Key generation depending on parameter
Abstract
FIELD: physics, computer engineering.SUBSTANCE: invention relates to computer resource security management. A computer-implemented method of controlling access to computer resources of a provider, wherein one or more computer resources of a computer resource provider are a part of a logical group of computer resources in a key zone from a plurality of key zones, the method comprising: receiving, from the main key source, a session key corresponding to a key zone, wherein the session key is generated at least by applying a hash function of a message authentication code to a secret certificate and the first set of one or more session parameters; receiving an electronic request to access one or more computer resources and a signature for the electronic request, which was generated based, at least in a part, on the secret certificate and the second set of one or more session parameters; generating, using one or more computer systems, a source signature at least by applying a hash function of a message authentication code to at least the electronic request and the received session key; and providing access to one or more computer resources.EFFECT: efficient management of computer resource security.27 cl, 24 dwg

Term
6 yearsleft in the term
Expires 28 September 2032.
- Priority
- Filed
- Granted
- Today
- Expires
27 claims: 18 independent, 9 dependent
- 1A computer-implemented method for controlling access to one or more computing resources, computing resources of the provider, and one or more computational resource provider computing resources are part of a logical group of computing resources in the key area of the plurality of key areas, the method comprising:running one or more computer systems operating on the basis of commands received from the primary source session key key corresponding to the key zone, the session key is generated at least by applying a hash message authentication code to the secret certificate and the first set of one or more parameters session, receiving an electronic request for access to one or more computational resources and signatures for electronic request, which has been generated based at least in part on secret certificate and the second set of one or more session parameters;generating by one or more computer systems original signature, at least by applying a hash message authentication code, at least to an electronic request received session key;and Ensuring access to one or more of the computing resources in response to a request generated when the original signature is the same signature adopted. 1. Компьютерно-реализуемый способ управления доступом к одному или более вычислительным ресурсам провайдера вычислительных ресурсов, причем один или более вычислительных ресурсов провайдера вычислительных ресурсов являются частью логической группы вычислительных ресурсов в зоне ключей из множества зон ключей, при этом способ содержит:под управлением одной или более компьютерных систем, функционирующих на основе выполняемых команд,получение от главного источника ключей ключа сеанса, соответствующего зоне ключей, причем ключ сеанса сгенерирован, по меньшей мере, путем применения хэш-функции кода аутентификации сообщений к секретному сертификату и первому набору из одного или более параметров сеанса;прием электронного запроса на доступ к одному или более вычислительным ресурсам и подписи для электронного запроса, которая была сгенерирована на основе, по меньшей мере, частично секретного сертификата и второго набора из одного или более параметров сеанса;генерирование при помощи одной или более компьютерных систем исходной подписи, по меньшей мере, путем применения хэш-функции кода аутентификации сообщений, по меньшей мере, к электронному запросу и полученному ключу сеанса;иобеспечение доступа к одному или более вычислительным ресурсам в ответ на запрос, когда сгенерированная исходная подпись эквивалентна принятой подписи.
- 8The computer-implemented method for controlling access to one or more computing resources, computing resources of the provider, and one or more computational resource provider computing resources are part of a logical group of computing resources in the key area of the plurality of key areas, the method comprising:running one or more computer systems operating on the basis of commands, reception of a session key, the session key is generated at least by applying a function, at least the secret certificate and the first set of one or more session parameters, the session key associated with the zone key, receiving electronic request for access to one or more computational resources and signatures for electronic request, generated based at least in part the second set of one or more parameters, determining by means of one or more computer systems is whether the received signature valid for a request, at least by applying a function, at least the second measure, to the electronic request and the obtained session key, and the signature adopted is determined as valid as a result of the fact that at least a first set of one or more parameters is equivalent to the second set of one or more parameters;ipredostavlenie requested electronically access that generated the original signature equivalent to the signature adopted. 8. Компьютерно-реализуемый способ управления доступом к одному или более вычислительным ресурсам провайдера вычислительных ресурсов, причем один или более вычислительных ресурсов провайдера вычислительных ресурсов являются частью логической группы вычислительных ресурсов в зоне ключей из множества зон ключей, при этом способ содержит:под управлением одной или более компьютерных систем, функционирующих на основе выполняемых команд,получение ключа сеанса, причем ключ сеанса сгенерирован, по меньшей мере, путем применения функции, по меньшей мере, к секретному сертификату и первому набору из одного или более параметров сеанса, причем ключ сеанса связан с зоной ключей;прием электронного запроса для обеспечения доступа к одному или более вычислительным ресурсам и подписи для электронного запроса, сгенерированного на основе, по меньшей мере, частично второго набора из одного или более параметров;определение при помощи одной или более компьютерных систем, является ли принятая подпись действительной для запроса, по меньшей мере, путем применения функции, по меньшей мере, к электронному запросу и полученному ключу сеанса, причем принятая подпись определяется как действительная в результате того, что по меньшей мере первый набор из одного или более параметров эквивалентен второму набору из одного или более параметров;ипредоставление запрашиваемого электронным образом доступа, когда сгенерированная исходная подпись эквивалентна принятой подписи.
- 9The computer-implemented method according to claim. 8, in which the function is a hash function. 9. Компьютерно-реализуемый способ по п. 8, в котором функция является хэш-функцией.
- 11A computer-implemented method according to claim. 8, in which the signature is determined by applying a function to the first set of input data containing the secret certificate request and a first set of one or more parameters and a second set of input data containing the session key and a first set of one or more parameters. 11. Компьютерно-реализуемый способ по п. 8, в котором подпись определяется путем применения функции как к первому набору входных данных, содержащих секретный сертификат, запрос и первый набор из одного или более параметров, так и ко второму набору входных данных, содержащих ключ сеанса и первый набор из одного или более параметров.
- 12A computer-implemented method according to claim. 8, further comprising:determining by one or more computer systems, whether the request corresponds to the first set of one or more parameters, and providing the requested access to electronically depends on determining that the request matches the first set of one or more parameters. 12. Компьютерно-реализуемый способ по п. 8, дополнительно содержащий определение при помощи одной или более компьютерных систем, соответствует ли запрос первому набору из одного или более параметров, причем предоставление запрашиваемого электронным образом доступа зависит от определения того, что запрос соответствует первому набору из одного или более параметров.
- 13A computer-implemented method according to claim. 8, wherein the first set of one or more parameters limit the time interval during which the session key can be used for the session. 13. Компьютерно-реализуемый способ по п. 8, в котором первый набор из одного или более параметров ограничивает интервал времени, в течение которого ключ сеанса может использоваться для сеанса.
- 14A computer-implemented method according to claim. 8, wherein the first set of one or more of the parameters corresponds to a set of one or more identifiers that are permitted to use the session key. 14. Компьютерно-реализуемый способ по п. 8, в котором первый набор из одного или более параметров соответствует набору из одного или более идентификаторов, которым разрешено использовать ключ сеанса.
- 15Permanent computer-readable media, which stores instructions that, when executed by one or more processors of a computer system implementing a computer system providing at least:receiving a session key generated at least partially by applying a function, at least for secret certificate and a set of one or more session parameters for generating the session key, the session key corresponds to a group of one or more computing resources into the area key of the plurality of key zones based on the signature of at least partially received electronic query session key to provide access to one or more computing resources, thereby generating a signature for a query;ipredostavleniya by coincide with the corresponding granted requests least signatures and query to check verifier computing device configured to determine whether a given signature coincide with the corresponding granted requests and perform one or more actions that enforce access requests when given signature . 15. Постоянный машиночитаемый носитель информации, на котором хранятся команды, которые при выполнении одним или более процессорами компьютерной системы обеспечивают осуществление компьютерной системой, по меньшей мере:получения ключа сеанса, сгенерированного, по меньшей мере, частично путем применения функции, по меньшей мере, к секретному сертификату и набору из одного или более параметров сеанса для генерирования ключа сеанса, причем ключ сеанса соответствует группе из одного или более вычислительных ресурсов в зоне ключей из множества зон ключей;подписи на основе, по меньшей мере, частично полученного ключа сеанса электронных запросов для обеспечения доступа к одному или более вычислительным ресурсам, тем самым генерируя подписи для запроса;ипредоставления, по меньшей мере, подписей и запросов для проверки верификатором вычислительного устройства, сконфигурированного с возможностью определять, совпадают ли предоставленные подписи с соответствующими предоставленными запросами, и выполнения одного или более действий, которые обеспечивают выполнение запросов доступа, когда предоставленные подписи совпадают с соответствующими предоставленными запросами.
- 18Permanent computer-readable data carrier according to claim. 15 wherein obtaining a session key does not require access to the secret certification computer system. 18. Постоянный машиночитаемый носитель информации по п. 15, в котором получение ключа сеанса не требует обеспечения доступа к секретному сертификату компьютерной системой.
- 19Permanent computer-readable medium of claim. 15 wherein the set of one or more characteristic parameters of the time period beyond which the verifier will not accept requests electronically signed using the session key. 19. Постоянный машиночитаемый носитель информации по п. 15, в котором набор из одного или более параметров характеризует период времени, вне которого верификатор не будет принимать запросы, подписанные электронным образом с использованием ключа сеанса.
- 20Permanent computer-readable medium of claim. 15 wherein the function is a hash function. 20. Постоянный машиночитаемый носитель информации по п. 15, в котором функция является хэш-функцией.
- 21Permanent computer-readable medium of claim. 15 wherein the application function is executed as part of the forming operation message authentication hash (HMAC). 21. Постоянный машиночитаемый носитель информации по п. 15, в котором применение функции выполняется как часть операции формирования хэш-кода аутентификации сообщений (НМАС).
- 22A computer system for providing access to computing resources, comprising:one or more processors ipamyat including a command that when executed by one or more processors of a computer system providing at least: obtaining a key, applying a function to a key and a set of one or more parameters to generate a session key, wherein the one or more parameters corresponding to one or more of the limitations of the session key while the session key corresponds to one or more of the computing resources of a plurality of key zones key zones;ipredostavleniya generated session key to another computing device to another computing device to allow signing requests using a session key in accordance with a set of one or more parameters. 22. Компьютерная система для обеспечения доступа к вычислительным ресурсам, содержащая:один или более процессоров ипамять, включающую в себя команды, которые при выполнении одним или более процессорами обеспечивают осуществление компьютерной системой, по меньшей мере:получения ключа;применения функции к ключу и набору из одного или более параметров для генерирования ключа сеанса, причем один или более параметров соответствуют одному или более ограничениям ключа сеанса, при этом ключ сеанса соответствует одному или более вычислительным ресурсам зоны ключей из множества зон ключей;ипредоставления сгенерированного ключа сеанса другому вычислительному устройству, чтобы разрешить другому вычислительному устройству подписывать запросы с использованием ключа сеанса в соответствии с набором из одного или более параметров.
- 23The computer system of claim. 22 wherein the one or more parameters to limit the time interval during which the generated session key may be used to query signature. 23. Компьютерная система по п. 22, в которой один или более параметров ограничивают интервал времени, в течение которого сгенерированный ключ сеанса может использоваться для подписи запросов.
- 24The computer system of claim. 22 wherein the one or more parameters limit the set of computational resources for which a session key may be used to provide access to one or more computational resources. 24. Компьютерная система по п. 22, в которой один или более параметров ограничивают набор вычислительных ресурсов, в отношении которого может использоваться ключ сеанса для обеспечения доступа к одному или более вычислительным ресурсам.
- 25The computer system of claim. 22 wherein the set of one or more parameters encoded with the document, and to use the function key and a set of one or more parameters includes applying a function to the document. 25. Компьютерная система по п. 22, в которой набор из одного или более параметров кодирован с помощью документа, причем применение функции к ключу и набору из одного или более параметров включает в себя применение функции к документу.
- 26The computer system of claim. 22 wherein the application of a hash function to a key and a set of one or more parameters includes calculating the result of applying a hash function to at least the first parameter of the set of one or more input parameters and computation result into a hash function. 26. Компьютерная система по п. 22, в которой применение хэш-функции к ключу и набору из одного или более параметров включает в себя вычисление результата применения хэш-функции, по меньшей мере, к первому параметру из набора из одного или более параметров и ввод вычисленного результата в хэш-функцию.
- 27The computer system of claim. 22 wherein one or more of the parameters limiting the use of the session key to the appropriate location. 27. Компьютерная система по п. 22, в которой один или более параметров ограничивают использование ключа сеанса к соответствующему местоположению.
