A secure method to replicate on-premise secrets in a computing environment
20 claims: 11 independent, 9 dependent
- 1コンピューティング環境で機密情報を安全に共有する方法であって、第1コンピューティング環境の第1エンティティによって、 第2コンピューティング環境の設定サービスによって保持された暗号化キーを用いて暗号化された第1機密情報であって、 前記第1コンピューティング環境に対応する 第1 機密情報を受信し、前記第1コンピューティング環境の第2エンティティから、前記第1エンティティと前記第2エンティティとの間で前記 第1 機密情報を共有するための要求を受信し、前記第2エンティティが、 前記 第2コンピューティング環境に関連付けられた 前記 設定サービスによって保持された信頼できるエンティティのリスト であって、前記第1コンピューティング環境に機密情報を格納する信頼できるエンティティのリスト に含まれた信頼できるエンティティであるか否かを判断し、前記第2エンティティが前記信頼できるエンティティの 前記 リストに含まれた信頼できるエンティティではないという判断に応答して、ディレクトリサービスで前記第2エンティティの加入を認証し、且つ証明機関で前記第2エンティティに対応するデジタル証明書を認証することによって、前記第2エンティティが信頼を確立することができるか否かを判断し、前記第2エンティティが信頼を確立することができたという判断、又は前記第2エンティティが信頼できるエンティティであるという判断に応答して、 前記第2エンティティによって生成され、且つ前記デジタル証明書に含まれたプライベート公開キー対の公開キーを用いて前記第1機密情報を暗号化することにより第2機密情報を生成し、 前記第2エンティティの 少なくとも1つの 動作を有効にするために 前記設定サービスを介して 前記第2エンティティ に 前記 第2 機密情報を 送信 する、方法。
- 2前記第2エンティティが信頼を確立することができたという判断に応答して、前記第2コンピューティング環境に関連付けられた前記設定サービスによって、前記第2エンティティを前記信頼できるエンティティの 前記 リストに追加することをさらに含む、請求項1に記載の方法。
- 3コンピューティングデバイスによって、 前記 暗号化キーを生成し、前記暗号化キーを用いて 情報を暗号化することにより 前記 第1 機密情報を 生成 し、前記暗号化キーを、格納のため、前記設定サービスに送信し、前記 第1 機密情報を前記第1エンティティに送信すること、をさらに含む、請求項1に記載の方法。
- 4前記第1エンティティは、前記第1コンピューティング環境の第1コネクタであり、前記第2エンティティは、前記第1コンピューティング環境の第2コネクタである、請求項1に記載の方法。
- 5前記第2エンティティが信頼を確立することができなかったという判断に応答して、前記第2エンティティと前記 第1 機密情報を共有するための要求を拒否すること、をさらに含む、請求項1に記載の方法。
- 6前記第2エンティティが信頼を確立することができるか否かの判断は、前記第2エンティティによって、1つ以上の信頼できるエンティティに関する情報を有するディレクトリサービスに加入し、プライベートキーと公開キーとを有するプライベート公開キー対を生成し、前記証明機関から、前記公開キーを有する、前記第2エンティティに対応する前記デジタル証明書を受信し、 前記 信頼できるエンティティの 前記 リストに加入するための要求であって、前記第2エンティティに対応する前記デジタル証明書を有する要求を前記設定サービスに送信すること、をさらに含む、請求項1に記載の方法。
- 7前記第2エンティティが信頼を確立することができるか否かの判断は、前記第1エンティティによって、前記設定サービスから、前記第2エンティティに対応する前記デジタル証明書を受信することをさらに含み、前記デジタル証明書は、前記第2エンティティによって生成されたプライベート公開キー対の公開キーを有している、請求項1に記載の方法。
- 8前記第2エンティティによって、前記送信された 前記第2 機密情報を受信し、前記受信された 前記第2 機密情報を前記プライベートキーを用いて復号すること、をさらに含む、請求項 1 に記載の方法。
- 9前記 第2 機密情報を前記第2エンティティによって復号したことに応答して、前記設定サービスによって、前記第2エンティティを前記信頼できるエンティティの 前記 リストに追加することをさらに含む、請求項 8 に記載の方法。
- 10前記第2エンティティから、前記 第1 機密情報を共有するための要求を受信することは、前記第1コンピューティング環境への前記第2エンティティの追加、前記 第1 機密情報を共有するためのユーザ要求、又は、前記 第1 機密情報を用いて前記第2エンティティを介して第1リソースへアクセスするための要求の少なくとも1つに応答するものである、請求項1に記載の方法。
- 11コンピューティング環境で機密情報を安全に共有するコンピューティングシステムであって、前記システムは、少なくとも第1エンティティ及び第2エンティティを含む第1コンピューティング環境と、少なくとも設定サービスを含む第2コンピューティング環境と、機密情報を共有する方法を実施するプログラミング命令を有する非一時的なコンピュータ読み取り可能な記憶媒体と、を備え、前記プログラミング命令は、前記第1エンティティに、 前記設定サービスによって保持された暗号化キーを用いて暗号化された第1機密情報であって、 前記第1コンピューティング環境に対応する 第1 機密情報を受信し、前記第1コンピューティング環境の前記第2エンティティから、前記第1エンティティと前記第2エンティティとの間で前記 第1 機密情報を共有するための要求を受信し、前記第2エンティティが、前記設定サービスによって保持された信頼できるエンティティのリスト であって、前記第1コンピューティング環境に機密情報を格納する信頼できるエンティティのリスト に含まれた信頼できるエンティティであるか否かを判断し、前記第2エンティティが前記信頼できるエンティティの 前記 リストに含まれた信頼できるエンティティではないという判断に応答して、ディレクトリサービスで前記第2エンティティの加入を認証し、且つ証明機関で前記第2エンティティに対応するデジタル証明書を認証することによって、前記第2エンティティが信頼を確立することができるか否かを判断し、前記第2エンティティが信頼を確立することができたという判断、又は前記第2エンティティが信頼できるエンティティであるという判断に応答して、 前記第2エンティティによって生成され、且つ前記デジタル証明書に含まれたプライベート公開キー対の公開キーを用いて前記第1機密情報を暗号化することにより第2機密情報を生成し、 前記第2エンティティの 少なくとも1つの 動作を有効にするために 前記設定サービスを介して 前記第2エンティティ に 前記 第2 機密情報を 送信 すること、を実行させる命令を含む、システム。
- 12前記第2エンティティが信頼を確立することができたという判断に応答して、前記設定サービスに、前記第2エンティティを前記信頼できるエンティティの 前記 リストに追加させる命令をさらに含む、請求項1 1 に記載のシステム。
- 13コンピューティングデバイスに、 前記 暗号化キーを生成し、前記暗号化キーを用いて 情報を暗号化することにより 前記 第1 機密情報を 生成 し、前記暗号化キーを、格納のため、前記設定サービスに送信し、前記 第1 機密情報を前記第1エンティティに送信すること、を実行させる命令をさらに含む、請求項1 1 に記載のシステム。
- 14前記第1エンティティは、前記第1コンピューティング環境の第1コネクタであり、前記第2エンティティは、前記第1コンピューティング環境の第2コネクタである、請求項1 1 に記載のシステム。
- 15前記第2エンティティが信頼を確立することができなかったという判断に応答して、前記第1エンティティに、前記第2エンティティと前記 第1 機密情報を共有するための要求を拒否させる命令をさらに含む、請求項1 1 に記載のシステム。
- 16前記第2エンティティが信頼を確立することができるか否かを判断するために、前記第2エンティティに、1つ以上の信頼できるエンティティに関する情報を有するディレクトリサービスに加入し、プライベートキーと公開キーとを有するプライベート公開キー対を生成し、前記証明機関から、前記公開キーを有する、前記第2エンティティに対応する前記デジタル証明書を受信し、 前記 信頼できるエンティティの 前記 リストに加入するための要求であって、前記第2エンティティに対応する前記デジタル証明書を有する要求を前記設定サービスに送信すること、を実行させる命令をさらに含む、請求項1 1 に記載のシステム。
- 17前記第2エンティティが信頼を確立することができるか否かを前記第1エンティティに判断させる命令は、前記第1エンティティに、前記設定サービスから、前記第2エンティティに対応する前記デジタル証明書を受信させる命令をさらに含み、前記デジタル証明書は、前記第2エンティティによって生成されたプライベート公開キー対の公開キーを有している、請求項1 1 に記載のシステム。
- 18前記第2エンティティに、前記送信された 前記第2 機密情報を受信し、前記受信された 前記第2 機密情報を前記プライベートキーを用いて復号すること、を実行させる命令をさらに含む、請求項 1 1に記載のシステム。
- 19前記暗号化された機密情報を前記第2エンティティによって復号したことに応答して、前記設定サービスに、前記第2エンティティを前記信頼できるエンティティの 前記 リストに追加させる命令をさらに含む、請求項 18 に記載のシステム。
- 20前記第2エンティティから、前記 第1 機密情報を共有するための要求を受信することは、前記第1コンピューティング環境への前記第2エンティティの追加、前記 第1 機密情報を共有するためのユーザ要求、又は、前記 第1 機密情報を用いて前記第2エンティティを介して第1リソースへアクセスするための要求の少なくとも1つに応答するものである、請求項1 1 に記載のシステム。
Independent claims20
88 paragraphs, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to US Patent Application No. 16/056,848, filed Aug. 7, 2018, the disclosure of which is incorporated herein by reference.
The present disclosure relates generally to computing systems. More particularly, the present disclosure relates to implementing systems and methods for replicating sensitive information in a computing environment that allows enhanced security.
Cloud computing allows users to take advantage of applications or services that run on remotely located computers rather than on their local computers. For example, data can be processed in the cloud by transferring the data from a client computer to a server computer. After data is processed at the server computer, the processed data is returned to the client computer. Thus, client computers offload processing tasks to computers in the cloud. While cloud computing has many advantages, information integrity and security have become important issues for system administrators. Because the data to be processed must be transferred over computer networks, it is particularly vulnerable to online computer security threats such as eavesdropping, interception, to name a few. Therefore, information security is of paramount importance when providing external services to one or more users.
