Resource locator with key
Abstract
Problem to be solved.To provide a method for generating a URL which gives access to a resource with a time limit for reading or overwriting.
Solution.The method includes information that enables an operation including storage or retrieval of data, information on an expiration date indicating that the URL has expired and cannot be used for accessing the resource, and information on the route to the resource. Build information including and as part of the URL, generate a signature to sign part of the URL with an encryption key, build part of the URL as a signed part of the URL with a signature, and build the other part of the URL Build as the unsigned part of the URL. The constructed URL is supplied to the user with the encryption key provided by the customer. [Selection diagram] Fig. 5

Term
13.8 yearsto projected expiry
Projected expiry 27 July 2040, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1読み出し又は上書きのために時間制限付きでリソースへのアクセスを与える、URLを生成するコンピュータ実施方法であって、 データの記憶または取り出しを含む動作を可能とする情報と、前記URLの期限が満了しリソースへのアクセスに使用できない旨を示す有効期限の情報と、リソースへの経路の情報とを含む情報を、URLの一部分として構築することと、 暗号化鍵によって前記URLの一部分に署名するための署名を生成することと、 前記URLの一部分を前記署名で前記URLの署名済部分として構築することと、 前記URLの他部分を前記URLの未署名済部分として構築することと、 顧客によって供給される暗号化鍵を持つユーザに前記署名済部分及び前記未署名部分を含む前記URLを供給することと、を備える、コンピュータ実施方法。
94 paragraphs, as filed
Cross-reference to related applications This application is a complete disclosure, US Pat. No. 14,037,282 filed September 25, 2013, entitled "RESOURCE LOCATORS WITH KEYS", and filed September 25, 2013. Incorporate US Patent Application No. 14 / 037,292, name "DATA SECURITY USING REQUEST-SUPPLIED KEYS" by reference for all purposes.
The security of computing resources and associated data is important in many situations. As an example, an organization often utilizes a network of computing devices to provide a robust set of services to its users. Networks often span multiple geographic boundaries and often connect with other networks. An organization, for example, competent managed by those internal network and other computing resources using both Interview computing resources may support its operation. Computers in this organization may, for example, communicate with computers in other organizations to access and / or provide data while using the services of another organization. Organizations often use hardware managed by other organizations to configure and operate remote networks, thereby reducing infrastructure costs and achieving other benefits. Such configurations of computing resources can make it difficult to ensure secure access to resources and the data they hold, especially as the scale and complexity of such configurations increase. ..
<p><patcit num="1"><text>U.S. Pat. No. 2013/0198519</text></patcit></p>
<p> The request is pre-generated to include the encryption key used to satisfy the request. The request can be encoded in a uniform resource locator and can also include credentials to allow the service provider to which the request is submitted to determine if the request has been approved. The request can be passed to various entities, which can then submit the request to the service provider. Upon receiving the request, the service provider can validate the credentials and use the encryption key encoded in the request to satisfy the request.</p>
Hereinafter, various embodiments according to the present disclosure will be described with reference to the drawings.
<figref num="1">It is a figure which shows the Example which becomes the example of the environment which can realize various embodiments.</figref><figref num="2">It is a figure which shows the Example which becomes the example of the environment which can realize various embodiments.</figref><figref num="3">It is a figure which shows the example which becomes the example of the uniform resource located (URL) according to at least one embodiment.</figref><figref num="4">FIG. 5 illustrates another embodiment of a URL according to at least one embodiment.</figref><figref num="5">FIG. 5 illustrates an exemplary embodiment of a process for providing access to data according to at least one embodiment.</figref><figref num="6">It is a figure which shows the example which becomes the example of the web page which follows at least one Embodiment.</figref><figref num="7">It is a figure which shows the example which becomes the example of the process for gaining access to data according to at least one embodiment.</figref><figref num="8">It is a figure which shows the example which becomes the example of the process for processing a request according to at least one embodiment.</figref><figref num="9">FIG. 5 illustrates an exemplary embodiment of a process for requesting and providing access to data according to at least one embodiment.</figref><figref num="10">It is a figure which illustrates the environment which can realize various embodiments.</figref>
In the following description, various embodiments will be described. For purposes of illustration, specific configurations and details are provided to provide a complete understanding of the embodiments. However, it will also be apparent to those skilled in the art that embodiments can be practiced without specific details. Moreover, well-known features may be omitted or simplified in order not to obscure the embodiments described.
The techniques described and proposed herein are the use of uniform resource locators (URLs) and computing resources (generally "resource locators") to allow access to service provider services. Includes other references to. URLs are used throughout this disclosure for illustrative purposes, but the techniques described herein are generally to locate other resource locators (ie, computing resources in the system). It should be understood that it can be applied to (instances of information available by the system). Moreover, the techniques described herein can generally be applied to electronic requirements.
In one embodiment, a customer of a service provider (eg, a computing resource service provider) utilizes one or more services of the service provider. As an example, customers can service to achieve various benefits such as reduced capital investment, easier data management, higher availability, less latency with distributed data processing equipment, and the like. You can use the provider's data storage service. To allow others (for example, a customer of a customer, or, in general, a user authorized by the customer) to access the customer's resources managed by the provider, the customer may use a pre-signed URL. Can be used. To generate a pre-signed URL, the customer may generate a URL (or generally a request) and an electronic (digital) signature of a portion of the URL. The portion of the URL used to generate the digital signature may include the encryption key used in processing the request. The encryption key can be provided in various forms. For example, an encryption key is plain text symmetric, which can be decrypted by a service provider using one or more encryption actions to meet the request, or decrypted in a decrypted manner. Key, public key-can be a plain text public key in a private key pair, or a symmetric key.
In general, the URL may be configured to encode authorization information that may include a request, an encryption key, and authentication information (eg, a digital signature) that can be used to validate the request. The URL may be provided by the customer to another entity, which entity is not necessarily a third party and is referred to in this disclosure as a third party, but is authorized by the customer to satisfy the service provider's requirements. Can be an entity. URLs can be provided to third parties in a variety of ways. For example, in some embodiments, the URL is provided to a web page or other organization of content that is transmitted over a network to a third party. Providing a URL is subject to one or more conditions, such as receiving a valid login credit certificate from a third party, receiving or promising payment from a third party, and / or other terms. obtain.
A third party may submit a request to the service provider in order to have the service provider meet the request. Prior to submitting the request, the third party may additionally indicate to the service provider the data to be manipulated and / or how to handle the request, such as one or more values for one or more parameters. Information can be added to the request. For example, the parameter may specify the choice of cryptographic scheme and / or mode of cryptographic scheme to use from multiple cryptographic schemes / modes configured with the capabilities used by the service provider.
Upon receiving the request, the service provider may verify the validity of the digital signature to determine if the request is met. The other behavior is whether meeting the request complies with the applicable policy of the simmering and / or one encoded in the request (eg, encoded as part of the authorization information) or This can be done in determining whether a requirement is met, such as determining whether to comply with multiple parameters (eg, expiration date). For requests that the service provider deems to be able to meet, the service provider extracts the encryption key from the request, decrypts the extracted encryption key (if applicable), and in fulfilling the request. It can perform one or more actions involved. An acknowledgment to the customer is provided, such as an acknowledgment that the request has been met and / or the result of performing one or more actions (eg, data decrypted using the key provided in the request). obtain.