Independent claims18
227 paragraphs in 4 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to US patent applications: №13 / 248,962, filed September 29, 2011, entitled "Formation of key based on parameters of objects" (Attorney Docket №90204-813889 (029400PC)); №13 / 248,953, filed September 29, 2011, entitled "Algorithms for the session, create a customer" (Attorney Docket №.90204-818478 (032300US)); and №13 / 248973, filed September 29, 2011, entitled "Algorithms for key generation" (Attorney Docket №90204-813890 (029500US)), the entire disclosure of which is incorporated herein by reference.
BACKGROUND
[0002] There are many types of computing environments. For example, often the organization to provide its users a set of functional services using a network of computing devices. Most network covering many geographical boundaries and connect with other networks. For example, to ensure that their work organizations can be used as the internal network of computing resources and computing resources managed by third parties. So, belonging to the organization of the computers can communicate with computers of other organizations, accessing and / or providing data for the use of services of another organization. In most cases, configuration and maintenance of remote networking using the hardware controlled by other organizations, thereby reducing infrastructure costs and other advantages are achieved.
[0003] In addition to the fact that a variety of computing environments are proven for a wide range of applications, the use of such media raises many complex issues. For example, setting the configuration of computer resources to achieve the objectives of an organization can have a negative impact on achieving other organization goals. For example, the effective management of computing resources, security is often achieved at the expense of the efficiency of access to data and services. It is very difficult to achieve a balance between security objectives and effectiveness, as it requires considerable effort and resources costs.
BRIEF DESCRIPTION OF THE DRAWINGS
[0004] FIG. 1 illustrates an exemplary computing environment that can be used to implement various aspects of the present invention, at least in accordance with one embodiment of the invention;
[0005] FIG. 2 illustrates an example environment comprising computing resource provider managing a plurality of failure zones, at least in accordance with one embodiment of the invention;
[0006] FIG. 3 illustrates an example computing environment in failure zone shown in FIG. 2, at least in accordance with one embodiment of the invention;
[0007] FIG. 4 illustrates a configuration example of a computing resource that can be used to provide a computing environment such as computing environment shown in FIG. 3, at least in accordance with one embodiment of the invention;
[0008] FIG. 5 shows a diagram illustrating the typical way in which the various elements involved in the computing environment may be given different levels of authority, at least in accordance with one embodiment of the invention;
[0009] FIG. 6 illustrates a diagram for explaining an exemplary method in which information can be transmitted between the authentication sides, at least in accordance with one embodiment of the invention;
[0010] FIG. 7 is a block diagram illustrating an example message signing process in accordance with an embodiment;
[0011] FIG. 8 is a block diagram of the signature verification process, at least in accordance with one embodiment of the invention;
[0012] FIG. 9 illustrates a diagram of a typical method for key distribution, at least in accordance with one embodiment of the invention;
[0013] FIG. 10 illustrates a typical scheme using the key distribution method in a process which provides different amounts of authority in accordance with at least one embodiment of the invention;
[0014] FIG. 11 illustrates a block diagram of a key generation process, at least in accordance with one embodiment of the invention;
[0015] FIG. 12 illustrates a scheme for generating multiple-key limited, at least according to one embodiment of the invention;
[0016] FIG. 13 illustrates a graphic example funktsiidlya receipt signature, at least in accordance with one embodiment of the invention;
[0017] FIG. 14 illustrates an example of how can be implemented and utilized by plural receiving key, at least in accordance with one embodiment of the invention;
[0018] FIG. 15 illustrates a diagram illustrating an exemplary method by which keys may be derived, at least in accordance with one embodiment of the invention;
[0019] FIG. 16 illustrates a diagram for explaining another exemplary method by which keys may be derived, at least in accordance with one embodiment of the invention;
[0020] FIG. 17 illustrates a diagram for explaining another exemplary method by which keys may be derived, at least in accordance with one embodiment of the invention;
[0021] FIG. 18 illustrates a block diagram for explaining a session initialization process, at least in accordance with one embodiment of the invention;
[0022] FIG. 19 illustrates a block diagram for explaining the process of generating the session key, at least in accordance with one embodiment of the invention;
[0023] FIG. 20 illustrates a block diagram for explaining the process of obtaining access to one or more computing resources during a session, at least in accordance with one embodiment of the invention;
[0024] FIG. 21 illustrates a block diagram for explaining a decision process of providing the requested access to one or more computing resources, at least in accordance with one embodiment of the invention;
[0025] FIG. 22 illustrates a block diagram for explaining a process of delegating authority, at least in accordance with one embodiment of the invention;
[0026] FIG. 23 illustrates a diagram explaining process of multiple delegation, at least in accordance with one embodiment of the invention; and
[0027] FIG. 24 illustrates a diagram for explaining a method by which a key may be obtained using keys with multiple powers.
IMPLEMENTATION OF THE INVENTION
[0028] The following description will address a number of embodiments of the invention. Specific configurations and details are set forth in order to provide the necessary comprehensive understanding of the invention. Thus those skilled in the art it will be apparent that the invention may be practiced without specific details. Furthermore, in order to facilitate understanding of the invention described by the well-known features may be omitted or simplified.
[0029] The algorithms proposed and disclosed herein include systems and methods for generating a key, according to various implementations of the invention. Keys can be used for various purposes, such as authentication and signing schemes in part messages. In the invention, the provider computing resources provide computing services to users based, at least in part on the electronic requests received from the user device using the services. Service may be any suitable service, including but not limited to, access to the data access operation performing computing resources, access to storage services and the like.
[0030] In order to ensure that these services are provided with adequate security, in various embodiments of the present disclosure are used requests authentication algorithms (also referred to as the "message") in order to verify the authenticity of the request. According to the invention, requests authentication algorithm is implemented using a hash message authentication code (HMAC) or other suitable algorithm, as described in detail below.
[0031] According to the invention, both sides of the authentication process (for example, users of services or a party acting in the interests of the user) and the authenticator (for example, a service provider or a party acting in the interests of the provider) share a secret certificate, which may be cited as the key. The authenticator may store the shared secret for a plurality of user certificates. As part of the transaction, the conductive side may sign the authentication request using the shared secret certificate, thereby creating a signature. Signature authenticator can be provided with the request. The authenticator can use its own copy of the shared secret certificate to generate a signature for the received requests and to decide whether requests are signed using the shared secret of the certificate by comparing whether the generated signature adopted (for example, whether the signatures are the same). If it is decided that the requests are signed using the shared secret certificate requests can be considered authentic and, therefore, a decision that needs to be satisfied.
[0032] Due to the fact that the above interaction is symmetric (i.e., when carrying out their roles side use a common authentication information), shared secret certificates stored in the authenticator can be used to authenticate the authentication process, both sides or act on their behalf. As a consequence, desirable to protect these high security certificates. Ensuring a high degree of security can adversely affect the performance and availability of the system. For example, a high degree of security can mean service centralized key storage. However, such a centralized system can lead to the formation of the "bottleneck", as the increase in the number of users and / or services causes more stress on a centralized system. If such a centralized system fails to authenticate requests can be difficult or impossible. Consequently, while the centralization leads to advantages with regard to safety and to the shortcomings with regard to scalability and availability of services.
[0033] In the invention, the negative effects of such systems (and other systems) is minimized using the protocol signature, based on artifacts shared secret certificate used to verify that the authenticator portion comprises shared secret certificate and, therefore, suitable for authorized access as defined in the signed requests using artifacts. In the invention, such artifacts are obtained by configuring computer authentication systems so as to receive a signature value based on at least a portion of the obtained shared certificate instead of the certificate shared. Formation of the certificate may be used in conjunction with the proviso that in practice it was not possible to determine the certificate used together, as described in more detail below.
[0034] For example, in the embodiment of the invention the part of the authentication process can put the signature in accordance with:
HMAC (M, HMAC (X, certificate))
wherein M - is a message, and HMAC (X, certificate) - is an artifact resulting from a public certificate of a secret. The value X may be a value known to the two sides and the authenticator of the authentication process, and can be shared. For example, X can be the current date encoded in a predetermined manner to ensure that the HMAC (X, certificate) side respectively computed authenticator and authentication process. As another example, X can be a service identifier with which the artifact may be used. As another example, X can be encoded by a plurality of semantic values and presented in a manner that both sides of the authentication process, and the artifact authenticator calculated respectively. The semantic value may be a restriction on the use of keys, including a value indicating that it is not necessary to use the resulting form of presentation of the key. In the case of a combination of the previous examples of this paragraph, the X can be encoded as "20110825 / DDS», where the sequence on the left of the slash is the date, and the sequence to the right of the slash is the name of a service that uses the artifact, calculated X. In most cases, X may be any value or range of values for encoded respectively two sides of the authenticator and authentication process. It should be noted that other suitable functions can also be used other than HMAC function as described below.
[0035] Returning to the example of using HMAC function of the invention, the values for X are selected to provide additional benefits. As noted, X can be (but not necessarily) correspond to one or more semantic values. In the invention uses semantic meaning, such as timestamps, service names, identifiers districts, and the like, to provide a system in which the artifacts are obtained in accordance with the algorithms of this embodiment of the invention, corresponding restrictions on the use of X derived keys. Thus, even though the break-generated keys that can be made available for unwanted side authentication, limiting using coded key makes it possible to minimize the adverse effects, in the case where the compromised keys. For example, the time limit is used to pick up the keys to ensure the system to effectively check whether the proposed signature made with the key that was valid at the time of adding a signature. As a specific example, if the key for the current date, and an authentication system accepts only the signatures submitted by the current date, the authentication system will decide that the signatures generated using the key received from the dates that differ from the current one, are invalid. Similarly, the key derived from the ID of a service may not be valid for use with another service. The following are other examples.
[0036] As noted, the various algorithms of the present disclosure, the invention allows for the keys to use the set parameters. The keys of the invention are obtained from the parameters set by repeated use HMAC function. For example, the key may be calculated as follows:
K<sub>S</sub>= HMAC (... HMAC (HMAC (HMAC (K, P<sub>1</sub>), P<sub>2</sub>), P<sub>3</sub>) ..., P<sub>N</sub>)
where K is a shared secret certificate and P<sub>i</sub> They are parameters. The key, K<sub>S</sub>It may be used to generate a signature, for example:
S = HMAC (K<sub>S</sub>, M),
where M - a message that can be canonized. Thus, taking into account the partial derivatives of the key to access the various components of a distributed computing system, the key is obtained multilevel. For example, K<sub>P1</sub>= HMAC (K, P<sub>1</sub>) Can be calculated and obtained access to one or more components of the distributed computing system. Components of taking K<sub>P1</sub>Can calculate K<sub>P2</sub>= HMAC (K<sub>P1</sub>, P<sub>2</sub>), Where P<sub>2</sub> It may be the same for each component or different for some or all components. The values of K<sub>P2</sub>Calculated various components can transmit other computing components distributed computing system that can compute K<sub>P3</sub>= HMAC (K<sub>P2</sub>, P<sub>3</sub>). Each component can be placed in a cache the results of calculations, and possible results calculated by other components. Thus, a higher degree of protection can be provided throughout the data storage process storing shared secret keys as key derivative calculation can be performed by other components of the distributed computing system.
[0037] The algorithms of the present disclosure, the present invention also include the initiation of sessions. For example, as already stated, to obtain the key can be used by the shared secret certificate and one or more parameters. Accordingly, the parameters for the session can be used to generate a certificate that can be used during that session. The certificate can be used by the user requesting the certificate or, in some implementations of the invention, a user who was handed a certificate and the right of access to one or more computing resources. In such cases, due to the fact that the object delegated such access uses a key derived from the shared secret certificate, but not the shared secret certificate maintained a high degree of protection, and no need to change the shared secret certificate to prevent the object of the future of use delegation. As described in more detail below, the delegate object can also become delegatorami using algorithms of the present disclosure, many of which are described in more detail below.
[0038] FIG. 1 illustrates sample aspects of a computing environment 100 for implementing aspects of the present disclosure of the invention, according to various embodiments. It should be understood that although for explanation purposes use a computing environment based on web technology, various embodiments of the invention, other appropriate computing environments may be used. The computing environment includes a client electronic device 102 comprising any suitable device suitable for sending and receiving query messages or information through the network 104 and suitable for sending information to the user device. Examples of client devices may be personal computers, mobile phones, portable devices for messaging, laptop computers, set-top box, PDAs, e-books and the like. Network may be any suitable network including an intranet, the Internet, a cellular network, a local area network, or any other similar network or combination thereof. The choice of components used for such systems may depend, at least to some extent upon the type of network and / or the selected computing environment. Protocols and components for transmitting data through such a network are well known and will not be considered in detail in this application. network data can be transmitted by means of wired or wireless connections or combinations thereof. In this example, the network uses the Internet, the web server 106 used as a computing environment for receiving requests and service response information, although it is obvious that alternative device serving a similar purpose for other networks may be used ordinary skill in the art manner.
