Distributed authentication in a protocol-based sphere of trust in which a given external connection outside the sphere of trust may carry communications from multiple sources
Abstract
A distributed authentication model that operates within a protocol-based sphere of trust. Rather than being able to communicate with any one of the computing systems internal to the sphere of trust, the amount of authentication is reduced by having the external computing systems initially communicate with a specific edge internal computing system. Many if not all of the internal computing systems then delegate the task of authentication to the edge computing system, and will rely on any authentication performed by the edge computing system. This allows the task of authentication to scale well for large protocol-based spheres of trust.
Claims
exact text as granted — not AI-modified1 . In a network environment including a protocol-based sphere of trust which includes a plurality of internal computing systems which trust communications between each other so long as the communications are in accordance with a particular protocol, but do not always trust communications between each other if the communication is not in accordance with the particular protocol, the network environment further including a plurality of external computing systems that are external to the protocol-based sphere of trust, at least some of the plurality of external computing systems communicating with a first internal computing system over a single connection, a method for a second internal computing system validating the identity of an originating external computing system that originated a communication that is received by the second internal computing system via the first internal computing system through the single connection, the method comprising the following:
an act of the second internal computing system receiving the communication from the first internal computing system using the particular protocol, the received communication being received either directly from the first internal computing system, or indirectly after having traveled a trusted chain leading using the particular protocol from the first internal computing system through one or more intermediary internal computing system, the communicating originating from an originating external computing system; an act of accessing a list of internal computing systems that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems; an act of determining that either the first internal computing system is on the list, or that at least one of the internal computing systems in the trusted chain is on the list; and an act of validating the identity of the originating external computing system by mere virtue of the act of determining and without separately authenticating the originating external computing system.
2 . A method in accordance with claim 1 ,
wherein the act of the second internal computing system receiving the communication from the first internal computing system using the particular protocol comprises an act of receiving the communication directly from the first internal computing system, and wherein the act of determining comprises an act of determining that the first internal computing system is on the list.
3 . A method in accordance with claim 1 ,
wherein the act of the second internal computing system receiving the communication from the first internal computing system using the particular protocol comprises an act of receiving the communication indirectly after having traveled a trusted chain leading from the first internal computing system through one or more intermediary internal computing system, and wherein the act of determining comprises an act of determining that at least one of the internal computing systems in the trusted chain is on the list.
4 . A method in accordance with claim 1 ,
wherein the act of determining that at least one of the internal computing systems in the trusted chain is on the list comprises an act of determining that the first internal computing system is on the list.
5 . A method in accordance with claim 1 ,
wherein the act of determining that at least one of the internal computing systems in the trusted chain is on the list comprises an act of determining that a most proximate internal computing system in the trusted chain is on the list.
6 . A method in accordance with claim 1 ,
wherein the particular protocol is Session Initiation Protocol (SIP).
7 . A method in accordance with claim 1 , wherein all of the plurality of internal computing systems in the protocol-based sphere of trust are within a common enterprise.
8 . A method in accordance with claim 7 , further comprising the following:
an act of adding a computing system to the list.
9 . A method in accordance with claim 8 , wherein the act of adding a computing system to the list is in response to an instruction from a system administrator of the enterprise.
10 . A method in accordance with claim 1 , wherein the plurality of internal computing systems are not in a common enterprise.
11 . A method in accordance with claim 1 , further comprising the following:
an act of adding a computing system to the list.
12 . A computer program product for use in a network environment including a protocol-based sphere of trust which includes a plurality of internal computing systems which trust communications between each other so long as the communications are in accordance with a particular protocol, but do not always trust communications between each other if the communication is not in accordance with the particular protocol, the network environment further including a plurality of external computing systems that are external to the protocol-based sphere of trust and that communicate with a first internal computing system over a single connection, the computer program product for implementing a method for a second internal computing system validating the identity of an originating external computing system that originated a communication that is received by the second internal computing system via the first internal computing system through the single connection, the computer program product comprising one or more computer-readable media having thereon the computer-executable instructions for performing the method, the method comprising the following:
an act of the second internal computing system receiving the communication from the first internal computing system using the particular protocol, the received communication being received either directly from the first internal computing system, or indirectly after having traveled a trusted chain leading using the particular protocol from the first internal computing system through one or more intermediary internal computing system, the communicating originating from an originating external computing system; an act of accessing a list of internal computing systems that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems; an act of determining that either the first internal computing system is on the list, or that at least one of the internal computing systems in the trusted chain is on the list; and an act of validating the identity of the originating external computing system by mere virtue of the act of determining and without separately authenticating the originating external computing system.
13 . A computer program product in accordance with claim 12 , wherein the one or more computer-readable media are physical media.
14 . A computer program product in accordance with claim 13 , wherein the one or more computer-readable media is system memory.
15 . A computer program product in accordance with claim 13 , wherein the one or more computer-readable media is persistent memory.
16 . In a network environment including a protocol-based sphere of trust which includes a plurality of internal computing systems which trust communications between each other so long as the communications are in accordance with a particular protocol, but do not always trust communications between each other if the communication is not in accordance with the particular protocol, the network environment further including a plurality of external computing systems that are external to the protocol-based sphere of trust and that communicate with a first internal computing system over a single connection, a method for a second internal computing system validating the identity of an originating external computing system that originated a communication that is received by the second internal computing system via the first internal computing system through the single connection, the method comprising the following:
an act of the second internal computing system receiving the communication from the first internal computing system using the particular protocol, the received communication being received either directly from the first internal computing system, or indirectly after having traveled a trusted chain leading using the particular protocol from the first internal computing system through one or more intermediary internal computing system, the communicating originating from an originating external computing system; and a step for determining whether to trust the communication without separately authenticating the originating external computing system.