FIG. 1 shows an example example of the environment 100 in which various embodiments can be realized. As illustrated in FIG. 1, environment 100 includes customer 102 and is also a service provider 104. The customer 102 of the service provider 104 may utilize the various services of the service provider in order to utilize the various computing resources provided by the service provider 104. For example, the customer 102 may operate his own service and utilize the computing resources of the service provider 104 in order to avoid the expense and / or complex problems of realizing his own computing resources. As an example, customer 102 may provide access to media files such as video files and / or audio files as a service to other customers. However, in order to avoid the expense and trouble of maintaining a sufficiently robust storage system, the customer 102 may utilize the data storage system of the service provider 104, which service provider has access to the data storage system. , Customer 102, etc. can be provided to a large number of customers.
As mentioned above, the customer 102 may have one or more customers of its own, and therefore the various techniques of the present disclosure act as a proxy for the data stored by the service provider 104. With respect to allowing a customer 102 to serve that customer who uses the services of the service provider 104 without the need for it. One way to do this includes a customer 102 who provides URL 106 to a third party 108, as illustrated in FIG. 1, which third party can be or generally be a customer of customer 102. , A user of the service of customer 102. As described in more detail below, URL 106 can be provided by customer 102 to third party 108 in various ways.
As discussed in more detail below, one way to provide URL 106 to a third party 108 is by using a web page or other interface that encodes the URL so that it can be selected by a human operator of the third party 108. Can be. As an exemplary embodiment, a human operator with an account with customer 102 may log in to customer 102's website and, as a result of logging in, have access to URL 106. URL 106 may be otherwise provided from customer 102 to third party 108 as well. For example, URL 106 can be encoded in an email message or other message from customer 102 to a third party 108. As another embodiment, URL 106 can be encoded into a document provided by customer 102 to third party 108 in any suitable manner. In general, any method by which a third party 108 has access to URL 106 is within the scope of this disclosure, regardless of whether providing access involves transmission to the third party 108 over the network of URL 106. It is considered to be.
Note that FIG. 1 illustrates the flow of information between a customer 102 and a third party 108, which can be an entity such as an organization and / or an individual. Although the data is shown to flow between entities, it should be understood that the data is transferred by the appropriate computing device for each entity, unless otherwise apparent from the context. Is explained below in connection with FIG. As an embodiment, URL 106 may be provided by Customer 102 from Customer 102's web or other server. Similarly, third-party 108 human operators are configured to receive information through personal computers, mobile devices, tablet computing devices, e-book readers, or, in general, networks or other data receiving interfaces. URL 106 can be received by the appropriate device, such as a device.
It should also be noted that although FIG. 1 shows that URL 106 is provided directly from customer 102 to third party 108, URL 106 can be provided in different ways, according to different embodiments. .. As mentioned above, the server of customer 102 may provide URL 106 to a third party 108, for example by encoding into a web page provided to customer 108. However, such servers can be implemented using computing resources such as virtual computer systems hosted by service provider 104 and / or one or more storage devices. In other words, the customer 102 may control providing the URL 106 to the third party 108, but the resources for which the URL 106 is provided to the third party 108 may not be hosted directly by the customer 102. In addition, URL 106 may pass through one or more intermediates not illustrated in FIG. Other variations are also considered to be within the scope of this disclosure.
As stated, upon receiving the URL 106, the third party 108 can use the URL 106 to access the services of the service provider 104. As an embodiment used throughout this disclosure, a third party 108 may use URL 106 to access data stored by service provider 104 on behalf of customer 102. In other words, customer 102 of service provider 104 uses URL 106 to allow a third party 108 to gain access to one or more computing resources, such as media files posted by service provider 104. Can be made possible. Although access to data (eg, retrieval of data) is used as an exemplary embodiment throughout this disclosure, the techniques described herein provide access to services in a number of ways. Please note that it can be used to provide. For example, URL 106 can be used to allow a third party 108 to use the resources of service provider 104 to store data. Such use may be useful, for example, when providing the ability to store data to a third party as part of a service provided by customer 102. In general, URL 106 can be used to provide access in any way that complies with the requirements that can be met by service provider 104.
Returning to the illustrated embodiment, the third party 108 may provide the URL to the service provider 104 in order to gain access to the resource hosted by the service provider 104. Various to allow the service provider 104 to determine how to meet the request submitted to the service provider 104 by a third party 108 using URL 106 and / or whether to meet the request. Information can be included in the URL. For example, as illustrated in FIG. 1, the URL 106 includes a digital signature 110, which can be verified by the service provider 104 by having access to the signature verification key 112 corresponding to the customer 102. it can. The signature verification key 112 can be, for example, a symmetric encryption key that the customer 102 also has access to. In such an embodiment, the service provider 104 uses one or more symmetric cryptographic signature verification algorithms to determine that the third party 108 has been authorized by the customer 102 to submit a request using URL 106. It can be used to verify the digital signature 110. As another embodiment, the signature verification key 112 can be the public key of the public key-private key pair, where the customer 102 has access to the private key of the public key-private key pair. Has. Customer 102 may use the private key to generate a digital signature 110, which can then be verified by service provider 104 upon receipt of signature 110 from a third party 108. In general, any type of information contained in URL 106 may be used, which determines that the service provider 104 determines that the request from customer 108 submitted using URL 106 has been approved by customer 102. To enable.
As illustrated in FIG. 1, URL 106 may also include encryption key 114. The encryption key 114 can be an encryption key that the customer 102 has access to. The type of encryption key contained in URL 106 can vary according to various embodiments. In some embodiments, for example, the encryption key 114 is a symmetric key used for encryption or decryption by the service provider 104. As another embodiment, the encryption key 114 can be the public key of a public key-private key pair, where the private key is held by customer 102 but not accessed by service provider 104. As yet another embodiment, the encryption key 114 may be included in the URL and the symmetric key may be included in the URL 106 in a form encrypted under another key, where the other keys are of various types. It may vary according to embodiments, but generally, upon receiving URL 106 from a third party 108, the service provider 104 encrypts itself or using another service, such as another third party service. A key that can be decrypted to use key 114. In general, to allow third-party 108 to provide URL 106 to service provider 104, and to allow service provider 104 to use encryption key 114 for one or more operations, Any method may be used in which the encryption key 114 may be provided to a third party 108 at URL 106. In this way, the third party 108 can use the service of the service provider 104 by using the encryption key 114 provided by the customer 102.
As an example of one method in which this is useful, customer 102 may utilize the data storage service of service provider 104 to store data, where the data is a key that is inaccessible to service provider 104. It is stored in the encrypted form used. By including the encryption key 114 in the URL 106 to the third party 108, the third party 108 allows the service provider 104 to use the encryption key 114 to decrypt the data stored in the data storage service by the customer 102. To enable it, a request can be submitted to service provider 104 using URL 106. Therefore, service provider 104 does not have the ability to access customer 102's data in plain text form until service provider 104 provides URL 106. Note that the third party 108 may submit the request to the service provider 104 using URL 106 in various ways. For example, a third-party 108 application may provide a URL as part of selectable user interface elements on a graphical user interface. Selecting selectable elements may allow an application, such as a third-party browser, to contact Domain Name Service (DNS) to determine the Internet Protocol (IP) address to which the request should be submitted. The request can then be submitted to the IP address, where the request can include URL 106. The information in URL 106 may then allow service provider 104 to process the request accordingly.