[0039] A typical computing environment comprises at least one application server 108 and data store 110. It should be understood that there may be several application servers, or other levels of components, processes or components that may be connected in series or otherwise arranged, and may interact with each other to perform tasks such as receiving data from the corresponding data store. As used herein, the term "data storage" refers to any device or combination of devices that can store, organize, access, and retrieve data which may contain any combination and number of data servers, databases, storage devices and storage media in any conventional distributed or clustered computing environment. The application server may comprise any suitable hardware and software for integration with the data warehouse, to the extent necessary to carry out one or more aspects of the application of the client device, processing multiple data access and business logic of applications. The application server provides access control services in the interaction with the data store and can generate information such as text, graphics, audio and / or video transmitted to the user by means of a web server in the form of HTML, XML, or other language, having a structure suitable for the example. Processing of requests and responses, as well as the delivery of information between the client device 102 and server application 108 may be processed by the Web server. It will be appreciated, the use of web servers and application servers not necessarily, and they are only typical components structured code as described herein may be performed in any suitable device or host system, as described herein.
[0040] The data store 110 may comprise a plurality of separate data tables, databases or other storage mechanisms, and a storage medium for storing data in relation to certain aspects of the invention. For example, the data store contains described mechanisms for storing production data 112 and user information 116 which may be used to process information about production activities. It is also shown that the data store includes a mechanism for storing event log data 114 which may be used for reporting, analysis, or for other similar purposes. It should be understood that there may be many other issues that may need to be stored in a data store, for example, a page of graphic information, and provide information on access rights, which can be stored in any of the mechanisms described above, if necessary, or other mechanisms in data store 110. data storage 110 can be used with the help of a logical connection with it to receive commands from the application server 108, as well as receive, update, or other data processing in response to his request. In one example, the user may receive a search query for a certain type of element. In this case, the data warehouse can provide access to user information to authenticate the user, and can provide access to the catalog details for information about the elements of this type. Then, the information may be returned to the user, for example, the results of listing on a web page, the user can browse using the browser on the user device 102. The benefit of the user information can be viewed on a separate page or in a browser window.
[0041] Typically, each server has an operating system that provides the execution of program instructions for the general administration and operation of such a server, and typically includes a computer readable media (e.g., hard disk drive, random access memory, read only memory, etc. .), which stores instructions that when executed by processor of the server allow the server to perform its function. The corresponding operating system and implementation of common functionality servers are known or commercially available and easily implemented by experts in the art, especially in light of the disclosure herein.
[0042] The computing environment in one embodiment of the invention is a distributed computing environment using multiple computer systems and components that are interconnected through communication lines, using one or more computer networks or direct connections. However, those skilled in the art will appreciate that such a system would work equally well in a system having more or fewer components illustrated in FIG. 1. Therefore, the image system 100 in FIG. 1 should be taken as being illustrative in nature and not limit the scope of the disclosure of the invention.
[0043] FIG. 2 illustrates an illustrative example of a computing environment 200 comprising a computing resource provider 202, which controls a plurality of zones 204 failure in accordance with at least one embodiment of the invention. In the invention, the computing resource provider is an organization that manages the computer hardware in the interests of one or more users 206. The computing resource provider may provide computing resources in different ways. For example, in the invention, computational resource provider 202 controls the hardware device that is configured for user 206. The computing resource provider 202 provides the interface 206 allows users to programmatically configure the computing resources of the hardware used. For example, the computing resource provider can administer hardware servers that run virtual computer systems, software controlled by the user. In another example, the computing resource provider 202 may manage various data stores to provide remote storage solutions, such as highly reliable data storage and data storage at the block level.
[0044] In an embodiment, rejection zone - a collection of computing resources, which are separated by one or more boundaries of failure, so that each zone is a failure resistant to other failure failure zone. As an example, each zone failure 204 may be a separate data center. Therefore, if one data center goes down, presumably due to a power failure or other destructive phenomenon, another data center can proceed. failure zones may be located in different geographical locations, and some or all of failure zones may be separated by state boundaries. For example, two or more failure zones may be located in different countries. Note that in order to clarify the present disclosure is provided with numerous examples where the failure data are band centers. However, failure zones can be defined in many other ways. For example, individual rooms in the same data center can be considered as separate areas of failure, in accordance with various embodiments of the invention. As another example, computing resources are located in the same place, but are driven by a different backup power generators and / or maintained by various network resources, so they can be considered as different failure zone. As another example, data centers can be clustered so that each cluster of the data center can be regarded as a failure zone. In addition, there may be many reasons why the failure zone can fail, including reasons related to electrical work, the work of the public network, political events and other causes.
[0045] In this embodiment, the users communicate with the provider 206, computing resources 202 via a network 208 such as the Internet. Members 206 may have the resources, arranged in one or more areas of failure 204, and can communicate with the resources by sending electronic messages, such as messages activation web service application programming interface (API) computing provider resource to configure and manage resources . Users can use the resources in many areas of failure in order to reduce the impact of potential problems, which affect the user's resources. The user who uses the computing resources of the provider 202 for use with open-access web site, for example, may administer the web server and the other servers in the individual zones of failure, in that if the servers in one failure zone fail, users will access a web site with access to servers in another failure area.
[0046] FIG. 3 illustrates in an illustrative example environment 300 in failure zone 302, which may be a zone failure computing resource provider, as shown in FIG. 2. In this embodiment, the failure zone 302 comprises computing resources used to provide various services for users. For example, as shown in FIG. 3, failure zone 302 comprises computing resources used to provide the service of long-term data storage, which can store quite a large amount of data with low operating costs and the possibility of redundancy. Such service may find use when you need storage of large amounts of data and / or high security storage. Zone 302 failure may also contain service data storage block level 306, allows the user to use the device data storage at the block level, physical devices and / or virtual devices. For example, users can connect a storage device at the block level to the computer systems used by them. Service virtual computer system 308 is also shown, which can provide users with computing services. In this embodiment, the virtual computer system service 308 provides users with services through the implementation of virtual computer systems on physical servers, administered by the provider of computing resources, although variants are possible, such as the physical location of the computer system dedicated for use by users. In an embodiment associated with the virtual computer systems, users, depending on their needs, can manage the virtual computing software systems. For example, as shown in FIG. 3, users can configure a virtual computer system 308, a virtual computer system maintenance services for virtual computing service provider users. Virtual computer systems, for example, can be configured to work with the public website. As users of the virtual computing resource provider and the users of these members in various embodiments, may have access to different services performed in the area of failure 302 by communication with the services through the network 310, as which may be network 208 described above in connection with FIG. 2.
[0047] It should be noted that the various embodiments of the invention, illustrated in FIG. 3, as in the case of all embodiments shown in the figures and described herein are by their nature are schematic and are considered as part of this invention disclosure. For example, other services than those shown, may be provided in zone 302 as a failure, or instead of addition shown services. For example, the dots as shown in FIG. 3, a failure zone 302 can execute additional services. In addition, some services may also use other services. For example, many services (such as 308 virtual computer system data storage block level service 306 and the service) together can be used for the operation of other services such as a service of a relational database, an e-mail service and, as a rule, computer service of any type, which is provided at the expense of computing resource provider.
[0048] As shown in FIG. 3, computing resource provider may comprise a separate verifier 312 for each service. The verifier may be a computing device, a plurality of computing devices, an application module or other resource that verifies certificates different made by users and possibly other computer systems. In one embodiment, the verifier 312 verifies the signature of messages that are generated according to various embodiments of the present application and are then provided to users along with the requests for access to computer resources as described in more detail below. Keys and other important information may be provided to the verifiers of the main source of the key that allows verifiers to check the information. It should be noted that each service having verifier is a clear example of a particular embodiment of the invention, so that other configurations are within the present disclosure. For example, a verifier can support multiple services, or all services, and even a lot of failure zones.
[0049] FIG. 4 illustrates a graphic example of the configuration computing resource that can be used to provide a computing environment such as computing environment shown in FIG. 3, at least in accordance with one embodiment of the invention. FIG. 4 illustrates a specific example in which the failure area in FIG. 3 is a data center. Thus, returning to FIG. 4, the data center 402 may comprise a plurality of racks 404-406. Data center 402 is an example of one or more data centers, which may be used in various embodiments of the present disclosure, such as data centers, as shown in FIG. 4. The ellipsis between the server racks 404 and 406 shows that the data center 402 may include any desired number of server racks, despite the fact that for clarity in FIG. 4 shows only two. Each server rack 404-406 can take part in the administration of services such as electrical service and data service to a plurality of server computers 408-414 and 416-422. Furthermore, the ellipsis indicates that the server racks 404-406 may comprise any desired number of server computers. For example, server computers 408-422 may include one or more virtual servers, computer systems (VCS) and / or one or more data storage servers. Each of the servers 408-422 may correspond to a unit dedicated resources.
[0050] FIG. 4, each server rack 404-406 displayed containing regiment switches 424-426. Shelf switches 424 and 426 may be responsible for switching digital data packets received and transmitted to the appropriate server computer systems 408-414 and 416-422. Shelf 424-426 switches can be connected to the switching matrix of the data center 428, and then to the selected boundary routers 430 that connect the data center 402 with one or more computer networks, including the Internet. Switching matrix may comprise any desired set of network components, including switches 432-438 interconnected (for clarity in FIG. 4, only four shown) of one or more types of commutation arranged in one or more levels of switching, along with routers, gateways, bridges, hubs , repeaters, firewalls, computers and their need for appropriate combinations. In at least one embodiment, switches 424-426 shelf edge router 430 and considered as part of the switch matrix 428. Switches 424-426 shelf, edge router component 430 and the switch matrix 428 are examples of network hardware 224 shown in Figure . 2.
[0051] As noted, various embodiments of the present disclosure provide an opportunity assigning different levels of authority set for various reasons. FIG. 5 illustrates a diagram illustrating an exemplary method in which the different elements involved in computing environment, may be assigned different levels of authority, at least in accordance with one embodiment of the invention. FIG. 5 shows a computing resource provider 502. As illustrated in FIG. 5, in the embodiment, the computing resource provider 502 has higher authority than the resources belonging to it, and may allocate these resources among the various powers of users. It should be noted that for purposes of explanation, consistent with the other drawings and description thereto, FIG. 5 illustrates the provider's computing resources 502, having power over the domain. However, the embodiment of the present disclosure is also applicable to other owners domain authority. For example, the owner of the office may be a government or government agency, its division or other organization or, as a rule, any entity with authority over some domain.
[0052] Returning to the illustrative examples, illustrated by FIG. 5, where computing resources provider 502 run his powers, enabling various departments entities have authority over the various sub-domains. For example, as illustrated in the figure, each of the 504 areas of failure computing resource provider submitted the relevant subdomain computing resource 502. Therefore, each zone failure ISP domain can have authority over their own resources, but not other resource failure area (although in some embodiments, the powers of some sub-domains can be used together). Therefore, according to an embodiment of the invention, rejection zone may provide the user access to computing resources in the failure zone, but no access to computing resources another failure area.
[0053] As noted above, each zone can comprise a failure of one or more services 506. Accordingly, as illustrated in FIG. 5, each service may be responsible for a subdomain corresponding denial of domain zone 504. Consequently, in the embodiment of the invention, the service can provide access to the resources available to the service, but not to other services. Each service can handle one or more members 508, and thus, each user may be responsible for a subdomain powers corresponding service 506. Consequently, in the invention, the user can provide access to the resources associated with the corresponding service, but not to the service of another user . As a specific illustrative example, consider the case in which the service is a virtual computing resource, the user can grant access (for example, shared) to their virtual computer systems, but not to the virtual computer systems of other users without their permission.
[0054] As noted, the localization of the partial powers shown in Fig. 5, is shown for illustrative purposes, and in the present disclosure, numerous embodiments of the invention are discussed. As noted above, embodiments of the present disclosure, domain authority applicable to domains is managed by the provider computing resources and subdomains, and may be determined in accordance with the particular needs and circumstances. Also, FIG. 5 is a virtual resource provider users with the smallest sub-domain powers. Thus the algorithms of the present disclosure may allow a user to divide the domains to one or more subdomains.
