastructure service may be stateless, the enclave 406 and / or infrastructure service may take into account the state corresponding to the operation during future execution to properly create the load balancer 404 and / or execute the action. Thus, the security element 408 may store the operation in a state to maintain the state corresponding to the operation. For example, the security element 408 may serialize the operation for storage to maintain the state corresponding to the operation. Serialization of the operation may result in the operation being stored by the security element 408 in a format that can be subsequently reconstructed for execution by the enclave 406 and / or infrastructure services.
[0066] The security element 408 may further sign the operation for storage. Signing the operation may be utilized to verify that the operation has not been tampered with prior to execution by the enclave 406 and / or infrastructure services. The security element 408 may sign the operation with ECDSA. For example, the security element 408 may utilize ECDSA with a key to sign the operation. The ECDSA-produced signature and key may be associated with the operation. The security element 408 may maintain the key within the enclave 406, while the security element 408 may share the signature with the client device 402. The security element 408 may then store the signed and serialized operation in memory of the security element 408, the enclave 406, and / or the infrastructure service. Using ECDSA for signing may provide post-quantum security and may utilize fewer clock cycles compared to legacy approaches.
[0067] The security element 408 may initiate an inquiry procedure to determine whether the client device 402 and / or a user utilizing the client device 402 should receive authorization for the creation of the load balancer 404 and / or the execution of the action. The security element 408 may identify an account (such as an email account, messaging account, social media account, or other account to which the authorizer may be provided messages), phone number, device, or some combination thereof, for the identified authorizer to provide authorization to the client device 402 and / or a user utilizing the client device 402. The security element 408 may send one or more requests to each of the authorizers requesting a response indicating whether the client device 402 and / or a user utilizing the client device 402 should be allowed authorization for the creation of the load balancer 404 and / or the action. The requests may include an indication of the client device 402 and / or a user of the client device 402 seeking authorization for the creation of the load balancer 404 and / or the action. The security element 408 may send a request to one or more of the account, phone number, device, or some combination thereof for each of the authorizers. The request may request the authorizer to respond with an indication that the client device 402 and / or a user utilizing the client device 402 should or should not be provided with authorization for the creation and / or action of the load balancer 404. In some cases, the security element 408 may send one or more repeat requests after an initial request requesting an indication of whether the client device 402 and / or a user of the client device 402 should or should not be allowed to authorize the creation and / or action of the load balancer 404.
[0068] The authorization arrangement 400 may include one or more authorizer devices 410, such as a first authorizer device 410a and a second authorizer device 410b. The authorizer devices 410 may correspond to one or more of the authorizers. For example, each of the authorizer devices 410 may include a device, one or more of the authorizers may have access to an account, phone number, and / or device to which a request is sent by the security element 408. Based on the identified authorizer, the security element 408 may, in some cases, identify an authorizer device 410 associated with the identified authorizer and send the request to the authorizer device 410. In some cases, the authorizer device 410 may include an input device that allows the authorizer to input an indication of whether the client device 402 and / or a user utilizing the client device 402 should be provided with authorization to create the load balancer 404 and / or perform an action.
[0069] The security element 408 may provide the request to each of the authorizer devices 410. For example, the security element 408 may send the request directly to each of the authorizer devices 410, to an account that may be accessed via the authorizer device 410, to a phone number associated with the authorizer device 410, or some combination thereof. In the illustrated embodiment, the security element 408 may send one or more requests to the first authorizer device 410a to seek instructions from the first authorizer and may send one or more requests to the second authorizer device 410b to seek instructions from the second authorizer. In some cases, the first authorizer device 410a and / or the second authorizer device 410b may display a user interface on the device that requests authorization instructions from the corresponding authorizer for the client device 402 and / or a user utilizing the client device 402. Each of the authorizer devices 410 may detect an indication from a corresponding authorizer of whether the client device 402 and / or a user utilizing the client device 402 should be provided with authorization for the creation and / or execution of the action of the load balancer 404. Based on the indication received from the authorizer, the authorizer device 410 may send an indication of whether the client device 402 and / or a user of the client device 402 should be allowed authorization for the creation and / or execution of the action of the load balancer 404. In some cases, one or more of the authorizer devices 410 may not be provided with an indication by an authorizer, in which case one or more of the authorizer devices that do not receive the indication may not provide a response to the security element 408.
[0070] The security element 408 may monitor for responses from the authorizer devices 410 and may receive responses from the authorizer devices 410. For example, the security element 408 may receive a first response from a first authorizer device 410a corresponding to a first authorizer and a second response from a second authorizer device 410b corresponding to a second authorizer in the illustrated embodiment. The security element 408 may determine whether the client device 402 and / or a user of the client device 402 should be authorized for the creation and / or action of the load balancer 404. In some embodiments, the security element 408 may wait until responses are received from all authorizers to which requests were sent before determining whether the client device 402 and / or a user of the client device 402 should be authorized for the creation and / or action of the load balancer. If the security element 408 determines that all of the authorizers have indicated that the client device 402 and / or the user utilizing the client device 402 should be authorized to create and / or perform actions on the load balancer 404, the security element 408 may determine that the client device 402 and / or the user utilizing the client device 402 should be authorized to create and / or perform actions on the load balancer 404. If any of the authorizers have indicated that the client device 402 and / or the user utilizing the client device 402 should not be authorized to create and / or perform actions on the load balancer 404, the security element 408 may determine that the client device 402 and / or the user utilizing the client device 402 is not authorized to create and / or perform actions on the load balancer 404.
[0071] In some cases, the security element 408 may not require a unanimous indication from an authorizer that the client device 402 and / or a user utilizing the client device 402 should be granted authorization to determine that the client device 402 and / or a user utilizing the client device 402 is authorized to create a load balancer 404 and / or perform an action. In these cases, the security element 408 may determine that the client has authorization based on a particular percentage of responses indicating that the client has authorization to create a load balancer 404 and / or perform an action, or based on responses corresponding to a particular authorizer indicating that the client has authorization to create a load balancer 404 and / or perform an action.
[0072] In some cases, the security element 408 may implement a timer for a response from an authorizer to determine whether the client has authorization to create the load balancer 404 and / or perform the action. For example, if the security element 408 determines that a corresponding response from an authorizer providing authorization to the client device 402 and / or a user utilizing the client device 402 to create the load balancer 404 and / or perform the action has not been received within a time period defined by a timer, the security element 408 may determine that the client device 402 and / or a user utilizing the client device 402 does not have authorization to create the load balancer 404 and / or perform the action.
[0073] If the security element 408 determines, based on the response from the authorizer, that the client does not have authorization to create a load balancer 404 and / or perform the action, the security element 408 may not perform the operation associated with the creation of the load balancer 404 and / or the action. The security element 408 may further remove the stored operation from memory based on a determination that the client does not have authorization to create a load balancer 404 and / or perform the action.
[0074] If the security element 408 determines, based on the response from the authorizer, that the client has authorization to create a load balancer 404 and / or perform the action, the security element 408 may perform the operation. For example, the security element 408 may retrieve the signed serialized operation from memory. The security element 408 may check the signature of the signed serialized operation to determine whether the operation has been tampered with. For example, the security element 408 may compare the signature of the signed serialized operation at the time of retrieval with the signature that was generated when the serialized operation was signed. If the signatures match, the security element 408 may determine that the operation has not been tampered with. If the signatures do not match, the security element 408 may determine that the operation has been tampered with.
[0075] If the security element 408 determines that the operation has been tampered with, the security element 408 may prevent the operation from being executed. If the security element 408 determines that the operation has not been tampered with, the security element 204 may continue to cause the serialized operation to be executed. For example, the security element 408 may cause the serialized operation to be executed by the enclave 406 and / or the infrastructure service, where serialization of the operation ensures that the state is taken into account when executing the operation. The execution of the operation may result in the creation of a load balancer 404. In the illustrated embodiment, the load balancer 404 may be created within the enclave 406. In other embodiments, the load balancer 404 may be created within another part of the infrastructure service. In some embodiments, the security element 408 may create the load balancer 404 at the edge of the enclave 406. The load balancer 404 may be located inside the firewall of the enclave 406 or outside of the firewall.
[0076] FIG. 5 illustrates an example procedure 500 for authorization of a client to perform an action according to some embodiments. Procedure 500 may be performed by an infrastructure service (such as the infrastructure services described in connection with FIG. 1, which may include a computing system and / or a cloud computing system, the cloud infrastructure of FIG. 9, the cloud infrastructure of FIG. 10, the cloud infrastructure of FIG. 11, and / or the cloud infrastructure of FIG. 12), an enclave (such as enclave 104 (FIG. 1), enclave 202 (FIG. 2), and / or enclave 406 (FIG. 4)), a security element (such as security element 108 (FIG. 1), security element 204 (FIG. 2), and / or security element 408 (FIG. 4)), or some combination thereof. Procedure 500 may be performed to determine whether a client device (such as client device 206 (FIG. 2) and / or client device 402 (FIG. 4)) is authorized to perform an action (such as creating a load balancer (such as load balancer 404 (FIG. 4)).
[0077] For simplicity, procedure 500 is described herein as being performed by a computing system, but it should be understood that procedure 500 may be performed by an infrastructure service, an enclave, a security element, or some combination thereof. In some embodiments, the computing system may include a cloud infrastructure service.
[0078] At 502, a computing system may receive a request for an action to be performed. For example, a security element may receive a request for an action to be performed by the computing system, the request being received from a client device. In some embodiments, the computing system may include a cloud infrastructure service. The cloud infrastructure service may receive the request for the action at the edge of the enclave (such as the edge of enclave 104 (FIG. 1)) in some embodiments. In some of these embodiments, the cloud infrastructure service may receive the request for the action outside of a firewall of the enclave. In some embodiments, the action may include creating a load balancer (such as load balancer 404 (FIG. 4)).