This document relates to systems and methods for securely sharing sensitive information in a computing environment. The method receives, by a first entity in the first computing environment, confidential information corresponding to the first computing environment, and from a second entity in the first computing environment, between the first entity and the second entity. whether the second entity is a trusted entity included in the list of trusted entities maintained by the configuration service associated with the second computing environment to judge. If the second entity is not a trusted entity included in the list of trusted entities, by authenticating the second entity's subscription with a directory service and authenticating the digital certificate corresponding to the second entity with a certification authority. , to determine whether the second entity can establish trust. The method further comprises, responsive to determining that the second entity was able to establish trust or determining that the second entity is a trusted entity, performing a second entity to effectuate operation of the second entity. 2 Share confidential information with entities. The first entity can be a first connector of the first computing environment and the second entity can be a second connector of the first computing environment.
In some scenarios, the method adds the second entity to a list of trusted entities by a configuration service associated with the second computing environment if the second entity is able to establish trust. may be included. Alternatively, the first entity may deny the request to share confidential information with the second entity if the second entity fails to establish trust.
In some other scenarios, the method includes generating an encryption key for encrypting sensitive information, encrypting the sensitive information using the encryption key, and sending the encryption key to the configuration service for storage. and transmitting the encrypted confidential information to the first entity.
In one or more scenarios, determining whether a second entity can establish trust involves subscribing to a directory service, generating a private-public key pair having a private key and a public key, and obtaining a private-public key pair from a certification authority. , receiving a digital certificate corresponding to the second entity with the public key, and sending a request to the configuration service to join the list of trusted entities. The request may include a digital certificate corresponding to the second entity. A directory service contains information about one or more trusted entities.
In some scenarios, determining whether a second entity can establish trust may include receiving, by the first entity, from the configuration service a digital certificate corresponding to the second entity. A digital certificate has a public key of a private public key pair generated by a second entity.
As an alternative and/or additionally, the method includes connecting the second entity and the confidential information to enable operation of the second entity by sending the confidential information to the second entity via the configuration service. may include sharing The first entity may further encrypt the confidential information prior to transmission using the public key of the private public key pair generated by the second entity and included in the digital certificate. Alternatively, the method may include receiving encrypted confidential information transmitted by the second entity and decrypting the received encrypted confidential information using the private key. . The configuration service may then add the second entity to the list of trusted entities in response to having the encrypted sensitive information decrypted by the second entity.
In one or more scenarios, receiving a request to share confidential information from a second entity may include addition of the second entity to the first computing environment, a user request to share confidential information, or , a request to access a first resource via a second entity using confidential information, and/or a combination thereof.
The present disclosure is prompted by reference to the following drawings, wherein like reference numerals represent like features throughout.
<figref num="1">FIG. 1 is a diagram of an exemplary system.</figref>
<figref num="2">FIG. 2 is a diagram of an exemplary computing device.</figref>
<figref num="3">FIG. 3 is a diagram of an exemplary computing environment.</figref>
<figref num="4">FIG. 4 is a flowchart illustrating an example method for securely transmitting and storing sensitive information through an external computing environment and sharing information between entities in an internal computing environment.</figref>
<figref num="5">FIG. 5 is a message flow diagram illustrating an example method of sharing and/or duplicating sensitive information between entities of an internal computing environment.</figref>
It will be readily appreciated that the components of the embodiments generally described herein and illustrated in the accompanying drawings can be arranged and designed in a wide variety of different configurations. Accordingly, the following more detailed description of the various illustrated embodiments is not intended to limit the scope of this disclosure, but is merely representative of the various embodiments. While various aspects of the embodiments are illustrated, the drawings are not necessarily drawn to scale unless stated otherwise.