[0055] Some embodiments of the present invention, the disclosure relates to signatures of messages. FIG. 6 shows a diagram 600 illustrating an exemplary method in which information can be transferred between the participants in the validation message signatures, at least in accordance with one embodiment of the invention. In an embodiment, source 602 provides a key to the message sender as a key 604, and signature verifier 606. Key source computer system may be configured to provide keys at least the message sender 604, and signature verifier 606. The source may also generate key keys, using different algorithms, including some described embodiments herein, or to receive a key from another source. The message sender 604 may be a computer system configured to send a message and signature verifier signature 606 or other component, working in conjunction with the signature verifier 606. The computer messages sender system 604 may be, for example, a computer system user computing resource provider. A signature verifier 606, the computer system may be configured to receive messages and signatures, and signature analysis to verify a message is valid, as described below. Signature verifier 606 may analyze the received message and signature to decide whether the signature was generated using a valid key K. It should be noted that while FIG. 6 illustrates the power key 602 separately from the sender 604 and the signature verifier 606, the source of the keys can also be the sender of the message or the signature verifier. For example, a computer resource provider, users can submit their own keys. User keys can then be provided to the verifier signature to verify the signatures. In addition, the message receiver 604, and a signature verifier 606 can receive a different key from the key source 602. For example, posts 604 and receiver, and a signature verifier 606 may receive a key extracted from the key message 604 sent by the sender by means of various embodiments of the present disclosure Summary of the invention.
[0056] As shown in FIG. 6, the signature verifier 606 receives messages and corresponding signature of the sender of the message 604. The messages can be, for example, electronic requests access to computer service 608. Messages can, for example, encode API calls to a web service. If analysis of the signature and the message indicates that the message is authentic, then the signature verifier shall notify the service (or a component that controls access to the service) that the sender of the message can get the requested access. For example, a signature verifier may miss a received message to the service, to enable it to fulfill the request. Accordingly, the service can be a computer system serving to query, as a set of services described below. It should be noted that while various components of FIG. 6 and others, as far as possible, are described as intended for a specific action and computer systems, they may also include a plurality of computing devices such as network computing devices configured to perform the joint action.
[0057] FIG. 7 illustrates a block diagram illustrating an example process 700 for signing messages accordingly embodiment. Some or all processes 700 (or any other process described herein, and variations and / or combinations thereof) may be controlled by one or more computer systems configured using the executable instructions, and may be implemented as code (e.g. , executable instructions, one or more computer program, or one or more applications) executed together on one or more processors, hardware, or combinations thereof. The code may be stored on a computer readable medium, such as a computer program, including a set of instructions executed by one or more processors. The computer readable medium may be a carrier for permanent storage of information.
[0058] In an embodiment of the invention, process 700 includes obtaining 701 a key K. The key may be produced by any suitable method. For example, the key may be generated by a computer system performing process 700. The key can be obtained in electronic form by a computer system performing the process 700. Generally, the resulting switch may be produced by any suitable method. The key can be any key that corresponds to the requirements for use in a particular signature algorithm. For example, if the scheme hash message authentication code (HMAC) with a secure hash algorithm (SHA) -256 cryptographic hashing function information, the key may be a sequence of bytes, for example, the sequence of 64 or fewer bytes. Also can use various cryptographic hash functions such as, SHA-224, SHA-384 and SHA-512.
[0059] In an embodiment, the process also involves canonicalization message M to form message M canonicalized<sub>c</sub>. Posts canonization may include ordering information in the message in a format that allows the verifier to check whether the signature is valid messages. As a rule, many data transmission protocols convert the bits containing the message at the same time leaving messages semantically identical. As a result, two semantically identical messages can contain different sets of bits and hence result in different signature may contain. Accordingly, the canonization makes it possible to check the signature by means of a simple test. However, it should be noted that some embodiments of the present invention disclosure do not require message canonicalization. For example, if the protocol number is not used leads to semantically identical messages with different sets of bits canonicalization is not necessary and it may be omitted. Usually canonicalization can be ignored in any case where the signature can be checked without successfully handling signing messages.
[0060] In the invention, the signature is generated by computing a HMAC (K, M<sub>c</sub>), Where HMAC () is a hash message authentication code function, as described above. HMAC function have several parameters which make them very useful for the various embodiments of this disclosure. For example, HMAC function may be advantageously calculated by the computer system, thereby enabling the computing resources for other tasks. In addition, the HMAC function are resistant to Restore lished pre-image (neinvertiruemymi). For example, given the signature S = HMAC (K, M) with a key K and a message M, and practically no information about the key K. For example, by calculation of S is impossible or at least impractical to obtain a practical way of S. HMAC K functions are also resistant to the restoration of the second prototype. In other words, for a given S = HMAC (K, M) and M is impossible or at least computationally impractical to find a message M ', different from M such that S = HMAC (K, M' ). Besides the function HMAC resistant to signature falsification. For example, the forecast for the S = HMAC (K, M) , the forecast is requested N times (N - positive integer), is allowed to obtain a maximum of N pairs of signature message. In other words, if we are given a set of pairs of signed message, it is impossible or impractical by calculation to determine the key or function that would produce a valid signature for the message is not from the set.
[0061] While the HMAC function is used, in particular for the various embodiments of the invention may be used and other functions. For example, it can be any function with the above properties HMAC functions. In addition, other features that do not necessarily have all (or any) of the above properties may be used, for example, in circumstances where security is not a priority, and / or when security is important, but is supported by the use of other mechanisms. It should be noted that a variety of explanations of various embodiments of the invention represent typical values in the substituted HMAC function, but such embodiments are possible. For example, the value in the substituted HMAC function (or other function) may be different. As described above, in a particular case, one of the initial values is key. In this reference value may be obtained from the key, or otherwise, based on at least a portion of the key. As an illustrative example, the initial value may contain key information such as the ID signature scheme (for example, the version identifier), which is added to the key as a prefix and suffix. The information, which may be another key way of another example, the initial value may be information obtained by means of matching key. The initial value provided in the form of a message can also be obtained from the message. As another exemplary embodiment, considered under this invention disclosure, the signature may be the result of the HMAC function, and one or more values derived from the output value HMAC function (or other suitable function). In some embodiments, the key and the message may proceed to the function in the reverse order.
[0062] Returning to the description of FIG. 7, as soon as the signature was generated by computing the HMAC (K, Mc), the signature and the message M are provided to the receiver 708, which may be a computing device, verify signatures, or other computing device, participating in the process of verifying the signature, such as a computing device that provides an interface for transmitting messages and signatures. As with all embodiments of the invention described in detail herein, various embodiments discussed in this invention disclosure. For example, canonized message M<sub>C</sub> the receiver may be provided instead of or in addition to the message M. In addition, the provision of M signature receiver and may also include other information such as the key identifier, which can be used to identify the data repository, associating the key with the identifier. Also other information such as parameters of coding techniques, as described below, may be provided with a message M and a signature.
[0063] FIG. 8 illustrates a block diagram for explaining an example of the signature verification process 800, at least in accordance with one embodiment of the invention. Shown in FIG. 8, process 800 may be performed by the verifier, as illustrated in FIG. 2. In addition, process 800 may be performed in response to receipt of the message signature, for example in response to another computer system that should perform a process 700 FIG. 7. In the embodiment of the invention, process 800 includes obtaining 802 a key K as described above. Preparation of the key K may also include other actions in various embodiments. For example, the process 800 is used by a computer system that verifies the signature generated from a set of keys (for example, from a plurality of computing provider resource users), and getting key K may include key selection from a set of keys in a data warehouse. A data warehouse can compare different keys with the key that is sent to verify the signature. For example, each user computing resource provider may have a key identifier (or more key IDs) used to refer to the data store and carry the appropriate identification key. The key identifier may be received along with receiving a message and the signature may be determined or otherwise, for example, as a result of the registration certificate. key identifier of the recipient (for example, the verifier posts) may apply to the storage of data for decision-making, whether the key identifier of the key in the data warehouse and, if not, may then itself generate a key, for example, using the algorithms described herein for the direct or indirect receipt of key from the shared secret certificate. To do this, the recipient must have a way of getting access to the key, which is in the embodiment, data in which coded information necessary for the key of data already available at the receiver (e.g., a key derived from the shared secret certificate). These data may be provided to the recipient along with the message sender's signature, or may be otherwise available to the recipient. Thus, the recipient can program automatic generation of keys using its assigned area and the code for the current date. As a rule, it can be used a method of producing the key used to generate the signature (or another key that can be used to verify signatures in some embodiments). The receiver can also be administered by a policy of acceptable and unacceptable ways of obtaining key consideration in relation to the request or to any other known characteristics of the receiver.
[0064] In an embodiment, the signature S and the message M 804. Signature S accepted and the message M can be obtained in electronic form from a sender, such as a computing device that performs process 700 FIG. 7. The message M is then canonized 806 for the definition of M<sub>c</sub> accordingly embodiment. With the canonization of M, in various embodiments, is monitored for the possibility of verifying the signature S. Accordingly, in the embodiment of the invention includes a process 800 to generate 808 signatures S 'by calculating the HMAC (K, M<sub>from</sub>). In an embodiment, S 'is equivalent to HMAC (K, M<sub>c</sub>), Despite the fact that, in various embodiments, S 'can be obtained from HMAC (K, Mc). For the purpose of clarity, the rest of process 800 will be described in view of the fact that S '= HMAC (K, M<sub>c</sub>), But within this disclosure, numerous variations are permissible.
[0065] Accordingly, in the embodiment, a decision is made 810 whether S 'equivalent signatures obtained S. In other words, a decision is made whether the received signature is adequate, for example, due to the fact that it has been generated using the key K. Therefore in the embodiment, if 810 decides that S 'and S are not equivalent, then the signature is unverified 812. However, if S' is equivalent to S, then the signature is checked 814. depending on whether the signature is verified can be carried out appropriate actions. For example, a message was requested access to computing resources, the requested access can be rejected (at least temporarily). Likewise, if the message has requested access to computing resources and the signature has been verified, the requested access can be permitted. However, it should be noted that the execution of the respective steps may largely depend on various embodiments of the invention, depending on the cause (s) that have been received and verified signature.
[0066] As noted above, various embodiments of this disclosure are useful for a variety of computing environments. In many computing environments, it is advisable to have a centralized management for the various aspects of security administration. For example, FIG. 9 shows a diagram 900 illustrating an exemplary method for key distribution in accordance with at least one embodiment of the invention. FIG. 9, the main source of key serves one or more data stores (collectively referred to as the "data store"), containing a variety of keys used by organizations. Keys can correspond, for example, users of computing resources organizations. Each user of the user group can, for example, be assigned to one or more keys. In an embodiment of the invention, at least some of the keys correspond to the users (and / or users users) organizations. For example, in the embodiment of the invention, the organization is a provider of computing resource and each user computing resource provider meets one or more keys that enable users users to access computing resources, the managed computing resource provider. Another embodiment of the process 800 FIG. 8, according to the embodiments described above in connection with FIG. 7, it is also within the disclosure of the invention.
[0067] As shown in FIG. 9, the source key 902 gives a plurality of keys 904. The zone key areas key may be the domain of organization, in which the received key is valid. For example, referring to FIG. 2, each key area 904 may correspond to a zone of failure, such as a data center. key zones may be, but not necessarily limited geographically. For example, each zone may correspond to a key country, district or other geographically localized area. key zones may also be otherwise defined manner. For example, each zone may correspond to a key service provided by the computing resource provider, the user organization, and the like. Although it was not shown in the example, the key zones can be subzone. For example, a key area of the country can match. Inside the country, there may be many districts that correspond to the key zone subzones. Keys in such embodiments, can be transmitted subbands.
[0068] As shown in FIG. 9, the key area 904 may transmit one or more keys to the verifier 906 key areas. For example, if a key area corresponds to the data center, computing device, the data center can distribute verifiers keys for each of the plurality of services provided by the data center computing resources. Thus, verifiers can be used to verify the signatures obtained with various requests. This key source releases its computing resources on signature verification, as well as reduced requirements for latency and bandwidth, especially in cases where the source of the keys 902 is geographically removed from service, the requests to which it carries out.
[0069] The spread of the key can be done in different ways. In this embodiment, keys are distributed by the recipient secure information channels. In some embodiments, the source of the keys distributes the same keys of each key area. Also, some keys can be used in several key areas. Source keys 902 may distribute keys within acceptable key zones, several key areas, while preventing distribution of keys key zones in which the keys can not be used. Therefore, in the example of computing resources provider source key 902 can distribute the key to the user only those key areas in which the user is able to use a key, such as data centers that are used to administer the user's computing resources.