FIG. 2 shows an exemplary embodiment of the service provider 200 environment according to various embodiments. As illustrated in FIG. 2, the service provider 200 includes a customer interface 202. The customer interface can be a subsystem of service provider 200, which allows the submission of requests from customers to be processed by service provider 200, as described above in connection with FIG. To do. Therefore, the customer interface may include suitable computing devices to provide the customer with the ability to submit requests to the service provider 200. This customer interface may include, for example, one or more web servers configured to receive requests over the Internet or another network. Although not so exemplified, other infrastructure may also be included in the customer interface 202, such as a suitable networking device that allows the customer interface 202 to operate properly for the customer of the service provider 200.
When receiving a request through customer interface 202, the request may be received with the appropriate credentials. For example, as illustrated in FIG. 2, the request can be received with a URL 204 containing a signature 206 of a portion of the URL. Signatures can be generated according to various embodiments. For example, the customer who generated the URL 204 may generate the signature 206 using the confidential information shared between the customer and the service provider 200. In another embodiment, the customer may be using an asymmetric digital signature scheme to sign URL 204 using the private key of the private key-public key pair. In general, any type of information used to authenticate URL 204 may be used, and in some embodiments the request may be submitted without such information.
However, as illustrated in FIG. 2, when receiving a request through customer interface 202, the request URL 204 is provided to service provider 200's authentication system 208 along with signature 206 (eg, through service provider 200's internal network). .. Alternatively, instead of the entire URL, a portion of the URL that is sufficient to generate the digital signature 206 may be provided. The authentication system 208 may be a subsystem of service provider 200 configured to authenticate the request, such as by verifying the electronic signature provided with the URL included with the request. Upon verifying the signature 206 at URL 204, the authentication system 208 may provide a response to the customer interface 202 indicating whether the signature 206 is valid. A device in customer interface 202 (eg, a web server) may use the information provided by authentication system 208 to determine how to process URL 204. For example, if the authentication system 208 indicates that the signature 206 is invalid, the customer interface 202 may reject the request. Similarly, if the information from the authentication system 208 indicates that the signature 206 at URL 204 is valid, the customer interface 202 may allow the request to be processed.
Although not illustrated in the figure, the authentication system 208 or another system operating within or on behalf of the service provider 200 performs other operations in connection with deciding how to handle the request. Can work like this. For example, the authentication system 208 or another system that works with it may be used to see one or more policies that can determine if a request can be met. Policy decisions are at least partially based on a variety of factors, including the requester's identity, the time of day, the logical identifier of where the data is stored or should be stored, and other contextual information. Can be done. Policies can be managed through customer interface 202 or through another interface with well-configured application programming interface (API) calls.
Returning to the embodiment illustrated in FIG. 2, if the authentication system 208 determines that the signature 206 is valid, the customer interface 202 may determine that it will process the request. Processing a request may include transferring encrypted data 210 between the customer interface 202 and the request processing infrastructure 212. The request processing infrastructure 212 may include one or more devices that operate collectively to provide the services of service provider 200. For example, as illustrated in FIG. 2, the request processing infrastructure may include multiple data storage systems 214 used to store data on behalf of the customer of service provider 200. It may also include other infrastructure, not illustrated, including network infrastructure. The movement of data, for example, through the network between the customer interface 202 and the request processing infrastructure 212, can occur in different ways according to different embodiments, according to different types of requests that can be submitted through the customer interface 202. For example, if the request to store data includes URL 204, the customer interface will utilize the key 216 provided at URL 204 to encrypt the data for storage in one or more of the data storage systems 214. The encrypted and encrypted data 210 can be transmitted to the request processing infrastructure 212.
Similarly, if the request is a request to retrieve data, the customer interface 202 processes the request with a communication that allows the customer interface 202 to provide data from one or more of the data storage systems 214. Can be transmitted to infrastructure 212. The customer interface 202 may then use the key 216 provided at URL 204 to decrypt the encrypted data 210 and provide the decrypted data to the customer who submitted the request. The service provider 200 environment illustrated in Figure 2 is simplified for illustrative purposes and also includes a number of other devices and subsystems, such as an accounting system that records customer use of the service provider 200. Note that it can be. In addition, service provider 200 may include equipment located at different geographic locations for duplication and / or availability purposes.
FIG. 3 shows an exemplary embodiment of URL 300 according to various embodiments. In one embodiment, as described above, the URL 300 may include a digital signature 302 of a portion of the URL 300 and an encryption key 304. URL300 may also contain other information such as route 306. Route 306 may include information that allows a service provider as described above to locate one or more resources associated with a request submitted via URL 300. Other information in URL300 may include information indicating one or more actions 308 performed by satisfying the request. Illustrative actions that can be specified include, but are not limited to, storing data, retrieving data, generating digital signatures of data, and other actions. In some embodiments, the URL may specify multiple actions, and the order in which the actions should be performed.
As illustrated, URL 300 includes an expiration date of 310. The expiration date can encode the value over the time until the URL 300 can no longer be used to submit a request that can be met to the service provider. In other words, the expiration date indicates the time it takes for a otherwise submitted request submitted using a URL to become unfulfillable because the time has been reached. As an example, referring to FIG. 1, customer 102 wishing to provide temporary access to certain data is to limit the amount of time URL 106 can use for third part 108. , URL 106 expiration date 310 can be used. To ensure that the signature 302 is valid only if the expiration date 310 has not been modified since it was issued by the customer, the expiration date 310 is the data at URL 300 used to generate the digital signature 302. Can be included in. In this way, accessing the URL after the expiration date does not provide the ability to access the data simply by modifying the expiration date. A service provider that receives URL 300 when determining whether a request is met may use the expiration date and / or other information to determine whether the request is met. For example, if the URL provides a request before the expiration date 310, the service provider may meet the request (assuming all other requirements to meet the request are met, if applicable). .. Similarly, if URL 300 is provided to the service provider with the request after the expiration date 310, the service provider may refuse any other requirements to meet the request. Although the expiration date is used throughout this disclosure as a parameter that potentially determines whether the provider meets the requirements, it should be noted that the criteria for meeting the requirements can be more complex. For example, a criterion that meets a requirement may be configured to meet the requirement even after the end time. Other context
As illustrated, URL 300 may also include other parameters 312. Other parameters can be parameters that allow the service provider to determine if and / or how to meet the request. For example, as mentioned above, URL300 may include an expiration date of 310. Another parameter contained in the other parameter 312 can be the start time, which indicates the time when URL300 will be available to submit the request to the service provider. The combination of start time and end time may provide a time window that can meet the request submitted using the URL. The start time is useful, for example, when blocking access to data until a certain time (eg, publishing a media file). Therefore, the service provider's customer may pre-generate one or more URLs that can be used to later submit to the service provider a request that can provide access to the data or otherwise be met. Can be done. Such an ability to pre-generate URLs that allow access to data in the future is a content delivery network (without providing access to certain data until it is desired to give such access. It provides technical advantages such as pre-preparing a CDN) and / or pre-configuring content with a URL.
Referring to FIG. 1, the other parameter of the URL illustrated in FIG. 3 is data in which one or more encryption operations are performed using encryption key 304 (or 114 when referring to FIG. 1). Parameters regarding how to meet the requirements, but are not limited to them, may include other information added by a third party.
FIG. 4 shows an exemplary embodiment of URL 400, which can be URL 300 discussed above or any URL generally described herein. As illustrated, the URL 400 includes a signed portion 402 and an unsigned portion 404. The signed portion may contain information whose modification can invalidate URL400. As discussed above as an example, the signed portion 402 may include an expiration date 406. In addition, the signed portion may include an encryption key 408. In general, the signed portion may include such information that the customer providing the URL 400 intends to prevent forgery of any information. Information is submitted using, for example, identification information authorized to submit URL400, timing information regarding when URL400 can be used (eg, one or more start and / or end times), and URL400. Other contextual information that determines whether and / or how to process a request can be mentioned. The unsigned portion of URL400 can be additional data added by a third party that performs one or more encryption operations using a digital signature 410, encryption key 408 as described above. Request data 412, and / or in general, may include a variety of information, such as information that can be modified by a third party without causing invalidity of the digital signature 410.