The examples presented herein may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. The described embodiments are in all respects only illustrative and should not be construed as limiting. The scope of the disclosure is, therefore, indicated by the appended claims and not by this detailed description. All changes which come within the meaning and range of equivalency of the claims are to be embraced within the scope of the disclosure.
References to features, advantages, or similar terms throughout this specification do not imply that all of the features and advantages that can be achieved are to be in any single embodiment. Rather, terms referring to features and advantages are understood to mean that at least one embodiment includes the particular feature, advantage, or property described in connection with the embodiment. Thus, discussion of the features and advantages, and similar language throughout this specification may, but do not necessarily, refer to the same embodiment.
Furthermore, the features, advantages, and characteristics described in this disclosure may be combined in any suitable manner in one or more embodiments. Persons of ordinary skill in the art will recognize, in light of the description herein, that the examples described herein can be practiced without one or more of the specific features or advantages of a particular embodiment. . In other instances, additional features and advantages may be recognized in particular embodiments that are not shown in all embodiments.
Throughout this specification, references to "one embodiment," "an embodiment," or similar language refer to the specific features described in relation to the illustrated embodiments; A structure or property is meant to be included in at least one embodiment. Thus, appearances of the phrases "in one embodiment," "in an embodiment," and similar phrases throughout this specification, although not necessarily, all refer to the same embodiment. may point.
As used in this document, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise. Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art. The term "comprising" as used in this document means "including, but not limited to."
As used herein, the term "sensitive information" refers to data that is protected from unauthorized access to protect the privacy and/or security of users or entities. Examples include access credentials, unique identifiers such as personal information, medical information, financial information, social security information, biometric data, trade secrets, customer and supplier information, employee data, and the like.
Often, in a computing environment, some resources of an enterprise are managed externally and reside within the computing environment of a service provider (e.g., an external service provider), while other resources of the enterprise reside within the enterprise. Managed and within the enterprise's own server or other computing device. However, external computing environments or servers (eg, cloud servers) are public and untrusted. As such, some entities may be reluctant to use applications that require access to sensitive information. A user may also transmit sensitive information (e.g., identification and authentication information) to an enterprise-controlled application or other resource on one of the enterprise's computing devices, but that sensitive information is , may be transmitted from the user's device to the internal resource via an external computing environment provided by the service provider. As a result, the service provider has access to that confidential information. For example, a service provider can control access to various resources or applications through a single sign-on system, which includes password managers (software applications/agents/processes, etc.) on the service provider's network or systems. ) is responsible for providing user credentials to secure applications. User credentials for a particular user are encrypted using an encryption key associated with that user and then stored in encrypted form, typically in a location accessible by the password manager. Requests by authenticated users to access secure applications that require user credentials are intercepted by the password manager and thus accessible by service providers. Furthermore, storing the cryptographic key associated with a user intact does not prevent that key from being stolen by a malicious entity, thereby preventing identification.
To prevent an external public computing environment from accessing sensitive information, for example, there are methods of encrypting sensitive information using encryption keys. The method stores a cryptographic key in a first computing environment and stores encrypted confidential information in a second computing environment such that the first computing environment (e.g., a public computing environment) cannot access the confidential information. It can also be stored in a computing environment (eg, a connector of the company's own internal computing environment or another server). Often, an enterprise's internal computing environment provides multiple servers (e.g., connectors) to supply sensitive information to one or more resources of the internal computing environment for reasons of redundancy, efficiency, and high availability. may be placed. However, direct communication is not necessarily carried out between multiple servers. Thus, for example, when a new server is set up and/or when sensitive information needs to be accessed after it has been encrypted and stored on the first server, or when sensitive information is updated , securely sharing or duplicating sensitive information between such servers remains a challenge.
Referring now to FIG. 1, shown is a schematic block diagram illustrating an exemplary computing environment in which embodiments described herein may be implemented. FIG. 1 illustrates one or more client machines 102A-102N (generally referred to herein as "client machines 102A") communicating with one or more servers 106A-106N (referred generally herein as "servers 106A-N"). ~N). A network 104 is provided between the client machines 102A-N and the servers 106A-N.
In one embodiment, computing environment 101 may comprise an appliance (not shown here) installed between servers 106A-N and client machines 102A-N. This appliance manages client/server connections and can, in some cases, load balance client connections across multiple backend servers. For example, the appliance provides communication links between client machines 102A-N and servers 106A-N for access to computing resources (cloud hardware and software resources) hosted by servers 106A-N in the computing environment. management server and/or another server, such as a computing environment connector (hereinafter "connector") that provides a Computing environment hardware and software resources may have private and/or public components. For example, a computing environment may be configured as a private computing environment or computing device for use by one or more specific customer or client computers and/or over a private network. In other embodiments, public or public-private computing environments may be used by other customers over open or closed networks.
Client machines 102A-N may be referred to in some embodiments as a single client machine or a single group of client machines, while servers 106A-N may be referred to as a single server or a single group of servers. is called In one embodiment, a single client machine communicates with multiple servers, while in another embodiment, a single server communicates with multiple client machines. In yet another embodiment, a single client machine communicates with a single server.
Client machines 102A-N, in some embodiments, may be referred to by any one of the following terms: client machine; client; client computer; client device; client computing device; local machine; remote machine. client node; endpoint; endpoint node; or second machine. Servers 106A-N, in some embodiments, are referred to by any one of the following terms: server; local machine; remote machine; server farm; host computing device;
In one embodiment, one or more of client machines 102A-N may be virtual machines. While a virtual machine can be any virtual machine, in some embodiments a virtual machine is any virtual machine managed by a hypervisor developed by Citrix Systems, IBM, VMware, or other hypervisors. can be a machine. In other embodiments, virtual machines may be managed by a hypervisor running on a server or a hypervisor running on a client machine.
A client machine 102A-N may, in some embodiments, execute, operate, or serve any one of the following applications: software; programs; executable instructions; virtual machines; hypervisors; Web-based clients; client-server applications; thin client computing clients; ActiveX controls; Java applets; Voice over Internet like soft IP telephony Protocol (VoIP) communication related software; applications for streaming video and/or audio; applications for facilitating real-time data communication; HTTP clients; FTP clients; Oscar clients; Telnet clients; set of instructions. Still other embodiments include one or more client machines 102A-N that display application output generated by remotely executing applications on servers 106A-N or other remotely located machines. In these embodiments, the client machines 102A-N can display application output in application windows, browsers, or other output windows. In one embodiment, the application is a desktop, while in other embodiments the application is an application that generates a desktop.