[0070] Various embodiments of the present disclosure also provides methods of dissemination of the key, which give a lot of benefits. FIG. 10 illustrates a diagram 1000 illustrating an exemplary method in a key distribution method that provides different levels of authority, in accordance with at least one embodiment of the invention. According to FIG. 10, the circuit 1000 comprises a power key 1002 key to the extension keys, directly or indirectly, to various key areas 1004 and 1006 verifiers in the same manner as described above in connection with FIG. 9. Although the diagram that, for clarity, described in 1000 using a key K and the key derived from R, embodiments of the invention described herein are also applicable in the case where the source acts as keys for dialing keys.
[0071] As shown in FIG. 10, key K is used as a base for other keys derived from C. For example, from the K key K<sub>1</sub>It transmitted and received in the first zone key (Key Zone<sub>1</sub>). In fact, the key to<sub>1</sub> (Or derived from K<sub>1</sub> keys) are acceptable in the first zone of the key, but not in another zone key, which has no K<sub>1</sub> (Or a key derived from the key K<sub>1</sub>). Likewise, each key area from among various other takes appropriate keys derived from key K. It should be noted that embodiments are possible, whereas FIG. 10 illustrates the keys derived from key K transmitted from the source key 1002 corresponding to the key area. For example, the key K can be transmitted to key areas, each key area, which takes a key K, the key K may be used to obtain one or more corresponding keys. For example, the key area 1004, labeled "Key Zone<sub>1</sub>"It can take the key and get out of it K<sub>1</sub>. Typically, various problems involved in obtaining the key and its transmission can be performed differently than illustrated in the various embodiments.
[0072] As shown in the explanatory example of Fig. 10, keys, key zones adopted in 1004, used to pick up the keys, which are then transmitted. For example, with regard to the key zone 1004 marked "Key Zone<sub>2</sub>"Key K<sub>2</sub>Obtained from the key K is used to obtain additional keys K<sub>2</sub>'And R<sub>2</sub>". Keys To<sub>2</sub>'And R<sub>2</sub>"1006 transferred to the appropriate verifiers for verifiers 1006 when verifying signatures. Therefore, in the embodiment of the invention, the verifier shall be accepted for<sub>2</sub>'Able to verify the signature generated using K<sub>2</sub>Taking into account that the verifier, which is not to take<sub>2</sub>'May not be able to verify the signature. advantages can be obtained in the transmission method key are explained using FIG. 9 and 10 (or respective variants). For example, by transmitting the key to several verifiers in several locations, instead of one or more centralized verifiers, achieved lower latency. In addition, referring to FIG. 10, by transmitting the received keys to other devices, which in turn receive additional keys, it is possible to distribute computation across multiple devices in multiple locations; thereby achieving a more rapid receipt of key and increase fault tolerance.
[0073] Keys can be done in many ways. FIG. 11 is a block diagram illustrating an example of the process of obtaining a key 1100, at least according to one embodiment of the invention. In the implementation of the invention the process 1100 includes obtaining the key K 1002<sub>i</sub>As described above. The key K<sub>i</sub> It may be any appropriate key, such as described above. Also, the key K<sub>i</sub> It may be, but not necessarily derived from another key, such as resulting from a process 1100 or another process. After obtaining the key K<sub>i</sub> of K<sub>i</sub> made a new key. In the illustrative example in FIG. 11 new key K K<sub>i + 1 </sub>calculated as (or is based on at least a portion of) HMAC (K<sub>i</sub>, R<sub>i + 1</sub>) Wherein R<sub>i + 1</sub> is information identifying one or more key limitations K<sub>i + 1</sub>. R<sub>i + 1</sub> can be, for example, the bit sequence encoding the information displayed, which uses key K<sub>i + 1</sub>. For example, R<sub>i + 1</sub> may encode a key area can be used where the key K<sub>i + 1</sub>. Restrictions may be based at least in part on geographic location, time, user identity, service and the like. Example limitations provided in the example described below.
[0074] In addition, as described in more detail below, the process 1100 to obtain the key can be used repeatedly. For example, a key generated by a process 1100 (or the corresponding embodiments) may be used to generate another key using the same or other restriction. Using the terminology as depicted in FIG, R<sub>i + 1</sub> can be, for example, a series of bits that encode the information displayed can be used where the key K<sub>i + 1</sub>. K<sub>i + 1</sub> could be the key K<sub>i</sub> for the next process cycle. For example, if process 1100 used for generating the key based on a geographical restriction generated key can be used to generate a key limitation based on date. Such a process can be used repeatedly, using a plurality of receiving key constraints. As more fully described below, using a number of restrictions for the key, one or more policy verifier can establish simultaneous signature verification. As a brief illustrative example, as part of the signature verification, the verifier can determine the expected signature from the restriction, such as coding the current date. If the signature has been provided so that generated at different dates, the signature verification is not passed, according to an embodiment of the invention. Typically, if the usage does not comply with the signature constraints used for the key, the signature verification can not be passed, in accordance with various embodiments of the invention.
[0075] FIG. 12 is a block diagram 1200 illustrating an illustrative example of obtaining key using multiple constraints, at least in accordance with one embodiment of the invention. FIG. 12 illustrates the preparation of a key using multiple constraints. In this example, the key and limiting by date used to obtain the date key (Kdaty, in the figure). The figure shows that the data is encoded as 20110715, corresponding to July 15, 2011, although the date may be encoded in various ways, and generally no information can be coded in a manner different from that shown in FIG. The key date is used with the District of limitation for the county key Kokruga. In this example, the county is coded with the help of the county identifier «USA-zone-1", which may correspond to one or several districts of the United States. Key Kokruga used with restriction on the service to get the key, Ksluzhby. In this example, the service is a virtual computer system, encoded by its abbreviation VCS. Key Ksluzhby used to request an identifier for a signing key, ie the key used to sign requests to the service. In this example, "vcs_zapros", which may correspond to a particular query type, which can be obtained VCS service. For example, "vcs_zapros" may correspond to a configuration request, a stop, or otherwise modify the virtual computer system. Signing key used to generate a signature that can be sent requests. The signature may be generated in any suitable manner similar to that described above.
[0076] As illustrated in FIG. 12, the request may be canonized in the form of M<sub>from</sub>Which is the initial value for generating the HMAC function signatures. Of course, various embodiments may be used, including options which canonicalization is not a requirement, and with functions other than HMAC, in accordance with various implementations of the invention. In addition, FIG. 12 illustrates a particular example of obtaining the signature in accordance with an embodiment of the invention. However, to obtain the signature can be used more or fewer restrictions, and restrictions can be used in a manner different from that specified. Moreover, despite the fact that Fig. 12 illustrates the preparation signature algorithms may be used for other objects that can not be treated as a signature in all applications. For example, as shown in FIG. 12 (and elsewhere) algorithms can typically be used for the key.
[0077] FIG. 13 is an illustrative example of a function 1300 for receiving a signature, in accordance with at least one embodiment of the invention. As illustrated in FIG. 13, the signature is computed as:
HMAC (HMAC (HMAC (HMAC (HMAC (K, date), DC), Service) protocol), Mc).
In this example, K is the key, "date" is a date coded, "district" is a coded identifier County, "service" is a coded ID service, "protocol" corresponds to a particular coded communication protocol, and M<sub>from</sub> It is canonized message. Therefore, as illustrated in FIG. 13, the signature is computed by calculating the multiple of the same HMAC function, each time with a different limit input values for HMAC function.
Signing key in this example is:
HMAC (HMAC (HMAC (HMAC (K, date), DC), Service) protocol), which is obtained by repeated use HMAC function, each time with a different constraint.
[0078] In the example of FIG. 13, can define different restrictions domain and designated intersection domain that defines the way in which the generated signature signing key, which would be suitable. In this particular example, the signature generated with signing key described using FIG. 13, which would be suitable for a specific date, a specific district for a particular service using a specific protocol. Consequently, if the request is signed using a signing key, but with a date different from the date specified initial value signature key, the signature to the request can be considered as anecdotal, even if the request is made for a particular service in a particular district.
[0079] Like other embodiments of the invention described herein addresses various embodiments within this invention disclosure. For example, FIG. 13 illustrates the repeated use of HMAC function. A plurality of functions can be used to determine a signature, and in some implementations of the invention, HMAC function is not used at each stage of obtaining signatures. Also, as noted, in various embodiments, various constraints may be used and different number of limitations.
[0080] Preparation of the key may be performed in various ways in accordance with various embodiments of the invention. For example, a separate computing device may compute signing key, in accordance with an embodiment of the invention. In other embodiments, multiple computing devices may share calculate signing key. As a specific illustrative example, the corresponding FIG. 13, a computer can calculate
Kokruga = HMAC (HMAC (K, date), DC)
and another computer can compute
Signing Klyuch = HMAC (Kokruga, service).
[0081] As another example, a separate computer system can perform different levels of calculating signature key. Referring to the example in the previous paragraph, instead of a single computer, calculating Kokruga one computer can compute
Kdaty = HMAC (K, date)
and another computer can compute
Kokruga = HMAC (Kdaty, DC).
FIG. 14 illustrates an example of how to obtain multiple key may be performed and used in accordance with at least one embodiment of the invention. In particular, FIG. 14 illustrates an example of a circuit 1400 that displays the elements of the set of distributed computing systems, computing a shared signing key (or another key, in various other embodiments). As shown in FIG. 14, each element of the group is a key provider of computer system 1402 that generates the key and provides the generated key to other computer systems. For example, the provider key labeled KlyuchProvaydera<sub>1</sub>It receives key K (from another source, or itself generate a key), and uses the key and limiting marked as R<sub>1</sub>To generate a key K<sub>1</sub>. KlyuchProvaydera<sub>1</sub> transmits key K<sub>1</sub> KlyuchuProvaydera<sub>2</sub>Which uses K<sub>2</sub> Another limitation, R<sub>2</sub>To generate another key K<sub>2</sub>. key Provider<sub>2</sub> transmits key K<sub>2</sub>key Provider<sub>3</sub>Which uses K<sub>3</sub> Another limitation, R<sub>3</sub>To generate another key K<sub>3</sub>. Depending on how many there are in a particular embodiment, the key provider,
These processes may continue as long as KlyuchProvaydera<sub>N-1</sub> transmits key K<sub>N-1</sub> key provider<sub>N</sub>Which uses K<sub>N-1</sub> Another limitation, R<sub>N</sub>To generate another signature key, K<sub>N</sub>. The key K<sub>N</sub> is then transmitted to the computer system 1404. The verification key, or any key K (s) derived from K (generally referred to as K<sub>i</sub> in the figure), can also be transferred signer computer system 1406, such as key exchange algorithm.
[0082] Follow the computer system 1406 may also, in various embodiments, to generate K<sub>N</sub> itself if, for example, restrictions R<sub>1</sub>-R<sub>N</sub> provided signatory system, and / or made public. In addition, the signing computer system 1406 itself can perform only a part of the process of obtaining K<sub>N</sub> in various embodiments of the invention. For example, a signing system may receive (perhaps corresponding key provider computer system) K<sub>i</sub>For some integer i is less than N and limitations of R<sub>i + 1</sub> to R<sub>N</sub>. Signs the system then uses K<sub>i</sub> and limitations on R<sub>i + 1</sub> to R<sub>N</sub> to generate a signature key, K<sub>N</sub>. Also contemplated are other embodiments within the scope of the present disclosure of the invention.
[0083] signed by the computer system 1406 may use the key K<sub>N</sub> for the signature of messages scanned verifier 1404. For example, as explained signing system 1406 calculates the signature S = HMAC (K<sub>N</sub>, M<sub>C</sub>), Where M<sub>C</sub> It is canonized version of M, which is also sent to the verifier. Due to the fact that the verifier has K<sub>N</sub>Verifier may canonize own message M and to calculate the HMAC (K<sub>N</sub>, M<sub>FROM</sub>) To decide whether the result corresponds to the calculation adopted by the signature S.
[0084] It should be noted that the various embodiments of the processes shown in FIG. 14, and the other processes described herein, despite the fact that the displays involved in reusing HMAC function can be used to produce many other function key. For example, at different times may have different types of functions a message authentication code (MAC) for the key. For example, the value of the MAC function of one type can be used as a base for the MAC functions of another type. Typically, in other types of functions instead of and / or as an addition to the functions HMAC and, in various embodiments of the invention may be the process of obtaining a key used, there is no need to use the same function several times for the key, but each time a function is needed, various functions may be used.