17 . A method in accordance with claim 16 , wherein the step for determining whether to trust the communication without separately authenticating the originating external computing system comprises the following:
an act of accessing a list of internal computing systems that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems; an act of determining that either the first internal computing system is on the list, or that at least one of the internal computing systems in the trusted chain is on the list; and an act of validating the identity of the originating external computing system by mere virtue of the act of determining and without separately authenticating the originating external computing system.
18 . In a network environment including a protocol-based sphere of trust which includes a plurality of internal computing systems which trust communications between each other so long as the communications are in accordance with a particular protocol, but do not always trust communications between each other if the communication is not in accordance with the particular protocol, the network environment further including a plurality of external computing systems that are external to the protocol-based sphere of trust and that communicate with a first internal computing system over a single connection, a method for the first internal computing system authenticating at least some of the plurality of external computing systems communicating on behalf of at least some of the plurality of internal computing systems, the method comprising the following:
an act of the first internal computing system establishing a connection with a first external computing system; an act of receiving a communication from the first external computing system over the connection using the particular protocol, the first communication originating from a second external computing system that may be the same as or different than the first external computing system, the first communication destined for or at least to pass through a second internal computing system; an act of authenticating the second external computing system; and an act of forwarding the first communication, or a derivative thereof, to the second internal computing system using the particular protocol, wherein the second internal computing system has access to a list of internal computing systems including the first internal computing system that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems.
19 . A method in accordance with claim 18 , wherein the communication is a first communication, further comprising the following:
an act of receiving a second communication from the first external computing system over the connection, the second communication originating from a third external computing system that is different than the second external computing system, the second communication destined for or at least to pass through a third internal computing system that may be the same as or different than the second internal computing system; an act of authenticating the third external computing system; and an act of forwarding the second communication, or a derivative thereof, to the third internal computing system, wherein the second internal computing system has access to a list of internal computing systems including the first internal computing system that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems.
20 . A method in accordance with claim 19 , wherein the second internal computing system and the third internal computing system is the same.
21 . A method in accordance with claim 19 , wherein the second internal computing system and the third internal computing system are different.
22 . A method in accordance with claim 21 , wherein the list accessible by the second internal computing system and the list accessible by the third internal computing system is the same list.
23 . A method in accordance with claim 21 , wherein the list accessible by the second internal computing system and the list accessible by the third internal computing system are different lists, though identical copies of each other.
24 . A method in accordance with claim 21 , wherein the list accessible by the second internal computing system and the list accessible by the third internal computing system are different lists, and not identical copies of each other.
25 . A method in accordance with claim 18 , wherein the second external computing system and the first external computing system are the same.
26 . A method in accordance with claim 18 , wherein the second external computing system is different than the first external computing system.
27 . A method in accordance with claim 26 , wherein the third external computing system is the same as the first external computing system.
28 . A method in accordance with claim 26 , wherein the third external computing system is different than the first external computing system.
29 . A method in accordance with claim 18 , wherein the particular protocol is Session Initiation Protocol (SIP).
30 . A method in accordance with claim 29 , wherein the act of authenticating the second external computing system is performed using Transport Layer Security (TLS).
31 . A method in accordance with claim 18 , wherein the communication is destined for the second internal computing system.
32 . A method in accordance with claim 18 , wherein the communication is to pass through the second internal computing system.
33 . A method in accordance with claim 32 , wherein the communication is destined for a third internal computing system.
34 . A method in accordance with claim 32 , wherein the communication is destined for a fourth external computing system.
35 . A computer program product for use in a network environment including a protocol-based sphere of trust which includes a plurality of internal computing systems which trust communications between each other so long as the communications are in accordance with a particular protocol, but do not always trust communications between each other if the communication is not in accordance with the particular protocol, the network environment further including a plurality of external computing systems that are external to the protocol-based sphere of trust and that communicate with a first internal computing system over a single connection, the computer program product for implementing a method for the first internal computing system authenticating at least some of the plurality of external computing systems communicating on behalf of at least some of the plurality of internal computing systems, the computer program product comprising one or more computer-readable media having thereon the computer-executable instructions for performing the method, the method comprising the following:
an act of the first internal computing system establishing a connection with a first external computing system; an act of receiving a communication from the first external computing system over the connection using the particular protocol, the first communication originating from a second external computing system that may be the same as or different than the first external computing system, the first communication destined for or at least to pass through a second internal computing system; an act of authenticating the second external computing system; and an act of forwarding the first communication, or a derivative thereof, to the second internal computing system using the particular protocol, wherein the second internal computing system has access to a list of internal computing systems including the first internal computing system that the second internal computing system trusts to authenticate external computing systems without the second internal computing system separately authenticating the external computing systems.
36 . A computer program product in accordance with claim 35 , wherein the one or more computer-readable media are physical media.
37 . A computer program product in accordance with claim 36 , wherein the one or more computer-readable media is system memory.
38 . A computer program product in accordance with claim 36 , wherein the one or more computer-readable media is persistent memory.Join the waitlist — get patent alerts
Track US2009199288A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.