[0079] At 504, the computing system may identify one or more authorizers. For example, the computing system may identify one or more authorizers from which authorization for the action is to be received. The authorization may correspond to the performance of the action on the client device. The authorizer may include one or more of the characteristics of an authorizer described throughout this disclosure. The authorizer may be identified based on the client device, a user of the client device, the action being requested, or some combination thereof. In some embodiments, the client device and / or a user of the client device may be associated with a subscriber to the computing system, and the authorizer may be associated with the same subscriber as the client device and / or the user of the client device. The computing system may identify one or more authorizers based on a determination that the client device and / or a user of the client device has not previously been granted authorization for the performance of the action.
[0080] At 506, the computing system may serialize one or more operations. For example, the computing system may serialize one or more operations that correspond to an action requested to be performed. The serialization of the one or more operations may include one or more of the features of serializing an operation described throughout this disclosure, such as serialized operation 306 (FIG. 3). A computing system that serializes one or more operations may maintain state regarding the corresponding operations such that the operations may be subsequently unfrozen for execution of the operations.
[0081] At 508, the computing system may sign the one or more serialized operations. For example, the computing system may sign the one or more serialized operations with ECDSA. Signing the one or more serialized operations with ECDSA may include one or more of the features of signing an operation with ECDSA described throughout this disclosure, such as signed serialized operations 306 (FIG. 3). For example, the computing system may utilize a key and ECDSA to generate a signature for signing the one or more serialized operations. The computing system may sign the one or more serialized operations with a signature.
[0082] At 510, the computing system may provide the signature to the client device. For example, the computing system may share the signature with the client device while maintaining the key utilized to generate the signature within the computing system, the enclave (such as enclave 104, enclave 202, and / or enclave 406), and / or the infrastructure service. Maintaining the key within the computing system, the enclave, and / or the infrastructure service may provide security against malicious actors, while sharing the signature may provide for identification of the client device. In some embodiments, 510 may be omitted.
[0083] At 512, the computing system may initiate an inquiry procedure. For example, the computing system may initiate an inquiry procedure for authorization of an action from each of one or more authorizers to determine whether one or more operations are authorized to be performed. The inquiry procedure may include one or more of the features of the inquiry procedure for an authorizer described throughout this disclosure. In some embodiments, the inquiry procedure may include sending at least one authorization request to each of the one or more authorizers. The computing system may further monitor for a response from each of the one or more authorizers to the at least one authorization request.
[0084] At 514, the computing system may determine that authorization has been received. For example, the computing system may determine that authorization for the action has been received from each of one or more authorizers. In particular, the computing system may determine that the client device and / or a user utilizing the client device has authorization to perform the action. The computing system may determine that authorization has been received by techniques described herein for determining that authorization has been received from the authorizers, such as all of the authorizers indicating that authorization should be granted, a subset of the authorizers indicating that authorization should be granted, or a particular group of the authorizers indicating that authorization should be granted. The action may, in some cases, be to create a load balancer, and the authorizer may indicate that the client device and / or a user utilizing the client device is authorized to create the load balancer. In some embodiments, 514 may be omitted.
[0085] At 516, the computing system may verify that the serialized one or more operations have not been tampered with. For example, the computing system may verify that the serialized one or more operations have not been tampered with based at least in part on a signature produced by signing the serialized one or more operations. The computing system may verify that the one or more operations have not been tampered with based on the signature from the signed serialized operation at the time of retrieval being the same as the signature at the time the serialized operation was signed. In some embodiments, 516 may be omitted.
[0086] At 518, the computing system may perform one or more operations. For example, the computing system may perform the one or more operations based at least in part on a determination that authorization for the action has been received. The computing system performing the one or more operations may cause an action requested by the client device to be performed. In some embodiments, the action may be the creation of a load balancer, and the one or more operations cause the load balancer to be created by the computing system. In embodiments in which the computing system is a cloud infrastructure service, the cloud infrastructure service may be configured to create a load balancer at an edge of an enclave of the cloud infrastructure service. In some embodiments, 518 may be omitted.
[0087] FIG. 6 illustrates another example procedure 600 for authorization of a client to perform an action according to some embodiments. Procedure 600 may be performed by an infrastructure service (such as the infrastructure services described in connection with FIG. 1, which may include a computing system and / or a cloud computing system, the cloud infrastructure of FIG. 9, the cloud infrastructure of FIG. 10, the cloud infrastructure of FIG. 11, and / or the cloud infrastructure of FIG. 12), an enclave (such as enclave 104 (FIG. 1), enclave 202 (FIG. 2), and / or enclave 406 (FIG. 4), a security element (such as security element 108 (FIG. 1), security element 204 (FIG. 2), and / or security element 408 (FIG. 4)), or some combination thereof. Procedure 600 may be performed to determine whether a client device (such as client device 206 (FIG. 2) and / or client device 402 (FIG. 4)) is authorized to perform an action (such as creating a load balancer (such as load balancer 404 (FIG. 4)).
[0088] For simplicity, procedure 600 is described herein as being performed by a security element, but it should be understood that procedure 600 may be performed by an infrastructure service, an enclave, a computing system, or some combination thereof. In some embodiments, the security element may be part of a cloud infrastructure service.
[0089] At 602, a security element may receive a request for an action to be performed. For example, the security element may receive a request for an action to be performed by a cloud infrastructure service. The security element may receive the request from a client device, such as client device 206 and / or client device 402. In some embodiments, the security element may be implemented at the edge of an enclave of the cloud infrastructure service (such as enclave 104, enclave 202, and / or enclave 406). Additionally, the security element may be implemented outside of a firewall of an enclave, in some embodiments. The security element may include a proxy or daemon of the cloud infrastructure service, in some embodiments.
[0090] At 604, the security element may prevent the secure information from being provided. For example, in some embodiments, the cloud infrastructure service may be a first cloud infrastructure service, the request may be received from a second cloud infrastructure service, and the client device may be the second cloud infrastructure service or some portion of the second cloud infrastructure service. The security element may prevent the secure information associated with the first cloud infrastructure service from being provided to the second cloud infrastructure service. The security element may, in some embodiments, prevent the secure information from being provided to the second cloud infrastructure service prior to receipt of a response received from one or more authorizers. In other embodiments, the security element may prevent the secure information from being provided to the second cloud infrastructure service for the entirety of procedure 600 and / or for the entirety of the interaction between the first cloud infrastructure service and the second cloud infrastructure service. In some embodiments, 604 may be omitted.
[0091] At 606, the security element may identify one or more authorizers. For example, the security element may identify one or more authorizers from which authorization for an action is to be received, the authorization corresponding to the performance of the action. The identified authorizer may be an authorizer that may provide authorization to the client device and / or a user utilizing the client device for the performance of the action. The authorizer may include one or more characteristics of the authorizers described throughout this disclosure, such as the authorizer being associated with the same subscriber of the cloud infrastructure service as the client device and / or a user utilizing the client device.
[0092] At 608, the security element may determine one or more operations. For example, the security element may determine one or more operations to be performed by the cloud infrastructure service to complete the action. The cloud infrastructure service may have the capability to perform one or more operations to complete the action requested by the client device. The security element may determine the one or more operations per the determination of operations for the action described throughout this disclosure.
[0093] At 610, the security element may serialize one or more operations. For example, the security element may serialize one or more operations that correspond to an action requested to be performed. The serialization of the one or more operations may include one or more of the features of serializing an operation described throughout this disclosure, such as serialized operation 306 (FIG. 3). A computing system that serializes one or more operations may maintain state regarding the corresponding operations such that the operations may be subsequently unfrozen for execution of the operations. In some embodiments, 610 may be omitted.
[0094] At 612, the security element may sign one or more operations. For example, the security element may sign one or more operations with ECDSA. Signing one or more serialized operations with ECDSA may include one or more of the features of signing an operation with ECDSA described throughout this disclosure, such as signed serialized operations 306 (FIG. 3). For example, the security element may utilize a key and ECDSA to generate a signature for signing one or more operations. The security element may sign one or more operations with a signature. In embodiments in which operations are serialized, the security element may sign the serialized one or more operations.
[0095] At 614, the security element may store the signed operation or operations. For example, the security element may store the signed operation or operations in a memory of the security element, a memory of the enclave, a memory of the cloud infrastructure service, or some combination thereof. In embodiments where the operations are serialized, the security element may store the signed serialized operation or operations.
[0096] At 616, the security element may initiate an inquiry procedure. For example, the security element may initiate an inquiry procedure for authorization of the action based at least in part on responses received from the one or more authorizers. The inquiry procedure may include one or more of the features of the inquiry procedure for the authorizers described throughout this disclosure. In some embodiments, the inquiry procedure may include sending at least one authorization request to the one or more authorizers. The security element may monitor for responses received from the one or more authorizers to the at least one authorization request.
[0097] At 618, the security element may determine that authorization has been received. For example, the security element may determine that authorization for the action has been received from each of one or more authorizers. In particular, the security element may determine that the client device and / or a user utilizing the client device has authorization to perform the action. The computing system may determine that authorization has been received by techniques for determining that authorization has been received from an authorizer described herein, such as all of the authorizers indicating that authorization should be granted, a subset of the authorizers indicating that authorization should be granted, or a particular group of the authorizers indicating that authorization should be granted. In some embodiments, 618 may be omitted.
[0098] At 620, the security element may verify that the one or more operations have not been tampered with. For example, the security element may verify that the one or more operations have not been tampered with based at least in part on a signature produced by signing the one or more operations. The computing system may verify that the one or more operations have not been tampered with based on the signature from the signed operation at the time of retrieval being the same as the signature at the time the operation was signed. In some embodiments, 620 may be omitted.
[0099] At 622, the security element may cause one or more operations to be performed. For example, the security element may cause one or more operations to be performed based at least in part on determining that authorization for the action has been received. A security element that causes one or more operations to be performed may cause an action requested by the client device to be performed. In some embodiments, 622 may be omitted.