URL400 is exemplified in a particular manner to illustrate various aspects of the present disclosure. A large number of variations are considered to be within the scope of this disclosure. For example, as illustrated in FIG. 4, URL400 indicates an encryption key in the signed portion of URL400. In addition to, or as an alternative to, the encryption key in the signed portion of the URL 400, the unsigned portion of the URL may include an encryption key. For example, in some embodiments, a customer of a service provider may provide a URL with a signed portion to a third party. A third party may add the encryption key to the URL and submit the request to the service provider using the URL with the additional encryption key, where satisfying the request is the signed part of the URL. Authorized by the customer through a signature generated on the basis of at least partly. In this way, the third party provides access to the encryption key to either the service provider (except when performing one or more encryption actions as part of fulfilling the request) or the customer. You can use one or more services of a service provider without any need. Therefore, a security breach or other event at either the customer or the service provider does not provide access to the encryption key and, as a result, does not allow access to the data in plain text form. In addition, the encryption operation is performed using both the key in the signed part of the URL (supplied by the customer) and the key in the unsigned part of the URL (supplied by a third party). obtain. In this way, access to data in plain text form requires collaboration between both third parties and customers. Other variants are also considered within the scope of this disclosure, including variants in which the service provider's key is used as an alternative or in addition.
FIG. 5 shows an exemplary embodiment of Process 500 for providing access to data according to various embodiments. Process 500 may be performed by any suitable system, such as a customer-operated system, as described above in connection with FIG. In one embodiment, process 500 comprises generating a portion of the URL to be signed at 502. Part of the URL may contain information that the entity performing the process 500 wants to prevent forgery. In various embodiments, the amount of information contained in a portion of the signed URL can vary. For example, a portion of a URL that is signed can be a route to a customer's resource, an encryption key, when and / or how the URL can be used to allow the service provider to meet the request. It may contain one or more URL parameters to define and / or other information.
If 502 generates a portion of the URL to be signed, process 500 may include using a signing key to sign the portion of the generated URL at 504. The signing key can be any encryption key, which provides a digital certificate that can be verified by a service provider capable of submitting a URL when used to generate a digital signature. For example, in some embodiments, the signing key can be confidential information shared between the entity performing the process 500 and the service provider. In other embodiments, the signing key can be the private key of the public key-private key pair, where the service provider authorizes the public key of the public key-private key pair (and optionally authorization). An institution) can be used to verify the electronic signature. Although FIG. 5 shows a portion of a signed URL that includes an encryption key, it should be noted that some embodiments may have a signature key that is contained in a portion other than the portion of the URL to be signed. Such inclusion of an encryption key can be used, for example, when key forgery is not an issue. For example, if a URL can be used to access data from a data storage device, the modified cryptographic key is generally not available for decrypting the data and, as a result, is protected against key modifications. It may not be necessary to do.
Using the signature key to generate the digital signature of the generated portion of the URL, process 500 may include completing the construction of the URL to include the digital signature in 506. As discussed, the 506 may also use other information, such as additional parameters of the URL, to complete the construction of the URL. When completed in 506, process 500 may include providing the completed URL to a third party in 508. The third party can be, for example, a customer of an entity that performs process 500 as described above. Providing the completed URL to a third party at 508 can be done in different ways, according to different embodiments. For example, as discussed in more detail below, a URL may be provided to a third party on a web page, where one or more requirements for accessing the web page before the web page is provided. May be needed. As in the exemplary embodiment, a third party may be required to perform a login / sign-in procedure to access a web page with the completed URL. In general, URLs can be provided in any way, such as electronic messages, or in any way that allows data to be passed from one system to the other. Furthermore, it should be noted that although third parties are used for illustrative purposes, the entity to which the URL is provided is not necessarily the third party to the provider or customer. For example, in one embodiment in which Process 500 is performed by an organization's system, the techniques described herein can be used to provide access to data to the organization's staff. Therefore, on behalf of a third party, the URL may be provided to users within the organization where Process 500 takes place. Other variations are also considered to be within the scope of this disclosure.
FIG. 6 is an exemplary example of a web page 600 that can be used to provide a URL according to various embodiments. As illustrated in FIG. 6, the web page 600 contains various contents. The content illustrated in web page 600 is exemplary in nature, and the type and appearance of the content, as well as its amount, can vary according to various embodiments. Web page 600 may be provided in different ways according to different embodiments. For example, a web page may be provided over a network to an application such as a third-party client browser application described above in connection with FIG. However, the web page 600 may generally be provided by any suitable device capable of receiving and processing the web page. Although web page 600 is used for purposes of illustration, URLs or other resource locators configured according to the various embodiments described herein provide content in different ways according to the various embodiments. Can be done. For example, content may be provided to mobile applications or other applications that are not necessarily classified as browser applications. In general, any method by which a URL or other resource locator may be provided is considered to be within the scope of this disclosure.
As illustrated in FIG. 6, the web page 600 includes various graphic user interface elements that allow navigation throughout the website to which the web page 600 is a part. In this embodiment, the web page 600 is part of an e-commerce website that provides access to video content, such as by providing streaming video content to one or more customers. For example, on the left side of a web page 600, various links 602 to different video genres are provided. In this embodiment, the link appears as a text word, which allows the link to be selected using a suitable input device such as a keyboard, mouse, touch screen, or other input device. Link selection can cause an application that displays a web page 600 to submit an http request to the server that provided the web page 600 or another server according to the URL associated with the link by programming the web page 600. In this embodiment, the web page 600 also includes a graphical user element configured as a play button 604. The play button 604 can be a graphical user interface element of the web page 600, where the code underneath the web page 600 is configured so that the input device selection of the button 604 causes the request to be submitted to the appropriate server. To.
In this example, the code for web page 600 includes URL 606, which can be configured according to the various techniques described herein. In this exemplary embodiment, URL606 includes a route 608 to a resource, which in this case is a video file. URL606 may also include encryption key 610, expiration date 612, and digital signature 614. Digital signatures can be generated at least partially for path 608, encryption key 610, and expiration date 612, and / or other information. In general, URL606 may contain additional information not illustrated in the figure. Therefore, when the user selects button 604, a properly configured request, an http request in this example, is submitted to the server using URL606. Although not illustrated in the figure, such a request uses Route 608 of URL606 to obtain the IP address of the server from Domain Name Service (DNS), and makes a request with URL606 on the Internet or other networks. Can be submitted by submitting to an IP address through.
The device processing the web page 600 may receive a response, which response may include the resource pointed to by route 608 if URL606 is valid at the time of submission of the request. As stated elsewhere herein, such a request may be denied if the URL was invalid, for example because the URL 606 was submitted after the expiration date 612, or because the URL 606 was modified.
