Authenticity assessment of the requester based on communication requests
The system dynamically authenticates requesters in SDN environments, addressing the lack of device verification in existing systems, thereby enhancing network security and efficiency by automatically adjusting network configurations based on request legitimacy.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- INTERNATIONAL BUSINESS MACHINE CORPORATION
- Filing Date
- 2021-11-24
- Publication Date
- 2026-05-11
AI Technical Summary
Existing network security systems, particularly in software-defined networks (SDN), lack effective methods to authenticate and verify the authenticity of requesting devices and applications, leading to potential security risks and inefficiencies in network configuration changes.
A method and system for dynamically establishing communication paths by evaluating the authenticity of requesters based on predefined rules, using a communication controller to assess the legitimacy of requests and modify network configurations accordingly, without requiring manual updates or modifying existing requesters.
Enhances network security by automatically authenticating devices and applications, reducing the risk of security breaches and minimizing manual configuration errors, while enabling rapid and efficient network adjustments.
Smart Images

Figure 0007856375000001 
Figure 0007856375000002 
Figure 0007856375000003
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of computing, and more specifically, to computer security.
Background Art
[0002] Generally, computer security, cyber security, or information technology security (IT security) can include protecting computer systems and networks from disruption or misdirection of services and applications running on a computer. The field of computer security is growing in importance due to the increasing dependence on computer systems, the Internet, wireless network standards, and the growth of smart devices including smartphones and apps. In computing, a firewall is one of the main ways to control traffic on a network. More specifically, a firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. Another method of computer protection can include endpoint authentication, an authentication mechanism used to verify the identity of external or remote connection devices on a network. For example, in a wireless network based on endpoint authentication, user authentication information such as a service set identifier (SSID) and password, and the security protocol used by the endpoint device are verified.
Summary of the Invention
[0003] A method is provided for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request. The method dynamically determines whether to establish a communication path from the requester to the destination over a communication network by evaluating the requester based on one or more authentication rules in response to receiving the communication request, wherein the one or more authentication rules are based on first information relating to the communication network, second information about the requester, and third information from the requester. The method may further include dynamically establishing the communication path for the requester on the communication network according to one or more communication attributes relating to the requester, in response to determining that the requester satisfies the one or more authentication rules.
[0004] A computer system is provided for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request. The computer system may include one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage devices, and program instructions stored in at least one of the one or more storage devices for execution by at least one of the one or more processors via at least one of the one or more memories. The computer system is capable of executing a method. The method may include dynamically determining whether to establish a communication path from the requester to a destination over a communication network by evaluating the requester based on one or more authentication rules in response to receiving the communication request, wherein the one or more authentication rules are based on first information relating to the communication network, second information about the requester, and third information from the requester. The method may further include dynamically establishing the communication path for the requester on the communication network according to one or more communication attributes relating to the requester, in response to determining that the requester satisfies the one or more authentication rules.
[0005] A computer program product is provided for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request. The computer program product may include one or more tangible computer-readable storage devices and program instructions stored in at least one of the one or more tangible computer-readable storage devices and executable by a processor. The computer program product includes program instructions for dynamically determining whether to establish a communication path from the requester to a destination over a communication network by evaluating the requester based on one or more authentication rules in response to receiving the communication request, wherein the one or more authentication rules include program instructions based on first information relating to the communication network, second information about the requester, and third information from the requester. The computer program product may further include program instructions for dynamically establishing the communication path for the requester on the communication network in accordance with one or more communication attributes relating to the requester, in response to determining that the requester satisfies the one or more authentication rules. [Brief explanation of the drawing]
[0006] The above and other objects, features, and advantages of the present invention will become apparent from the following detailed description relating to exemplary embodiments. These embodiments should be read in conjunction with the accompanying drawings. Note that the various features in the drawings are not to scale, as they are for clarity to facilitate understanding of the invention by those skilled in the art in conjunction with the detailed description.
[0007] [Figure 1] This figure shows a networked computer environment according to one embodiment. [Figure 2] This is an operation flowchart illustrating the steps performed by a program for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request, according to one embodiment. [Figure 3] This is a block diagram showing the system architecture of a program for dynamically establishing a communication path for a requester by evaluating the truthfulness of the requester and the communication request, according to one embodiment. [Figure 4] Figure 1 is a block diagram of an exemplary cloud computing environment, including the computer system shown in Figure 1, according to one embodiment of this disclosure. [Figure 5] Figure 4 is a block diagram of the functional layers of an exemplary cloud computing environment according to one embodiment of this disclosure. [Modes for carrying out the invention]
[0008] Detailed embodiments of the claimed structure and method are disclosed herein. However, it should be understood that the embodiments described herein are merely illustrative of the claimed structure and method, which can be embodied in various forms. The present invention may be embodied in many different forms and should not be construed as being limited to the exemplary embodiments described herein. In order to avoid unnecessarily obscuring the embodiments presented herein, well-known features and technical details may be omitted.