[0100] FIG. 7 illustrates a first portion of another example procedure 700 for client authorization for execution of an action according to some embodiments. FIG. 8 illustrates a second portion of an example procedure 700 according to some embodiments. Procedure 700 may be performed by an infrastructure service (such as the infrastructure services described in connection with FIG. 1, which may include a computing system and / or a cloud computing system, the cloud infrastructure of FIG. 9, the cloud infrastructure of FIG. 10, the cloud infrastructure of FIG. 11, and / or the cloud infrastructure of FIG. 12), an enclave (such as enclave 104 (FIG. 1), enclave 202 (FIG. 2), and / or enclave 406 (FIG. 4)), a security element (such as security element 108 (FIG. 1), security element 204 (FIG. 2), and / or security element 408 (FIG. 4)), or some combination thereof. Procedure 700 may be performed to determine whether a client device (e.g., client device 206 (FIG. 2) and / or client device 402 (FIG. 4)) is authorized to perform an action (e.g., creating a load balancer (e.g., load balancer 404 (FIG. 4))).
[0101] For simplicity, procedure 700 is described herein as being performed by a computing system, but it should be understood that procedure 700 may be performed by an infrastructure service, an enclave, a security element, or some combination thereof. In some embodiments, the security element may be part of a cloud infrastructure service.
[0102] At 702, a computing system may implement a security element. For example, the computing system may include a cloud infrastructure service for implementing a security element at an edge of an enclave of the cloud infrastructure service. The security element may include one or more of the features of security element 108, security element 204, and / or security element 408. In some embodiments, 702 may be omitted.
[0103] At 704, the computing system may identify a request for an action to be performed. For example, the computing system may identify a request for an action to be performed by the computing system, the request being received from a client device (such as client device 206 and / or client device 402). In some embodiments, the computing system may include a cloud infrastructure service, which in some embodiments may receive the request for the action at the edge of the cloud infrastructure service's enclave. In some of these embodiments, the cloud infrastructure service may receive the request for the action outside the firewall of the enclave. In some embodiments in which the computing system implements a security element, the security element may identify the request for the action.
[0104] At 706, the computing system may identify one or more authorizers. For example, the computing system may identify one or more authorizers from which authorization for an action is to be received, the authorization corresponding to performance of the action for the client device. The authorizer may include one or more of the characteristics of an authorizer described throughout this disclosure. The authorizer may be identified based on the client device, a user of the client device, the action being requested, or some combination thereof. In some embodiments, the client device and / or a user of the client device may be associated with a subscriber to the computing system, and the authorizer may be associated with the same subscriber as the client device and / or the user of the client device. The computing system may identify one or more authorizers based on a determination that the client device and / or a user of the client device has not previously been granted authorization for performance of the action.
[0105] At 708, the computing system may determine one or more operations to be performed. For example, the computing system may determine one or more operations to be performed by the computing system to complete an action. The computing system may have the capability to perform one or more operations to complete an action requested by the client device. The computing system may determine the one or more operations by the determination of operations for an action, as described throughout this disclosure.
[0106] At 710, the computing system may serialize the one or more operations. The serialization of the one or more operations may include one or more of the features of serializing an operation described throughout this disclosure, such as serialized operation 306 (FIG. 3). A computing system that serializes one or more operations may maintain state regarding the corresponding operations such that the operations may be subsequently unfrozen for execution of the operations.
[0107] At 712, the computing system may sign the serialized one or more operations. For example, the computing system may sign the serialized one or more operations with ECDSA. Signing the one or more serialized operations with ECDSA may include one or more of the features of signing an operation with ECDSA described throughout this disclosure, such as signed serialized operations 306 (FIG. 3). For example, the computing system may utilize a key and ECDSA to generate a signature for signing the one or more serialized operations. The computing system may sign the one or more serialized operations with a signature.
[0108] At 714, the computing system may store the signed and serialized one or more operations. For example, the computing system may store the signed and serialized one or more operations in a memory. The memory may be a memory of the computing system, a memory of a security element, a memory of an infrastructure service, or some combination thereof. Procedure 700 may proceed from 716 of FIG. 7 to 716 of FIG. 8.
[0109] At 802, the computing system may initiate an inquiry procedure. For example, the computing system may initiate an inquiry procedure for authorization of an action from one or more authorizers. The inquiry procedure may include one or more of the features of the inquiry procedure for the authorizers described throughout this disclosure. In some embodiments, the inquiry procedure may include sending at least one authorization request to each of the one or more authorizers. The computing system may further monitor for a response from each of the one or more authorizers to the at least one authorization request.
[0110] At 804, the computing system may determine that authorization has been received. For example, the computing system may determine that authorization for the action has been received from each of one or more authorizers. In particular, the computing system may determine that the client device and / or a user utilizing the client device has authorization to perform the action. The computing system may determine that authorization has been received by a technique for determining that authorization has been received from an authorizer described herein, such as all of the authorizers indicating that authorization should be granted, a subset of the authorizers indicating that authorization should be granted, or a particular group of the authorizers indicating that authorization should be granted. In some embodiments, 804 may be omitted.
[0111] At 806, the computing system may retrieve the signed serialized one or more operations. For example, the computing system may retrieve the signed serialized one or more operations from memory. The computing system may retrieve the signed serialized one or more operations based on a determination that authorization has been received. In some embodiments, 806 may be omitted.
[0112] At 808, the computing system may verify that the signed serialized one or more operations have not been tampered with. For example, the computing system may verify based at least in part on a signature produced by performing a signing of the serialized one or more operations. The computing system may verify that the one or more operations have not been tampered with based on the signature from the signed serialized operation at the time of retrieval being the same as the signature at the time the serialized operation was signed. In some embodiments, 808 may be omitted.
[0113] At 810, the computing system may perform one or more operations. For example, the computing system may perform the one or more operations based at least in part on the authorization and the signed serialized one or more operations retrieved from memory. In some embodiments, the computing system may perform the one or more operations further based at least in part on verification that the signed serialized one or more operations have not been tampered with. The computing system performing the one or more operations may cause an action requested by the client device to be performed. In some embodiments, 810 may be omitted.
[0114] As mentioned above, Infrastructure as a Service (IaaS) is one particular type of cloud computing. IaaS can be configured to provide virtualized computing resources over a public network (e.g., the Internet). In an IaaS model, a cloud computing provider can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), or the like). In some cases, an IaaS provider can also provide various services (e.g., billing, monitoring, logging, load balancing and clustering, etc.) to accompany those infrastructure components. These services can then be policy driven, so that an IaaS user can implement policies to drive load balancing to maintain application availability and performance.
[0115] In some cases, an IaaS customer may access resources and services over a wide area network (WAN), such as the Internet, and may use the cloud provider's services to install the remaining elements of the application stack. For example, a user may log into an IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as databases, create storage buckets for workloads and backups, and even install enterprise software into the VMs. The customer may then use the provider's services to perform a variety of functions, including balancing network traffic, troubleshooting application issues, monitoring performance, managing disaster recovery, and more.
[0116] In most cases, the cloud computing model will require the involvement of a cloud provider, which may be, but is not required to be, a third-party service that specializes in providing (e.g., offering, renting, selling) IaaS. An entity may even choose to deploy a private cloud, becoming its own provider of infrastructure services.
[0117] In some examples, IaaS deployment is the process of placing a new application, or a new version of an application, onto a prepared application server, or the like. The IaaS deployment may also include the process of preparing the server (e.g., installing libraries, daemons, etc.). This is often managed by the cloud provider below the hypervisor layer (e.g., server, storage, network hardware, and virtualization). The customer may then be responsible for controlling the (OS), middleware, and / or application deployment (e.g., on top of self-service virtual machines (e.g., that can be spun up on demand)).
[0118] In some instances, IaaS provisioning may refer to acquiring computers or virtual hosts for use and even installing needed libraries or services on those computers or virtual hosts. In most cases, deployment does not include provisioning, which may need to be performed first.
[0119] In some cases, there are two distinct challenges with IaaS provisioning. First, there is the initial challenge of provisioning an initial set of infrastructure before anything is running. Second, there is the challenge of evolving the existing infrastructure (e.g., adding new services, modifying services, removing services, etc.) once everything has been provisioned. In some cases, these two challenges can be addressed by allowing the configuration of the infrastructure to be defined declaratively. In other words, the infrastructure (e.g., what components are needed and how those components interact) can be defined by one or more configuration files. Then, the overall topology of the infrastructure (e.g., what resources depend on which and how those resources work together with each other) can be described declaratively. In some cases, once the topology is defined, workflows can be generated that create and / or manage the different components described in the configuration files.
[0120] In some examples, the infrastructure may have many interconnected elements. For example, there may be one or more virtual private clouds (VPCs) (e.g., potentially on-demand pools of configurable and / or shared computing resources), further known as a core network. In some examples, there may also be one or more inbound / outbound traffic group rules and one or more virtual machines (VMs) provisioned to define how the network's inbound and / or outbound traffic will be set up. Other infrastructure elements, such as load balancers, databases, or the like, may also be provisioned. The infrastructure may evolve incrementally as more and more infrastructure elements are desired and / or added.
[0121] In some instances, continuous deployment techniques may be used to enable deployment of infrastructure code across various virtual computing environments. In addition, the described techniques may enable infrastructure management within these environments. In some instances, a service team may write code that is desired to be deployed to one or more, but often many, different production environments (e.g., across various different geographic locations, sometimes spanning the entire world). However, in some instances, the infrastructure to which the code will be deployed must first be set up. In some instances, provisioning may be done manually, provisioning tools may be utilized to provision resources, and / or deployment tools may be utilized to deploy the code once the infrastructure is provisioned.