Servers 106A-N, in some embodiments, run a thin client or a remote presentation client or other client program that uses a remote display protocol to obtain display output generated by applications running on the server. and send the application display output to the remote client machines 102A-N. A thin client or remote display protocol can be any one of the following protocols: the Independent Computing Architecture (ICA) protocol manufactured by Citrix Systems, Inc. of Fort Lauderdale, Florida; Remote Desktop Protocol (RDP) manufactured by Microsoft Corporation.
Computing environment 101 may include two or more servers 106A-N such that servers 106A-N are logically grouped into server farms. A server farm may provide servers that are geographically dispersed and logically grouped within the server farm, or may provide servers that are logically grouped in close proximity to each other within the server farm. good. Geographically distributed servers within a server farm may communicate using a WAN, MAN, or LAN in some embodiments. Here, different geographical regions can be characterized as: different continents; different regions on one continent; different countries; different states; different cities; different campuses; Any combination. In some embodiments, a server farm is managed as a single entity, while in other embodiments a server farm may provide multiple server farms.
In some embodiments, the server farms run substantially similar types of operating system platforms (eg, WINDOWS®, UNIX®, LINUX®, or macOS® from Microsoft Corporation of Redmond, Washington). Trademark)) can be provided with servers 106A-N. In other embodiments, a server farm may comprise a first group of servers running a first type of operating system platform and a second group of servers running a second type of operating system platform. . In other embodiments, a server farm may comprise multiple servers running different types of operating system platforms.
In some embodiments, computing environment 101 may comprise two or more servers 106A-N such that servers 106A-N are divided into one or more subgroups, each subgroup comprising: Managed and/or operated by different entities. For example, a first entity operates and/or manages a first subgroup of servers on-premises on individual or shared computing devices or environments, and a second entity operates on individual or shared computing devices or environments. , operating and/or managing a second subgroup of servers on-premises, and a third entity operating and/or managing a third subgroup of servers on-premises with personal or shared computing devices or environments; or manage.
In some embodiments, servers 106A-N may be any type of server. For example, a server can be any of the following types of servers: file servers; application servers; web servers; proxy servers; appliances; network appliances; a firewall; a web server; an application server as a master application server; a server running Active Directory; or a server running an application acceleration program that provides firewall, application, or load balancing functionality. In some embodiments, the server may be a RADIUS server that includes a remote authentication dial-in user service. In embodiments where the server comprises an appliance, the server may be an appliance manufactured by any one of the following manufacturers: Citrix Application Networking Group; Silver Peak Systems, Inc; Riverbed Technology, Inc.; F5 Networks, Inc.; or Juniper Networks, Inc. Some embodiments receive requests from one or more client machines 102A-N, forward the requests to a second server 106B, and respond to requests generated by the client machines 102A-N from the second server 106B. and a first server 106A that responds with a response of The first server 106A obtains a list of applications available to the client machines 102A-N and also obtains address information associated with the application server hosting the application identified in the list of applications. can be done. The first server 106A then presents responses to client requests using a web interface and communicates directly with the client machines 102A-N to allow the client machines 102A-N to access the identified applications. .
In some embodiments, servers 106A-N can run any one of the following applications: a thin client application that sends application display data to a client using a thin client protocol; a remote display presentation application. Such. Another embodiment comprises a server that is, for example, an application server such as: an email server that provides email services, such as MICROSOFT EXCHANGE manufactured by Microsoft Corporation; a web or Internet server; a desktop sharing server; a collaboration server; or any other type of application server. Yet other embodiments comprise a server running one or more hosted server applications (eg, WEBEX® provided by Cisco, Inc.).
Client machines 102A-N may, in some embodiments, be client nodes seeking access to resources provided by a server. In other embodiments, servers 106A-N provide client machines 102A-N with access to host resources. Servers 106A-N, in some embodiments, act as master nodes to communicate with one or more client machines 102A-N or servers 106A-N. In some embodiments, the master node may identify and provide to one or more clients or servers address information associated with the server hosting the requested application. In still other embodiments, the master node may be a server farm, client machine, cluster of client nodes, or an appliance.
One or more client machines 102A-N and/or one or more servers 106A-N can send data over a network 104 interposed between machines and appliances in the computing environment 101. . Network 104 may comprise one or more sub-networks, interposed between any combination of client machines 102A-N, servers 106A-N, computing machines and appliances contained within computing environment 101. be able to. In some embodiments, network 104 may employ any of the following: a local area network (LAN); a metropolitan area network (MAN); a wide area network (WAN); client machines 102A-N and servers 106A-. N; a primary public network with private sub-networks; a primary private network with public sub-networks 4; or a primary private network with private sub-networks. Yet another embodiment comprises a network 104 that may employ any of the following network types: point-to-point networks; broadcast networks; telecommunications networks; data communications networks; computer networks; ATM (asynchronous transfer mode) networks; a SONET (Synchronous Optical Network) network; an SDH (Synchronous Digital Hierarchy) network; a wireless network; a wired network; The network topology of network 104 may vary depending on the embodiment, and candidate network topologies include: bus network topology; star network topology; ring network topologies; repeater-based network topologies; or tiered-star network topologies. Additional embodiments comprise a network 104 of cellular networks that use protocols to communicate between mobile devices. Any one of the following may be employed as such a protocol: AMPS; TDMA; CDMA; GSM; GPRS UMTS; or any other protocol capable of transmitting data between mobile devices.
Referring now to FIG. 2, a detailed block diagram of an exemplary architecture of computing device 200 is shown. Here, client machine 102 and server 106 shown in FIG. 1 may be arranged and/or implemented as any embodiment of computing device 200 . Accordingly, the following description of computing device 200 is sufficient to understand client machine 102 and/or server 106 of FIG.
Computing device 200 may have more or fewer components than those shown in FIG. However, the illustrated components are sufficient to disclose an exemplary embodiment implementing the solution. The hardware architecture of Figure 2 is one embodiment of a representative computing device configured to facilitate sharing or duplication of sensitive information between entities or servers (e.g., connectors) in a secure enterprise computing environment. represents. Accordingly, the computing device 200 of FIG. 2 implements at least some of the methods for sharing and/or duplicating sensitive information in a computing environment via multiple communication channels, as described below.
Some or all components of computing device 200 may be implemented in hardware, software, and/or a combination of hardware and software. Hardware includes, but is not limited to, one or more electronic circuits. Electronic circuits may include, but are not limited to, passive elements (eg, resistors and capacitors) and/or active elements (eg, amplifiers and/or microprocessors). Passive and/or active devices may be configured, arranged, and/or programmed to perform one or more of the methods, procedures, or functions described herein.
As shown in FIG. 2, computing device 200 is connected to a user interface 202, a central processing unit (CPU) 206, a system bus 210, and other portions of computing device 200 via system bus 210. and a hardware entity 214 connected to the system bus 210 . User interface 202 may provide input devices (eg, keypad 250) and output devices (eg, speakers 252, display 254, and/or light emitting diodes 256) for controlling operation of computing device 200. Facilitate user software interaction.