[0009] As described above, embodiments of the present invention generally relate to the field of computing, and more specifically to computer and network security. Specifically, the exemplary embodiments described below provide systems, methods, and program products for improving the generation of network flows based on application requests and for measuring the authenticity of requests. More specifically, the present invention can improve the technical field related to computer and network security by evaluating the strength of the requester's authenticity and the validity of the request based on rules that can determine whether to subsequently modify the network for the requested action. For example, the present invention may include a communications controller capable of interpreting rules for evaluating the strength of the requester's authenticity and the validity of the requested network action. The communications controller can also maintain awareness of pre-approved applications and predefined network attributes associated with them. The communications controller uses this information to evaluate communications requests and enables only those that are permitted according to a predefined policy, based on the strength of the requester's authenticity and the appropriateness of the request for the requested connection. In response, network configuration changes may be sent to a network such as a software-defined network (SDN) to enable the allowed traffic and disable it when communication is no longer needed.
[0010] Specifically, as mentioned earlier regarding computer security, firewalls and endpoint authentication are two common methods for controlling network connectivity and traffic. However, firewalls often require considerable time to determine the complex set of addresses, ports, and protocols to allow or block, potentially delaying critical business workflows. Furthermore, once the desired access control is defined for a firewall, a change window is usually required, during which many network-connected devices must be manually updated to implement the desired control. This manual configuration process is time-consuming and prone to errors. Moreover, access control often remains active for extended periods even after the applications or systems to which it was initially implemented have been decommissioned. This can lead to security risks, as allowed ports and protocols may be used for malware or other undesirable traffic.
[0011] The advent of SDN has enabled network devices to be programmatically reconfigured rapidly, reducing both the time required to implement changes and the potential for human error. Currently, the reconfiguration process is a centralized approach, where an all-knowing network provider directs the creation and deletion of acceptable network flows. Furthermore, the network provider may install firewalls within the network to control flows, and in SDN, the network provider can control flows by having the network generate dynamic routes under the network provider's control, or by creating instances of firewalls specifically for the purpose of supporting appropriate flows and flow control. However, the root cause of hackers' past successes was the lack of device authentication methods to verify computer devices. This root cause led to the development of endpoint authentication and protocols such as SFTP and HTTPS, where devices must prove their identity as part of establishing a connection. However, SDN is shifting its concept from route creation by an all-knowing service provider to on-demand route creation by requestors such as computer devices and applications on the network. This is made possible by providing SDN systems with access to application programming interfaces (APIs), through which devices can instruct the SDN to create, delete, or modify paths across the network. Furthermore, endpoint / device authentication may be used to authenticate devices, but the requester may include not only computer devices but also applications running on the devices, or microservices associated with the device, the application, or both. Therefore, it may be impossible for an omniscient network provider to be aware of all possible devices, applications, or microservices.Similarly, the application is made into a temporary container that is created as needed and then destroyed, and network flow is required throughout the application's lifespan.
[0012] Therefore, to avoid large-scale security breaches, networks need a way to evaluate the authenticity of requesting devices, given the reality that in SDN, endpoint devices generally cannot be modified to actively participate in proving their authenticity (i.e., devices must prove their concept). Furthermore, such a solution to this problem needs to operate without modifying existing requesters or existing network protocols, as the installed base of requesters is enormous and the cost of changing the network and interactions with requesters could be immeasurable. Thus, it may be advantageous to provide methods, computer systems, and computer program products for dynamically (i.e., automatically, in real time) establishing a communication path for communication requests by evaluating the strength of the requester's authenticity and the legitimacy of the request based on rules that can determine whether to subsequently modify the network to allow the requested action.
[0013] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions containing one or more executable instructions for performing a specific logical function. In some other implementations, the functions shown within a block may be executed in an order different from the order shown in each diagram. For example, depending on the functions involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may be executed in reverse order. Each block in a block diagram or flowchart, or both, and combinations of multiple blocks in a block diagram or flowchart, or both, can be executed by a dedicated hardware-based system that performs a specific function or operation, or executes a combination of dedicated hardware and computer instructions.
[0014] Referring here to Figure 1, an exemplary networked computer environment 100 according to one embodiment is shown. The networked computer environment 100 may include a computer 102 having a processor 104 and a data storage device 106 and capable of running a software program 114. The networked computer environment 100 may further include a microphone (not shown). The software program 114 may be an application program such as an internet application or one or more apps or both, running on a client computer 102 such as a desktop, laptop, tablet, and mobile phone device. An authenticity / legitimacy evaluation program 108 may communicate with the software program 114. The networked computer environment 100 may further include a server 112 and a communication network 110. The networked computer environment 100 may include multiple computers 102 and a server 112, but only one is shown for the sake of simplicity in the illustration. For example, the multiple computers 102 may include multiple interconnected devices such as mobile phones, tablets, and laptops associated with one or more users.
[0015] In at least one implementation, this embodiment may include a database 116. The database 116 may run on a server 112. The communication network 110 may include various types of communication networks, such as a software-defined network (SDN), wide area network (WAN), local area network (LAN), telecommunications network, wireless network, public switched circuit network or satellite network, or a combination thereof. Note that Figure 1 is merely an example of one implementation and does not imply any limitation on environments in which different embodiments can be implemented. Many modifications are possible to the illustrated environment based on design and implementation requirements.
