MLchartDataset catalogue

Patent · US11356255B1 · B1 · US

System and method for securely connecting applications to middleware services in a cloud platform

(11) Publication number
US11356255B1
(21) Application number
16/731,568
(22) Filing date
2019-12-31
(30) Priority date
2019-12-31
(43) Publication date
2022-06-07
(45) Date of grant
2022-06-07
(51) IPC
H04L 9/08; H04L 9/32; H04L 9/40
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 9/0894, 63/0807, 63/083, 9/3226
(73) Assignee
Virtuozzo International GmbH
(72) Inventors
Pavel Emelyanov; Alexey Kobets
(54) Title
System and method for securely connecting applications to middleware services in a cloud platform
(57) Abstract

Disclosed herein are systems and methods for secure authentication of a managed application. In one aspect, an exemplary method comprises receiving, by a cloud platform, a request from a managed application to connect to a middleware service, determining that the managed application is authenticated to use the middleware service based on the secret, obtaining a secret associated with the managed application and the middleware service from a secret store, connecting to the middleware service using the secret to establish a secure connection, and delegating, to the managed application, the secure connection between the managed application and the middleware service.

Full text
View on Google Patents

Claims (20)

  1. A method for secure authentication of a managed application, comprising: providing, by a cloud platform, the managed application with an identifier for a middleware service; after providing the identifier, receiving, by the cloud platform, an upload of the managed application; generating, by the cloud platform, a secret associated with the managed application and the middleware service; storing the secret in a secret store; after receiving the upload, receiving, by the cloud platform, a request from the managed application to connect_to the middleware service; determining that the managed application is authenticated to use the middleware service based on the secret; obtaining the secret associated with the managed application and the middleware service from the secret store; connecting to the middleware service using the secret to establish a secure connection; and delegating, to the managed application, the secure connection between the managed application and the middleware service.
  2. The method of claim 1, wherein the secret is generated based on the managed applications directive to use the middleware service.
  3. The method of claim 1, further comprising: connecting to the middleware service upon execution of middleware connection call in the managed application.
  4. The method of claim 1, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.
  5. The method of claim 4, further comprising: obtaining a connection handler for handling the secure connection from the second process; and passing the connection handler to the first process.
  6. The method of claim 5, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor.
  7. The method of claim 5, further comprising: performing obtaining the secret and determining whether the managed application is authenticated in kernel address space of an operating system (OS) executing on the hardware processor, wherein the kernel address space is protected from user address space at a hardware level by the OS.
  8. The method of claim 1, wherein the secret store is one of a key value store or a key management service.
  9. A system for secure authentication of a managed application, the system comprising: a memory; and at least one processor configured to: provide the managed application with an identifier for a middleware service; after providing the identifier, receive an upload of the managed application; generate a secret associated with the managed application and the middleware service; store the secret in a secret store; after receiving the upload, receive, by the cloud platform, a request from the managed application to connect_to the middleware service; determine that the managed application is authenticated to use the middleware service based on the secret; obtain the secret associated with the managed application and the middleware service from the secret store; connect_to the middleware service using the secret to establish a secure connection; and delegate to the managed application, the secure connection between the managed application and the middleware service.
  10. The system of claim 9, wherein the secret is generated based on the managed applications directive to use the middleware service.
  11. The system of claim 9, the processor further configured to: connect_to the middleware service upon execution of middleware connection call in the managed application.
  12. The system of claim 9, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.
  13. The system of claim 12, wherein the processor is further configured to: obtain a connection handler for handling the secure connection from the second process; and pass the connection handler to the first process.
  14. The system of claim 13, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor.
  15. A non-transitory computer readable medium storing thereon computer executable instructions for secure authentication of a managed application, the instructions including instructions for: providing, by a cloud platform, the managed application with an identifier for a middleware service; after providing the identifier, receiving, by the cloud platform, an upload of the managed application; generating, by the cloud platform, a secret associated with the managed application and the middleware service; storing the secret in a secret store; after receiving the upload, receiving, by the cloud platform, a request from the managed application to connect_to the middleware service; determining that the managed application is authenticated to use the middleware service based on the secret; obtaining the secret associated with the managed application and the middleware service from the secret store; connecting to the middleware service using the secret to establish a secure connection; and delegating, to the managed application, the secure connection between the managed application and the middleware service.
  16. The non-transitory computer readable medium of claim 15, wherein the secret is generated based on the managed applications directive to use the middleware service.
  17. The non-transitory computer readable medium of claim 16, the instructions further comprising instructions for: connecting to the middleware service upon execution of middleware connection call in the managed application.
  18. The non-transitory computer readable medium of claim 15, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.
  19. The non-transitory computer readable medium of claim 18, wherein the instructions further include instructions for: obtaining a connection handler for handling the secure connection from the second process; and passing the connection handler to the first process.
  20. The non-transitory computer readable medium of claim 19, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor.