At least some of hardware entities 214 perform actions that involve accessing and using memory 212 . Memory 212 may employ RAM, disk drives, and/or compact disk read-only memory (CD-ROM). Hardware entity 214 includes a disk drive unit 216 having a computer-readable storage medium 218 . Computer readable storage medium 218 stores one or more sets of instructions 220 (eg, software code) that perform one or more of the methods, procedures, or functions described herein. . Instructions 220 may reside wholly or at least partially within memory 212 and/or CPU 206 during execution by computing device 200 . Memory 212 and CPU 206 may also constitute machine-readable media. As used herein, the term "machine-readable medium" refers to a single medium or multiple media (e.g., a centralized or distributed database and/or associated caches and servers). The term "machine-readable medium" as used herein is also capable of storing, encoding, or carrying the set of instructions 220 for execution by the computing device 200 and the computing device. Also refers to any medium that causes 200 to perform any one or more of the methods described herein.
In some scenarios, hardware entity 214 is an electronic circuit (e.g., , processor). In this regard, it should be appreciated that the electronic circuitry may access and execute software applications 224 installed on computing device 200 . The functionality of software application 224 will become clear as the discussion progresses.
It should be appreciated that computing device 200 may be an example of a computer system usable in connection with various implementations disclosed herein. However, the systems and methods disclosed herein are not limited in this regard, and other suitable computer system architectures may be used without limitation. Specialized hardware implementations, including but not limited to application specific integrated circuits, programmable logic arrays, other hardware devices, etc., can also be configured to perform the methods described herein. be. The applications in which the devices and systems can be implemented are also extensive in various electronic and computer systems. In some scenarios, a function can be performed by two or more specific interconnected hardware modules or devices, with associated control and data signals communicated between and through the modules; It can be implemented as part of an application specific integrated circuit. As such, the exemplary system is applicable to software, firmware, and hardware implementations.
It should also be appreciated that embodiments may take the form of a computer program product on a tangible computer-usable storage medium (eg, hard disk or CD-ROM). A computer-usable storage medium may have computer-usable program code embodied in the medium. The term computer program product as used herein refers to a device with all the features that enable it to perform the methods described herein. Computer programs, software applications, computer software routines, and/or other variations of these terms, in the present context, are terms that cause an intelligent system to directly perform a specified function or to: means any representation in any language, code, or notation of a set of instructions intended to cause a specified function to be performed after either or both of a) or b) of: a) another language, code, or transliteration, or b) reproduction in different material formats.
As shown in FIG. 3, computing environment 300 includes external service providers 314 that provide public services and resources (ie, external services 318). The computing environment further comprises a client device 302 and an internal computing environment comprising connectors 310A-N that facilitate communication between the internal computing environment and the external computing environment.
The system 300 shows that some of the enterprise's resources are in an external computing environment managed externally and managed by an external service provider, while other enterprise resources are managed within the enterprise and are managed by the enterprise. It may take the form of a computing environment such as within its own server or other computing device (internal resources 308). A variation of the term "internal" as used herein is one or more computing devices controlled by the enterprise (i.e., managed by the enterprise itself and/or not controlled by an external service provider). , a trusted internal computing environment) and resources and applications stored in it. As an example, resources can be stored on a company's on-premises server for remote access by authorized users associated with the company. For example, certain software applications (eg, internal resources) may be stored on servers controlled and managed by the enterprise and accessible by one or more employees. A variation of the term "external" as used herein is one or more computing devices managed by and/or controlled by an external service provider (i.e., more secure and "trusted"). Can refer to resources and applications stored in an untrusted computing environment based on isolation from corporate networks. As an example, external resources can be stored on the servers of external service providers for access by authorized users associated with the enterprise. In such examples, external resources can also be associated with the enterprise. Resources (internal and/or external) can include, but are not limited to, networks, files, data, computing devices, applications, modules, services, functions, and other entities.
Users of a computing environment (e.g., computing environment 300) access internal resources installed on geographically distant internal computing devices and/or access external resources located on external servers or You may wish to use external resources. Users may connect with internal resources and/or connect with external resources via external services and/or otherwise communicate. For example, when users access internal and/or external resources, they must provide identification and authentication information (eg, username and password) to the internal and/or external resources for authentication. In such examples, as described in more detail below, the identification and authentication information is reversibly encrypted and transmitted to internal resources and/or transmitted to external resources via external services, It can then be decoded and used by internal and/or external resources. Using the principles described herein, it is understood that other types of sensitive information can also be reversibly encrypted and sent to internal resources and/or sent to external resources via external services. , will be understood.
Computing environment 300 may include external service providers 314 that provide public services and resources. External service providers 314 may comprise applications and/or other resources stored on computing devices (not shown) that are accessible to users over the Internet. External service provider 314 may also transfer information from a particular internal computing device to another internal computing device at different premises of an enterprise not belonging to external service provider 314 . As an example, a computing device belonging to an enterprise computing environment located at a particular geographical location may, via an external computing environment, access another computing device belonging to that enterprise computing environment located at a different geographical location. Information can be sent to a computing device (or it may be a different computing device at the company).
External service providers 314 may provide various external resources and/or services (external services 318). Examples of external services include configuration services, single sign-on password services to on-premises active directories, authentication services (e.g., knowledge-based authentication services, second factor authentication services, etc.), self-service password reset services (SSPR services), on-premises Examples include, but are not limited to, active directory access services, data store access services, and the like.
In embodiments, the configuration service may handle all inter-service communications within the external computing environment of the external service provider 314 (and/or internal resources). The configuration service 316 can maintain and manage a list of all services of external service providers, and enable these services to advertise their respective addresses or endpoints including the functionality they provide. and Only when a service is successfully registered with the configuration service is it active and able to communicate with other services and applications. After setting registration, the setting service 316 shares the list of all active and registered services as active services. The configuration service 316 can store any service directory or list and related information in configuration storage. Configuration storage may comprise any of a variety of forms of storage and/or memory, such as the storage and/or memory described in connection with FIGS. Information associated with each service may be stored separately or together in the configuration storage and stored in various formats. In embodiments, the configuration service 316 may also store identification credentials, encryption keys, confidential information, and the like. The configuration service 316 also stores sensitive information in the enterprise's internal computing environment and requests to share the sensitive information from the new server (e.g., connector) to one or more of the enterprise's trusted servers (e.g., Stores a real-time list of trusted connectors, e.g.
