Nova Patents
CA2847713C

Parameter based key derivation

Abstract

Systems and methods for authentication generate keys from secret credentials shared between authenticating parties and authenticators. Generation of the keys may involve utilizing specialized information that, as a result of being used to generate the keys, renders the generated keys usable for a smaller scope of uses than the secret credential. Further, key generation may involve multiple invocations of a function where each of at least a subset of the invocations of the function results in a key that has a smaller scope of permissible use than a key produced from a previous invocation of the function. Generated keys may be used as signing keys to sign messages. One or more actions may be taken depending on whether a message and/or the manner in which the message was submitted complies with restrictions of the key's use.

CA2847713C, drawing sheet 1
Sheet 1 of 24

Term

6 yearsleft in the term

Expires 28 September 2032.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

145 claims: 23 independent, 122 dependent

  1. 1
    EMBODIMENTS IN WHICH AN EXCLUSIVE PROPERTY OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS:1· A computer-implemented method for managing access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, the method comprising: obtaining, from a central key authority, a session key corresponding to the key zone, the session key having been generated by at least applying a hash-based message authentication code function to a secret credential and a first set of one or more session parameters;receiving an electronic request to access one or more computing resources and a signature for the electronic request that was generated based at least in part on the secret credential and a second set of one or more session parameters;generating, by the one or more computer systems, a reference signature by at least applying the hash-based message authentication code function to at least the electronic request, and the obtained session key;and providing access to the one or more computing resources, in response to the request, when the generated reference signature is equivalent to the received signature.
  2. 8
    A computer-implemented method for managing access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, comprising:obtaining a session key, the session key having been generated by at least applying a function to at least a secret credential and a first set of one or more session parameters, the session key being associated with the key zone;receiving an electronic request to access the one or more computing resources and a signature for the electronic request generated based at least in part on a second set of one or more parameters;CA 2847713 2020-01-17 determining, by the one or more computer systems, whether the received signature is valid for the request by at least applying the function to at least the electronic request and the obtained session key, the received signature being determined valid as a result of at least the first set of one or more parameters being equivalent to the second set of one or more parameters;and providing the electronically requested access when the generated reference signature is equivalent to the received signature.
  3. 15
    A non-transitory computer-readable storage medium having stored thereon instructions that, if executed by one or more processors of a computer system, cause the computer system to at least:obtain a session key generated at least in part by application of a function to at least a secret credential and a set of one or more session parameters to generate a session key, the session key corresponding to a grouping of one or more computing resources in a key zone of a plurality of key zones;sign, based at least in part on the obtained session key, electronic requests for access to the one or more computing resources, thereby generating signatures for the request;and submit at least the signatures and the requests for verification by a verifier computing device configured to determine whether the submitted signatures match corresponding submitted requests and take one or more actions that cause the requests for access to be fulfilled when the submitted signatures match the corresponding submitted requests.
  4. 22
    A computer system for providing access to computing resources, comprising:one or more processors;and memory including instructions that, if executed by the one or more processors, cause the computer system to at least: obtain a key;apply a function to the key and to a set of one or more parameters to generate a session key, the one or more parameters corresponding to one or more restrictions on the session key, the session key corresponding to one or more computing resources of a key zone of a plurality of key zones;and provide the generated session key to another computing device to enable the other computing device to sign requests using the session key in accordance with the set of one or more parameters.
  5. 28
    A computer-implemented method for providing access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, the method comprising:receiving, from an authenticating party, electronic information encoding a message, a signature for the message, and a set of one or more restrictions on keys derived from a secret credential shared with the authenticating party, the signature being determinable by applying a hash-based message authentication code function to the message, the secret credential, and the set of one or more restrictions, but also being undeterminable having only the hash-based message authentication code function but without having the set of one or more restrictions;obtaining, from a central key authority, a key corresponding to the key zone, the key being generated at least in part using at least a subset of the set of one or more restrictions;CA 2847713 2020-01-17 calculating, by the one or more computer systems, a value of a hash-based message authentication code fonction by at least inputting into the hash-based message authentication code fonction: first input based at least in part on the obtained key;and second input based at least in part on the set of one or more restrictions;determining, by the one or more computer systems and based at least in part on the calculated value, whether the signature is valid;and providing access to the one or more computing resources when determined that the signature is valid.