[0122] 9 is a block diagram 900 illustrating an example pattern of an IaaS architecture in accordance with at least one embodiment. A service operator 902 may be communicatively coupled to a secure host tenancy 904, which may include a virtual cloud network (VCN) 906 and a secure host subnet 908. In some examples, the service operator 902 may use one or more client computing devices, which may be portable handheld devices (e.g., iPhone®, cellular phones, iPad®, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., Google Glass® head-mounted displays) that run software such as Microsoft Windows Mobile® and / or various mobile operating systems such as iOS, Windows Phone, Android, BlackBerry 8, Palm OS, and the like, and are enabled for Internet, email, short message service (SMS), Blackberry®, or other communications protocols. Alternatively, the client computing devices may be general purpose personal computers, including, by way of example, personal and / or laptop computers running various versions of Microsoft Windows, Apple Macintosh, and / or Linux operating systems. The client computing devices may be workstation computers running any of a variety of commercially available UNIX or UNIX-like operating systems, including, without limitation, various GNU / Linux operating systems, such as Google Chrome OS.Alternatively, or in addition, the client computing device may be any other electronic device that can access the VCN 906 and / or the Internet and has the capability to communicate over the network, such as a thin-client computer, an Internet-enabled gaming system (e.g., a Microsoft Xbox gaming console with or without a Kinect® gesture input device), and / or a personal messaging device.
[0123] VCN 906 may include a local peering gateway (LPG) 910 that may be communicatively coupled to a secure shell (SSH) VCN 912 via an LPG 910 owned in the SSH VCN 912. The SSH VCN 912 may include an SSH subnet 914, and the SSH VCN 912 may be communicatively coupled to a control plane VCN 916 via an LPG 910 owned in the control plane VCN 916. Furthermore, the SSH VCN 912 may be communicatively coupled to a data plane VCN 918 via an LPG 910. The control plane VCN 916 and the data plane VCN 918 may be owned in a service tenancy 919, which may be owned and / or operated by the IaaS provider.
[0124] The control plane VCN 916 may include a control plane demilitarized zone (DMZ) tier 920 that serves as a perimeter network (e.g., a portion of an enterprise network between the enterprise intranet and an external network). DMZ-based servers may have limited responsibility and help keep intrusions contained. Additionally, the DMZ tier 920 may include one or more load balancer (LB) subnets 922, a control plane app tier 924 that may include app subnets 926, a control plane data tier 928 that may include database (DB) subnets 930 (e.g., a front-end DB subnet and / or a back-end DB subnet). The LB subnet 922 carried in the control plane DMZ tier 920 may also be communicatively coupled to an app subnet 926 carried in the control plane app tier 924 and to an Internet gateway 934 that may be carried in the control plane VCN 916, which may be communicatively coupled to a DB subnet 930 carried in the control plane data tier 928, as well as to a service gateway 936 and a network address translation (NAT) gateway 938. The control plane VCN 916 may include the service gateway 936 and the NAT gateway 938.
[0125] The control plane VCN 916 may include a data plane mirrored app tier 940 that may include an app subnet 926. The app subnet 926 contained in the data plane mirrored app tier 940 may include a virtual network interface controller (VNIC) 942 that may run a compute instance 944. The compute instance 944 may communicatively couple the app subnet 926 of the data plane mirrored app tier 940 to the app subnet 926 that may be contained in the data plane app tier 946.
[0126] The data plane VCN 918 may include a data plane app layer 946, a data plane DMZ layer 948, and a data plane data layer 950. The data plane DMZ layer 948 may include a LB subnet 922, which may be communicatively coupled to an app subnet 926 of the data plane app layer 946 and an Internet gateway 934 of the data plane VCN 918. The app subnet 926 may be communicatively coupled to a service gateway 936 of the data plane VCN 918 and a NAT gateway 938 of the data plane VCN 918. The data plane data layer 950 may further include a DB subnet 930, which may be communicatively coupled to the app subnet 926 of the data plane app layer 946.
[0127] The Internet gateways 934 of the control plane VCNs 916 and the data plane VCNs 918 may be communicatively coupled to a metadata management service 952, which may be communicatively coupled to the public Internet 954. The public Internet 954 may be communicatively coupled to NAT gateways 938 of the control plane VCNs 916 and the data plane VCNs 918. The service gateways 936 of the control plane VCNs 916 and the data plane VCNs 918 may be communicatively coupled to cloud services 956.
[0128] In some examples, a service gateway 936 in the control plane VCN 916 or in the data plane VCN 918 can make application programming interface (API) calls to cloud services 956 without traversing the public Internet 954. The API calls from the service gateway 936 to the cloud services 956 can be unidirectional: the service gateway 936 can make the API call to the cloud services 956, and the cloud services 956 can send the requested data to the service gateway 936. However, the cloud services 956 may not initiate the API call to the service gateway 936.
[0129] In some examples, the secure host tenancy 904 may be directly connected to a service tenancy 919 that may be otherwise separate. The secure host subnet 908 may communicate with the SSH subnet 914 through an LPG 910 that may enable bidirectional communication through otherwise separate systems. Connecting the secure host subnet 908 to the SSH subnet 914 may give the secure host subnet 908 access to other entities in the service tenancy 919.
[0130] The control plane VCN 916 may enable users of the service tenancy 919 to set up or otherwise provision desired resources. The desired resources provisioned in the control plane VCN 916 may be deployed or otherwise used in the data plane VCN 918. In some examples, the control plane VCN 916 may be separate from the data plane VCN 918, and the data plane mirror app layer 940 of the control plane VCN 916 may communicate with the data plane app layer 946 of the data plane VCN 918 via a VNIC 942, which may be held in the data plane mirror app layer 940 and the data plane app layer 946.
[0131] In some examples, a user, or customer, of the system may make a request, such as a create, read, update, or delete (CRUD) operation, through the public Internet 954, which may communicate the request to a metadata management service 952. The metadata management service 952 may communicate the request to the control plane VCN 916 through an Internet gateway 934. The request may be received by a LB subnet 922 held in the control plane DMZ layer 920. The LB subnet 922 may determine that the request is valid, and in response to this determination, the LB subnet 922 may send the request to an app subnet 926 held in the control plane app layer 924. If the request is validated and requires a call to the public Internet 954, the call to the public Internet 954 may be sent to a NAT gateway 938, which may make the call to the public Internet 954. Storage items that may be desired to be stored by the request may be stored in the DB subnet 930.
[0132] In some examples, data plane mirror app layer 940 may facilitate direct communication between control plane VCN 916 and data plane VCN 918. For example, it may be desired that changes to configuration, updates, or other suitable modifications be applied to resources held in data plane VCN 918. Through VNIC 942, control plane VCN 916 may communicate directly with resources held in data plane VCN 918 and thereby perform the changes to configuration, updates, or other suitable modifications on those resources.
[0133] In some embodiments, the control plane VCN 916 and the data plane VCN 918 may be held in a service tenancy 919. In this case, a user or customer of the system may not own or operate either the control plane VCN 916 or the data plane VCN 918. Instead, an IaaS provider may own or operate the control plane VCN 916 and the data plane VCN 918, both of which may be held in a service tenancy 919. This embodiment may allow for network isolation that may prevent a user or customer from interacting with other users' or customers' resources. Furthermore, this embodiment may allow a user or customer of the system to store databases privately without having to rely on the public internet 954 for storage, which may not have the desired level of threat protection.
[0134] In another embodiment, the LB subnet 922 maintained in the control plane VCN 916 may be configured to receive signals from the service gateway 936. In this embodiment, the control plane VCN 916 and the data plane VCN 918 may be configured to be called by the IaaS provider's customers without calling the public Internet 954. The IaaS provider's customers may desire this embodiment because databases used by the customers may be stored on the service tenancy 919, which may be controlled by the IaaS provider and may be isolated from the public Internet 954.
[0135] 10 is a block diagram 1000 illustrating another example pattern of an IaaS architecture in accordance with at least one embodiment. A service operator 1002 (e.g., service operator 902 of FIG. 9 ) may be communicatively coupled to a secure host tenancy 1004 (e.g., secure host tenancy 904 of FIG. 9 ), which may include a virtual cloud network (VCN) 1006 (e.g., VCN 906 of FIG. 9 ) and a secure host subnet 1008 (e.g., secure host subnet 908 of FIG. 9 ). The VCN 1006 may include a local peering gateway (LPG) 1010 (e.g., LPG 910 of FIG. 9 ), which may be communicatively coupled to a secure shell (SSH) VCN 1012 (e.g., SSH VCN 912 of FIG. 9 ) via an LPG 910 held in the SSH VCN 1012. SSH VCN 1012 may include an SSH subnet 1014 (e.g., SSH subnet 914 of FIG. 9), and SSH VCN 1012 may be communicatively coupled to a control plane VCN 1016 via an LPG 1010 owned in the control plane VCN 1016 (e.g., control plane VCN 916 of FIG. 9). The control plane VCN 1016 may be owned in a service tenancy 1019 (e.g., service tenancy 919 of FIG. 9), and the data plane VCN 1018 (e.g., data plane VCN 918 of FIG. 9) may be owned in a customer tenancy 1021, which may be owned or operated by a user or customer of the system.
[0136] The control plane VCN 1016 may include a control plane DMZ tier 1020 (e.g., control plane DMZ tier 920 of FIG. 9 ) that may include a LB subnet 1022 (e.g., LB subnet 922 of FIG. 9 ), a control plane app tier 1024 (e.g., control plane app tier 924 of FIG. 9 ) that may include an app subnet 1026 (e.g., app subnet 926 of FIG. 9 ), and a control plane data tier 1028 (e.g., control plane data tier 928 of FIG. 9 ) that may include a database (DB) subnet 1030 (e.g., similar to DB subnet 930 of FIG. 9 ). The LB subnet 1022 carried in the control plane DMZ tier 1020 may also be communicatively coupled to an app subnet 1026 carried in the control plane app tier 1024 and an Internet gateway 1034 (e.g., Internet gateway 934 of FIG. 9 ) that may be carried in the control plane VCN 1016, which may be communicatively coupled to a DB subnet 1030 carried in the control plane data tier 1028, as well as a service gateway 1036 (e.g., service gateway 636 of FIG. 9 ) and a network address translation (NAT) gateway 1038 (e.g., NAT gateway 938 of FIG. 9 ). The control plane VCN 1016 may include the service gateway 1036 and the NAT gateway 1038.
