Secure inter-service communications in a cloud computing system

    公开(公告)号:US11296892B2

    公开(公告)日:2022-04-05

    申请号:US16688459

    申请日:2019-11-19

    Abstract: Secure communications between services or components of a cloud computing system, are facilitated by generating at a first service provided by a first computing entity of a cloud computing system, a request for computing resources, generating at the first computing entity a digital data signature based at least on the request, using a private key associated with the first service; and inserting the digital data signature within an HTTP header associated with the request. A computer data network is used to communicate the request to a second service. The second service extracts the digital data signature and uses a public key to validate the digital data signature.

    SCOPED VIEW OF CLOUD CONTROL PLANE FOR DEVELOPMENT OF NEW SERVICES

    公开(公告)号:US20180337835A1

    公开(公告)日:2018-11-22

    申请号:US15600894

    申请日:2017-05-22

    CPC classification number: H04L41/5096 H04L41/5038 H04L41/5051

    Abstract: Methods, systems, computer-readable media, and apparatuses method for integrating a cloud service under development with a production cloud system that includes at least one production service. A first scope is assigned for use in testing the first cloud service under development with the production cloud system, in which the first scope restricts access of the first cloud service under development to the production cloud system. A first user of the production cloud system is assigned to the first scope. A second scope is assigned to services of the production cloud system, which does not restrict access of the services of the production cloud system. Access to the first cloud service under development and to the at least one production cloud service is provided to the first user. Other users of the production cloud system are not provided access to the first cloud service under development.

    Methods and systems for allocating and de-allocating delivery groups across multiple server farms

    公开(公告)号:US09866496B2

    公开(公告)日:2018-01-09

    申请号:US14566553

    申请日:2014-12-10

    CPC classification number: H04L47/70 G06F9/5077

    Abstract: The embodiments are directed to methods and apparatuses for pairing delivery group machines with one or more server farms in computing networks. The methods and apparatus can allocate machines in a delivery group across one or more server farms in a manner that maximizes efficiency through better computer resource usage. The methods and apparatuses select a server farm having a largest available capacity, and allocate machines from a delivery group to the server farm. If the quantity of delivery group machines exceeds the server farm capacity, the remaining machines are allocated to a second server farm. The methods and appliances also provide for de-allocating server farms, by selecting a server farm with the least allocated capacity, and de-allocating one or more delivery group machines from the selected server farm to reduce the number of utilized server farms.

    Pre-authorization for service-to-service requests

    公开(公告)号:US11336640B2

    公开(公告)日:2022-05-17

    申请号:US16292786

    申请日:2019-03-05

    Inventor: Felipe Leon

    Abstract: Methods and systems for authorizing a service request between two services in a network environment are disclosed. One method includes, in a recurring background process occurring separate from a service request, having a target service obtain a pre-authorization token including a signature of the request service. In response to confirming the pre-authorization token was issued by the request service, the pre-authorization token is acknowledged and stored for access by instance(s) of the target service. The acknowledged pre-authorization token is saved for use with service requests to the target service from the request service. In response to receiving a service request including pre-authorization token at an instance of the target service, the method confirms the pre-authorization token matches a stored, acknowledged pre-authorization token, and, if so confirmed, authorizes the service request. Pre-authorization tokens have a set duration. The methods and systems reduce computational overhead of the authorization, resulting in decreased latency.

    SECURE INTER-SERVICE COMMUNICATIONS IN A CLOUD COMPUTING SYSTEM

    公开(公告)号:US20200092109A1

    公开(公告)日:2020-03-19

    申请号:US16688459

    申请日:2019-11-19

    Abstract: Secure communications between services or components of a cloud computing system, are facilitated by generating at a first service provided by a first computing entity of a cloud computing system, a request for computing resources, generating at the first computing entity a digital data signature based at least on the request, using a private key associated with the first service; and inserting the digital data signature within an HTTP header associated with the request. A computer data network is used to communicate the request to a second service. The second service extracts the digital data signature and uses a public key to validate the digital data signature.

    PRE-AUTHORIZATION FOR SERVICE-TO-SERVICE REQUESTS

    公开(公告)号:US20200287894A1

    公开(公告)日:2020-09-10

    申请号:US16292786

    申请日:2019-03-05

    Inventor: Felipe Leon

    Abstract: Methods and systems for authorizing a service request between two services in a network environment are disclosed. One method includes, in a recurring background process occurring separate from a service request, having a target service obtain a pre-authorization token including a signature of the request service. In response to confirming the pre-authorization token was issued by the request service, the pre-authorization token is acknowledged and stored for access by instance(s) of the target service. The acknowledged pre-authorization token is saved for use with service requests to the target service from the request service. In response to receiving a service request including pre-authorization token at an instance of the target service, the method confirms the pre-authorization token matches a stored, acknowledged pre-authorization token, and, if so confirmed, authorizes the service request. Pre-authorization tokens have a set duration. The methods and systems reduce computational overhead of the authorization, resulting in decreased latency.

    Scoped view of cloud control plane for development of new services

    公开(公告)号:US10382293B2

    公开(公告)日:2019-08-13

    申请号:US15600894

    申请日:2017-05-22

    Abstract: Methods, systems, computer-readable media, and apparatuses method for integrating a cloud service under development with a production cloud system that includes at least one production service. A first scope is assigned for use in testing the first cloud service under development with the production cloud system, in which the first scope restricts access of the first cloud service under development to the production cloud system. A first user of the production cloud system is assigned to the first scope. A second scope is assigned to services of the production cloud system, which does not restrict access of the services of the production cloud system. Access to the first cloud service under development and to the at least one production cloud service is provided to the first user. Other users of the production cloud system are not provided access to the first cloud service under development.

Patent Agency Ranking