[0016] The client computer 102 may communicate with the server computer 112 via a communication network 110. The communication network 110 may include connections such as wired, wireless link, or fiber optic cable. As illustrated with reference to Figure 3, the server computer 112 may include internal component 1102a and external component 1104a, respectively, and the client computer 102 may include internal component 1102b and external component 1104b, respectively. The server computer 112 may also operate in a cloud computing service model such as Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS). The server 112 may also be deployed in a cloud computing deployment model such as a private cloud, community cloud, public cloud, or hybrid cloud. The client computer 102 may be, for example, a mobile device, telephone, personal digital assistant, netbook, laptop computer, tablet computer, desktop computer, or any type of computing device capable of running programs and accessing a network.
[0017] The networked computer environment 100 may further include a communication controller 136 capable of executing an authenticity and legitimacy evaluation program 108. According to various implementations of this embodiment, the communication controller 136 may include one or more servers or other computing devices or both, and / or may be embedded in the communication network 110 or various storage devices such as a network-connected server 112 or a cloud storage service (but not limited to these). The communication controller 136 may interact with the communication network 110. The communication controller 136 may be configured to dynamically evaluate communication requests by evaluating the authenticity of the requester and the legitimacy of the request based on rules that allow the authenticity and legitimacy evaluation program 108 to determine whether to subsequently modify the communication network 110 to permit the requested action. Specifically, the communication controller 136 may be configured so that the authenticity and legitimacy evaluation program 108 receives the communication request, determines whether and to what extent the request should be honored, and instructs the communication network 110 to perform network configuration as necessary.
[0018] According to one embodiment, the requester may be any entity such as an application, microservice, software component, hardware component, and computing device. The entity can request the communication network 110 to establish a communication path to a destination. For example, the requester may include a database application requesting a connection to another database application for the purpose of backing up a database, a laptop application requesting a connection to a server application such as an email client requesting communication with an email server, or a microservice requesting a connection to a database such as a microservice looking up weather information for a specific location, or a combination thereof.
[0019] As will be explained in more detail with reference to Figure 2, the communication controller 136 and the authenticity and legitimacy evaluation program 108 may evaluate the strength of authenticity of the requester on the network path based on one or more combinations of authenticity assertions, which may include authenticity assertions based on information from the communication network 110, authenticity assertions based on information about the requester, authenticity assertions based on information from the requester, and authenticity assertions based on information about the network operator / owner. For example, during the setup phase, the communication controller 136 may be configured, by an authenticity and legitimacy evaluation program 108, to determine which requesters are permitted to communicate with the communication controller 136 on the communication network 110, to establish required / recommended communication attributes for some communication types, specific communications, or both, to establish the level of legitimacy required for a requester (or category of requesters) to prove their authenticity, and to establish evaluation rules for evaluating the appropriateness of requests (for example, determining the threshold number of authenticity assertions that a requester must satisfy before establishing a communication path for them).
[0020] According to one embodiment, communication attributes may include required or preferred characteristics of a communication path. These characteristics are not limited to, but include, the physical routing of a communication path through a specific physical location or region or country, requirements for maximum or minimum route latency, requirements for high availability routes, requirements for routes capable of accommodating a minimum packet size, requirements for routes providing minimum or maximum throughput, requirements for routes existing only during specific time periods or days of the week, requirements for encryption of the route and its encryption strength, and requirements for minimum and maximum duration of the route. Also according to one embodiment, physical network connectivity information may include attributes of the physical connectivity used by the requester to connect itself to the communication network 110. This information may include physical link identification information, physical link type and characteristics (i.e., 10 Gigabit link speed, Ethernet, wired, fiber), switch port identification information, and the physical location of the link (i.e., Real-Time Transport Protocol (RTP) campus (North Carolina, United States)). Furthermore, according to one embodiment, the logical network connection information may include attributes relating to the logical connection that the requester is using to connect itself to the communication network 110. This may include an IP address, IP subnet, VLAN ID, default router IP address, and network stack provider.
[0021] Next, Figure 2 is an operation flowchart 200 showing the steps performed by the authenticity and legitimacy evaluation program 108 to dynamically evaluate and process a communication request by evaluating the strength of the requester's authenticity and the legitimacy of the request based on rules that can determine whether to subsequently modify the communication network 110 to allow the requested action. Specifically, in step 202 of Figure 2, as described above, the communication controller 136 and the authenticity and legitimacy evaluation program 108 may receive a communication request from a requester. As described above, the requester may be any entity that can request the communication network 110 to establish a communication path to a destination. For example, the requester may include a database application requesting a connection to another database application, a laptop application running on a client computer 102 requesting a connection to a server application running on server 112, or a microservice requesting a connection to database 116, or a combination thereof. According to one embodiment, the requester may send a signal to the communication controller 136 or the communication network 110 (capable of transmitting the communication request to the communication controller 136). For example, the communication network 110 may receive a Domain Name System (DNS) resolution query from the requester and notify the communication controller 136 of this DNS query. It should be noted that, to those skilled in the art, there may be multiple ways to identify a communication request. Therefore, the above method should not be considered limiting.