[0137] The control plane VCN 1016 may include a data plane mirror app layer 1040 (e.g., data plane mirror app layer 940 of FIG. 9 ), which may include an app subnet 1026. The app subnet 1026 contained in the data plane mirror app layer 1040 may include a virtual network interface controller (VNIC) 1042 (e.g., VNIC 942 of FIG. 9 ), which may run a compute instance 1044 (e.g., similar to compute instance 944 of FIG. 9 ). The compute instance 1044 may facilitate communication between the app subnet 1026 of the data plane mirror app layer 1040 and the app subnet 1026, which may be contained in the data plane app layer 1046, via the VNIC 1042 contained in the data plane mirror app layer 1040 and the VNIC 1042 contained in the data plane app layer 1046 (e.g., data plane app layer 946 of FIG. 9 ).
[0138] The Internet gateway 1034 contained in the control plane VCN 1016 may be communicatively coupled to a metadata management service 1052 (e.g., metadata management service 952 of FIG. 9 ), which may be communicatively coupled to a public Internet 1054 (e.g., public Internet 954 of FIG. 9 ). The public Internet 1054 may be communicatively coupled to a NAT gateway 1038 contained in the control plane VCN 1016. The service gateway 1036 contained in the control plane VCN 1016 may be communicatively coupled to cloud services 1056 (e.g., cloud services 956 of FIG. 9 ).
[0139] In some examples, the data plane VCN 1018 may be owned in the customer tenancy 1021. In this case, the IaaS provider may provide each customer with a control plane VCN 1016, and the IaaS provider may set up a unique compute instance 1044 owned in the service tenancy 1019 for each customer. Each compute instance 1044 may enable communication between the control plane VCN 1016 owned in the service tenancy 1019 and the data plane VCN 1018 owned in the customer tenancy 1021. The compute instance 1044 may enable resources provisioned in the control plane VCN 1016 owned in the service tenancy 1019 to be deployed or otherwise used in the data plane VCN 1018 owned in the customer tenancy 1021.
[0140] In another example, an IaaS provider customer may have a database that resides in the customer tenancy 1021. In this example, the control plane VCN 1016 may include a data plane mirror app layer 1040 that may include an app subnet 1026. The data plane mirror app layer 1040 may reside in the data plane VCN 1018, but the data plane mirror app layer 1040 may not reside in the data plane VCN 1018. That is, the data plane mirror app layer 1040 may have access to the customer tenancy 1021, but the data plane mirror app layer 1040 may not reside in the data plane VCN 1018 or be owned or operated by the IaaS provider customer. The data plane mirror app layer 1040 may be configured to make calls to the data plane VCN 1018, but may not be configured to make calls to any entities held in the control plane VCN 1016. A customer may want to deploy or otherwise use resources in the data plane VCN 1018 that are provisioned in the control plane VCN 1016, and the data plane mirror app layer 1040 can facilitate the customer's desired deployment or other usage of the resources.
[0141] In some embodiments, the IaaS provider's customer may apply filters to the data plane VCN 1018. In this embodiment, the customer may determine what the data plane VCN 1018 may access, and the customer may limit access from the data plane VCN 1018 to the public Internet 1054. The IaaS provider may not be able to filter or otherwise control access of the data plane VCN 1018 to any outside networks or databases. Customer filtering and control of the data plane VCN 1018 held in the customer tenancy 1021 may help isolate the data plane VCN 1018 from other customers and from the public Internet 1054.
[0142] In some embodiments, the cloud services 1056 may be called by the service gateway 1036 to access services that may not be located on the public Internet 1054, the control plane VCN 1016, or the data plane VCN 1018. The connection between the cloud services 1056 and the control plane VCN 1016 or the data plane VCN 1018 may not be persistent or continuous. The cloud services 1056 may be located on different networks owned or operated by the IaaS provider. The cloud services 1056 may be configured to receive calls from the service gateway 1036 and may not be configured to receive calls from the public Internet 1054. Some cloud services 1056 may be isolated from other cloud services 1056, and the control plane VCN 1016 may be isolated from cloud services 1056 that may not be in the same region as the control plane VCN 1016. For example, control plane VCN 1016 may be located in "region 1," and cloud service "deployment 9" may be located in region 1 and in "region 2." If a call to deployment 9 is made by a service gateway 1036 hosted in control plane VCN 1016 located in region 1, the call may be sent to deployment 9 in region 1. In this example, control plane VCN 1016 or deployment 9 in region 1 may not be communicatively coupled to or otherwise in communication with deployment 9 in region 2.
[0143] 11 is a block diagram 1100 illustrating another example pattern of an IaaS architecture in accordance with at least one embodiment. A service operator 1102 (e.g., service operator 902 of FIG. 9 ) may be communicatively coupled to a secure host tenancy 1104 (e.g., secure host tenancy 904 of FIG. 9 ), which may include a virtual cloud network (VCN) 1106 (e.g., VCN 906 of FIG. 9 ) and a secure host subnet 1108 (e.g., secure host subnet 908 of FIG. 9 ). VCN 1106 may include an LPG 1110, which may be communicatively coupled to an SSH VCN 1112 via an LPG 1110 (e.g., LPG 910 of FIG. 9 ) held in the SSH VCN 1112 (e.g., SSH VCN 912 of FIG. 9 ). SSH VCN 1112 may include an SSH subnet 1114 (e.g., SSH subnet 914 of FIG. 9), and SSH VCN 1112 may be communicatively coupled to a control plane VCN 1116 via an LPG 1110 held in a control plane VCN 1116 (e.g., control plane VCN 916 of FIG. 9) and to a data plane VCN 1118 via an LPG 1110 held in a data plane VCN 1118 (e.g., data plane 918 of FIG. 9). The control plane VCN 1116 and the data plane VCN 1118 may be held in a service tenancy 1119 (e.g., service tenancy 919 of FIG. 9).
[0144] The control plane VCN 1116 may include a control plane DMZ tier 1120 (e.g., control plane DMZ tier 920 of FIG. 9 ) that may include a load balancer (LB) subnet 1122 (e.g., LB subnet 922 of FIG. 9 ), a control plane app tier 1124 (e.g., control plane app tier 924 of FIG. 9 ) that may include an app subnet 1126 (e.g., similar to app subnet 926 of FIG. 9 ), and a control plane data tier 1128 (e.g., control plane data tier 928 of FIG. 9 ) that may include a DB subnet 1130. The LB subnet 1122 maintained in the control plane DMZ tier 1120 may be communicatively coupled to an app subnet 1126 maintained in the control plane app tier 1124 and to an Internet gateway 1134 (e.g., Internet gateway 934 of FIG. 9 ) that may be maintained in the control plane VCN 1116, which may be communicatively coupled to a DB subnet 1130 maintained in the control plane data tier 1128, as well as to a service gateway 1136 (e.g., service gateway 936 of FIG. 9 ) and a network address translation (NAT) gateway 1138 (e.g., NAT gateway 938 of FIG. 9 ). The control plane VCN 1116 may include the service gateway 1136 and the NAT gateway 1138.
[0145] The data plane VCN 1118 may include a data plane app layer 1146 (e.g., data plane app layer 946 of FIG. 9 ), a data plane DMZ layer 1148 (e.g., data plane DMZ layer 948 of FIG. 9 ), and a data plane data layer 1150 (e.g., data plane data layer 950 of FIG. 9 ). The data plane DMZ layer 1148 may include a trusted app subnet 1160 and an untrusted app subnet 1162 of the data plane app layer 1146, as well as a LB subnet 1122, which may be communicatively coupled to an Internet gateway 1134 maintained in the data plane VCN 1118. The trusted app subnet 1160 may be communicatively coupled to a service gateway 1136 maintained in the data plane VCN 1118, a NAT gateway 1138 maintained in the data plane VCN 1118, and a DB subnet 1130 maintained in the data plane data layer 1150. The untrusted app subnet 1162 may be communicatively coupled to a service gateway 1136 maintained in the data plane VCN 1118 and to a DB subnet 1130 maintained in the data plane data layer 1150. The data plane data layer 1150 may include a DB subnet 1130, which may be communicatively coupled to a service gateway 1136 maintained in the data plane VCN 1118.
[0146] The untrusted app subnet 1162 may include one or more primary VNICs 1164(1)-(N), which may be communicatively coupled to tenant virtual machines (VMs) 1166(1)-(N). Each tenant VM 1166(1)-(N) may be communicatively coupled to a respective app subnet 1167(1)-(N), which may be hosted in a respective container egress VCN 1168(1)-(N), which may be hosted in a respective customer tenancy 1170(1)-(N). Each secondary VNIC 1172(1)-(N) may facilitate communication between the untrusted app subnet 1162 hosted in the data plane VCN 1118 and the app subnet hosted in the container egress VCN 1168(1)-(N). Each container egress VCN 1168(1)-(N) may include a NAT gateway 1138, which may be communicatively coupled to the public Internet 1154 (e.g., public Internet 954 in FIG. 9).
[0147] An Internet gateway 1134, carried in the control plane VCN 1116 and in the data plane VCN 1118, may be communicatively coupled to a metadata management service 1152 (e.g., metadata management system 952 of FIG. 9 ), which may be communicatively coupled to the public Internet 1154. The public Internet 1154 may be communicatively coupled to a NAT gateway 1138, carried in the control plane VCN 1116 and in the data plane VCN 1118. A service gateway 1136, carried in the control plane VCN 1116 and in the data plane VCN 1118, may be communicatively coupled to cloud services 1156.
[0148] In some embodiments, the data plane VCN 1118 may be integrated with a customer tenancy 1170. This integration may be useful or desirable for an IaaS provider's customer in some cases, such as cases where support may be desired when executing code. A customer may provide code for execution that may be disruptive, may communicate with other customer resources, or may otherwise cause undesirable effects. In response, the IaaS provider may determine whether or not to execute the code provided to the IaaS provider by the customer.
