US2022086164A1PendingUtilityA1

Edge-node authentication and security for functions as a service

Assignee: AT & T IP I LPPriority: May 20, 2019Filed: Nov 22, 2021Published: Mar 17, 2022
Est. expiryMay 20, 2039(~12.8 yrs left)· nominal 20-yr term from priority
H04L 63/105H04L 63/1458H04L 63/108H04L 63/0884H04L 63/08H04L 63/102
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes identifying a first validation parameter of a first network node and a second validation parameter of a second network node. The method includes creating an authentication node based on the first and second validation parameters. The method also includes receiving a request to access a microservice that utilizes the first network node and the second network node. The authentication node analyzes the request to make a validation determination indicative of whether the request satisfies the first and second validation parameters and controls access to the microservice based on the validation determination.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A device, comprising:
 a processing system including a hardware processor; and   a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:
 identifying a first validation parameter in code of a first network node of a network; 
 tracing a route through the network to determine connectivity between the first network node and a second network node; 
 identifying a second validation parameter of the second network node; and 
 creating an authentication node in the network based on the first and second validation parameters, the authentication node operative to: 
 receiving, by the authentication node, a request from a requesting entity in data communication with the network to access a virtual function of the first network node and the second network node; 
 determining, by the authentication node, a validation for the request; and 
 controlling access, by the authentication node, to the virtual function based on the validation for the request. 
   
     
     
         2 . The device of  claim 1 , wherein the determining a validation for the request comprises:
 determining, by the authentication node, whether the request satisfies the first and second validation parameters.   
     
     
         3 . The device of  claim 1 , wherein the identifying a first validation parameter comprises confirming an incoming message complies with a predetermined message format. 
     
     
         4 . The device of  claim 1 , wherein the operations further comprise gathering authentication parameters for the virtual function. 
     
     
         5 . The device of  claim 1 , wherein the operations further comprise:
 terminating access to the virtual function after an amount of time has elapsed.   
     
     
         6 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a hardware processor, facilitate performance of operations, the operations comprising:
 identifying a first network node of a network;   identifying a first validation parameter of the first network node;   tracing a route in the network to determine connectivity between the first network node and a second network node;   identifying a second validation parameter of the second network node;   creating an authentication node based on the first and second validation parameters, wherein the authentication node is located at an edge of the network;   receiving a request to access a microservice that utilizes the first network node and the second network node, wherein the microservice comprises a function as a service (FaaS);   validating, by the authentication node, the request to determine whether the request satisfies the first and second validation parameters; and   controlling, by the authentication node, access to the microservice based on the validating.   
     
     
         7 . The non-transitory machine-readable medium of  claim 6 , wherein the identifying a first validation parameter of the first network node comprises parsing code of the first network node. 
     
     
         8 . The non-transitory machine-readable medium of  claim 7 , wherein the identifying a second validation parameter of the second network node comprises parsing code of the second network node. 
     
     
         9 . The non-transitory machine-readable medium of  claim 6 , wherein the operations further comprise:
 instantiating the first network node in the network, wherein the instantiating the first network node is responsive to a determination that the request satisfies the first validation parameter and the second validation parameter;   instantiating the second network node in the network, wherein the instantiating the second network node is responsive to the determination that the request satisfies the first validation parameter and the second validation parameter; and   directing the request to access the microservice based on the instantiating the first network node and the instantiating the second network node.   
     
     
         10 . The non-transitory machine-readable medium of  claim 9 , wherein the operations further comprise:
 determining an expected travel time in the network for providing a response to the request;   determining that an actual travel time for the request in the network exceeds the expected travel time; and   terminating the request based on the actual travel time exceeding the expected travel time.   
     
     
         11 . The non-transitory machine-readable medium of  claim 10 , wherein the operations further comprise:
 identifying a source of the request; and   blocking future requests from the source of the request.   
     
     
         12 . The non-transitory machine-readable medium of  claim 6 , wherein the operations further comprise:
 determining the request does not satisfy at least one of the first validation parameter and the second validation parameter, invalidating the request; and   rejecting the request based on the invalidating the request.   
     
     
         13 . The non-transitory machine-readable medium of  claim 6 , wherein the identifying a first validation parameter comprises determining the first validation parameter comprises a message format and wherein the identifying a second validation parameter comprises determining the second validation parameter comprise a message format. 
     
     
         14 . The non-transitory machine-readable medium of  claim 6 , wherein the identifying a first validation parameter comprises determining the first validation parameter comprises a message length and wherein the identifying a second validation parameter comprises determining the second validation parameter comprise a message length. 
     
     
         15 . A method, comprising:
 identifying, by a processing system including a hardware processor, a first validation parameter of a first network node of a network;   identifying, by the processing system, a second validation parameter of a second network node in the network;   creating, by the processing system, an authentication node based on the first validation parameter and the second validation parameter;   receiving, by the processing system, a request to access a microservice that utilizes the first network node and the second network node;   determining, by the processing system, whether the request satisfies the first validation parameter and the second validation parameter; and   controlling, by the processing system, access to the first network node and the second network node for the microservice based on the determining whether the request satisfies the first validation parameter and the second validation parameter.   
     
     
         16 . The method of  claim 15 , wherein the identifying a first validation parameter of the first network node comprises:
 determining, by the processing system, that the first validation parameter comprises a message format.   
     
     
         17 . The method of  claim 15 , wherein the identifying a second validation parameter of the second network node comprises:
 determining, by the processing system, that the second validation parameter comprises an authentication parameter.   
     
     
         18 . The method of  claim 15 , further comprising:
 measuring, by the processing system, an amount of time associated with the request to access the microservice.   
     
     
         19 . The method of  claim 15 , comprising:
 terminating, by the processing system, access to the microservice based on the amount of time exceeding a predetermined access time threshold.   
     
     
         20 . The method of  claim 15 , wherein the predetermined access time threshold is based upon an expected amount of time for performing the microservice.

Join the waitlist — get patent alerts

Track US2022086164A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.