[0022] Next, in step 204, upon receiving the communication request, the communication controller 136 may use the authenticity and legitimacy evaluation program 108 to evaluate the authenticity of the requester and the communication request. Specifically, the authenticity and legitimacy evaluation program 108 may perform the authenticity evaluation based on a set of authentication rules (i.e., authenticity assertions) that govern whether a connection should be established between the requester and the desired server / database to process the action requested in the communication request. More specifically, for example, as described above, the authenticity and legitimacy evaluation program 108 may perform the authenticity evaluation based on a requester and an received request that satisfy one or more of the authenticity assertions, which may include authenticity assertions based on information from the communication network 110, authenticity assertions based on information about the requester, authenticity assertions based on information from the requester, and authenticity assertions based on information about the network operator / owner.
[0023] For example, in the case of an authenticity assertion based on information from the communication network 110, the authenticity / validity evaluation program 108 may cause the communication controller 136 to query the communication network 110 regarding the physical network attributes of the requester, query the communication network 110 regarding the logical network connection information of the requester, or query the communication network 110 regarding the connection history of the requester, or a combination thereof. Also, for example, in the case of an authenticity assertion based on information about the requester, the authenticity / validity evaluation program 108 may cause the communication controller 136 to scan the requester for observable attributes such as open ports or the version / level of the operating system (OS) related to the requester, or both, take a fingerprint of the requester, or query an identity authority that guarantees the authenticity of the requester, or a combination thereof. Also, for example, in the case of an authenticity assertion based on information from the requester, the authenticity / validity evaluation program 108 may cause the communication controller 136 to receive the identity credential of the requester from the requester as part of the request, or query the requester to receive the identity credential from the requester. Further, for example, in the case of an authenticity assertion based on information about the network operator / owner, the authenticity / validity evaluation program 108 may cause the communication controller 136 to query the network operator regarding the allowed connection configuration. The determination of whether the authenticity evaluation is true (i.e., satisfied) can be based on whether a single authenticity assertion is true, or some combination of different authenticity assertions, or an indicator of weighted authenticity assertions where the sum of the weights exceeds a threshold. Thus, there may be numerous techniques for combining various possible authenticity assertions based on the configuration.
[0024] For example, the communication controller 136 may receive a DNS query from an application 114 running on a client computer 102. Here, the DNS query may be a request to execute a microservice requesting weather information for New York City. Thus, the DNS query can be interpreted as a request to establish a temporary connection between the requester (i.e., the application) and the database 116, which holds weather information about New York City, so that the requester can query the database 116. Accordingly, the authenticity evaluation program 108 may perform an authenticity evaluation of the requester and the communication request to determine whether the requester (i.e., the application) is authentic, trustworthy, or both, in order to establish a communication path on the communication network 110 between the requester and the database 116. Therefore, the authenticity and legitimacy evaluation program 108 may, based on the authenticity assertions described above, identify the physical location of the requesting application, determine whether that physical location is a trustworthy location or device or both, determine whether the application's logical connection is correct (for example, whether the application's IP address is understandable), or, based on the connection history, determine whether the application has made similar connections to the database 116 in the past 16 days, or perform a combination of these actions. In this way, based on whether one or more combinations of these authenticity assertions are met, or based on whether the authenticity assertions with the greatest weight are met, or both, the authenticity and legitimacy evaluation program 108 may decide whether to dynamically establish a communication path through the communication network 110 and allow the requesting application to connect to the database 116.
[0025] Next, in step 206, in response to determining that the communication request is appropriate, more specifically, in response to the requester satisfying the required number of authenticity assertions, the authenticity and validity evaluation program 108 causes the communication controller 136 to instruct the communication network 110 to establish a communication path (i.e., a network connection) defined by the required communication attributes. As described above, the communication attributes may include requirements or recommended characteristics of the communication path. The characteristics are not particularly limited, but may include physical routing of the communication path through a specific physical location or region or country, requirements regarding maximum or minimum path latency, requirements regarding highly available paths, requirements regarding paths capable of accommodating a minimum packet size, requirements that the path exists only at a specific time, requirements that the path be encrypted and the encryption strength thereof, or requirements regarding the minimum and maximum duration of the path or a combination thereof. Thus, continuing from the above example, based on satisfying one or more combinations of the described authenticity assertions, the authenticity and validity evaluation program 108 may dynamically establish a communication path through the communication network 110 such that the requester application can connect to the database 116 containing weather information for New York City. Further, in step 208, when the communication path becomes unnecessary for the requester and the communication request, the authenticity and validity evaluation program 108 may cause the communication controller 136 to automatically terminate the network connection (i.e., the established communication path) for the requester based on the communication attributes.
[0026] Note that FIGS. 1 and 2 merely illustrate one implementation form and do not imply any limitation regarding the implementation manners of different embodiments. Based on design and implementation requirements, many changes are possible to the illustrated environment.
[0027] The present invention may be a system, method, or computer program product or a combination thereof. The computer program product may include a computer-readable storage medium storing computer-readable program instructions for causing a processor to perform an aspect of the present invention. The computer-readable storage medium may be a tangible device capable of holding and storing instructions used by an instruction execution device. The computer-readable storage medium may, for example, be an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device or a suitable combination thereof. More specific examples of computer-readable storage mediums include a portable computer diskette, a hard disk, RAM, ROM, EPROM (or flash memory), SRAM, CD-ROM, DVD, memory stick, floppy disk, a punch card or grooved raised structure, a mechanically encoded device on which instructions are recorded, and suitable combinations thereof. The computer-readable storage mediums used herein should not be interpreted as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., optical pulses passing through optical fiber cables), or electrical signals transmitted through wires.