Description

The present disclosure relates generally to the field of application security in cloud platforms, more specifically, to systems and methods for securely connecting applications to middleware services in a cloud platform.

Clients can deploy software applications in a cloud computing platform in order to take advantage of the distributed resources provided by the platform. Inside most platforms there are one or more instances of middleware services. Middleware services are additional services that are launched in the platform and that applications may want to use. Examples of middleware services include databases, message-queueing services, crypto key stores, and the like. When developing the application, a client writes code that connects to and authenticates with the middleware service using a “secret” (e.g., password), as seen in FIG. 1, for example.

However, a problem may arise. The computing platform gives the application code access to the secret while protecting the secret from being leaked or disclosed to untrusted parties and places. However, providing the secret to the application code likely increases the risk of the secret being compromised.

Presently, solutions to this problem include allowing a client to generate the secret themselves. According to this solution, the burden of keeping the secret secure rests with the client. Then the secret is to be transferred into the cloud platform using some protected mechanism for safety. However, putting the burden on the client is also undesirable as it may lead to a compromised secret.

Citations (6)

  • US20030191935A1
  • US20160352665A1
  • US20170013015A1
  • US20180159856A1
  • US20200145385A1
  • US20200287894A1
Record as JSON
{
  "publication_number": "US11356255B1",
  "country": "US",
  "kind": "B1",
  "title": "System and method for securely connecting applications to middleware services in a cloud platform",
  "abstract": "Disclosed herein are systems and methods for secure authentication of a managed application. In one aspect, an exemplary method comprises receiving, by a cloud platform, a request from a managed application to connect to a middleware service, determining that the managed application is authenticated to use the middleware service based on the secret, obtaining a secret associated with the managed application and the middleware service from a secret store, connecting to the middleware service using the secret to establish a secure connection, and delegating, to the managed application, the secure connection between the managed application and the middleware service.",
  "claims": [
    "1. A method for secure authentication of a managed application, comprising: providing, by a cloud platform, the managed application with an identifier for a middleware service; after providing the identifier, receiving, by the cloud platform, an upload of the managed application; generating, by the cloud platform, a secret associated with the managed application and the middleware service; storing the secret in a secret store; after receiving the upload, receiving, by the cloud platform, a request from the managed application to connect_to the middleware service; determining that the managed application is authenticated to use the middleware service based on the secret; obtaining the secret associated with the managed application and the middleware service from the secret store; connecting to the middleware service using the secret to establish a secure connection; and delegating, to the managed application, the secure connection between the managed application and the middleware service.",
    "2. The method of claim 1, wherein the secret is generated based on the managed applications directive to use the middleware service.",
    "3. The method of claim 1, further comprising: connecting to the middleware service upon execution of middleware connection call in the managed application.",
    "4. The method of claim 1, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.",
    "5. The method of claim 4, further comprising: obtaining a connection handler for handling the secure connection from the second process; and passing the connection handler to the first process.",
    "6. The method of claim 5, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor.",
    "7. The method of claim 5, further comprising: performing obtaining the secret and determining whether the managed application is authenticated in kernel address space of an operating system (OS) executing on the hardware processor, wherein the kernel address space is protected from user address space at a hardware level by the OS.",
    "8. The method of claim 1, wherein the secret store is one of a key value store or a key management service.",
    "9. A system for secure authentication of a managed application, the system comprising: a memory; and at least one processor configured to: provide the managed application with an identifier for a middleware service; after providing the identifier, receive an upload of the managed application; generate a secret associated with the managed application and the middleware service; store the secret in a secret store; after receiving the upload, receive, by the cloud platform, a request from the managed application to connect_to the middleware service; determine that the managed application is authenticated to use the middleware service based on the secret; obtain the secret associated with the managed application and the middleware service from the secret store; connect_to the middleware service using the secret to establish a secure connection; and delegate to the managed application, the secure connection between the managed application and the middleware service.",