The computing environment 300 may also include client devices 302 . The client device 302 is a personal computer, laptop, tablet, smart phone, etc., and may have the components of one or more of the computing devices described above. In embodiments, client device 302 is a remote computing device, such as a user's personal device (eg, the user possesses client device 302) and logs into an internal and/or external computing environment. and/or may otherwise be accessed after user authentication. As another example, client device 302 may be owned by a company that manages and controls its internal computing environment (eg, company-issued laptop). In such an example, when the user connects the client device 302 to a terminal on the corporate premises, the client device 302 belongs to the internal computing environment. Otherwise, when the user uses the client device 302 off the corporate premises (e.g., at the user's home), the client device 302 does not belong to the internal computing environment (e.g., has a virtual private network (VPN) connection). via) and/or otherwise accessible after user authentication.
Client device 302 can have a web browser 306 and programs such as receiver 304 which is client software installed on client device 302 . Receiver 304 allows client device 302 to access internal and/or external services. The web browser 306 allows the client device 302 to securely access certain applications managed, configured and/or provided by an external service provider and running on the client device 302 (rather than via a remote session). becomes possible. This allows users to leverage local processing power while still allowing administrators to centrally manage licenses and settings. For example, an administrator can configure and publish encryption applications, authentication applications, etc., that run on the client device 302 to take advantage of local processors without incurring network delays. can be done. Such applications may be exposed by, for example, administrative user interface (Admin UI) 350 for use by client device 302 . Other examples include, but are not limited to, graphics UIs, low-level software development kits (SDKs), and the like. In another example, client device 302 can use receiver 304 to securely access applications, virtual desktops, and data stored in internal and/or external computing environments. An example of receiver 304 is the Citrix Receiver developed by Citrix Systems, Inc., based in Fort Lauderdale, Florida, USA.
Client device 302 may also include a data encryption module 320 that encrypts sensitive information. Alternatively and/or additionally, the client device has access to a data encryption module 320 that encrypts sensitive information exposed by the Admin UI 350 and accessed by the client device 302 using the web browser 304. may be used as Data encryption module 320 may comprise key generator 321 , key exchange module 322 and encryptor 323 . Key generator 321 can generate symmetric and/or asymmetric encryption keys (described below) to encrypt sensitive information. Keys can be generated using random key generators, pseudo-random key generators, or other key generators.
The key exchange module 322 can securely transmit one or more symmetric or asymmetric cryptographic keys to the external computing environment's configuration service 316 (or another external entity). The configuration service 316 (or another external entity) can store cryptographic keys and transmit the stored cryptographic keys to internal and/or external resources or services. The encryptor 323 can generate encrypted data by reversibly encrypting data such as confidential information using the encryption key generated by the key generator 321 . It will be appreciated that encryptor 323 may encrypt data by subjecting it to various operations now known or may be known to those skilled in the art. In one embodiment, encryptor 323 may be a software module that generates encrypted confidential information by performing a mathematical algorithm on the key and confidential information. Those skilled in the art will recognize that the exact encryption technique used can vary within the scope of the embodiments described herein.
Returning to FIG. 3, the internal computing environment of computing environment 300 may also parse, intercept, and/or forward messages sent between external and internal computing environments. One or more connectors 310A, 310B, . . . 310N may also be provided. In embodiments, one or more of connectors 310A, 310B, ..., 310N do not belong to the internal computing environment and may be included in different networks. The internal computing environment can also have one or more internal resources 308 . Connectors 310A-N can facilitate communication between internal resources 308 and services provided by external service providers (external services 318). In embodiments, the connectors 310A, 310B, . may access the service. An authentication module can authenticate the user based on the identification authentication information. Examples of identification and authentication information include, but are not limited to, password-based authentication, knowledge-based authentication, biometric-based authentication, second factor authentication, and the like.
In embodiments, external service 318 may be configured to require and/or cause one or more operations to be performed by internal resource 308 while providing external service 318 . However, internal resource 308 may require presentation of sensitive information (eg, a password) before allowing such operations to be performed. For example, when using an external service (e.g. SSPR service) to perform a password reset service to change a password associated with an internal resource (e.g. an on-premises Active Directory), the password reset is sent to the on-premises Active Directory. Ask the SSPR service to run. However, the on-premises directory may require the SSPR service to provide sensitive information, such as old passwords, credentials to authenticate the user, before allowing password resets. However, storing such sensitive information in external service 318 may pose security concerns.
The internal computing environment of computing environment 300 may also include a directory service 312 (eg, an active directory). In embodiments, the directory service 312 maintains a list of all connectors 310A-N available to and/or provided by an internal computing environment that includes the functionality it provides; can be managed. Only when connector 310 is successfully registered with active directory 312 is it permitted to establish a communication link between the internal computing environment and an external service or resource. When adding a new connector, the new connector can be subscribed to directory service 312 so that communication with the new connector can be controlled by directory service 312 . Directory service 312 may comprise any of a variety of forms of storage and/or memory, such as the storage and/or memory described in connection with FIGS. In embodiments, directory service 312 may also store user accounts, user account security information, and the like.
In embodiments, the computing environment 300 also receives requests for certificates (such as digital certificates), validates information contained in the requests, issues certificates, and revokes certificates. An engine 330 may also be provided. A certification authority 330 is a trusted entity that certifies that a signature has been authorized and authenticated in an electronic communication context. In other words, the certification authority 330 verifies that the digital signature actually belongs to the entity identified in the certificate, according to the standards that allow the signature to be used in related applications (such as building trust for new connectors in this disclosure). Acts as a digital-to-analog notary for certifying Generally, the certification authority 330 provides (a) information identifying the authorized party, (b) the authorized party's public key, and (c) a digitally signed, i.e., the certification authority's private key. provide a certificate containing information identifying the certification authority 330, encrypted using
In some embodiments, certification authority 330 may be located within and/or managed by the internal computing environment to further enhance the security of sensitive information.
In embodiments, upon client device 302 first receiving sensitive information that is later used by external service 318 to cause internal resource 308 to perform a desired operation, client device 302 may include and/or (e.g., Admin The encryption module 320, accessed by the client device 302 (via the UI), can be used to generate keys and encrypt sensitive information using the keys. The encryption module 320 can then send the generated key to the configuration service 316 of the external service provider 314 and send the encrypted sensitive information to the connector (eg, the first connector 310A). A first connector can share confidential information with a group of trusted connectors 310A-N. This ensures that external services 318 do not access and/or store sensitive information in encrypted and/or unencrypted form. Later, when the external service 318 wants an action to be performed by the internal service 308, the external service 318 requests a copy of the encryption key from the configuration service 316 and sends the received key to the trusted connectors 310A-N. can do. The trusted connector uses the received key to decrypt the stored encrypted sensitive information and requests the required action from the internal service 308 by providing the decrypted sensitive information for authentication. can do.
The computing environment described above for sharing or duplicating confidential information between entities (e.g., connectors) of the internal computing environment is for purposes of illustration and can be set up to support the embodiments described herein. Those skilled in the art will appreciate that the type of architecture is not limiting. Similar principles can apply to the storage and transmission of information between any two computing environments. Any two computing environments may be internal computing environments of two different entities, internal computing environments of a single enterprise, two external computing environments, and/or an internal computing environment and an external computing environment. include, but are not limited to. Further, similar principles can be applied to sharing sensitive information between any two entities of a computing environment (eg, an internal computing environment) upon establishment of trust.