[0028] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing device / processing device. Alternatively, they can be downloaded to an external computer or external storage device via a network (e.g., the Internet, LAN, WAN, or wireless network, or a combination thereof). The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers or edge servers, or a combination thereof. A network adapter card or network interface within each computing device / processing device receives computer-readable program instructions from the network and transfers them for storage in a computer-readable storage medium in each computing device / processing device.
[0029] The computer-readable program instructions for performing the operations of the present invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the C programming language and similar programming languages. The computer-readable program instructions can be executed as a standalone software package, either entirely on the user's computer or partially on the user's computer. Alternatively, they can be executed partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including LANs and WANs, or it may be connected to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), and programmable logic arrays (PLAs), can execute computer-readable program instructions by utilizing state information of computer-readable program instructions in order to customize the electronic circuits for the purpose of performing aspects of the present invention.
[0030] Aspects of the present invention are described herein with reference to flowcharts or block diagrams, or both, of methods, apparatus (systems), and computer program products according to embodiments of the present invention. Each block in a flowchart or block diagram, or both, and combinations of blocks in a flowchart or block diagram, or both, are executable by computer-readable program instructions.
[0031] These computer-readable program instructions can be provided to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device for the production of a machine. This creates a means for these instructions, executed via the processor of such a computer or other programmable data processing device, to perform functions / operations identified in one or more blocks in a flowchart or block diagram, or both. These computer-readable program instructions can further be stored in a computer-readable storage medium that can be instructed to function in a particular manner for a computer, a programmable data processing device, or other device, or a combination thereof. Thus, the computer-readable storage medium containing the instructions constitutes a product containing instructions for performing functions / operations identified in one or more blocks in a flowchart or block diagram, or both.
[0032] Alternatively, a computer execution process may be generated by loading computer-readable program instructions into a computer, another programmable device, or other device, and having a series of operational steps executed on that computer, other programmable device, or other device. This ensures that the instructions executed on the computer, other programmable device, or other device perform functions / operations identified by one or more blocks in a flowchart, block diagram, or both.
[0033] Figure 3 is a block diagram 1100 of the internal and external components of the component shown in Figure 1, according to an exemplary embodiment of the present invention. Note that Figure 3 is merely an example of one implementation configuration and does not imply any limitations regarding environments in which different embodiments can be implemented. Many modifications may be made to the illustrated environment based on design and implementation requirements.
[0034] The data processing systems 1102 and 1104 represent any electronic device capable of executing machine-readable program instructions. The data processing systems 1102 and 1104 may also represent a smartphone, computer system, PDA, or other electronic device. Examples of computing systems, environments, configurations, or combinations that can be represented by the data processing systems 1102 and 1104 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, network PCs, minicomputer systems, and distributed cloud computing environments including any of the systems or devices described above.
[0035] The user client computer 102 (Figure 1), the communication controller 136 (Figure 1), and the network server 112 (Figure 1) each include sets of internal components 1102a, b and external components 1104a, b, as shown in Figure 3. Each set of internal components 1102a, b includes one or more processors 1120 on one or more buses 1126, one or more computer-readable RAMs 1122, one or more computer-readable ROMs 1124, and one or more operating systems 1128 and one or more computer-readable tangible storage devices 1130. One or more operating systems 1128, software programs 114 (Figure 1) in client computers 102 (Figure 1), and authenticity and legitimacy evaluation programs 108 (Figure 1) in communication controllers 136 (Figure 1) are stored in one or more computer-readable tangible storage devices 1130 for execution by one or more processors 1120 via one or more of their respective RAMs 1122 (typically including cache memory). In the embodiment shown in Figure 3, each of the computer-readable tangible storage devices 1130 is a magnetic disk storage device of an internal hard drive. Alternatively, each of the computer-readable tangible storage devices 1130 is a semiconductor storage device such as a ROM 1124, EPROM, flash memory, or any other computer-readable tangible storage device capable of storing computer programs and digital information.
[0036] Each set of internal components 1102a and b also includes an R / W drive or interface 1132 for reading from and writing to one or more portable computer-readable tangible storage devices 1137, such as CD-ROMs, DVDs, memory sticks, magnetic tapes, magnetic disks, optical disks, and semiconductor storage devices. Software programs, such as the authenticity and legitimacy evaluation program 108 (Figure 1), can be stored in one or more of the respective portable computer-readable tangible storage devices 1137, read via their respective R / W drives or interfaces 1132, and loaded into their respective hard drives 1130.
[0037] Each set of internal components 1102a and 1102b also includes a network adapter or interface 1136, such as a TCP / IP adapter card, a wireless Wi-Fi® interface card, or a 3G or 4G wireless interface card, or other wired or wireless communication links. The authenticity and legitimacy evaluation program 108 (Figure 1) and the software program 114 (Figure 1) can be downloaded from an external computer to the client computer 102 (Figure 1) and the network server 112 (Figure 1) via the network (e.g., the Internet, a local area network, or another wide area network) and the respective network adapter or interface 1136. The software program 114 (Figure 1) in the client computer 102 (Figure 1) and the authenticity and legitimacy evaluation program 108 (Figure 1) in the communication controller 136 (Figure 1) are loaded from the network adapter or interface 1136 to their respective hard drives 1130. The network may consist of copper, fiber optic, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof.