[0085] FIG. 15 is a diagram 1500 illustrating an exemplary method in which the keys can be obtained by multiple constraints, in accordance with at least one embodiment of the invention. The example illustrated by FIG. 15 refers to the users, such as user provider computing resources. However, as noted, the algorithms described herein, including algorithms described in connection with FIG. 15 can be used in many other situations.
[0086] As shown, the user key, K<sub>User</sub>Is part of a set of long-term user keys, each key can be used by the user for a certain period of time, for example until the user designated key update the new key, or otherwise change the key. The keys can also be used by one or more users for an indefinite period of time. Key user, K<sub>User</sub>, Is used to produce one or more key county in the manner described above. For example, as illustrated in FIG. 15, two key district can be generated, for example, by calculating HMAC (K<sub>User</sub>, USA-E-1), and HMAC (K<sub>User</sub>, USA-N-1), where USA-E-1 and USA-N-1 are the identifiers of the respective districts. Similarly, counties keys may be used to date key, the validity of which may be limited by date, the date used for coding keys. Each choice keys can be used to obtain service keys, for example, the method described above.
[0087] Thus, in various embodiments of the invention, the date of the keys can be used with the corresponding services only on the day and in the area used for the encryption keys. New keys can be generated to date each day, taking into consideration that the county keys and long keys the user can be generated less frequently. Preparation key using multiple constraints illustrated eg in Fig. 15 and elsewhere in the present disclosure of the essence of the invention provides numerous advantages. For example, receiving key using the method described in connection with FIG. 15, if the signing key is compromised (eg maliciously obtained by a third party), protection limited to the specific vulnerability of the district, and a specific date using a particular service. Other services will continue to be unaffected. These benefits are valid for other ways in which the keys can be obtained.
[0088] FIG. 16, for example, a circuit 1006 illustrating another exemplary method by which the keys can be prepared in accordance with at least one embodiment of the invention. FIG. 16 illustrates the concept, in a sense, similar to the one shown in FIG. 16. In this FIG. 16 long-term user keys are used to get the date keys. Keys are used to obtain the date of the county key. County keys used for key services. Keys may be performed in accordance with various implementations described herein.
[0089] FIG. 17 shows a circuit 1700 illustrating another exemplary method by which the keys can be prepared in accordance with at least one embodiment of the invention. FIG. 17 long-term user keys are used for the month of keys. The keys month are used to obtain keys County. Keys used for the county receipt of keys. Keys are used to obtain the date of service keys. Preparation of various keys can be performed by a method consistent with that described above.
[0090] As described above, various algorithms of the present disclosure of the invention provide a new way to generate sessions. Sessions can be a period of time for which a collection of one or more actions, where the end (or other termination) session is the basis for prohibiting the aggregate of one or more actions. FIG. 18 is a block diagram illustrating an example of the session initiation process 1800, in accordance with at least one embodiment of the invention. Process 1800 may be performed by any suitable computing device or jointly any suitable set of computing devices. For example, process 1800 may be performed by the client computing device user resource provider. As another example, in another embodiment of the invention related to Figs. 3, one of the service areas of failure can be a session-service and one or more computing devices, takes part in the provision of services, may perform process 1800.
[0091] Returning to FIG. 18, in the embodiment, the process 1800 includes receiving 1802 a key K. The key K may be any appropriate key, such as key obtained by using other keys, such as the method described above. For example, the key K can be transmitted to a computing device involved in implementation of the process 1800. At some point in time (for example, immediately after receipt of the key K, as shown in the figure), in the embodiment, session initiation request 1804. The request may be accepted may be an electronic request, such as described above. Besides, in the embodiment, the request is signed and verified using the algorithms of the disclosure of the invention. Also, the request may be a unique request, depending on the particular computing environment used to implement the process 1800. For example, if process 1800 executed by the client device (eg, user device, user computing resource provider) for the generation of the session, the session initiation request can be accepted client module device.
[0092] In the invention, the session parameters are determined 1806. The parameters of the session may be information that indicates one or more of the generated session limits. Typical parameters include, but are not limited to, duration of session identifiers valid users of the generated session key, one or more services, which generated an acceptable session key, restrictions on the actions performed by using a session key, any of the limitations described above, and others. The parameters may be encoded in an electronic form, in accordance with predetermined format requirements to monitor the production of coherent calculations involved in obtaining the session key. For example, dates can be queried for encoding in YYYYMMDD format. Other parameters may have its own format requirements. Moreover, the determination session parameters can be made in various ways. For example, the parameters may be the default parameters for the session, such as session key is useful only for the range of action for the initiator predefined session initiation request for a predetermined period of time (e.g., twenty-four hour period). As another example, the parameters can be provided as part of the received request or otherwise therewith. For example, the parameters can be generated in accordance with the original user data from the requestor and coded respectively predetermined scheme.
[0093] In an embodiment, after the parameters have been determined, they are used to compute 1808 the session key, K<sub>S</sub>. Calculation of the session key K<sub>S </sub>It can be made in many ways. For example, in one embodiment, the session key K<sub>S</sub> It can be calculated as (or otherwise, based on at least a portion)
HMAC (K, Parametry_Seansa)
where Parametry_Seansa are coded parameters which have been defined 1806. Parametry_Seansa can be encoded in a predetermined manner which ensures consistency of the calculated data. The session key K<sub>S</sub> It can also be calculated by other methods, such as described below in FIG. 19.
[0094] Once the session key K<sub>S</sub> calculated 1808 in the embodiment of the invention, the session key K<sub>S</sub> available for use. Providing a session key may be performed in various ways in various embodiments of the invention. For example, the session key may be provided to the module requester to provide requesters the possibility to sign the message session key. The session key can also be provided by another network device, another device to provide an opportunity to sign the message session key. For example, the session key can also be provided delegated object for which the session is initiated. For example, the requester may have specified delegating object in its composition or otherwise together with a request to initiate a session. The session key can also be provided in electronic form in accordance with the information provided by the requester (i.e. delegatoru), for example, via e-mail or other electronic address.
[0095] As noted above, FIG. 19 shows an example illustrative process 1900 that may be used to generate the signature accordingly embodiment. Process 1900 may be performed by one or more computing device, such as one or more of computing device 1800 performs the process described above in connection with FIG. 18. Process 1900, as shown in FIG. 19 comprises receiving session parameters, such as those described above. Since the session parameters that have obtained in the embodiment, the intermediate key, K<sub>i + 1</sub> 1904 is calculated as:
K<sub>i + 1</sub>= HMAC (K<sub>i</sub>, P<sub>i</sub>)
where K<sub>i</sub> may be the key to the description of FIG. 18 for the first calculation of K<sub>i + 1</sub>And P<sub>i</sub> is the i-th session parameter settings. session parameters can be arranged according to a predetermined arrangement for checking the consistency of computing the signature key.
[0096] In an embodiment, a decision 1906 whether additional parameters are used to generate the session key. If there are additional parameters in the embodiment, the index i is increased by one and 1908 K<sub>i + 1</sub> again calculated 1904. If the decision is made that there are no additional parameters, whereas K<sub>S</sub> selected 1910 to the value of K<sub>i + 1</sub>.
[0097] FIG. 20 is a block diagram illustrating an example process 2000 for access to one or more computational resources for the session in accordance with at least one embodiment of the invention. It should be noted that while FIG. 20 illustrates a process 2000 to access one or more computing resources, as in the case of other herein described processes, the process 2000 can be modified to any situation in which the signature used processes. Process 2000 may be performed by user computer system requesting access to one or more of the computing resource, for example, client computer system illustrated FIG. 1, and / or user computer system as described elsewhere herein. In an embodiment, the process 2000 includes obtaining a session key K<sub>S</sub>. The session key may be produced by any suitable method, such as e-mail. The session key may be derived from a computer system object delegating access to one or more computing resources, or another computer system, such as a computer system serving together with one or more of a computer system that performs a process to generate K<sub>S</sub>.
[0098] In an embodiment, R is generated request 2004. The request message R can be, for example, as described above. Request then canonicalization R 2006 in an embodiment of the invention, and the signature is calculated 2008 from the canonicalized message, such as the calculation of the signature (or otherwise, at least a portion of) HMAC (K<sub>S</sub>, R<sub>C</sub>). Immediately after generation of the signature, the signature S and R provides query 2010. For example, as described above, the signature S and the request R may be provided in the form of electronic computer system interface involved in managing requests and verifying signatures. Signature S and query R, as in the case with the signatures and messages in general, may be provided together in a single communication channel, in separate communication channels or shared by several communication channels. Together with the signature S and R may also request other information is available. For example, it can be provided identification information to allow the verifier opportunity to choose the correct key to generate a signature, which will be verified signature adopted. Identification can be carried out, for example, a key identifier to be used when generating the signature comparison. It may also be provided and used other information required in various embodiments of the invention.
[0099] FIG. 21 is a block diagram illustrating an example process 2100 a decision whether to grant the requested access to one or more computing resources, in accordance with at least one embodiment of the invention. As illustrated in FIG. 12, the process 2100 includes the 2102 signing key K<sub>S</sub>. As in other presentation herein of obtaining a signing key, signing key may be obtained by various methods, for example, obtaining a signing key from another source, removing a signing key from the memory, calculating a signing key from available information, and the like.
[0100] In the invention, the received request R canonized the form R<sub>C</sub>For example, the method described above. It should be noted that embodiments are possible, as is the case with other processes described herein. For example, a computer system performs process variant 2100 (or other process) can only take canonicalized message canonicalization and may be performed by another computing device. Returning to the description of FIG. 21, the signature S 'is computed as (or otherwise, at least a portion of) HMAC (K<sub>S</sub>, R<sub>C</sub>). Calculated signing key S 'is compared with the 2110 approved the signature S to determine whether the two signatures equivalent. If it is determined that the two are not equivalent to the signature, the session is defined as a 2112 unacknowledged and appropriate action, such as the refusal to the request can be made. If the two signatures are determined to be equivalent, the session is validated in 2114, and can be taken the appropriate action, such as providing access to one or more computing resources.
[0101] The algorithms of the present disclosure, the invention may be used to provide delegation of authority. FIG. 22 is a block diagram showing an illustrative example of a process 2200 for delegating authority, at least in accordance with one embodiment of the invention. Process 2200 may be performed by a computing device, such as computing device user, attempts to delegate access to one or more computing resources, computing device or computing resource provider, or any suitable device. As illustrated in FIG. 22, process 2200 includes receiving 2202 the session key K<sub>si</sub>. The session key K<sub>si</sub> may be prepared by any suitable method, for example, a method in which the above described keys as received. In addition, the session key may be a key generated as part of the delegate access to one or more computing resource. For example, the session key can be generated by performing the process in 2200 or the relevant option.
[0102] In the invention, the session parameters are determined 2204. session parameters may be determined in any suitable manner, such as described above in connection with FIG. 18. session parameters defined in 2204, can be generated new session key K<sub>s (i + 1)</sub>For example, as described above, comprising, as described above in connection with FIG. 19. The generated once,
a new session may be granted for delegation. For example, the session key may be sent in an email delegate object. The session key may be directly or indirectly available to the delegation object. For example, the session key may be given delegatoru delegator and may be responsible for providing the session key to one or more objects delegation. Object delegation may also be provided and other information. For example, the object of delegation of session parameters can be provided to allow the project to provide the delegation with the signatures of session parameters, thus allowing the recipient (for example, the verifier) session parameters to generate the expected signature to check whether the given valid signatures. For example, the recipient can use the parameters to generate a session key from a secret or a certificate obtained through this key, and use a session key to generate a signature for the canonized version of the corresponding sign messages. Typically, parameters can be made available to the recipient signature in any suitable manner to enable the recipient to verify the signature on the message and delegated object does not necessarily need access to parameters independent of the delegating object.
[0103] FIG. 23, for example, shows a block diagram 2300 showing how many times can be delegated privileges. Delegator 2302 may wish to allow one or more access privilege delegation delegate object 2304. Object 2304, however, in this example, may wish to provide one or more delegated privileges to another object 2306. Therefore, in this example, the object may become delegirovaniya2304 delegatorom. Similarly, delegating 2306 sites may wish to provide access to another object delegate, and the delegation of the object may want to allow access to the other delegate object, and so on up until eventually one or more privileges allowed to still another aspect of delegation 2308.