FIG. 7 shows an exemplary embodiment of Process 700 for accessing data according to various embodiments. Process 700 may be performed by any suitable system, such as the third party system described above in connection with FIG. 1, but as mentioned, the system performing process 700 is not necessarily performed by process 700. Not necessarily a third party to other entities involved in the matter. In one embodiment, process 700 includes retrieving a URL from a provider's customer at 702. At 702, the URL can be obtained in different ways according to different embodiments, such as through a web page as described above, or otherwise. Once retrieved at 702, the request can be submitted to the provider at 704 using the retrieved URL. In some embodiments, the URL is provided to the provider as a request formatted in a format acceptable to the provider, such as following HTTP. However, in some embodiments, submitting a request to the provider using the retrieved URL in 704 may include modifying the URL before submitting the request. For example, in some embodiments, the URL submits a request to perform one or more actions with the encryption key provided by the URL for the data added to the URL by the system performing the process 700. Can be used to As another example, the system performing Process 700 knows how to handle the request and / or information that may be required by the provider in addition to a valid signature of the retrieved URL to satisfy the request. One or more parameters can be added to the URL for various purposes, such as instructing the provider to supply. Other information useful to the system and / or provider performing the process 700 may also be included.
Adding to the retrieved URL may include adding information to a portion of the URL other than the portion used to generate the digital signature included with the retrieved URL. In this way, information can be added to the URL without disabling the digital signature. At 704, when submitting a request to the provider using the URL obtained, process 700 makes a request from the provider at 706, assuming the request was submitted properly, or else it can be met. Get the processed result. For example, the response from the provider may include the result, depending on one or more actions specified by the request. As an example, if the request was to encrypt or decrypt the data provided with the request, or otherwise the data specified by the request, the result obtained at 706, if necessary. Can include encrypted or decrypted data. In general, the results obtained at 706 can vary depending on the encryption operation performed using the encryption key provided in the request.
FIG. 8 shows an exemplary embodiment of Process 800 for providing access to data. Process 800 may be performed by a suitable system such as a service provider's web server as described above. In one embodiment, process 800 comprises receiving a request with a URL at 802. The URL may include an encryption key and digital signature and / or other information as described above. At 804, the digital signature can be extracted from the URL, and at 806, it can be used to determine if the request is valid. In 806, determining whether a request is valid can be performed in different ways according to different embodiments, such as by using a symmetric signature verification algorithm or an asymmetric signature verification algorithm to verify the electronic signature. , This may include communicating with an authorization body to determine the validity of the digital signature using the public key of the public key-private key pair.
If 806 determines that the signature is invalid, process 800 may include denying the request at 808. The request may be rejected at 808 in various ways according to various embodiments, such as by communicating that the request has been rejected and / or transmitting one or more reasons for the rejection. Also, other methods may be used in which the request may be rejected simply by not satisfying the request, etc., without necessarily requiring the transmission of communications in response to the request. In general, any method can be used in which the request can be denied. However, if 806 determines that the signature is valid, process 800 may include extracting the encryption key from the URL received at 802 at 810. The extracted encryption key can be used at 812 to process (ie, satisfy) the request. Processing a request can include using an encryption key to perform one or more encryption actions on the data contained with the request, or otherwise specified by the request. At 814, a response to the request may be provided. At 814, providing a response is the result of performing one or more encryption operations using an encryption key (eg, encrypted data, decrypted data, and / or digital signature), and / Alternatively, it may include providing an acknowledgment that such an action has been taken.
Process 800 has been described in a particular manner for illustrative purposes, but variations are considered to be within the scope of this disclosure. For example, FIG. 8 shows a request being processed on the condition that the signature is valid. However, one or more other actions may be taken to determine if the request should be processed. As an embodiment, determining whether a request is valid may include checking whether the request complies with the policy. Therefore, a policy composed of service provider customers can be checked to determine if meeting a request complies with the policy. In addition, as mentioned above, the URL may contain various contextual information as to whether and / or how the request should be made. Therefore, in 806, determining whether a request is valid while doing process 800 is to check if such a condition is met, and / or such contained in the URL. It may include processing the request according to the information. In general, satisfying a requirement may require that one or more conditions be met, and the mode in which the requirement is met may at least partially depend on the parameters specified in the requirement.
Further, in some embodiments, the use of an encryption key may involve the process performing one or more actions, which actions depend on the system and generally by the entity on which the process 800 takes place. Lost access to the encryption key. The action of losing access to an encryption key is, for example, overwriting one or more memory locations where the encryption key is stored, and / or processing such memory for subsequent requests. It can include taking one or more actions that allow the location to be overwritten. In general, any action can be taken that immediately or ultimately loses access to the encryption key. In this way, the customer who supplies the key at the URL ensures that the service provider has access to the encryption key for a limited duration corresponding to when the encryption key needs to meet the request. Can be. Other variations are also considered to be within the scope of this disclosure.
FIG. 9 shows an exemplary embodiment of the process for providing access to data according to one embodiment. As illustrated in FIG. 9, the process can be carried out by a suitable system and, in this particular embodiment, optionally by multiple systems indicated by broken lines that separate the actions of process 900 from each other. In one embodiment, process 900 comprises wrapping the cryptographic secret at 902 so that the customer can unwrap (use) it by the provider. Wrapping the cryptographic secret can be done, for example, by encrypting the cryptographic secret with an appropriate encryption key so that the key can be unwrapped (decrypted) by the provider. For example, cryptographic secrets can be wrapped using confidential information shared between the provider's customers and the provider. As another embodiment, the cryptographic secret can be wrapped using the public key of the public key-private key pair, where the provider uses the private key from the public key-private key pair. You can unwrap the encrypted secret. Although FIG. 9 illustrates that the wrapped cryptographic secret can be unwrapped by the provider, in general, a variant of the disclosure is that the provider does not unwrap the cryptographic secret itself, but rather the provider. Note that you can have another system (eg, a third party system) that unwraps the cryptographic secret instead.
Returning to the exemplary embodiment of FIG. 9, at 904, the customer may construct a URL with a wrapped secret. The URL can be constructed at 904 as described above. Then, at 906, the customer can sign the URL by generating a digital signature of the constructed URL using the appropriate signing key. Then, at 908, the URL may be completed to include the digital signature. Then, at 910, the completed URL may be provided to a third party as described above. At 910, providing the completed URL, at 912, a third party may use the completed URL to submit a request to the provider. As an example, the URL is encoded in a web page or other content so that the third party application can choose to have the third party application submit a request to the provider using the completed URL. obtain.
When the request is submitted to the provider, at 914, the provider can normalize and validate the request. Note that normalization can be done to reverse the various ways in which a request can be modified while transmitting the request from one entity to the other. Normalization can be done, for example, to ensure that the verification of the digital signature is done correctly. For example, if the request is valid, additional properties that are inserted into or removed from the request are removed as needed to ensure that the digital signature is valid as well. And / or can be added. At 910, upon validating the request, the provider may unwrap the encryption secret by performing an appropriate encryption algorithm to crack the encryption key (or otherwise, by letting it do). At 912, the request can then be processed using the encryption key, and at 914, the provider performs one or more encryption operations performed by the provider and / or the encryption operation. It may respond to third party requests, such as by providing an acknowledgment of that. As mentioned above, then at 916, the provider may lose access to the cryptographic secret as described above.
The embodiments of the present disclosure can be described with reference to the following appendices.
Appendix 1 A cryptography implemented on a computer that, under the control of one or more computer systems configured with executable instructions, does not have access by the one or more computer systems prior to receiving the request. Using the encryption key to receive the request from the requester to perform one or more actions, the request includes a uniform resource locator, which is said to be one or more of the uniform resource locators. Receiving, including the electronic signature generated by the first entity, and also including the encryption key, based on a portion of the uniform resource locator and confidential information inaccessible to the requester, at least in part. And, on the condition that it is determined whether the electronic signature is valid and this determination indicates that the electronic signature is valid, the one or more operations shown above are applied to the data. To use the encryption key from the request to generate the result of the one or more operations, and to provide the result of the one or more operations in accordance with the request. When, One or more to lose access to the encryption key after using the encryption key from the request to perform the indicated one or more operations on the data. The way it is implemented on a computer, including doing and.