  6. 34
    A computer-implemented method for providing access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, the method comprising:obtaining electronic information encoding (i) a message, (ii) a first signature for the message, and (iii) a set of one or more parameters, the first signature having been generated based at least in part on (i) the message, (ii) a secret credential, and (iii) the set of one or more parameters, the first signature further being CA 2847713 2020-01-17 undeterminable having only the message and the secret credential but without the set of one or more parameters;deriving a second credential based at least in part on the secret credential and at least a subset of the set of one or more parameters, the second credential being obtained from a central key authority and being associated with the key zone;generating, based at least in part on the derived second credential, a second signature;determining whether the first signature matches the second signature;and providing access to the one or more computing resources when the generated second signature matches the first signature.
  7. 43
    A non-transitory computer-readable storage medium having stored thereon instructions that, if executed by a computer system, cause the computer system to at least:obtain an intermediate key that is derived from at least a secret credential and one or more parameters for use of the intermediate key, the secret credential being obtained from a central key authority and corresponding to a grouping of computing resources in a key zone of a plurality of key zones;apply, based at least in part on the obtained intermediate key, at least a portion of a signature generation process that results in a signature for a message, the signature generation process configured such that the signature is undeterminable, by the signature generation process, to a computing device having the message, the secret credential, and the signature but lacking the one or more restrictions;and provide the message, the signature, and the one or more parameters to another computer system for access to at least a portion of the computing resources, the CA 2847713 2020-01-17 providing enabling analysis, based at least in part on the one or more parameters and the message, of the signature to determine whether the signature is valid.
  8. 49
    A computer system, comprising:one or more processors;and memory including instructions that, if executed by the one or more processors of the computer system, cause the computer system to at least: CA 2847713 2020-01-17 receive one or more electronic communications that collectively encode a message, a signature for the message, and one or more parameters, the signature being generated based at least in part on a secret credential and the one or more parameters;analyze, based at least in part on the one or more parameters, an intermediate credential derived from at least a portion of the one or more parameters and the secret credential, the message and signature to determine whether the signature is valid, the secret credential being obtained from a central key authority and corresponding to one or more computing resources of a key zone of a plurality of key zones;and take one or more actions contingent on determining that the signature is valid.
  9. 57
    A computer-implemented method of authentication for providing access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, the method comprising:receiving, by the one or more computer systems, a message and a signature of the message from an authenticating party;generating, by the one or more computer systems and based at least in part on the received message, an expected signature by at least invoking a hash-based message authentication code function multiple times such that: at least one invocation of the hash-based message authentication code function involves an input to the hash-based message authentication code function that is based at least in part on a secret credential shared with the authenticating party, the secret credential being received from a central key authority and corresponding to the key zone;and at least another invocation of the hash-based message authentication code function involves a result from a previous invocation of the hash-based message authentication code function as an input to the hash-based message authentication code function;determining, by the one or more computer systems, whether the received signature matches the expected signature;and taking, by the one or more computer systems, when determined that the received signature matches the expected signature, one or more actions for which authentication of the received message is required. CA 2847713 2020-01-17
  10. 64
    A computer-implemented method of authenticating access to one or more computing resources of a computing resource provider, the one or more computing resources of the computing resource provider being part of a logical grouping of computing resources in a key zone of a plurality of key zones, comprising:generating, by the one or more computer systems and based at least in part on a received message, an expected signature by at least performing multiple invocations of a set of one or more functions such that at least one invocation involves a result from a first function from the set of one or more functions as an input to a second function of the set of one or more functions, the result being based at least in part on a secret credential shared with the authenticating party, the second credential being obtained from a central key authority and being associated with the key zone;determining, by the one or more computer systems, whether a signature received in connection with the message matches the expected signature;and taking, by the one or more computer systems, when determined that the received signature matches the expected signature, one or more actions for which authentication of the received message is required.