[0104] Therefore, in this example, initial delegator 2302 sends a request seansoorientirovannoy delegating authentication service 2310, which may be the service area of failure as described above. In response, in the embodiment, the authentication service seansoorientirovannaya generates and provides delegatoru session key 2302, for example, described above in connection with FIG. 22. Delegator in 2302 then, in the embodiment of the invention provides a session key, they passed by the authentication service seansoorientirovannoy 2310 delegatoru 2304. delegate object 2304 may provide the session key to another aspect of delegating 2306. In the same way the delegation object in 2306 could get a scope of privileges obtained delegate object 2304 which could be the same as the level of privileges granted delegate object 2306.
[0105] Thus, as shown in FIG. 23, 2304 the delegation of the object can send the request to the delegation seansoorientirovannoy authentication service in 2310 and take another session key that has been generated seansoorientirovannoy authentication service 2310 in response to a delegation request. delegate object 2304 may provide a session key next item 2306. The next delegation delegating object 2306 may provide the session key to another delegate object, or as described above, may also send a request seansoorientirovannoy delegating authentication service 2310, which would then generate a session key, and provide key session object 2306 delegating to the requesting delegation. As illustrated in FIG. 23, it can continue on, and one or more delegate object may attempt to use the key that they took.
[0106] In this particular example, delegate object 2308 provides session key computing resource 2312 with the request. As indicated above, the request may comprise the session key while the session key may be provided separately from the request. Computing resource 2312 may be any of the computing resources described above or any desired computing resource. policy management service 2314 may include a verifier, for example, as described above, and the query may check the computing resource demands on the reliability. Computer resource management service 2312 and 2314 the policy may also be a single component, despite the fact that shown in FIG. 23 separately. Also, despite the fact that Fig. 23 illustrates one seansoorientirovannuyu authentication service 2310 is used to generate session keys, various implementations of the invention may use different seansoorientirovannye authentication service.
[0107] As noted above, in addition to the illustrative examples provided herein, many variations are considered, within the scope of this invention disclosure. FIG. 24 is a diagram 2400 showing illustrative example manner in which the keys can be prepared by keys of a plurality of sources, respectively, an embodiment of the invention. FIG. 23 user key K<sub>User</sub> It is the key of a set of user keys, administered computing resource provider. As in the case of the embodiments of the invention described above, although FIG. 23 is regarded as a good example, in connection with a computing resource provider, addresses and other embodiments that fall within this disclosure of the invention.
[0108] FIG. 24 is administered to a set of key sources, where various key sources correspond to different domains of authority. Each authentication key received from the user key K<sub>User</sub>May be, for example, transferred to different zones of failure as described above. failure zones may be, for example, data centers under a different political jurisdiction. It should be noted that embodiments are possible, whereas FIG. 24 illustrates a distributed authorization key derived from a single user to the key<sub>User</sub>. For example, the distributed authorization keys may be prepared independently. As another example, one or more distributed authorization keys can be derived from the shared key, one or more other keys can be derived from a different common key and so forth.
[0109] In an embodiment of the invention, it is possible to combine a lot of authority in the authorization for access to one or more computing resources. For example, as shown in FIG. 24, to obtain other keys may be used subsets distributed authorization keys. For example, as shown in FIG. 23, to obtain two combined authorization key uses an authorization key, and marked Avt1 Avt2. For combined authorization key, in the embodiment of the invention, HMAC value calculated (f (Avt1, Avt2), R), where R is one of the constraints, for example, as described above. For example, f is a function of the distributed authorization keys and may have more than two dimensions. For example, there are three distributed authorization key Avt1, Avt2 and Avt3 as shown in FIG. 23, the argument of f (Avt1, Avt2, Avt3) for calculating a combined authentication key as (or otherwise, based at least partially on) HMAC (f (Avt1, Avt2, Avt3), R).
[0110] Numerous variants of keys from different sources are considered as part of this invention disclosure. For example, the source can generate (or have already generated) key (K<sub>spec</sub>), Using various embodiments of the present disclosure of the invention. Each source K<sub>spec</sub> It may correspond to the partial derivative of the key, which may be public coding (decoding or otherwise available to the message sender, and a signature verifier) limits its use to generate K<sub>spec</sub>. For example, the private key can be derived
(K1 / 20110810 / usa-east-1 / DDS, K2 / 20110810 / org_name / jp1 / DDS), where each sequence between slashes is a limitation. This encoding information is referred to as "key path". The X can be a more general example, a private key derivative<sub>1</sub>/.../X<sub>n</sub>Where each value of X<sub>i</sub> (For i between 1 and n) corresponds to the parameter, for example, the option described above. The partial derivative key from suitable sources can be encoded as an n-line, regarded as a derivative of a key. For example, directly above n-row can be (spec<sub>1</sub>, spec<sub>2</sub>, ..., Spec<sub>n</sub>), Where each entry is a key way for the corresponding K<sub>spec</sub>. It should be noted that the derived keys (and / or key path) encodes accurate key using (complete restriction between all authorized keys) so that the owner of the key is authorized by the signature generation / key. In addition, the partial key selected is available as hosts posts and verifiers signature, random distribution used to generate keys and signatures parameters possible since, for example, the message sender receives information defining the order of the parameters that were used to generating a signature key and can thus generate a signature key and a message respectively.
[0111] The value for the function HMAC (Kspec, key-derivative) may then be obtained or calculated for each of the sources of suitable, i.e., sources must be generated for each key. This quantity can be computed by the client, which received signing key for signing messages, or may be calculated by another device, and subsequently provided to the client, in various embodiments. Each of these variables may be considered as a special key for the purpose of the following discussion. The semantics of each of these private keys, in the embodiment of the invention is that they are valid only when combined with the structure mentioned below (and some exemplary structures mentioned below), and, when combined, form the intersection specifications derivatives encoded key.
[0112] In order to generate a signing key for signing messages, the value for
K<sub>S</sub> = HMAC (chastn_klyuch<sub>1</sub>+ ... + Chastn_klyuch<sub>n</sub>Key-derivative)
where "+" can refer to any associative operation with the private keys that surround the symbol in the formula. "+" Symbol may be, for example, the operation excluding OR (XOR) of the bits containing the private key. "+" Symbol can also refer to any suitable operation or function.
[0113] To verify the signature used for signing the message, the verifier can get every private key, combine private keys, as described above, to form a signing key to sign the received message and compare the result with the expected result for signature verification, for example, as described above.
[0114] Exemplary embodiments of the disclosure, the invention may be described in the following paragraphs:
Item 1. A computer-implemented method for providing services, comprising:
running one or more computer systems, which operate on the basis of commands,
receiving from the party authenticating electronic encoded information comprising message, the message signature and a set of one or more restrictions on keys derived from the shared by side authentication secret certificate, the signature may be determined by applying a hash message authentication code to the message, secret certificate and a set of one or more restrictions, and may be undetectable with only a hash message authentication code without a set of one or more constraints;
receiving key generated at least partly by means of at least a subset of the set of one or more constraints;
calculating by means of one or more computer systems, a hash value of message authentication code by at least entering into a hash message authentication code function:
first input value based at least in part on the received key, and
second input value based at least in part on a set of one or more constraints;
determining whether the signature is valid, by one or more computer systems and at least partially based on the computed values; and
providing access to one or more of the computing resources in the case of determining that the signature is valid.
Item 2. The computer-implemented method of claim 1, wherein:
the message contains a request for access to one or more computational resources;
the method further comprises determining whether the set of points of one or more constraints that the request should be satisfied; and
providing access to one or more computing resources is possible by determining that constraints indicate that the request should be granted.
Item 3. The computer-implemented method of claim 2, wherein the encoded information comprising a set of one or more constraints are encoded using a specific document, wherein the step of determining whether a set of constraints indicates that the request should be granted, It includes a document analysis, based on the context in which the request was received.
Item 4. The computer-implemented method of claim 1, wherein.:
the message contains a request for access to a computing resource from said one or more computational resources;
encoded information comprising a set of one or more constraints includes information indicating a computing resource; and
providing access to one or more computing resources includes providing access to a computing resource if the computing resource coincides with said computing resource.
Item 5. The computer-implemented method of claim 1, wherein.:
encoded information comprising a set of one or more constraints corresponds to the period of time during which a message is valid; and
determining whether the signature is valid, based at least in part on whether the message was granted for an appropriate time period.
Item 6. The computer-implemented method of claim 1, wherein.:
encoded information comprising a set of one or more constraints corresponds limitation based at least in part on the location; and
determining whether the signature is valid, based at least in part on the fact whether the same location, at least one of the one or more computer systems, with the location.
Item 7. The computer-implemented method for providing services, comprising:
running one or more computer systems, which operate on the basis of commands,
receive electronic encoded information comprising (i) a message, (ii) a first signature of the message and (iii) a set of one or more parameters, wherein the first signature is generated at least in part on (i) messages, (ii) the secret certificate and (iii) a set of one or more parameters, and also the first signature is indeterminate if only the secret message and the certificate, but not a set of one or more parameters;
preparing a second certificate, at least partly based on a secret certificate and at least a subset of the set of one or more parameters;
generating a second signature, at least in part on a certificate obtained by the second;
determining whether the first signature matches the second signature; and
providing access to one or more computer resources, when the second signature is generated coincides with the first signature.
Item 8. The computer-implemented method of claim 7, wherein obtaining the second certificate includes certificate input function in secret and at least a subset of the set of one or more parameters.
Item 9. A computer-implemented method according to claim. 8, in which the function is a symmetric message authentication function.
Item 10. A computer-implemented method claim. 9, wherein the symmetric message authentication function is a hash function.
Item 11. A computer-implemented method of claim 9, wherein the input function to the secret certificate and at least a subset of the one or more parameters is performed as part of the forming operation message authentication hash (HMAC).
Item 12. A computer-implemented method according to claim. 8, wherein generating the second signature includes the input values into output function and function parameter from the set of one or more parameters.
Item 13. A computer-implemented method of claim 7, in which coded information comprising one or more parameters comprises the encoded electronic document containing a set of one or more parameters.
. Item 14. A computer-implemented method of claim 8, wherein:
generating a second signature based at least partially on the key;
a set of one or more parameters includes one or more constraints on the use of the key and
providing access to one or more computational resources is performed in accordance with one or more constraints.
Item 15. A computer-implemented method of claim 14 wherein the key is based at least partly on the result of the secret certificate input function.
Item 16. Permanent computer-readable media, which stores instructions that, when executed by a computer system providing a computer system implementing at least:
preparing an intermediate key based on at least the secret certificate and one or more parameters that define the use of an intermediate key;
applying, at least in part on the received intermediate key, at least part of the process of signature generation, which provides a message signature, the process of generating the signature is configured so that the signature is not detected by generating process signature computing device having a message, secret certificate and signature, but does not contain one or more constraints; and
of messages, signatures and the one or more parameters of the other computer system, configured to analyze the signature of at least partially based on one or more parameters and messages to determine whether the signature is valid.
Item 17. Permanent computer-readable medium of claim. 16 wherein the one or more parameters of one or more encoded restrictions on the use of the intermediate key, which are implemented at least partially above another computer system.
Item 18. Permanent computer-readable data carrier according to claim. 16 wherein the one or more constraints correspond to at least the period of time during which the intermediate key can be used, the location where the intermediate-key may be used, or one or more services, to access the key intermediate that may be used.
Item 19. Permanent computer-readable data carrier according to claim. 16 wherein the instructions when the computer system allows the computer system to generate a signature of a computer system without access to the secret certificate.
Item 20. Permanent computer-readable medium of claim. 19 wherein the presence of a set of one or more parameters determined using the signature generation process signature using the shared secret key certificate or an intermediate.
Item 21. Permanent computer-readable data carrier according to claim. 19 wherein receiving the intermediate key includes the algorithm provides that at least one output hash value is entered using at least one of the parameters to a hash -function.
Item 22. A computer system comprising:
one or more processors and
a memory containing the commands that allow the implementation of a computer system when performing one or more processors of a computer system, at least:
receiving one or more electronic data that together provide encoding messages and message signature of one or more parameters, and the signature generated at least partly based on a secret certificate and one or more parameters;
assay to determine whether the signature of at least partially based on one or more parameters, intermediate certificate obtained at least on the basis of a fragment of one or more parameters and the secret certificate, but excluding the secret certificate messages and signatures; and
performing one or more actions that can occur when determining that the signature is valid.
. Paragraph 23. The computer system of claim 22, wherein:
memory and one or more processors are part of a first server system, located in the first geographical location;
second computer system comprises a server system, placed in a second geographic location, wherein the second server system is configured to generate different signatures for at least partly based on a secret certificate;
the first server system, and the second server system does not contain the secret of the certificate;
message and signature analysis includes the input into a function, at least a fragment of one or more parameters and intermediate certificate; and
a first server system, and the second server system does not contain any information by which the same signature may be generated using a function based on the message.