    "10. The system of claim 9, wherein the secret is generated based on the managed applications directive to use the middleware service.",
    "11. The system of claim 9, the processor further configured to: connect_to the middleware service upon execution of middleware connection call in the managed application.",
    "12. The system of claim 9, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.",
    "13. The system of claim 12, wherein the processor is further configured to: obtain a connection handler for handling the secure connection from the second process; and pass the connection handler to the first process.",
    "14. The system of claim 13, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor.",
    "15. A non-transitory computer readable medium storing thereon computer executable instructions for secure authentication of a managed application, the instructions including instructions for: providing, by a cloud platform, the managed application with an identifier for a middleware service; after providing the identifier, receiving, by the cloud platform, an upload of the managed application; generating, by the cloud platform, a secret associated with the managed application and the middleware service; storing the secret in a secret store; after receiving the upload, receiving, by the cloud platform, a request from the managed application to connect_to the middleware service; determining that the managed application is authenticated to use the middleware service based on the secret; obtaining the secret associated with the managed application and the middleware service from the secret store; connecting to the middleware service using the secret to establish a secure connection; and delegating, to the managed application, the secure connection between the managed application and the middleware service.",
    "16. The non-transitory computer readable medium of claim 15, wherein the secret is generated based on the managed applications directive to use the middleware service.",
    "17. The non-transitory computer readable medium of claim 16, the instructions further comprising instructions for: connecting to the middleware service upon execution of middleware connection call in the managed application.",
    "18. The non-transitory computer readable medium of claim 15, wherein the receiving, connecting and determining are performed in a first process, and the obtaining of the secret and delegating the secure connection are performed using a second process.",
    "19. The non-transitory computer readable medium of claim 18, wherein the instructions further include instructions for: obtaining a connection handler for handling the secure connection from the second process; and passing the connection handler to the first process.",
    "20. The non-transitory computer readable medium of claim 19, wherein passing the connection handler is performed by using a file handler passing mechanism of an underlying operating system (OS) executing on a hardware processor."
  ],
  "description_excerpt": "The present disclosure relates generally to the field of application security in cloud platforms, more specifically, to systems and methods for securely connecting applications to middleware services in a cloud platform.\n\nClients can deploy software applications in a cloud computing platform in order to take advantage of the distributed resources provided by the platform. Inside most platforms there are one or more instances of middleware services. Middleware services are additional services that are launched in the platform and that applications may want to use. Examples of middleware services include databases, message-queueing services, crypto key stores, and the like. When developing the application, a client writes code that connects to and authenticates with the middleware service using a “secret” (e.g., password), as seen in FIG. 1, for example.\n\nHowever, a problem may arise. The computing platform gives the application code access to the secret while protecting the secret from being leaked or disclosed to untrusted parties and places. However, providing the secret to the application code likely increases the risk of the secret being compromised.\n\nPresently, solutions to this problem include allowing a client to generate the secret themselves. According to this solution, the burden of keeping the secret secure rests with the client. Then the secret is to be transferred into the cloud platform using some protected mechanism for safety. However, putting the burden on the client is also undesirable as it may lead to a compromised secret.",
  "cpc": [
    "H04L 9/0894",
    "H04L 63/0807",
    "H04L 63/083",
    "H04L 9/3226"
  ],
  "ipc": [
    "H04L 9/08",
    "H04L 9/32",
    "H04L 9/40"
  ],
  "assignees": [
    "Virtuozzo International GmbH"
  ],
  "inventors": [
    "Pavel Emelyanov",
    "Alexey Kobets"
  ],
  "filing_date": "2019-12-31",
  "publication_date": "2022-06-07",
  "grant_date": "2022-06-07",
  "priority_date": "2019-12-31",
  "application_number": "US-201916731568-A",
  "family_id": "81852580",
  "cited_by_count": 9,
  "citations": [
    "US20030191935A1",
    "US20160352665A1",
    "US20170013015A1",
    "US20180159856A1",
    "US20200145385A1",
    "US20200287894A1"
  ]
}

Record 1,141 of 8,000 in Patents full text (MLC-0201). Request the full dataset.