[0149] In some examples, a customer of an IaaS provider may grant temporary network access to the IaaS provider and request a function to be attached to the data plane app layer 1146. Code to execute the function may be executed in VMs 1166(1)-(N), and the code may not be configured to execute anywhere else on the data plane VCN 1118. Each VM 1166(1)-(N) may be connected to one customer tenancy 1170. Each container 1171(1)-(N) held in a VM 1166(1)-(N) may be configured not to execute code. In this case, there may be double isolation (e.g., containers 1171(1)-(N) executing code where containers 1171(1)-(N) may be hosted in at least VMs 1166(1)-(N) hosted in untrusted app subnet 1162) that may help prevent incorrect or otherwise undesired code from damaging the IaaS provider's network or from damaging a different customer's network. Containers 1171(1)-(N) may be communicatively coupled to customer tenancy 1170 and may be configured to send or receive data from customer tenancy 1170. Containers 1171(1)-(N) may not be configured to send or receive data from any other entity in data plane VCN 1118. Upon completion of executing the code, the IaaS provider may kill or otherwise discard containers 1171(1)-(N).
[0150] In some embodiments, trusted app subnet 1160 may execute code that may be owned or operated by the IaaS provider. In this embodiment, trusted app subnet 1160 may be communicatively coupled to DB subnet 1130 and configured to perform CRUD operations on DB subnet 1130. Untrusted app subnet 1162 may be communicatively coupled to DB subnet 1130, but in this embodiment, the untrusted app subnet may be configured to perform read operations on DB subnet 1130. Containers 1171(1)-(N) that may be hosted on each customer's VMs 1166(1)-(N) and that may execute code from the customer may not be communicatively coupled to DB subnet 1130.
[0151] In other embodiments, the control plane VCN 1116 and the data plane VCN 1118 may not be directly communicatively coupled. In this embodiment, there may not be direct communication between the control plane VCN 1116 and the data plane VCN 1118. However, communication may occur indirectly in at least one manner. An LPG 1110 may be established by an IaaS provider that may facilitate communication between the control plane VCN 1116 and the data plane VCN 1118. In another example, the control plane VCN 1116 or the data plane VCN 1118 may make a call to a cloud service 1156 via a service gateway 1136. For example, a call from the control plane VCN 1116 to the cloud service 1156 may include a request for a service that may communicate with the data plane VCN 1118.
[0152] 12 is a block diagram 1200 illustrating another example pattern of an IaaS architecture in accordance with at least one embodiment. A service operator 1202 (e.g., service operator 902 of FIG. 9 ) may be communicatively coupled to a secure host tenancy 1204 (e.g., secure host tenancy 904 of FIG. 9 ), which may include a virtual cloud network (VCN) 1206 (e.g., VCN 906 of FIG. 9 ) and a secure host subnet 1208 (e.g., secure host subnet 908 of FIG. 9 ). VCN 1206 may include an LPG 1210, which may be communicatively coupled to an SSH VCN 1212 via an LPG 1210 (e.g., LPG 910 of FIG. 9 ) held in the SSH VCN 1212 (e.g., SSH VCN 912 of FIG. 9 ). SSH VCN 1212 may include SSH subnet 1214 (e.g., SSH subnet 914 of FIG. 9), and SSH VCN 1212 may be communicatively coupled to control plane VCN 1216 via LPG 1210 held in control plane VCN 1216 (e.g., control plane VCN 916 of FIG. 9) and to data plane VCN 1218 via LPG 1210 held in data plane VCN 1218 (e.g., data plane 918 of FIG. 9). Control plane VCN 1216 and data plane VCN 1218 may be held in service tenancy 1219 (e.g., service tenancy 919 of FIG. 9).
[0153] The control plane VCN 1216 may include a control plane DMZ layer 1220 (e.g., control plane DMZ layer 920 of FIG. 9 ) that may include a LB subnet 1222 (e.g., LB subnet 922 of FIG. 9 ), a control plane app layer 1224 (e.g., control plane app layer 924 of FIG. 9 ) that may include an app subnet 1226 (e.g., app subnet 926 of FIG. 9 ), and a control plane data layer 1228 (e.g., control plane data layer 928 of FIG. 9 ) that may include a DB subnet 1230 (e.g., DB subnet 1130 of FIG. 11 ). LB subnet 1222 maintained in control plane DMZ layer 1220 may be communicatively coupled to app subnet 1226 maintained in control plane app layer 1224 and to an Internet gateway 1234 (e.g., Internet gateway 934 of FIG. 9 ) that may be maintained in control plane VCN 1216, and app subnet 1226 may be communicatively coupled to DB subnet 1230 maintained in control plane data layer 1228, as well as to service gateway 1236 (e.g., service gateway of FIG. 9 ) and network address translation (NAT) gateway 1238 (e.g., NAT gateway 938 of FIG. 9 ). Control plane VCN 1216 may include service gateway 1236 and NAT gateway 1238.
[0154] Data plane VCN 1218 may include a data plane app layer 1246 (e.g., data plane app layer 946 in FIG. 9 ), a data plane DMZ layer 1248 (e.g., data plane DMZ layer 948 in FIG. 9 ), and a data plane data layer 1250 (e.g., data plane data layer 950 in FIG. 9 ). Data plane DMZ layer 1248 may include trusted app subnet 1260 (e.g., trusted app subnet 1160 in FIG. 11 ) and untrusted app subnet 1262 (e.g., untrusted app subnet 1162 in FIG. 11 ) of data plane app layer 1246, as well as a LB subnet 1222, which may be communicatively coupled to an Internet gateway 1234 maintained in data plane VCN 1218. The trusted app subnet 1260 may be communicatively coupled to a service gateway 1236 hosted in the data plane VCN 1218, a NAT gateway 1238 hosted in the data plane VCN 1218, and a DB subnet 1230 hosted in the data plane data layer 1250. The untrusted app subnet 1262 may be communicatively coupled to a service gateway 1236 hosted in the data plane VCN 1218, and a DB subnet 1230 hosted in the data plane data layer 1250. The data plane data layer 1250 may include the DB subnet 1230, which may be communicatively coupled to a service gateway 1236 hosted in the data plane VCN 1218.
[0155] The untrusted app subnet 1262 may include primary VNICs 1264(1)-(N), which may be communicatively coupled to tenant virtual machines (VMs) 1266(1)-(N) residing in the untrusted app subnet 1262. Each tenant VM 1266(1)-(N) may execute code in a respective container 1267(1)-(N), which may be communicatively coupled to the app subnet 1226, which may be housed in a data plane app layer 1246, which may be housed in a container egress VCN 1268. Each secondary VNIC 1272(1)-(N) may facilitate communication between the untrusted app subnet 1262, which is housed in the data plane VCN 1218, and the app subnetwork, which is housed in the container egress VCN 1268. The container egress VCN may include a NAT gateway 1238, which may be communicatively coupled to the public Internet 1254 (e.g., public Internet 954 of FIG. 9 ).
[0156] An Internet gateway 1234, carried in the control plane VCN 1216 and in the data plane VCN 1218, may be communicatively coupled to a metadata management service 1252 (e.g., metadata management system 952 of FIG. 9 ), which may be communicatively coupled to the public Internet 1254. The public Internet 1254 may be communicatively coupled to a NAT gateway 1238, carried in the control plane VCN 1216 and in the data plane VCN 1218. A service gateway 1236, carried in the control plane VCN 1216 and in the data plane VCN 1218, may be communicatively coupled to cloud services 1256.
[0157] In some examples, the pattern illustrated by the architecture of block diagram 1200 of FIG. 12 may be considered an exception to the pattern illustrated by the architecture of block diagram 1100 of FIG. 11 and may be desirable for customers of an IaaS provider when the IaaS provider cannot directly communicate with the customer (e.g., disconnected regions). Each container 1267(1)-(N) hosted in a VM 1266(1)-(N) for each customer may be accessed in real time by the customer. The containers 1267(1)-(N) may be configured to make calls to each secondary VNIC 1272(1)-(N) hosted in an app subnet 1226 of a data plane app tier 1246, which may be hosted in a container egress VCN 1268. Secondary VNICs 1272(1)-(N) may send calls to NAT gateway 1238, which may send calls to the public Internet 1254. In this example, containers 1267(1)-(N) that may be accessed in real time by customers may be isolated from control plane VCN 1216 and may be isolated from other entities held in data plane VCN 1218. Containers 1267(1)-(N) may further be isolated from resources from other customers.
[0158] In another example, a customer may use containers 1267(1)-(N) to call cloud service 1256. In this example, the customer may execute code in containers 1267(1)-(N) that requests a service from cloud service 1256. Containers 1267(1)-(N) may send the request to secondary VNICs 1272(1)-(N), which may send the request to a NAT gateway, which may send the request to public Internet 1254. Public Internet 1254 may send the request to LB subnet 1222, which is held in control plane VCN 1216, via Internet gateway 1234. In response to determining that the request is valid, the LB subnet may send the request to app subnet 1226, which may send the request to cloud service 1256 via service gateway 1236.
[0159] It should be understood that the IaaS architectures 900, 1000, 1100, 1200 depicted in the figures may have components other than those depicted. Additionally, the embodiments shown in the figures are merely some examples of cloud infrastructure systems that may incorporate embodiments of the present disclosure. In some other embodiments, the IaaS systems may have more or fewer components than shown in the figures, may combine two or more components, or may have different configurations or arrangements of components.
[0160] In some embodiments, the IaaS system described herein may include a suite of application, middleware, and database service offerings delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner. An example of such an IaaS system is Oracle Cloud Infrastructure (OCI), offered by the present assignee.