  11. 74
    A computer system for authentication, comprising:one or more processors;and memory including instructions executable by the one or more processors to cause the computer system to at least: CA 2847713 2020-01-17 obtain a result of an algorithm used to process at least a first input based at least in part on a credential shared with an authenticating party, the credential corresponding to a grouping of computing resources in a key zone of a plurality of key zones;apply the algorithm to input based at least in part on the obtained result and input based at least in part on information from an authenticating party to generate a second result;determine whether the second result matches a received signature from the authenticating party;and take one or more actions as a result of determining that the second result matches the received signature.
  12. 80
    A non-transitory computer-readable storage medium having stored thereon instructions that, if executed by one or more processors of a computer system, cause the computer system to at least:CA 2847713 2020-01-17 obtain a signing key that is based at least in part on multiple inputs for a process involving one or more invocations of a function, at least one input of the multiple inputs being based at least in part on a secret credential shared with an authenticator computing device, the secret credential corresponding to one or more computing resources of a key zone of a plurality of key zones;generate a signature for a message by at least inputting the obtained signing key into the function;and submit the generated signature to the authenticator computing device in connection with the message to enable the authenticator computing device to determine, based at least in part on the shared credential, whether the signature is authentic and take one or more actions when the signature is determined to be authentic.
  13. 86
    A computer-implemented method, comprising:receiving a delegation request from a first entity, fulfilment of which involves granting a second entity an access privilege to a computing resource;generating a session key based at least in part on a restriction and a secret credential shared with the first entity, the restriction indicating a limitation on access to be granted to the second entity;providing the session key to the first entity;receiving, from the second entity, an access request to access the computing resource, the access request including information that indicates access to the session key;validating the access request based at least in part on the session key;and granting, to the second entity, access to the computing resource.
  14. 92
    A system, comprising:one or more processors;and memory including instructions that, if executed by the one or more processors, cause the system to: receive a delegation request from a first entity, fulfilment of which involving granting a second entity an access privilege to a computing resource;in response to receipt of the delegation request: generate a session key based at least in part on passing a secret credential, shared between the first entity and the one or more CA 2847713 2020-01-17 processors, and a session restriction through a cryptographic hash algorithm, the session restriction indicating a limitation on access to be granted to the second entity;and provide the session key to the first entity;receive an access request from the second entity to access the computing resource, the access request associated with the session key;and in response to receipt of the access request: validate the access request based at least in part on the session key;and grant, to the second entity, access to the computing resource.
  15. 102
    A non-transitory computer-readable storage medium having stored thereon executable instructions that, if executed by one or more processors of a computer system, cause the computer system to at least:receive a first request from a first entity, fulfilment of which involving granting a second entity an access privilege to a computing resource;generate a session key based at least in part on a restriction and a secret credential shared between the first entity and the computer system, the restriction indicating a limitation on access to be granted to the second entity;provide the session key, usable at least in part to prove possession of an access privilege to a computing resource, to the first entity;receive a second request to access the computing resource, fulfilment of which involves providing a second entity access to a computing resource, the second request associated with the session key;validate the second request based at least in part on the session key;and fulfill the second request by providing access to the computing resource depending at least in part on validation of the session key.
  16. 106