Appendix 2 The uniform resource locator further encodes a path that identifies the data, and using the encryption key to perform one or more of the indicated actions means that the code for accessing the data. The computer-implemented method described in Appendix 1, including the use of encrypted routes.
Appendix 3 The computer-implemented method of Appendix 1-2, wherein at least some of the data is supplied by the requester in the request.
Appendix 4 The portion of the uniform resource locator indicates an expiration date, and the use of the encryption key to perform one or more of the indicated actions receives the request prior to the expiration date. The method realized by the computer described in any one of the appendices 1 to 3, which is performed on the condition that the above is further performed.
Appendix 5 Receiving the request is made by the service provider, the first entity is a customer of the service provider, and the requester is not a customer of the service provider, any one of Appendix 1-4. The method implemented on the computer described in one.
Appendix 6 Using the encryption key to perform one or more of the indicated actions further ensures that the requirement complies with one or more policies configured by the first entity. A method performed as a condition and realized by the computer described in any one of Appendix 1 to 5.
Appendix 7 The request contains information added to the first uniform resource locator generated by the first entity to generate the request, and the cipher to perform the indicated one or more actions. The use of the encryption key is realized by the computer according to any one of Supplementary note 1 to 6, which is at least partially based on the information added to the first uniform resource locator.
Appendix 8 The uniform resource locator includes the encryption key in an encrypted form, and the method further comprises using the encryption key to perform one or more of the indicated operations. A method implemented on a computer according to any one of Appendix 1 to 7, comprising decrypting the encrypted key in an encrypted form.
Appendix 9 A system comprising one or more processors and a memory containing an instruction, the instruction from the requesting side to the system when executed by the one or more processors. Receiving a request, the request comprising a pre-generated portion containing authorization information and an encryption key generated by a first entity, and said authorization information making said request. Using the encryption key to perform one or more actions, and one or more actions performed, provided that the first entity determines that authorization is to be met. A system that lets you provide and do the results of.
Appendix 10 The system according to Appendix 9, wherein the pre-generated portion is formatted as a uniform resource locator.
Appendix 11 The one or more actions include accessing the data stored by the first entity in encrypted form and using the encryption key to decrypt the data, the result. The system according to Appendix 9-10, comprising transmitting the decrypted data to the requesting party.
Appendix 12 The request further includes data added to the pre-generated portion, and performing the one or more operations using the encryption key is added to the pre-generated portion. 9. The system according to Appendix 9-11, which comprises performing one or more encryption operations on the data.
Appendix 13 The system according to Appendix 9-12, wherein the authorization information includes an electronic signature generated using confidential information that the requester cannot access.
Appendix 14 The authorization information specifies one or more conditions for the context for submitting the request, and the encryption key can be used to perform one or more actions. The system according to Appendix 9-13, provided that the request is received in compliance with one or more conditions.
Appendix 15 The system according to Appendix 9-14, wherein the one or more conditions define a duration that can meet the requirement.
Appendix 16 The authorization information includes an electronic signature generated based at least partially on the encryption key, and the authorization information indicating authorization by the first entity requires that the electronic signature be valid. The system described in Appendix 9 to 15.
Appendix 17 The system further comprises a requesting side and a customer system different from the requesting side, wherein the customer system provides a representation of the request for use in submitting the request, thereby providing a representation of the request. The system according to Appendix 9-16, which enables the request to be received from the request side.
Appendix 18 A non-temporary computer-readable storage medium having instructions stored therein, which are requested to the computer system when executed by one or more processors of the computer system. And to generate the information that encodes the encryption key, to generate the electronic signature of the information that can be verified by the service provider that can satisfy the request, and to provide the information and the electronic signature to the service provider. And to make the information and the digital signature available to the service provider to use the encryption key to meet the request, a non-temporary computer readable Storage medium.
Appendix 19 The non-temporary computer-readable storage medium according to Appendix 18, wherein making the information and the electronic signature available comprises generating a uniform resource locator containing the information and the electronic signature. ..
Appendix 20 Making the information and the electronic signature available includes providing a web page composed of selectable elements, which, when selected, provide the information and the electronic signature. The non-temporary computer-readable storage medium according to Appendix 18-19, which causes the service provider to transmit the request including the above.
Appendix 21 The non-temporary computer-readable storage medium of Appendix 19-20, wherein providing the web page comprises providing the web page to a third party different from the service provider.
Appendix 22 The information further encodes an identifier for a resource hosted by the service provider, and the request specifies one or more actions performed in connection with the resource, according to Appendix 18-21. A non-temporary computer-readable storage medium.
Appendix 23 The non-temporary computer-readable storage medium according to Appendix 18-22, wherein the information encodes the encryption key in plain text form.
Appendix 24 The non-temporary description of Appendix 18-23, wherein the information encodes one or more conditions for the submission of the request so that the request can be met by the service provider. A computer-readable storage medium.
Other variations are considered to be within the scope of this disclosure. For example, the type and method by which the key is provided in the URL, or generally the requirement to the provider, can vary according to various embodiments. Several techniques that may be combined with the techniques of the present disclosure are US Patent Application No. 14,037,282 filed September 25, 2013, named "RESOURCE LOCATORS WITH KEYS", and filed September 25, 2013. It is described in US Patent Application No. 14 / 037,292, entitled "DATA SECURITY USING REQUEST-SUPPLIED KEYS", which is incorporated herein by reference for all purposes.
FIG. 10 illustrates aspects of an exemplary environment 1000 for realizing aspects according to various embodiments. As will be appreciated, a web-based environment is used for explanatory purposes, but different environments may be used as needed to realize the various embodiments. The environment includes the electronic client device 1002, any suitable device that can operate to send and receive requests, messages, or information through the appropriate network 1004 and convey the information to the user of the device. Devices can be mentioned. Examples of such client devices include personal computers, mobile phones, handheld messaging devices, laptop computers, tablet computers, set-top boxes, personal digital assistants, embedded computer systems, e-book readers and the like. The network includes any suitable network, including an intranet, the Internet, a cellular network, a local area network, or any other such network, or a combination thereof. The components used in such a system may at least partially depend on the type of network and / or environment selected. Protocols and components for communicating over such networks are well known and are not discussed in detail herein. Communication over networks can be made possible by wired or wireless connections, and combinations thereof. In this embodiment, as will be apparent to those skilled in the art, this network includes the Internet, but in the case of other networks, as the environment includes a web server 1006 for receiving requests and serving content accordingly. , Alternative devices can be used that serve similar purposes.