Paragraph 24. The computer system of claim 22, wherein.:
computer system corresponds to a specific service; and
said one or more actions include the provision of access to this service.
Paragraph 25. The computer system of claim. 24 wherein one or more of the parameters limiting the use of an intermediate certificate in the implementation of access to the service.
. Paragraph 26. The computer system of claim 22, wherein:
message and signature analysis includes applying a hash function to an intermediate certificate;
one or more parameters include a plurality of intermediate restrictions on the use of the certificate; and
wherein the computer system is configured to enforce such restrictions.
. Paragraph 27. The computer system of claim 22, wherein:
message and signature analysis includes applying a hash function to the key, which is obtained based on a secret certificate; and
command when the one or more processors of a computer system implementation further provide a computer system receiving the received key authentication key from the computer system.
Paragraph 28. The computer system of claim. 27, in which the team, further ensuring the implementation of the computer system of obtaining the key from a computer key authentication system, ensure the implementation of the computer system of obtaining the key from a computer key authorization system until receiving the message.
Paragraph 29. The computer system of claim. 22 wherein the intermediate certificate determined by another computer system other than said computer system.
[0115] Also can be made different embodiments of the invention in a wide range of operating environments, which in some cases may include one or more user computers, the computing device or processing devices that can be used for any number of applications. The user or client devices may include any number of personal computers of general application, such as desktop or laptop computers running standard operating systems as well as cellular, wireless and mobile devices running the mobile software and are able to support a number of network protocols and message protocols. Such systems may also include a number of workstations, working with all types of commercially available operating systems, and other well-known applications for purposes such as the development and management of databases. These devices may also include other electronic devices such as terminals, thin clients, gaming systems and other devices that can communicate through a network.
[0116] Most embodiments of the invention utilize at least one network, which may be well known to those skilled in the art, to maintain the exchange of data with any of the variants of commercially-available protocols, e.g., TCP / IP, OSI, FTP, UPnP, NFS, CIFS, and AppleTalk. The network may be, for example, computer local area network, wide area network, a virtual overlay network, networks, internet, intranet, extranet, a switched public telephone network, an infrared network, a wireless network and any suitable combination thereof.
[0117] In embodiments using a web server, a web server can perform any of a number of server applications or middle managers, including HTTP servers, FTP servers, CGI servers, data servers, Java servers and business application servers. The server (s) may also be a program execution function, or scripts in response to a request from a user device, such as performing one or more Web applications that can be implemented, written in any programming language, such as one or more scripts or programs , Java<sup>®</sup>, C, C #, or C ++, or any language for writing scripts, such as Perl, Python, or the TCL, as well as the appropriate combination thereof. The server (s) may also include database servers, including without limitation commercially available servers from Oracle<sup>®</sup>, Microsoft<sup>®</sup>, Sybase<sup>®</sup>, And IBM<sup>®</sup>.
[0118] The computing environment, which may include data storage and other memory and storage media as described below. These information carriers may be in various locations, such as local data storage (and / or placed therein) of one or more computers or remotely from all computers in a network. In a particular embodiment, the aggregate, the information may be kept in a storage area network ( «SAN»), known to those skilled in the art. Likewise, the files required to perform the functions typical of PCs, servers or other network devices may be stored locally and / or, if desired, remotely. In the case where the system comprises a computer device, each such device may include hardware elements that may be electrically connected by a bus, the elements comprising, for example, at least one central processing unit (CPU), at least one input device, (e.g., a mouse, a keyboard, a controller, a touch screen or the keypad), and at least one output device (such as display device, printer or speaker). Such a system may also include one or more data storage devices such as disk drives, optical storage devices, semiconductor memory devices such as RAM ( «RAM») or read only memory ( «ROM»), as well as removable media , memory card, flash memory cards, and so on.
[0119] Such devices may also include computer-readable data storage media reader, a communication device (e.g., modem, network adapter (wireless or wired), an infrared communication device, etc.), and memory functioning as described above. Reader of machine-readable data storage means may be connected to a computer-readable storage media, or configured to receive computer readable media presented remote, local, fixed and / or removable storage devices and storage media for temporarily and / or more permanent, storage , transmission, and retrieval of machine-readable information. Various devices and systems also typically contain a number of software applications, modules, services, or other items, combined with at least one functioning memory device, including the operating system and application software, for example, the client application or Web browser. It will be appreciated that alternative embodiments may have the form of the embodiments described above. For example, can also be used by hardware and / or user-specific elements are configured can be implemented in hardware, software (including mobile software, such as applets), or both, and other means. It may also be employed to communicate with other computing devices such as network input-output devices.
[0120] Recording media and computer-readable media for placing the code or code fragments that may contain any suitable carriers known to those skilled in the art, including storage media and communication media, such as, but not limited to, volatile and nonvolatile, removable or non-removable media implemented in any method or technology information storage and / or transmission of information such as computer readable instructions, data structures, program modules, or other data, including RAM, ROM, EEPROM, flash memory or other storage technology, CD- ROM, CD-ROM DVD format or other optical media, magnetic tape cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and to which access can be granted to the system devices. Based on the spirit of the invention and the disclosure provided herein idea, one skilled in the art will appreciate other ways and / or methods of implementing various embodiments of the invention.
[0121] The description and drawings, accordingly, are illustrative rather than limiting. Thus it will be evident that various modifications and changes may be made without departing from the spirit and scope of the present invention into effect provided by the claims.
[0122] Other embodiments of the present disclosure correspond to the idea of the invention. Therefore, while the disclosed algorithms are susceptible to various modifications and alternative constructions, some embodiments of the invention are shown graphically and described in detail above. It should be understood that it makes no sense to limit the invention to the specific form or forms disclosed, but on the contrary, there is a sense in disclosing all modifications, alternative constructions and equivalents arising from the spirit and scope of the invention as defined in the appended claims.
[0123] The terms "comprising", "having" and "comprising" is meant an open-ended terms (ie, meaning "including, without limitation"), except as otherwise indicated. The term "coupled" means either partially or entirely, "included", "connected to" or "coupled together", even if there is anything. Enumeration of ranges of values herein is intended merely to serve as a means of reducing belonging individually to each separate value as derived from the range, except the displayed herein otherwise, and each separate value is incorporated into the specification as if it was set forth in the present application separately. All methods described herein can be performed in any appropriate order, except displayed herein or otherwise clearly not otherwise conflicting context. The use of any and all examples, or exemplary language (including "for example") provided herein is intended merely to better illuminate embodiments of the invention and offers no restrictions on the scope of the invention boundaries, except when stated otherwise. Application Language herein shall mean any undeclared display element as an integral part of the practice of the invention.
[0124] A preferred embodiment of the invention of this disclosure described herein, including the best mode known to the inventors for practicing the invention. Variations of those preferred embodiments may become apparent to those skilled in the art from reading the foregoing description. The inventors suggest that those skilled will be involved in the art, and imply that the invention may be practiced otherwise than as specifically described herein. Accordingly, this invention, which includes all modifications and equivalents of the subject invention set forth in the appended claims and to the present application under current legislation. Moreover, any combination of the above-described elements in all possible embodiments, respectively, covered by the invention, except for the displayed herein otherwise inconsistent with context clearly.
[0125] All references, including publications, patent applications, and patents, cited herein and incorporated in its composition by reference to the same extent as if each reference were individually and specifically displayed incorporated by reference and was set forth in the present the application in its entirety.
Contents4
25 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US20030120940A1 | Cites | United States of America |
| US20040172535A1 | Cites | United States of America |
| US20070234410A1 | Cites | United States of America |
| US5956404A | Cites | United States of America |
| US6601172B1 | Cites | United States of America |
55 members in 11 offices
Priority claims19
| Document | Office | Kind | Date |
|---|---|---|---|
| 13248953 | United States of America | – | |
| 13248962 | United States of America | – | |
| 13248973 | United States of America | – | |
| 201113248953 | United States of America | A | |
| 201113248953 | United States of America | A | |
| 201113248962 | United States of America | A | |
| 201113248962 | United States of America | A | |
| 201113248973 | United States of America | A | |
| 201113248973 | United States of America | A | |
| 2012058083 | United States of America | W | |
| 2012058083 | United States of America | W | |
| 13248953 | – | – | – |
| 13248962 | – | – | – |
| 13248973 | – | – | – |
| US2012058083 | – | – | – |
| US201113248953 | – | – | – |
| US201113248962 | – | – | – |
| US201113248973 | – | – | – |
| WO2012US58083 | – | – | – |
Members55
| Document | Office | Kind | |
|---|---|---|---|
| CA2847713A1 | Canada | A1 | |
| US2013086661A1 | United States of America | A1 | |
| US2013086662A1 | United States of America | A1 | |
| US2013086663A1 | United States of America | A1 | |
| WO2013049689A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2012315674A1 | Australia | A1 | |
| CN103842984A | China | A | |
| EP2761487A1 | European Patent Office (EPO) | A1 | |
| SG2014012264A | Singapore | A | |
| JP2014531855A | Japan | A | |
| IN3111DEN2014A | India | A | |
| EP2761487A4 | European Patent Office (EPO) | A4 | |
| US9178701B2 | United States of America | B2 | |
| RU2014117153A | Russian Federation | A | |
| US9197409B2 | United States of America | B2 | |
| US9203613B2 | United States of America | B2 | |
| US2016021118A1 | United States of America | A1 | |
| RU2582540C2This record | Russian Federation | C2 | |
| SG10201608067QA | Singapore | A | |
| JP6082015B2 | Japan | B2 | |
| JP2017069989A | Japan | A | |
| BR112014007665A2 | Brazil | A2 | |
| CN103842984B | China | B | |
| CN107017984A | China | A | |
| RU2636105C1 | Russian Federation | C1 | |
| AU2012315674B2 | Australia | B2 | |
| US9954866B2 | United States of America | B2 | |
| AU2018202251A1 | Australia | A1 | |
| US2018205738A1 | United States of America | A1 | |
| AU2012315674B9 | Australia | B9 | |
| RU2670778C1 | Russian Federation | C1 | |
| RU2671052C1 | Russian Federation | C1 | |
| EP2761487B1 | European Patent Office (EPO) | B1 | |
| RU2670778C9 | Russian Federation | C9 | |
| SG10201903265PA | Singapore | A | |
| EP3493070A1 | European Patent Office (EPO) | A1 | |
| JP6527179B2 | Japan | B2 | |
| BR122015024906A2 | Brazil | A2 | |
| JP2019149833A | Japan | A | |
| AU2018202251B2 | Australia | B2 | |
| RU2709162C1 | Russian Federation | C1 | |
| AU2020200584A1 | Australia | A1 | |
| US10721238B2 | United States of America | B2 | |
| EP3493070B1 | European Patent Office (EPO) | B1 | |
| CN107017984B | China | B | |
| US2020296108A1 | United States of America | A1 | |
| EP3742300A1 | European Patent Office (EPO) | A1 | |
| CA2847713C | Canada | C | |
| AU2020200584B2 | Australia | B2 | |
| RU2019137439A | Russian Federation | A | |
| JP6895478B2 | Japan | B2 | |
| BR112014007665B1 | Brazil | B1 | |
| BR122015024906B1 | Brazil | B1 | |
| RU2019137439A3 | Russian Federation | A3 | |
| US11356457B2 | United States of America | B2 |
Numbers
- Publication
- 0002582540
- Publication, DOCDB
- 2582540
- Publication, EPODOC
- RU2582540
- Application
- 201411715308
- Application, DOCDB
- 2014117153
- Application, EPODOC
- RU20140117153
Titles2
- Russian
- ФОРМИРОВАНИЕ КЛЮЧА В ЗАВИСИМОСТИ ОТ ПАРАМЕТРА
- English
- KEY GENERATION DEPENDING ON PARAMETER
Classification
- CPC, 21
- H04L9/0861
- G06F21/335
- H04L9/0643
- H04L9/0816
- H04L9/085
- H04L9/088
- H04L9/0891
- H04L9/0894
- H04L9/3242
- H04L9/3247
- H04L63/06
- H04L63/08
- H04L63/0884
- H04L63/10
- H04L63/101
- H04L63/102
- H04L63/107
- H04L63/108
- H04L9/083
- H04L9/50
- G06F21/33
- IPC, 3
- G06F15 16
- H04L29 06
- H04L9 32