[0038] Each of the sets of external components 1104a and 1104b may include a computer display monitor 1121, a keyboard 1131, and a computer mouse 1135. External components 1104a and 1104b may also include a touchscreen, a virtual keyboard, a touchpad, a pointing device, and other human interface devices. Each of the sets of internal components 1102a and 1102b also includes a device driver 1140 for interfacing with the computer display monitor 1121, the keyboard 1131, and the computer mouse 1135. The device driver 1140, the R / W drive or interface 1132, and the network adapter or interface 1136 consist of hardware and software (stored in the storage device 1130 or ROM 1124 or both).
[0039] While this disclosure includes a detailed description of cloud computing, it should be understood that the implementations of the teachings described herein are not limited to cloud computing environments. Rather, embodiments of the present invention can be implemented in combination with any other type of computing environment that is currently known or may be developed in the future.
[0040] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and deployed with minimal administrative effort or interaction with service providers. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.
[0041] The characteristics are as follows: On-demand self-service: Cloud consumers can unilaterally prepare computing power, such as server time and network storage, automatically as needed, without requiring human interaction with service providers. Broad network access: Computing power is available over the network and accessible through standard mechanisms. This facilitates utilization by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, PDAs). Resource pooling: A provider's computing resources are pooled and delivered to multiple consumers using a multi-tenant model. Various physical and virtual resources are dynamically allocated and reallocated as needed. Generally, consumers have a sense of location independence because they do not manage or know the exact location of the resources provided. However, consumers may be able to identify the location at a higher level of abstraction (e.g., country, state, data center). Rapid Elasticity: Computing power can be prepared quickly and flexibly, allowing it to scale out automatically and immediately, and to be quickly released and scale in immediately. To consumers, the computing power available for preparation often appears unlimited and can be purchased in any quantity at any time. Measured Services: Cloud systems leverage metric capabilities at a certain level of abstraction, appropriate for the type of service (e.g., storage, processing, bandwidth, active user accounts), to automatically control and optimize resource usage. Resource usage can be monitored, controlled, and reported, providing transparency to both service providers and consumers.
[0042] The service model is as follows: Software as a Service (SaaS): The functionality offered to consumers is the ability to use the provider's applications running on a cloud infrastructure. These applications can be accessed from various client devices via thin client interfaces such as web browsers (e.g., webmail). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functions, except for configuring a limited number of user-specific applications. Platform as a Service (PaaS): The functionality offered to consumers is the ability to deploy applications they have created or acquired to cloud infrastructure using programming languages and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, and storage, but they can control the deployed applications and, in some cases, the configuration of their hosting environment. Infrastructure as a Service (IaaS): The functionality provided to consumers is the provision of processors, storage, networking, and other basic computing resources that enable consumers to deploy and run any software, including operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but they can control the operating system, storage, and deployed applications, and in some cases, partially control certain network components (e.g., host firewalls).
[0043] The deployment model is as follows: Private Cloud: This cloud infrastructure is operated exclusively for a specific organization. This cloud infrastructure can be managed by that organization or a third party and can reside on-premises or off-premises. Community Cloud: This cloud infrastructure is shared by multiple organizations to support a specific community with common interests (e.g., mission, security requirements, policies, and compliance). This cloud infrastructure can be managed by the organization or a third party and can reside on-premises or off-premises. Public Cloud: This cloud infrastructure is provided to a large number of people or large industry groups and is owned by organizations that sell cloud services. Hybrid Cloud: This cloud infrastructure combines two or more cloud models (private, community, or public). While maintaining the unique entities of each model, they are bound together by standards or individual technologies to achieve data and application portability (e.g., cloud bursting for load balancing across clouds).
[0044] Cloud computing environments are service-oriented environments that emphasize statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is the infrastructure, which includes a network of interconnected nodes.
[0045] Here, Figure 4 shows an exemplary cloud computing environment 1200. As shown in the figure, the cloud computing environment 1200 includes one or more cloud computing nodes 4000. Local computer devices used by cloud consumers (e.g., PDA or mobile phone 1200A, desktop computer 1200B, laptop computer 1200C, or automotive computer system 1200N, or a combination thereof) can communicate with these. Nodes 10 can communicate with each other. Nodes 4000 can be grouped physically or virtually (not shown) in one or more networks, such as the private, community, public, or hybrid clouds or a combination thereof. This allows the cloud computing environment 1200 to provide infrastructure, platforms, or software as a service, or a combination thereof, without requiring cloud consumers to maintain resources on their local computer devices. Please note that the types of computer devices 1200A to N shown in Figure 4 are merely examples, and the computing node 4000 and the cloud computing environment 2000 can communicate with any type of electronic device via any type of network, a network addressable connection (e.g., using a web browser), or both.
[0046] Here, Figure 5 shows a set of functional abstraction layers 1300 provided by the cloud computing environment 1200 (Figure 4). It should be understood that the components, layers, and functions shown in Figure 5 are illustrative only, and the embodiments of the present invention are not limited to these. As illustrated, the following layers and corresponding functions are provided.