An exemplary environment includes at least one application server 1008 and a data store 1010. Some application servers, layers or other elements, processes, or processes that can interact to perform tasks such as retrieving data from the appropriate data store, which can be chained or otherwise configured. Please understand that there can be components. Servers, as used herein, can be implemented in a variety of ways, such as hardware devices or virtual computer systems. In some contexts, a server can refer to a program module running on a computer system. As used herein, the term "data store" refers to any device or combination of devices that can store, access, and retrieve data from any number of data servers, databases, data. Storage devices, data storage media, and any combination thereof may be included in any standard, distributed, or clustered environment. The application server is part of the data access and business logic for integrating with the data store and for the application, as needed, to execute one or more application aspects for the client device. Any suitable hardware and software for handling (and most) can be included. The application server may work with the data store to provide access control services, and in this example a hypertext markup language (HTML), an extended markup language (XML), or another suitable It is possible to generate content such as text, graphics, audio, and / or video that is transferred to the user that may be provided to the user by the web server in the form of a structured language. All requests and responses, as well as the delivery of content between the client device 1002 and the application server 1008, shall be handled by the web server. Can be done. A web server and application server are required because the structured code discussed herein can run on any suitable device or host machine, as discussed elsewhere herein. However, it should be understood that these are merely exemplary components. Moreover, the operations described herein as performed by a single device can be performed collectively by multiple devices that can form a distributed system, unless otherwise apparent from the context.
The data store 1010 can include several separate data tables, databases, or other data storage mechanisms, and a medium for storing data related to a particular aspect of the disclosure. For example, the illustrated data store may include a mechanism for storing product data 1012 and user information 1016 that can be used to provide product-side content. The data store is also shown to include a mechanism for storing log data 1014, which mechanism can be used for reporting, analysis, or other such purposes. There can be many other aspects that may need to be stored in the data store, such as page image information and access right information, which may optionally be in one of the mechanisms listed above, or in the data store 1010. It should be understood that it can be remembered in the additional mechanism of. Data store 1010 can operate through its associated logic to receive instructions from application server 1008 and retrieve, update, or otherwise process data accordingly. In one embodiment, the user may submit a search request for a particular type of item through a device operated by the user. In this case, the data store may have access to user information to validate the user's identity and access to catalog details to obtain information about that type of item. The information can then be returned to the user in a result list or the like on a web page that the user can view via a browser on the user device 1002. Information on a particular item of interest can be viewed on a dedicated page or window in your browser. However, the embodiments of the present disclosure are not necessarily limited to the content of the web page, but may be more generally applicable to the processing request in general, where the request is not necessarily a request for the content. Please note that.
Each server generally includes an operating system that provides executable program instructions for general management and operation of that server, and generally when the server is run by the server's processor, the server Includes a computer-readable storage medium (eg, hard disk, random access memory, read-only memory, etc.) that stores instructions that enable it to perform its intended function. Suitable embodiments of the general functionality of the operating system and server are known or commercially available and are readily accomplished by one of ordinary skill in the art, especially in light of the disclosure herein.
The environment in one embodiment is a distributed computing environment that utilizes multiple computer systems and components interconnected via communication links using one or more computer networks or direct connections. However, it will be appreciated by those skilled in the art that such systems can operate reasonably well in systems with fewer or more components than illustrated in FIG. Therefore, the description of System 1000 in FIG. 10 is essentially an example and should not be considered as limiting the scope of this disclosure.
Various embodiments can also be implemented in a wide variety of operating environments, and in some cases, one or more user computers that can be used to run any of a number of applications. , Computing devices, or processing devices can be included. Users or client devices include many general purpose personal computers, such as desktop computers, laptop computers, or tablet computers that run standard operating systems, as well as many networking and messaging protocols that run mobile software. Any of the cellular devices, wireless devices, and handheld devices that can be supported can be mentioned. Such systems also include a number of workstations running any of a variety of off-the-shelf operating systems and other known applications for purposes such as development and database management. These devices also include other electronic devices such as dummy terminals, thin clients, gaming systems, and other devices that can communicate over the network.
Various embodiments of the present disclosure include transmission control protocols / Internet protocols (TCP / IP), protocols that operate at various layers of the Open System Interconnect (OSI) model, and file transfer protocols (FTP). Supports communication using any of a variety of commercially available protocols such as Universal Plug and Play (UpnP), Network File System (NFS), Common Internet File System (CIFS), and AppleTalk. Utilize at least one network that is well known to those skilled in the art. The network can be, for example, a local area network, a wide area network, a virtual private network, the Internet, an intranet, an extranet, a public exchange telephone network, an infrared network, a wireless network, or any combination thereof.
In an embodiment using a web server, the web server includes a hypertext transfer protocol (HTTP) server, an FTP server, a common gateway interface (CGI) server, a data server, a Java® server, and a business application. It can run any of a variety of servers or middle tier applications, including servers. The server (s) may also respond to requests from user devices in any programming language such as Java®, C, C #, or C ++, or any scripting language such as Perl, Python, or TCL. It may also be possible to execute a program or script, such as by executing one or more web applications that may be realized as one or more scripts or programs written in combination thereof. Servers (s) also include, but are not limited to, database servers commercially available from Oracle®, Microsoft®, Sybase®, and IBM®. Can also be mentioned.
The environment can include various data stores, as well as other memory and storage media, as discussed above. These can be in various locations, such as on a storage medium that is local to (and / or resides in) one or more of the computers, or on a storage medium that is remote from any or all of the computers across the network. Can exist in. In a particular set of embodiments, the information may reside within a storage area network (SAN) well known to those of skill in the art. Similarly, any necessary files for performing functions originating from a computer, server, or other network device may be stored locally and / or remotely, as needed. If the system includes computer-controlled devices, each such device can include a hardware element that can be electrically connected via a bus, which element is, for example, at least one central processing unit ("" A "CPU" or "processor"), at least one input device (eg, mouse, keyboard, controller, touch screen, or keypad) and at least one output device (eg, display device, printer, or speaker). Including. Such systems also include disk drives, optical storage devices, and solid-state storage devices such as random access memory (RAM) or read-only memory (ROM), as well as removable media devices, memory cards, flash cards, and the like. , Can also include one or more storage devices.
Such devices may also include computer readable storage media readers, communication devices (eg, modems, network cards (wireless or wired), infrared communication devices, etc.), and working memory, as described above. .. A computer-readable storage medium reader is a storage that temporarily and / or permanently contains computer-readable storage media that represent remote, local, fixed, and / or removable storage devices, as well as computer-readable information. Can be connected to, transmitted, and retrieved from a storage medium, or can be configured to accept the storage medium. The system and various devices also generally include a number of software applications, modules, services, or other devices located within at least one working memory device, including the operating system and application programs such as client applications or web browsers. Also includes elements. It should be understood that alternative embodiments may have a number of variations from those described above. For example, customized hardware can also be used, and / or certain elements can be implemented in hardware, software (including portable software such as applets), or both. In addition, connections to other computing devices such as network input / output devices may be used.
Storage media and computer readable media for containing code or parts of code include RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technology, compact disk read. Stores only memory (CD-ROM), digital versatile disk (DVD), or other optical storage device, magnetic cassette, magnetic tape, magnetic disk storage device, or other magnetic storage device, or desired information. Stores and / or transmits information such as computer-readable instructions, data structures, program modules, or other data, including any other medium that can be used for and accessible by system devices. Known in the art, including, but not limited to, storage and communication media, including, but not limited to, volatile and non-volatile removable and non-removable media realized by any method or technique for the purpose. Any suitable medium that is or is used. Based on the disclosures and teachings provided herein, one of ordinary skill in the art will recognize other means and / or methods for realizing various embodiments.
Therefore, the specification and drawings should be considered as exemplary, not limiting. However, it will become clear that various modifications and modifications can be made without departing from the broader intent and scope of the invention described in the claims.
Other variants are within the scope of this disclosure. Thus, the disclosed approach allows for a variety of modified and alternative structures, but specific exemplary embodiments are shown in the drawings and described in detail above. However, without any intent to limit the invention to the particular form disclosed, conversely, the invention is all within the spirit and scope of the invention, as defined in the appended claims. It should be understood that it is intended to include modifications, equivalents, and alternatives of.