Referring to FIG. 4, an example method 500 for transmitting sensitive information through an external untrusted computing environment and sharing the sensitive information between connectors in a secure corporate computing environment is shown. An example computing environment 300 is shown in FIG. Process 400 may be performed by a system such as system 100 . For example, in one or more embodiments, process 400 shown in FIG. 4 and/or one or more steps thereof may be performed by a computing device (eg, any device of FIGS. 1-2). In other embodiments, the process illustrated in FIG. 4 and/or one or more steps thereof are embodied in computer-executable instructions stored in a computer-readable medium, such as non-transitory computer-readable memory. can be Alternatively or additionally, any step of process 400 may be performed by any client device, gateway device, connector, external service provider, and/or third party server or computing device. Alternatively or additionally, any step of process 400 may be performed with any browser plug-in, Admin UI, or the like.
Method 400 may begin at 402 with a client device (or another entity or computing device) of a computing environment receiving confidential information. In an embodiment, for example, the confidential information may later be used to access a first resource (associated with a first computing environment) and/or cause the first resource to perform a desired operation. Can have authentication information. For example, a client device may receive identification credentials for accessing resources upon initial authentication of a user during logon. In embodiments, the client device may receive information for transmission to the recipient for use in subsequent logins. Recipients may include, for example, a first resource, another resource associated with the first computing environment, and/or another resource in a different computing environment than the first resource's computing environment. However, as described below, the client device can intercept sensitive information and store it in encrypted form at the connector. This ensures that unencrypted sensitive information is not transmitted and/or stored to untrusted entities. An untrusted entity includes, for example, a computing environment other than the first computing environment or a resource other than the first resource. For example, an administrator can provide sensitive information with a privileged password to authorize a user to modify the user's access credentials corresponding to one or more resources using the SSPR service. The first resource can be any internal and/or external resource.
In the embodiment, the client device receives information such as information content (e.g., keywords, tags, etc.), information type, user information (e.g., when the user is an administrator), sender's device information, and so on. having sensitive information that can be used to access the first resource and/or cause the first resource to perform a desired action, based on, the recipient's resource or application description, the intended use of the information, etc. can be confirmed. For example, a client device may determine that received information includes sensitive information if the received information has keywords such as passwords, usernames, social security numbers, account numbers, and the like. In another example, a client device may determine that received information includes sensitive information if the received information has an authentication token to authenticate the user or device. Sensitive information may include user ID (e.g. user number, username, etc.) and/or password, personal identification number (PIN), smart card ID, security certificate (e.g. public key certificate), and user characteristics (e.g. , fingerprint reader, iris scan, voice recognizer or other biometric device), or any data used to authenticate access to a particular application or resource, but It is not limited to these.
Upon receiving the confidential information, the client device can transmit the confidential information to the first connector of the first computing environment for storage (404). Here, confidential information must be transmitted through the second computing environment or can be used by resources associated with the second computing environment. A first connector can serve as a communication channel between a first computing environment and a second computing environment. In embodiments, the first computing environment may be a trusted computing environment, such as an enterprise's internal computing environment, and the second computing environment may be an untrusted external computing environment. Subsequently, the first connector can share sensitive information with the second connector if the second connector can establish trust, eg, via an untrusted computing environment (discussed below).
Alternatively and/or additionally, the first connector may receive sensitive information for storage from another entity and/or directly from the user.
In an embodiment, prior to sending sensitive information to the first connector, the client device uses the Admin The encryption module (exposed by the UI) can be used to generate keys for encrypting sensitive information and to encrypt sensitive information. Upon encryption, the client device may send the generated key to the configuration service (or another service, resource or computing device) and send the encrypted sensitive information to the first connector for storage. can. Deleting the key from memory by the client device can prevent the client device from decrypting the encrypted information. In embodiments, the client device may also remove unencrypted confidential information from memory after encryption. Thus, sensitive information required to access a first resource is stored in encrypted form at a first connector associated with a computing environment, and the key for decrypting that information is stored at that connector. stored at a configuration service associated with another computing environment that is different from the computing environment associated with the .
At 406, the second connector can request the first connector to share the encrypted confidential information. For example, in response to a second resource receiving a request from a user to cause a first resource to perform an operation using a second connector (where the second connector is used as a communication channel with the first resource). can also work.), the second connector can request confidential information. In embodiments, a second resource may be associated with the first computing environment. Alternatively, the second resource may be associated with a computing environment other than the first computing environment. For example, a user, via the SSPR service (second resource), may request access to an active directory (first resource) to act to change the user's password. In embodiments, the request may include the user's identity credentials, which may be used before the request is granted to cause the first resource to perform the requested operation, e.g. , must be authenticated by comparison with stored identification authentication information. In embodiments, the second resource may receive requests from users via client devices (eg, receivers).
Alternatively and/or additionally, requests for sensitive information by a second connector may be made at the time of new connector offerings , e.g., to improve the performance of the enterprise's computing environment, or on a periodic basis. Alternatively, it may be performed when requested by the user.
A first connector can share sensitive information with a second connector if the second connector has already joined the directory service as a trusted connector. Specifically, the first connector is one or more trusted connectors included in the list of trusted connectors maintained by the configuration service (those that have already been authenticated as trusted connectors using the method described below) and confidential Information can be shared. However, if the second connector is not already included in the list of trusted connectors, the second connector must first establish trust as described below. It should be noted that although this disclosure describes storing sensitive information on connectors in the internal computing environment and sharing sensitive information among one or more connectors, it is not possible to store sensitive information among other entities in the internal computing environment. Similar principles can be used for storing and sharing confidential information.
At 408, the first connector may determine whether the second connector is a trusted connector included in a list of trusted connectors maintained by the configuration service. If the second connector is a trusted connector on the list maintained by the configuration service (408: YES), then the first connector can send encrypted sensitive information to the second connector ( 412). On the other hand, if the second connector is not in the list of trusted connectors (408: NO), then the second connector must establish trust (410), as described below in FIG. If the second connector cannot establish trust, the first connector may reject the request (414). On the other hand, if the second connector is able to establish trust, the first connector can send the stored sensitive information to the second connector (412).
In an embodiment, after receiving the request, if the second connector is able to access the sensitive information, the second resource retrieves the key used to encrypt the sensitive information from the configuration service and combines that key with the user request. can be sent to the second connector. The second connector uses the key to decrypt the previously shared sensitive information, and uses the decrypted sensitive information (e.g., using an appropriate authentication module to convert the received identification authentication information to the decrypted sensitive information). The user can be authenticated by comparing the identity authentication information contained in the .