    A computer-implemented method, comprising; generating a signing key by performing at least:obtaining a key that is a shared secret between a client device and a computer system of a service;deriving, based at least in part on the shared secret and information indicating a date on which use of the signing key is to be restricted, a date key whose use is limited to the date;deriving, based at least in part on the date key and infonnation indicating a region in which use of the signing key is to be restricted, a region key whose use is restricted to both the date and the region;and deriving, based at least in part on the region key and information indicating a service to which use of the signing key is to be restricted, a CA 2847713 2020-01-17 service key whose use is restricted to the date, the region, and the service;obtaining, at the computer system of the service, a canonicalized message from the client device and a first digital signature;deriving, at the computer system of the service, a second digital signature based at least in part on the canonicalized message and the signing key;and determining, at the computer system of the service, that the canonicalized message is authentic as a result of the first digital signature matching the second digital signature.
  17. 112
    A non-transitory computer-readable storage medium storing thereon instructions executable by one or more processors of a first computer system to cause the first computer system to:generate a signing key by performing at least: obtaining a key that is a shared secret between the first computer system and a second computer system;deriving, based at least in part on the shared secret and information indicating a date on which use of the signing key is to be restricted, a date key whose use is limited to the date;deriving, based at least in part on the date key and information indicating a region in which use of the signing key is to be restricted, a region key whose use is restricted to both the date and the region;and deriving, based at least in part on the region key and information indicating a service to which use of the signing key is to be restricted, a service key whose use is restricted to the date, the region, and the service;canonicalize a message to result in a canonicalized message;derive a digital signature of the canonicalized message based at least in part on the canonicalized message and the signing key;and transmit the canonicalized message and the digital signature to the second computer system.
  18. 116
    The non-transitory computer-readable storage medium of claim Π2, wherein the information indicating the date, the information indicating the region, and the information indicating the service are encoded as strings.
  19. 117
    A system, comprising:one or more processors;and memory storing instructions executable by the one or more processors to cause the system to: obtain a signing key by at least: obtaining a key that is a shared secret between the system and another system;and utilize a cryptographic hash function, the key, information indicating a date to which use of the signing key is to be restricted, information indicating a region in which use of the signing key is to be restricted, and information indicating a service to which use of the signing key is to be restricted to derive the signing key;obtain a canonicalized message;and use the signing key to generate a digital signature of the canonicalized message. CA 2847713 2020-01-17
  20. 121
    A computer-implemented method, comprising:obtaining a first cryptographic key;using the first cryptographic key and a plurality of restriction identifiers to derive a second cryptographic key;using the second cryptographic key and a request for access to a set of resources to generate a digital signature of the request;providing the request with the digital signature as a digitally signed request to access the set of resources;and receiving a response to the digitally signed request, the response granting access to the set of resources based on verifying that an expected signature, which is based on the first cryptographic key and the plurality of restriction identifiers, matches the digital signature. CA 2847713 2020-01-17
  21. 129
    A computer readable medium storing instructions that, when executed by one or more processors, direct the one or more processors to execute the method of any one of claims 121 to 128.
  22. 130
    A system comprising:at least one processor;and CA 2847713 2020-01-17 the computer readable medium of claim 129, wherein the at least one processor and the computer readable medium are configured to cause the at least one processor to execute the instructions stored on the computer readable medium to cause the at least one processor to execute the method of any one of claims 121 to 128.
  23. 131
    A system, comprising:memory to store instructions executable by one or more processors to cause the system to: obtain a first cryptographic key;use the first cryptographic key and a set of restriction identifiers to derive a plurality of cryptographic keys;and distribute the plurality of cryptographic keys among a plurality of services, wherein at least one service of the plurality of services uses at least one cryptographic key of the plurality of cryptographic keys to generate a request signature to enable signing an access request to a computing resource with the request signature, the request signature based on the access request and on at least one restriction identifier of the set of restriction identifiers.
  24. 142
    A non-transitory computer-readable storage medium storing executable instructions that, when executed by one or more processors of a computer system, cause the computer system to at least:obtain a first cryptographic key;use the first cryptographic key and a set of restriction identifiers to derive a plurality of cryptographic keys;and distribute the plurality of cryptographic keys among a plurality of services, wherein at least one service of the plurality of services uses at least one cryptographic key of the plurality of cryptographic keys, the at least one cryptographic key based on at least one restriction identifier of the set of restriction identifiers, to enable signing an access request, to a computing resource, with a request signature, the request signature based on the access request and the at least one cryptographic key, the access request subject to a restriction corresponding to the at least one restriction identifier.
Independent claims24