[0047] The hardware and software layer 60 includes hardware components and software components. Examples of hardware components include a mainframe 61, a reduced instruction set computer (RISC) architecture-based server 62, server 63, blade server 64, storage 65, and a network and network components 66. In some embodiments, the software components include network application server software 67 and database software 68.
[0048] The virtualization layer 70 provides an abstraction layer. From this layer, virtual entities such as virtual servers 71, virtual storage 72, virtual networks 73 including virtual private networks, virtual applications and operating systems 74, and virtual clients 75 can be provided.
[0049] As an example, the management layer 80 can provide the following functions: Resource preparation 81 enables the dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and pricing 82 enables cost tracking as resources are used within the cloud computing environment and billing or invoicing for the consumption of these resources. As an example, these resources may include licenses for application software. Security enables not only protection of data and other resources but also identification and verification of cloud consumers and tasks. The user portal 83 provides consumers and system administrators with access to the cloud computing environment. Service level management 84 enables the allocation and management of cloud computing resources to ensure that requested service levels are met. Service Level Agreement (SLA) planning and execution 85 enables the pre-arrangement and procurement of cloud computing resources that are expected to be needed in the future in accordance with the SLA.
[0050] Workload layer 90 provides examples of capabilities available in a cloud computing environment. Examples of workloads and capabilities available from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analytics processing 94, transaction processing 95, and authenticity and legitimacy assessment 96. The authenticity and legitimacy assessment program 108 (Figure 1) can be delivered "as a service on the cloud" (i.e., as software as a service (SaaS)) and can dynamically establish a communication path for communication requests by assessing the strength of the requester's authenticity and the legitimacy of the request based on rules that can determine whether to subsequently modify the communication network to allow the requested action.
[0051] While various embodiments of the present invention have been described as examples, they are not intended to be exhaustive or limit the invention to these embodiments. As will be apparent to those skilled in the art, many modifications and variations are possible without departing from the scope of each embodiment described. The terminology used herein has been selected to best describe the principles, practical applications, or technical improvements to the technology observed in the market of each embodiment, or to enable others skilled in the art to understand each embodiment disclosed herein.
Claims
1. A method for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request, In response to receiving the aforementioned communication request, the system dynamically determines whether to establish a communication path from the requester to the destination via the communication network by evaluating the requester based on one or more authentication rules, wherein the one or more authentication rules are based on first information related to the communication network, second information about the requester, and third information from the requester, and the first information related to the communication network includes one or more physical network attributes related to the requester, logical network connection information related to the requester, and connection history information related to the requester. In response to determining that the requester satisfies one or more authentication rules, the communication path for the requester is dynamically established on the communication network according to one or more communication attributes associated with the requester. Methods that include...
2. The method according to claim 1, wherein the requester is selected from a group including at least one of an application, a microservice, a software component, a hardware component, and a computing device.
3. By evaluating the authenticity of the requester and the communication request, a communication path for the requester is established. A method for dynamically establishing, Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, The decision to establish or not is made dynamically, and the one or more authentication rules are said to be The first piece of information relating to the communication network, the second piece of information about the requester, and the required Based on the third piece of information from Kyugen, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network This includes dynamically establishing the aforementioned communication path, The one or more authentication rules described above are based on fourth information about permitted connections provided by the network operator, and evaluating the requester based on said fourth information from the network operator is, A method including querying the network operator about acceptable connection configurations.
4. By evaluating the authenticity of the requester and the communication request, a communication path for the requester is established. A method for dynamically establishing, Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, The decision to establish or not is made dynamically, and the one or more authentication rules are said to be The first piece of information relating to the communication network, the second piece of information about the requester, and the required Based on the third piece of information from Kyugen, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network To dynamically establish the aforementioned communication path, Includes, Evaluating the requester based on the first information related to the communication network is, Determining one or more physical network attributes related to the requester, To determine the logical network connection information related to the aforementioned requester, To determine connection history information related to the aforementioned requester, Methods that further include the above.
5. Evaluating the aforementioned requester based on the second piece of information about the requester means that Scanning the requester for observable attributes, including open ports and the operating system version associated with the requester, Obtaining information about the requester from the inventory or database, The method according to claim 1, further comprising:
6. Evaluating the requester based on the third piece of information from the requester means that The method according to claim 1, further comprising querying the requester and receiving information related to the requester and identity verification information.
7. The method according to claim 1, further comprising automatically terminating the established communication path in response to determining that the communication path for the requester is no longer needed.
8. A computer system for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request, The computer system includes one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage devices, and program instructions stored in at least one of the one or more storage devices for execution by at least one of the one or more processors via at least one of the one or more memories, In response to receiving the aforementioned communication request, the system dynamically determines whether to establish a communication path from the requester to the destination via the communication network by evaluating the requester based on one or more authentication rules, wherein the one or more authentication rules are based on first information related to the communication network, second information about the requester, and third information from the requester, and the first information related to the communication network includes one or more physical network attributes related to the requester, logical network connection information related to the requester, and connection history information related to the requester. In response to determining that the requester satisfies one or more authentication rules, the communication path for the requester is dynamically established on the communication network according to one or more communication attributes associated with the requester. A computer system capable of performing methods including those mentioned above.