Although the embodiments described herein store encryption keys in the configuration service, other computing environments than the first computing environment may be used without departing from the principles disclosed herein. A person skilled in the art will understand that the computing device or module of may store the key. For example, encryption keys may be stored by a single sign-on service of the second computing environment.
Referring to FIG. 5, in accordance with one or more exemplary aspects described herein, prior to sharing sensitive information with the second connector, the second connector prevents external computing environments from accessing the sensitive information. 4 shows an exemplary message flow 500 for establishing that is a trusted connector (ie, 414 in FIG. 4). In one or more embodiments, the steps of FIG. 5 and/or one or more steps thereof may be performed by one or more computing devices. In other embodiments, the method shown in FIG. 5 and/or one or more steps thereof are embodied in computer-executable instructions stored in a computer-readable medium, such as non-transitory computer-readable memory. can be In some examples, one or more of the steps in Figure 5 may be performed in a different order. Also, in some examples, one or more of the steps of FIG. 5 may be omitted and/or otherwise not performed.
At 502, a second connector can subscribe or register as a trusted connector with a directory service associated with the first resource. In embodiments, to subscribe the second connector to the directory service, the trust relationship may be verified, for example, by verifying the user's credentials (e.g., administrator credentials) associated with the subscription request.
At 504, the second connector can generate a public/private key pair. Public/private key pairs are well known and will not be described in detail. The second connector may send the public key to a certification authority (CA) to request a public key certificate (506). The CA issues a digital certificate (e.g., a machine certificate such as an X.509 certificate, a proprietary certificate such as a public key infrastructure (PKI) certificate, etc.) containing a public key corresponding to the second connector's private key and can be signed (508). Before the CA issues a public key certificate, for example, if a second connector signs a request for a public key certificate, the CA verifies that the signature is valid. 2 The authenticity of the connector can be verified. Thus, the CA acts as a trusted third party verifying the identity of the second connector. After verifying the second connector's signature, the CA can sign the public key certificate and return it to the second connector.
Upon receiving the digital certificate, the second connector can send a request to the configuration service to join the group of trusted connectors (510). Alternatively, the request may be sent to another entity that stores a list of trusted connectors that can access and/or store sensitive information. The request has a digital certificate containing the public key of the second connector. In embodiments, a group of trusted connectors may correspond to or relate to, for example, a resource, computing environment, sensitive information set, enterprise, user, computing device, service provider, or a combination thereof.
At 512, the configuration service may identify a connector (e.g., the first connector) from the group of trusted connectors storing sensitive information and transmit the request containing the digital certificate to the identified connector. (514). The transmitted request also contains information identifying the second connector and the certificate. As described above, the configuration service maintains a list of trusted connectors that have access to and/or store sensitive information, and identifies any of the trusted connectors as storing sensitive information. It can be identified as a connector.
In embodiments, if the group of trusted connectors is empty, i.e., if the configuration service has no connectors with previously established trust, the configuration service may create a new group of trusted connectors. . A new group of trusted connectors can be associated, for example, with a resource, computing environment, sensitive information set, enterprise, user, or a combination thereof. Confidential information associated with these combinations can be accessed and/or stored. The configuration service can then add the second connector to the new group without performing steps 514-536.
Upon receiving a request with information identifying a second connector and a certificate transmitted from the configuration service, the identified connector authenticates the received certificate by sending an authentication request with the certificate to the CA. Then, it can be determined whether the CA actually issued and signed the digital certificate (516). The CA can authenticate the received certificate (518), for example, by verifying the signature. The identified connector may also determine whether the second connector has joined the directory service as a trusted connector by sending information identifying the second connector to the directory service (520). Either the CA or the directory service cannot authenticate that the digital certificate was in fact issued by a CA and/or that the second connector has joined the directory service as a trusted connector. , the identified connector can deny the request for sensitive information.
On the other hand, if the CA and directory service authenticate that the digital certificate is genuine (518) and that the second connector is subscribed to the directory service as a trusted connector (522), the identified connector , the stored confidential information can be encrypted using the public key contained in the digital certificate (524). The identified connector can then send the encrypted confidential information to the second connector via the configuration service (526 and 528).
The second connector can use the private key corresponding to the public key (from the private public key pair) to decrypt the received sensitive information and store the information (530). The second connector may then request the configuration service to add the second connector to a list of trusted connectors storing sensitive information (532). The configuration service may add the second connector to the list of trusted connectors (534) and send confirmation to the second connector that it has been added to the group of trusted connectors (536). The second connector can then access and/or replicate information received by any connector in the group of trusted connectors.
In an embodiment, prior to receiving the transmitted request from the configuration service (i.e., step 514), if the group of trusted connectors has not received the requested sensitive information, the identified connector may send the sensitive information. You can notify the configuration service that you don't have it. The configuration service can then add the second connector to the group of trusted connectors without performing steps 516-536. The second connector can then share or copy confidential information upon receipt by any connector of the group of trusted connectors.
While the embodiments described herein assume that multiple trusted connectors store sensitive information and share sensitive information between multiple trusted connectors, any deviation from the principles disclosed herein may be used. other computing devices or modules of the first computing environment and/or another computing environment (but not the second computing environment) may store and/or share confidential information without will be understood by those skilled in the art. For example, local storage servers, devices, and/or internal resources of the first computing environment may store and/or share confidential information.
Although the system and method have been shown and described with respect to one or more implementations, equivalent modifications and alterations will occur to others skilled in the art upon the reading and understanding of this specification and the annexed drawings. Moreover, although certain features may be disclosed with respect to only one of some implementations, such features may be disclosed in other implementations as desirable and advantageous for any or particular application. can be combined with one or more other features of Accordingly, the breadth and scope of the disclosure should not be limited by any of the above descriptions. Rather, the scope of the disclosure should be defined according to the appended claims and their equivalents.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US20140047513A1 | Cites | United States of America |
| JP2017533630A | Cites | Japan |
9 members in 6 offices
Members9
| Document | Office | Kind | |
|---|---|---|---|
| CA3102920A1 | Canada | A1 | |
| US2020053059A1 | United States of America | A1 | |
| WO2020033020A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2020033020A8 | World Intellectual Property Organization (WIPO) | A8 | |
| AU2019319064A1 | Australia | A1 | |
| EP3834391A1 | European Patent Office (EPO) | A1 | |
| JP2021533599A | Japan | A | |
| JP7145308B2This record | Japan | B2 | |
| US11611541B2 | United States of America | B2 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 7145308
- Application
- 2021500288
Titles2
- Japanese
- コンピューティング環境でオンプレミスの秘密を複製する安全な方法
- English
- A secure way to replicate on-premises secrets in your compute environment
Classification
- CPC, 6
- H04L63/101
- H04L63/0442
- H04L63/08
- H04W12/04
- H04L9/321
- H04L63/0823
- IPC, 3
- H04L9 32
- H04L9 08
- G06F21 33
