Three-Tiered Security and Computational Architecture
Abstract
A computing system, method, and storage medium prevent denial of provision of a network service by a server computer to an authorized client device. The computing system receives network service data that include a credential, then transmits that credential to a cloud-based identity system. The computing system responsively receives data pertaining to either zero or one identities related to the credential. If the data pertain to zero identities, the transaction is immediately terminated, preventing denial of the service. Only when the data pertain to exactly one identity does the computing system transmit the data to the server computer. Moreover, the computing system may terminate the transaction unless the server computer is similarly validated by the cloud-based identity system, thereby preventing access from an unauthorized device. The computing system may hide a network address of the client device from the server computer, and vice versa, and perform other useful supporting functions.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computing system for preventing denial of provision of a network service by a server computer to an authorized client device, the computing system comprising:
a first data port coupled to the authorized client device using a first communications network; a second data port coupled to the server computer using a second communications network; and a computing processor coupled to the first data port and second data port, the computing processor configured to:
receive, using the first data port, network service data that include a client credential;
transmit the client credential to a cloud-based identity system;
responsively receive, from the cloud-based identity system, data pertaining to either zero or one identities that were validated using the transmitted client credential; and
transmit the network service data to the server computer using the second data port only when the responsively received data pertain to exactly one identity.
2 . A computing system according to claim 1 , wherein the authorized client device comprises a desktop computer, or a laptop computer, or a tablet computer, or a smartphone.
3 . A computing system according to claim 1 , wherein the first communications network comprises a local area network.
4 . A computing system according to claim 1 , wherein the second communications network comprises the Internet.
5 . A computing system according to claim 1 , wherein the credential is a surrogate certificate identifier that is specific to a user of the authorized client device.
6 . A computing system according to claim 1 , wherein the computing processor is further configured to avoid communicating a network address of the client device to the server computer using the second data port, and to avoid communicating a network address of the server computer to the client device.
7 . A computing system according to claim 1 , wherein the computing processor is further configured to:
receive, from the server computer using the second data port, network service data that include a server credential; transmit the server credential to the cloud-based identity system; responsively receive data pertaining to either zero or one identities that the cloud-based identity system has validated using the server credential; and only when the responsively received data pertain to exactly one identity, transmit the network service data to the authorized client device using the first data port.
8 . A computing system according to claim 1 , wherein the network service data include data for changing another network service provided by the server computer, or data for changing a security feature of the server computer, or data for impersonating a user of the authorized client device, or any combination of these.
9 . A method of preventing denial of provision of a network service by a server computer to an authorized client device, the method comprising executing, by a computing system having a first data port coupled to the authorized client device using a first communications network and a second data port coupled to the server computer using a second communications network, processes comprising:
receiving, using the first data port, network service data that include a client credential; transmitting the client credential by the computing system to a cloud-based identity system; responsively receiving, by the computing system from the cloud-based identity system, data pertaining to either zero or one identities that were validated using the transmitted client credential; and transmitting the network service data to the server computer using the second data port only when the responsively received data pertain to exactly one identity.
10 . A method according to claim 9 , wherein the authorized client device comprises a desktop computer, or a laptop computer, or a tablet computer, or a smartphone.
11 . A method according to claim 9 , wherein receiving using the first data port includes receiving from a local area network, or receiving using the second data port includes receiving from the Internet, or both.
12 . A method according to claim 9 , further comprising:
avoiding communicating a network address of the client device to the server computer using the second data port; and avoiding communicating a network address of the server computer to the client device.
13 . A method according to claim 9 , further comprising:
receiving, from the server computer using the second data port, network service data that include a server credential; transmitting the server credential to the cloud-based identity system; responsively receiving data pertaining to either zero or one identities that the cloud-based identity system has validated using the server credential; and only when the responsively received data pertain to exactly one identity, transmitting the network service data to the authorized client device using the first data port.
14 . A method according to claim 9 , wherein the network service data include data for changing another network service provided by the server computer, or data for changing a security feature of the server computer, or data for impersonating a user of the authorized client device, or any combination of these.
15 . A computer program product comprising a tangible, non-transitory, computer readable storage medium, having stored thereon a computer program which, when executed by a computing system having a first data port coupled to the authorized client device using a first communications network and a second data port coupled to the server computer using a second communications network, causes the computing system to perform processes for preventing denial of provision of a network service by a server computer to an authorized client device, the processes comprising:
receiving, using the first data port, network service data that include a client credential; transmitting the client credential by the computing system to a cloud-based identity system; responsively receiving, by the computing system from the cloud-based identity system, data pertaining to either zero or one identities that were validated using the transmitted client credential; and transmitting the network service data to the server computer using the second data port only when the responsively received data pertain to exactly one identity.
16 . A storage medium according to claim 15 , wherein the process for receiving using the first data port includes receiving from a desktop computer, or a laptop computer, or a tablet computer, or a smartphone.
17 . A storage medium according to claim 15 , wherein the process for receiving using the first data port includes receiving from a local area network, or the process for receiving using the second data port includes receiving data from the Internet, or both.
18 . A storage medium according to claim 15 , wherein the processes further include:
avoiding communicating a network address of the client device to the server computer using the second data port; and avoiding communicating a network address of the server computer to the client device.
19 . A storage medium according to claim 15 , wherein the processes further include:
receiving, from the server computer using the second data port, network service data that include a server credential; transmitting the server credential to the cloud-based identity system; responsively receiving data pertaining to either zero or one identities that the cloud-based identity system has validated using the server credential; and only when the responsively received data pertain to exactly one identity, transmitting the network service data to the authorized client device using the first data port.
20 . A storage medium according to claim 15 , wherein the network service data include data for changing another network service provided by the server computer, or data for changing a security feature of the server computer, or data for impersonating a user of the authorized client device, or any combination of these.Join the waitlist — get patent alerts
Track US2017295142A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.