[0161] 13 illustrates an example computer system 1300 upon which various embodiments may be implemented. The system 1300 may be used to implement any of the computer systems described above. As shown in the figure, the computer system 1300 includes a processing unit 1304 that communicates with several peripheral subsystems via a bus subsystem 1302. These peripheral subsystems may include a processing acceleration unit 1306, an I / O subsystem 1308, a storage subsystem 1318, and a communication subsystem 1324. The storage subsystem 1318 includes a tangible computer-readable storage medium 1322 and a system memory 1310.
[0162] The bus subsystem 1302 provides a mechanism for allowing the various components and subsystems of the computer system 1300 to communicate with one another as intended. Although the bus subsystem 1302 is shown diagrammatically as a single bus, alternative embodiments of the bus subsystem may utilize multiple buses. The bus subsystem 1302 may be any of a variety of types of bus structures including a memory bus or memory controller, a peripheral bus, and a local bus using any of a variety of bus architectures. For example, such architectures may include a Peripheral Component Interconnect (PCI) bus, which may be implemented as an Industry Standard Architecture (ISA) bus, a MicroChannel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a mezzanine bus manufactured to the IEEE P1386.1 standard.
[0163] A processing unit 1304 (e.g., a conventional microprocessor or microcontroller), which may be implemented as one or more integrated circuits, controls the operation of the computer system 1300. One or more processors may be included in the processing unit 1304. These processors may include single-core or multi-core processors. In some embodiments, the processing unit 1304 may be implemented as one or more independent processing units 1332 and / or 1334, with a single or multi-core processor included in each processing unit. In other embodiments, the processing unit 1304 may even be implemented as a quad-core processing unit formed by integrating two dual-core processors into a single chip.
[0164] In various embodiments, the processing unit 1304 may execute various programs in response to program code and may maintain multiple simultaneously executing programs or processes. At any given time, some or all of the program code to be executed may reside in the processor 1304 and / or in the storage subsystem 1318. Through suitable programming, the processor 1304 may provide various functionality as described above. The computer system 1300 may additionally include a processing acceleration unit 1306, which may include a digital signal processor (DSP), special purpose processor, and / or the like.
[0165] The I / O subsystem 1308 may include user interface input devices and user interface output devices. User interface input devices may include a keyboard, a pointing device such as a mouse or trackball, a touchpad or a touch screen integrated into a display, a scroll wheel, a click wheel, a dial, a button, a switch, a keypad, an audio input device with a voice command recognition system, a microphone, and other types of input devices. User interface input devices may include, for example, a motion sensing and / or gesture recognition device such as a Microsoft Kinect® motion sensor that allows a user to control and interact with an input device such as a Microsoft Xbox® 360 game controller through a natural user interface using gestures and verbal commands. User interface input devices may also include an eye gesture recognition device such as a Google Glass® blink detector that detects eye activity from a user (e.g., a "blink" while taking a picture and / or making a menu selection) and translates the eye gesture as input to an input device (e.g., Google Glass®). In addition, the user interface input devices may include a voice recognition sensing device that allows a user to interact with a voice recognition system (e.g., the Siri® navigator) via voice commands.
[0166] User interface input devices may further include, without limitation, three-dimensional (3D) mice, joysticks or pointing sticks, game pads, and graphic tablets, as well as audio / visual devices such as speakers, digital cameras, digital camcorders, portable media players, webcams, image scanners, fingerprint scanners, barcode readers 3D scanners, 3D printers, laser range finders, and eye-tracking devices. In addition, user interface input devices may include medical imaging input devices such as, for example, computed tomography, magnetic resonance imaging, position emission tomography, medical sonography devices, etc. User interface input devices may further include audio input devices such as, for example, MIDI keyboards, digital musical instruments, and the like.
[0167] User interface output devices may include a display subsystem, indicator lights, or non-visual displays such as audio output devices, etc. Display subsystems may be flat panel devices such as those using cathode ray tubes (CRTs), liquid crystal displays (LCDs) or plasma displays, projection devices, touch screens, and the like. In general, use of the term "output device" is intended to include all possible types of devices and mechanisms for outputting information from computer system 1300 to a user or to another computer. For example, user interface output devices may include various display devices that visually convey text, graphics, and audio / video information, such as, without limitation, monitors, printers, speakers, headphones, automobile navigation systems, plotters, voice output devices, and modems.
[0168] Computer system 1300 may include a storage subsystem 1318 that includes software elements shown as currently located in system memory 1310. The system memory 1310 may store program instructions that are loadable and executable on the processing unit 1304, as well as data generated during the execution of these programs.
[0169] Depending on the configuration and type of computer system 1300, the system memory 1310 may be volatile (such as random access memory (RAM)) and / or non-volatile (such as read only memory (ROM), flash memory, etc.). RAM typically contains data and / or program modules that are immediately accessible to and / or currently being operated on and executed by the processing unit 1304. In some implementations, the system memory 1310 may include a number of different types of memory, such as static random access memory (SRAM) or dynamic random access memory (DRAM). In some implementations, a basic input / output system (BIOS), which contains the basic routines that help to transfer information between elements within the computer system 1300, such as during start-up, may typically be stored in ROM. By way of example and not by way of limitation, system memory 1310 further illustrates application programs 1312, which may include client applications, a web browser, a middle tier application, a relational database management system (RDBMS), etc., program data 1314, and operating system 1316. By way of example, operating system 1316 may include various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems, various commercially available UNIX® or UNIX-like operating systems (including, without limitation, various GNU / Linux operating systems, Google Chrome® OS, and the like), and / or mobile operating systems such as iOS, Windows® Phone, Android® OS, BlackBerry® OS, and Palm® OS operating systems.
[0170] The storage subsystem 1318 may further provide a tangible computer-readable storage medium for storing basic programming and data constructs that provide the functionality of some embodiments. Software (programs, code modules, instructions) that, when executed by a processor, provide the functionality described above may be stored in the storage subsystem 1318. These software modules or instructions may be executed by the processing unit 1304. The storage subsystem 1318 may further provide a repository for storing data used by the present disclosure.
[0171] Storage subsystem 1300 may further include a computer readable storage medium reader 1320, which may be further connected to a computer readable storage medium 1322. Along with, and optionally in combination with, the system memory 1310, the computer readable storage medium 1322 may comprehensively represent remote, local, fixed, and / or removable storage devices plus storage media for temporarily and / or more permanently holding, storing, transmitting, and retrieving computer readable information.
[0172] The computer readable storage medium 1322 carrying the code or a portion of the code may further include any suitable medium known or used in the art, including, but not limited to, storage media and communication media, such as volatile and non-volatile, removable and non-removable media, implemented in any manner or technology for storing and / or transmitting information. This computer readable storage medium 1322 may include tangible computer readable storage media, such as RAM, ROM, Electronically Erasable Programmable ROM (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device, or other tangible computer readable medium. This computer readable storage medium 1322 may further include non-tangible computer readable media, such as data signals, data transmissions, or any other medium that may be used to transmit the desired information and that may be accessed by the computing system 1300.
[0173] By way of example, the computer readable storage medium 1322 may include a hard disk drive that reads from or writes to non-removable, non-volatile magnetic media, a magnetic disk drive that reads from or writes to a removable, non-volatile magnetic disk, and an optical disk drive that reads from or writes to a removable, non-volatile optical disk, such as a CD ROM, DVD, and Blu-Ray® disk or other optical media. The computer readable storage medium 1322 may include, but is not limited to, a Zip® drive, a flash memory card, a Universal Serial Bus (USB) flash drive, a Secure Digital (SD) card, a DVD disk, a digital video tape, and the like. The computer-readable storage medium 1322 may further include solid-state drives (SSDs) based on non-volatile memory, such as flash memory-based SSDs, enterprise flash drives, solid-state ROM, and the like, SSDs based on volatile memory, such as solid-state RAM, dynamic RAM, static RAM, DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and the like, as well as hybrid SSDs using a combination of DRAM and flash memory-based SSDs. The disk drives and their associated computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer system 1300.
[0174] The communications subsystem 1324 provides an interface to other computer systems and networks. The communications subsystem 1324 serves as an interface for receiving data from and transmitting data to systems other than the computer system 1300. For example, the communications subsystem 1324 may enable the computer system 1300 to connect to one or more devices via the Internet. In some embodiments, the communications subsystem 1324 may include radio frequency (RF) transceiver components for accessing wireless voice and / or data networks (e.g., using cellular telephone technology, advanced data network technologies such as 3G, 4G, or EDGE (enhanced data rates for global evolution), WiFi (IEEE 802.11 family of standards, or other mobile communications technologies, or any combination thereof), global positioning system (GPS) receiver components, and / or other components. In some embodiments, the communications subsystem 1324 may provide wired network connectivity (e.g., Ethernet) in addition to or instead of a wireless interface.
[0175] In some embodiments, the communications subsystem 1324 may also receive incoming communications in the form of structured and / or unstructured data feeds 1326, event streams 1328, event updates 1330, and the like for one or more users that may be using the computer system 1300.
[0176] By way of example, the communications subsystem 1324 may be configured to receive real-time data feeds 1326 from users of social networks and / or other communications services, such as web feeds such as Twitter® feeds, Facebook® updates, Rich Site Summary (RSS) feeds, and / or real-time updates from one or more third party sources.
[0177] Additionally, the communications subsystem 1324 may be further configured to receive data in the form of a continuous data stream, which may include an event stream 1328 of real-time events and / or event updates 1330, which may be continuous or open-ended in nature without a clear end. Examples of applications that generate continuous data may include, for example, sensor data applications, financial tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automobile traffic monitoring, and the like.
[0178] The communications subsystem 1324 may further be configured to output structured and / or unstructured data feeds 1326, event streams 1328, event updates 1330, and the like to one or more databases, which may be in communication with one or more streaming data source computers coupled to the computer system 1300.
[0179] The computer system 1300 may be one of a variety of types, including a handheld portable device (e.g., an iPhone® cellular phone, an iPad® computing tablet, a PDA), a wearable device (e.g., a Google Glass® head mounted display), a PC, a workstation, a mainframe, a kiosk, a server rack, or any other data processing system.