The use of the terms "a" and "an" and "the" in the context of describing the disclosed embodiments (particularly in the context of the claims), as well as similar referents, is herein used. Unless otherwise indicated or clearly inconsistent with the context, it should be construed to include both singular and plural. The terms "prepare," "have," "contain," and "contain" are to be construed as open-ended terms (ie, meaning "contain, but not limited to") unless otherwise noted. I want to. The term "connected" is attached, which is partially or wholly contained therein, even if there is an interruption in the middle, when unmodified and when referring to a physical connection. Or interpret it as being joined to each other. The enumeration of the range of values herein is intended solely to serve as an easy way to reference each value within that range individually, unless otherwise indicated herein. And each value is incorporated herein as if it were listed individually herein. The use of the term "set" (eg, "set of items") or "subset" is a non-empty set with one or more parts, unless otherwise noted or inconsistent with the context. Please be interpreted as a thing. Furthermore, unless otherwise noted or inconsistent with the context, the term "subset" of a corresponding set does not necessarily mean an appropriate subset of the corresponding set, and the subset and the corresponding set are equivalent. possible.
Conjunctions such as idioms in the form of "at least one of A, B, and C" or "at least one of A, B, and C" are otherwise specified or otherwise. Unless clearly inconsistent with the context, the context can generally be any non-empty subset of the item, term, etc. A or B or C, or A and B and C pairs. It should be understood that it is used to present. For example, in an example example of a set with three terms used in the above concatenation, "at least one of A, B, and C" and "at least one of A, B, and C." "Refers to any of the pairs {A}, {B}, {C}, {A, B}, {A, C}, {B, C}, {A, B, C}. Thus, such conjunctions are generally intended to mean that a particular embodiment requires the presence of at least one A, at least one B, and at least one C, respectively. do not.
The operations of the processes described herein can be performed in any suitable order unless otherwise indicated herein or where there is no apparent contradiction in the context. The processes described herein (or variants and / or combinations thereof) can be performed under the control of one or more computer systems configured with executable instructions and, by hardware or a combination thereof. It can be implemented as code that runs collectively on one or more processors (eg, executable instructions, one or more computer programs, or one or more applications). This code may be stored on a computer-readable storage medium, for example in the form of a computer program containing multiple instructions that can be executed by one or more processors. The computer-readable storage medium can be non-temporary.
The use of any and all examples, or exemplary words (eg, "etc.") provided herein is merely intended to clarify embodiments of the present invention. Unless otherwise claimed, the scope of the invention is not limited. No word in the specification indicates that any unpatented element is essential to the practice of the invention. Please be interpreted as.
Preferred embodiments of the present disclosure are described herein, including the best methods known to the inventor, etc., for performing the present invention. Those skilled in the art will appreciate variations of these preferred embodiments by reading the above description. We anticipate that such modifications will be adopted as needed, and we will practice embodiments of the present disclosure other than those specifically described herein. Intended to be. Therefore, the scope of this disclosure includes all modifications and equivalents of the subject matter described in the claims attached to this specification as permitted by applicable law. Moreover, any combination of the elements in all possible variations of the elements described above is included by the scope of the present disclosure unless otherwise indicated herein or clearly inconsistent with the context.
All references, including publications, patent applications, and patents cited herein, are shown as if each document were individually and specifically incorporated by reference, and as a whole herein. As described, they are incorporated herein by reference to the same extent.
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| US2002083178A1 | Cites | United States of America | A | Search report |
| JP2003242124A | Cites | Japan | A | Search report |
| JP2006128873A | Cites | Japan | A | Search report |
| US2013247218A1 | Cites | United States of America | A | Search report |
57 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 14037282 | United States of America | – | |
| 201314037282 | United States of America | A |
Members57
| Document | Office | Kind | |
|---|---|---|---|
| US2015089233A1 | United States of America | A1 | |
| US2015089244A1 | United States of America | A1 | |
| CA2923437A1 | Canada | A1 | |
| CA2923438A1 | Canada | A1 | |
| CA3229997A1 | Canada | A1 | |
| WO2015048039A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2015048042A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9237019B2 | United States of America | B2 | |
| US9311500B2 | United States of America | B2 | |
| US2016127330A1 | United States of America | A1 | |
| CN105580311A | China | A | |
| CN105612716A | China | A | |
| US2016217290A1 | United States of America | A1 | |
| EP3050249A1 | European Patent Office (EPO) | A1 | |
| EP3050257A1 | European Patent Office (EPO) | A1 | |
| JP2016530850A | Japan | A | |
| JP2016535550A | Japan | A | |
| EP3050257A4 | European Patent Office (EPO) | A4 | |
| EP3050249A4 | European Patent Office (EPO) | A4 | |
| US9819654B2 | United States of America | B2 | |
| US2018041480A1 | United States of America | A1 | |
| US10037428B2 | United States of America | B2 | |
| JP2018137802A | Japan | A | |
| JP6389895B2 | Japan | B2 | |
| JP2018160919A | Japan | A | |
| US2019034644A1 | United States of America | A1 | |
| US2019068560A1 | United States of America | A1 | |
| EP3050257B1 | European Patent Office (EPO) | B1 | |
| CN105580311B | China | B | |
| EP3525395A1 | European Patent Office (EPO) | A1 | |
| US10412059B2 | United States of America | B2 | |
| CN110266671A | China | A | |
| EP3050249B1 | European Patent Office (EPO) | B1 | |
| CN105612716B | China | B | |
| EP3611873A1 | European Patent Office (EPO) | A1 | |
| CN111277573A | China | A | |
| JP2020184800AThis record | Japan | A | |
| JP6787952B2 | Japan | B2 | |
| JP2021022945A | Japan | A | |
| US10936730B2 | United States of America | B2 | |
| US2021173948A1 | United States of America | A1 | |
| US11146538B2 | United States of America | B2 | |
| JP7007985B2 | Japan | B2 | |
| EP3525395B1 | European Patent Office (EPO) | B1 | |
| EP4040718A1 | European Patent Office (EPO) | A1 | |
| CN111277573B | China | B | |
| JP7175550B2 | Japan | B2 | |
| EP3611873B1 | European Patent Office (EPO) | B1 | |
| EP4236203A2 | European Patent Office (EPO) | A2 | |
| EP4040718B1 | European Patent Office (EPO) | B1 | |
| US11777911B1 | United States of America | B1 | |
| EP4236203A3 | European Patent Office (EPO) | A3 | |
| CA2923437C | Canada | C | |
| US2024126895A1 | United States of America | A1 | |
| CA2923438C | Canada | C | |
| US12135796B2 | United States of America | B2 | |
| JP7581013B2 | Japan | B2 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Notice of transfer of a case for reconsideration by examiners before appeal proceedingsAppealJAPANESE INTERMEDIATE CODE: C21C21 | C21 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Trial request (containing other claim documents, opposition documents)OppositionJAPANESE INTERMEDIATE CODE: C60C60 | C60 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2020184800
- Application
- 126140
Titles2
- Japanese
- 鍵を有するリソースロケーター
- English
- Resource locator with key
Classification
- CPC, 9
- H04L63/0428
- H04L9/321
- H04L63/102
- H04L63/123
- H04L63/168
- H04L67/02
- H04L63/108
- H04L9/3247
- H04L63/10
- IPC, 1
- H04L9 32