9. The computer system according to claim 8, wherein the requester is selected from a group comprising at least one of an application, a microservice, a software component, a hardware component, and a computing device.
10. By evaluating the authenticity of the requester and the communication request, a communication path for the requester is established. A computer system for dynamically establishing, One or more processors, one or more computer-readable memories, and one or more computers A readable tangible storage device and at least one of the one or more memories thereof and in order to be executed by at least one of the one or more processors Includes program instructions stored in at least one of the above storage devices. Furthermore, the aforementioned computer system Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, The decision to establish or not is made dynamically, and the one or more authentication rules are said to be The first piece of information relating to the communication network, the second piece of information about the requester, and the required Based on the third piece of information from Kyugen, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network To dynamically establish the aforementioned communication path, A method including the following is possible: The one or more authentication rules described above are based on fourth information about permitted connections provided by the network operator, and evaluating the requester based on said fourth information from the network operator is, A computer system that includes querying the network operator about acceptable connection configurations.
11. By evaluating the authenticity of the requester and the communication request, a communication path for the requester is established. A computer system for dynamically establishing, One or more processors, one or more computer-readable memories, and one or more computers A readable tangible storage device and at least one of the one or more memories thereof and in order to be executed by at least one of the one or more processors Includes program instructions stored in at least one of the above storage devices. Furthermore, the aforementioned computer system Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, The decision to establish or not is made dynamically, and the one or more authentication rules are said to be The first piece of information relating to the communication network, the second piece of information about the requester, and the required Based on the third piece of information from Kyugen, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network To dynamically establish the aforementioned communication path, A method including the following is possible: Evaluating the requester based on the first information related to the communication network is, Determining one or more physical network attributes related to the requester, To determine the logical network connection information related to the aforementioned requester, To determine connection history information related to the aforementioned requester, A computer system that further includes this.
12. Evaluating the aforementioned requester based on the second piece of information about the requester means that Scanning the requester for observable attributes, including open ports and the operating system version associated with the requester, Obtaining information about the requester from the inventory or database, The computer system according to claim 8, further comprising:
13. Evaluating the requester based on the third piece of information from the requester means that The computer system according to claim 8, further comprising querying the requester and receiving identity authentication information related to the requester.
14. The computer system according to claim 8, further comprising automatically terminating the established communication path in response to determining that the communication path for the requester is no longer needed.
15. A computer program for dynamically establishing a communication path for a requester by evaluating the authenticity of the requester and the communication request, Includes program instructions that can be executed by the processor, and such program instructions are A program instruction for dynamically determining whether to establish a communication path from the requester to the destination via a communication network by evaluating the requester based on one or more authentication rules in response to receiving the aforementioned communication request, wherein the one or more authentication rules are based on first information related to the communication network, second information about the requester, and third information from the requester, and the first information related to the communication network includes one or more physical network attributes related to the requester, logical network connection information related to the requester, and connection history information related to the requester, In response to determining that the requester satisfies one or more authentication rules, program instructions for dynamically establishing the communication path for the requester on the communication network according to one or more communication attributes associated with the requester, A computer program that includes [this].
16. The computer program according to claim 15, wherein the requester is selected from a group including at least one of an application, a microservice, a software component, a hardware component, and a computing device.
17. A communication path for a requester by evaluating the authenticity of the requester and the communication request. A computer program for dynamically establishing, Includes program instructions that can be executed by the processor, and such program instructions are Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, A program instruction for dynamically determining whether to establish or not one or more authentications The rules include: first information relating to the communication network, and second information about the requester. The report, and the program instructions based on the third piece of information from the requester, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network Program instructions for dynamically establishing the aforementioned communication path, Includes, The one or more authentication rules described above are based on fourth information about permitted connections provided by the network operator, and evaluating the requester based on said fourth information from the network operator is, A computer program that includes querying the network operator about acceptable connection configurations.
18. By evaluating the authenticity of the requester and the communication request, a communication path for the requester is established. A computer program for dynamically establishing, Includes program instructions that can be executed by the processor, and such program instructions are Upon receiving the aforementioned communication request, the requester is authenticated based on one or more authentication rules. By evaluating the communication path from the requester to the destination via the communication network, A program instruction for dynamically determining whether to establish or not one or more authentications The rules include: first information relating to the communication network, and second information about the requester. The report, and the program instructions based on the third piece of information from the requester, In accordance with the determination that the requester satisfies one or more of the authentication rules, According to one or more communication attributes associated with the requester, the requester on the communication network Program instructions for dynamically establishing the aforementioned communication path, Includes, The program instruction for evaluating the requester based on the first information related to the communication network is: A program instruction for determining one or more physical network attributes related to the requester, A program instruction for determining logical network connection information related to the requester, A program instruction for determining connection history information related to the requester, A computer program that further includes this.
19. Evaluating the aforementioned requester based on the second piece of information about the requester means that Program instructions for scanning a requester for observable attributes, including open ports and the version of the operating system associated with the requester, Program instructions for obtaining information about the requester from an inventory or database, The computer program according to claim 15, further comprising:
20. A program instruction for evaluating the requester based on the third piece of information from the requester is: The computer program according to claim 15, further comprising a program instruction for querying the requester and receiving identity authentication information related to the requester.