[0180] Due to the ever-changing nature of computers and networks, the description of the computer system 1300 depicted in the figure is intended only as a specific example. Many other configurations are possible having more or fewer components than the system depicted in the figure. For example, customized hardware may even be used, and / or certain elements may be implemented in hardware, firmware, software (including applets), or a combination. Furthermore, connections to other computing devices, such as network input / output devices, may be used. Based on this disclosure and the teachings provided herein, one skilled in the art will perceive other ways and / or methods for implementing various embodiments.
[0181] Although specific embodiments have been described, various modifications, alterations, alternative configurations, and equivalents are also encompassed within the scope of the present disclosure. The embodiments are not limited to operating in some specific data processing environments, but can freely operate in multiple data processing environments. In addition, while the embodiments have been described using a specific sequence of transactions and steps, it should be apparent to one skilled in the art that the scope of the present disclosure is not limited to the sequence of transactions and steps described. Various features and aspects of the embodiments described above may be used individually or jointly.
[0182] Furthermore, while the embodiments have been described using a particular combination of hardware and software, it should be appreciated that other combinations of hardware and software are also within the scope of the present disclosure. The embodiments may be implemented solely in hardware, or solely in software, or using a combination thereof. The embodiments may be implemented by using a computer program product that includes computer programs / instructions that, when executed by a processor, cause the processor to perform any of the methods described in the present disclosure. The various processes described herein may be implemented on the same processor, or on different processors in any combination. Thus, when a component or module is described as being configured to perform certain operations, such configuration may be achieved, for example, by designing an electronic circuit to perform the operations, by programming a programmable electronic circuit (such as a microprocessor) to perform the operations, or any combination thereof. Processes may communicate using various techniques, including, but not limited to, conventional techniques for inter-process communication, and different pairs of processes may use different techniques, or the same pair of processes may use different techniques at different times.
[0183] Thus, the specification and drawings should be evaluated in an illustrative rather than restrictive sense. However, it will be apparent that additions, subtractions, deletions, and other modifications and alterations may be made to the specification and drawings without departing from the broader spirit and scope as set forth in the claims. Thus, although certain disclosed embodiments have been described, these embodiments are not intended to be limiting. Various modifications and equivalents are within the scope of the following claims.
[0184] In the context of describing the disclosed embodiments (especially in the context of the claims that follow), the use of the terms "a" and "an" and "the" and similar referents should be interpreted to encompass both the singular and the plural, unless otherwise indicated herein or clearly contradicted by the context. The terms "including," "having," "comprising," and "holding" should be interpreted as open-ended terms (i.e., meaning "including, but not limited to"), unless otherwise noted. The term "connected" should be interpreted as being held in, attached to, or integrally connected, either partially or wholly, even if there is something intervening. The recitation of ranges of values herein is intended to serve merely as a shorthand method of referring individually to each separate value within the range, unless otherwise indicated herein, and each separate value is incorporated into this specification as if that value were individually recited herein. All methods described herein may be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. Any examples or use of exemplary language (e.g., "etc.") provided herein are intended merely to better shed light on the embodiments and do not pose limitations on the scope of the disclosure unless otherwise claimed. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the disclosure.
[0185] Disjunctive language such as the phrase "at least one of X, Y, or Z" is intended to be understood in context as being generally used to state that an item, term, etc., can be either X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z), unless specifically stated otherwise. As such, such disjunctive language is generally not intended to, and should not, imply that some embodiments require that at least one of X, at least one of Y, or at least one of Z, respectively, be present.
[0186] Preferred embodiments of the present disclosure, including the best mode known for carrying out the present disclosure, are described herein. Variations of these preferred embodiments may become apparent to those skilled in the art upon reading the foregoing description. Those skilled in the art should be able to use such variations as appropriate, and the present disclosure may be practiced in other ways than as specifically described herein. Accordingly, the present disclosure includes all modifications and equivalents of the subject matter recited in the claims appended hereto as permitted by applicable law. Moreover, any combination of the above-described elements in all possible variations of these preferred embodiments is encompassed by the present disclosure, unless otherwise indicated herein.
[0187] All references cited in this specification, including publications, patent applications, and patents, are hereby incorporated by reference to the same extent as if each reference was individually and specifically indicated to be incorporated by reference and was discussed in its entirety in this specification.
[0188] In the foregoing specification, aspects of the present disclosure have been described with reference to specific embodiments of the present disclosure, but those skilled in the art will recognize that the present disclosure is not limited to those embodiments. The various features and aspects of the present disclosure described above may be used individually or jointly. Moreover, the embodiments may be utilized in any number of environments and applications beyond those described herein without departing from the broader spirit and scope of the present specification. Thus, the present specification and drawings should be regarded as illustrative rather than restrictive.
Claims
1. 1. A computer program comprising instructions that, when executed by a computing system, cause the computing system to: receiving a request for an action to be performed by the computing system, the request being received from a client device; identifying one or more authorizers from which authorization for the action is to be received, the authorization corresponding to performance of the action on the client device; serializing one or more operations corresponding to the action; signing the serialized operation or operations using an elliptic curve digital signature algorithm; a computer program that initiates an inquiry procedure about the authorization of the action from each of the one or more authorizers to determine whether the one or more operations are authorized to be performed.
2. The instructions, when executed by the computing system, further cause the computing system to: determining that the authorization for the action has been received from each of the one or more authorizers; verifying that the serialized one or more operations have not been tampered with based at least in part on a signature produced by the signing of the serialized one or more operations; The computer program product of claim 1 , further comprising: causing the one or more operations to be performed based at least in part on the determination that the authorization for the action has been received.
3. 3. The computer program product of claim 1, wherein signing the serialized one or more operations includes generating a signature, the instructions, when executed by the computing system, further causing the computing system to provide the signature to the client device.
4. Initiating the inquiry procedure is sending at least one authorization request to each of the one or more authorizers; and monitoring for a response to the at least one authorization request from each of the one or more authorizers.
5. 3. The computer program product of claim 1 or claim 2, wherein the computing system includes a cloud infrastructure service, the cloud infrastructure service configured to receive the request for the action at an edge of an enclave of the cloud infrastructure service.
6. The computer program product of claim 5 , wherein the cloud infrastructure service is configured to receive the request for the action outside a firewall of the enclave.
7. The actions include creating a load balancer, and the instructions, when executed by the computing system, cause the computing system to: determining that the authorization for the action has been received from each of the one or more authorizers; The computer program product according to claim 1 or 2, further causing the computer program product to perform the following:
8. 8. The computer program product of claim 7, wherein the computing system is a cloud infrastructure service, the cloud infrastructure service configured to create the load balancer at an edge of an enclave of the cloud infrastructure service.
9. 1. A method for determining authorization for an action on a cloud infrastructure service, comprising: receiving, by a security element, a request for an action to be performed by the cloud infrastructure service; the security element identifying one or more authorizers from which authorization for the action is to be received, the authorization corresponding to the performance of the action; The method comprises: the security element determining one or more operations to be performed by the cloud infrastructure service to complete the action; the security element signing the one or more operations with an elliptic curve digital signature algorithm; the security element storing the one or more signed operations; The method further comprising: the security element initiating a query procedure regarding the authorization of the action based at least in part on responses received from the one or more authorizers.
10. 10. The method of claim 9, further comprising the security element serializing the one or more operations, and wherein the signing of the one or more operations comprises signing the serialized one or more operations.
11. the security element determining that the authorization for the action has been received from each of the one or more authorizers; the security element verifying that the one or more operations have not been tampered with based at least in part on a signature produced by the signing of the one or more operations; 11. The method of claim 9 or claim 10, further comprising causing the security element to perform the one or more operations based at least in part on the determining that the authorization for the action has been received.
12. The method of claim 9 or claim 10, wherein the security element is implemented at the edge of an enclave of the cloud infrastructure service.
13. The method of claim 12 , wherein the security element is implemented outside a firewall of the enclave.
14. The method of claim 12 , wherein the security element comprises a proxy or daemon for the cloud infrastructure service.
15. Initiating the inquiry procedure is the security element sending at least one authorization request to the one or more authorizers; 11. The method of claim 9 or claim 10, further comprising: the security element monitoring for the response to the at least one authorization request received from the one or more authorizers; and whether the one or more operations will be performed by the cloud infrastructure service is based at least in part on the response.
16. 11. The method of claim 9 or claim 10, wherein the cloud infrastructure service is a first cloud infrastructure service and the request is received from a second cloud infrastructure service, the method further comprising the security element preventing secure information associated with the first cloud infrastructure service from being provided to the second cloud infrastructure service prior to receipt of the response received from the one or more authorizers.
17. 1. A computing system comprising: a memory for storing operations for execution by the computing system; one or more processors coupled to the memory, the one or more processors: identifying a request for an action to be performed by the computing system, the request being received from a client device; identifying one or more authorizers from which authorization for the action is to be received, the authorization corresponding to performance of the action on the client device; determining one or more operations to be performed by the computing system to complete the action; serializing the one or more operations; signing the serialized operation or operations with an elliptic curve digital signature algorithm; storing the signed serialized operation or operations in the memory; A computing system that initiates a query procedure regarding authorization for the action from the one or more authorizers.
18. The one or more processors further determining that the authorization for the action has been received from each of the one or more authorizers; Retrieving the signed serialized operation or operations from the memory; 20. The computing system of claim 17, wherein the one or more operations are performed based at least in part on the authorization and the signed serialized one or more operations retrieved from the memory.
19. 20. The computing system of claim 18, wherein the one or more processors are further for verifying that the signed serialized one or more operations have not been tampered with based at least in part on a signature produced by the signing of the serialized one or more operations, and wherein the one or more operations are to be executed based at least in part on the verification that the signed serialized one or more operations have not been tampered with.
20. 20. The computing system of claim 17 or claim 18, wherein the computing system includes a cloud infrastructure service, and wherein the one or more processors further implement a security element at an edge of an enclave of the cloud infrastructure service, the security element identifying the request for the action.