Edge-node authentication and security for functions as a service
Abstract
A method includes identifying a first validation parameter of a first network node and a second validation parameter of a second network node. The method includes creating an authentication node based on the first and second validation parameters. The method also includes receiving a request to access a microservice that utilizes the first network node and the second network node. The authentication node analyzes the request to make a validation determination indicative of whether the request satisfies the first and second validation parameters and controls access to the microservice based on the validation determination.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A device, comprising:
a processing system including a hardware processor; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:
identifying a first validation parameter in code of a first network node of a network;
tracing a route through the network to determine connectivity between the first network node and a second network node;
identifying a second validation parameter of the second network node; and
creating an authentication node in the network based on the first and second validation parameters, the authentication node operative to:
receiving, by the authentication node, a request from a requesting entity in data communication with the network to access a virtual function of the first network node and the second network node;
determining, by the authentication node, a validation for the request; and
controlling access, by the authentication node, to the virtual function based on the validation for the request.
2 . The device of claim 1 , wherein the determining a validation for the request comprises:
determining, by the authentication node, whether the request satisfies the first and second validation parameters.
3 . The device of claim 1 , wherein the identifying a first validation parameter comprises confirming an incoming message complies with a predetermined message format.
4 . The device of claim 1 , wherein the operations further comprise gathering authentication parameters for the virtual function.
5 . The device of claim 1 , wherein the operations further comprise:
terminating access to the virtual function after an amount of time has elapsed.
6 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a hardware processor, facilitate performance of operations, the operations comprising:
identifying a first network node of a network; identifying a first validation parameter of the first network node; tracing a route in the network to determine connectivity between the first network node and a second network node; identifying a second validation parameter of the second network node; creating an authentication node based on the first and second validation parameters, wherein the authentication node is located at an edge of the network; receiving a request to access a microservice that utilizes the first network node and the second network node, wherein the microservice comprises a function as a service (FaaS); validating, by the authentication node, the request to determine whether the request satisfies the first and second validation parameters; and controlling, by the authentication node, access to the microservice based on the validating.
7 . The non-transitory machine-readable medium of claim 6 , wherein the identifying a first validation parameter of the first network node comprises parsing code of the first network node.
8 . The non-transitory machine-readable medium of claim 7 , wherein the identifying a second validation parameter of the second network node comprises parsing code of the second network node.
9 . The non-transitory machine-readable medium of claim 6 , wherein the operations further comprise:
instantiating the first network node in the network, wherein the instantiating the first network node is responsive to a determination that the request satisfies the first validation parameter and the second validation parameter; instantiating the second network node in the network, wherein the instantiating the second network node is responsive to the determination that the request satisfies the first validation parameter and the second validation parameter; and directing the request to access the microservice based on the instantiating the first network node and the instantiating the second network node.
10 . The non-transitory machine-readable medium of claim 9 , wherein the operations further comprise:
determining an expected travel time in the network for providing a response to the request; determining that an actual travel time for the request in the network exceeds the expected travel time; and terminating the request based on the actual travel time exceeding the expected travel time.
11 . The non-transitory machine-readable medium of claim 10 , wherein the operations further comprise:
identifying a source of the request; and blocking future requests from the source of the request.
12 . The non-transitory machine-readable medium of claim 6 , wherein the operations further comprise:
determining the request does not satisfy at least one of the first validation parameter and the second validation parameter, invalidating the request; and rejecting the request based on the invalidating the request.
13 . The non-transitory machine-readable medium of claim 6 , wherein the identifying a first validation parameter comprises determining the first validation parameter comprises a message format and wherein the identifying a second validation parameter comprises determining the second validation parameter comprise a message format.
14 . The non-transitory machine-readable medium of claim 6 , wherein the identifying a first validation parameter comprises determining the first validation parameter comprises a message length and wherein the identifying a second validation parameter comprises determining the second validation parameter comprise a message length.
15 . A method, comprising:
identifying, by a processing system including a hardware processor, a first validation parameter of a first network node of a network; identifying, by the processing system, a second validation parameter of a second network node in the network; creating, by the processing system, an authentication node based on the first validation parameter and the second validation parameter; receiving, by the processing system, a request to access a microservice that utilizes the first network node and the second network node; determining, by the processing system, whether the request satisfies the first validation parameter and the second validation parameter; and controlling, by the processing system, access to the first network node and the second network node for the microservice based on the determining whether the request satisfies the first validation parameter and the second validation parameter.
16 . The method of claim 15 , wherein the identifying a first validation parameter of the first network node comprises:
determining, by the processing system, that the first validation parameter comprises a message format.
17 . The method of claim 15 , wherein the identifying a second validation parameter of the second network node comprises:
determining, by the processing system, that the second validation parameter comprises an authentication parameter.
18 . The method of claim 15 , further comprising:
measuring, by the processing system, an amount of time associated with the request to access the microservice.
19 . The method of claim 15 , comprising:
terminating, by the processing system, access to the microservice based on the amount of time exceeding a predetermined access time threshold.
20 . The method of claim 15 , wherein the predetermined access time threshold is based upon an expected amount of time for performing the microservice.Join the waitlist — get patent alerts
Track US2022086164A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.