SOFTWARE AUTHENTICATION
According to an embodiment, a computing system includes a server configured to provide an authentication indicator to least one software application for enabling the software application to provide at least one computing feature. The authentication indicator is generated based on at least two identifiers that are distinct from a hardware identifier of a device on which a software application is running
1 . A computing system, comprising:
a server configured to provide an authentication indicator to least one software application for enabling the software application to provide at least one computing feature, the authentication indicator being generated with a content of the authentication indicator based on at least two identifiers that are distinct from a hardware identifier of a device on which the software application is running.
2 . The system of claim 1 , wherein the at least two identifiers are selected from
an Internet Protocol address of the device,
a domain name associated with the device,
a customer identifier associated with the device,
metadata associated with the device,
an Internet Protocol address associated with another application, and
a domain name associated with another application.
3 . The system of claim 1 , wherein the device is part of a cloud computing system.
4 . The system of claim 3 , wherein the application is running on at least one virtual machine instance on the device.
5 . The system of claim 1 , wherein the device comprises a plurality of computing devices.
6 . The system of claim 1 , wherein the software application utilizes the authentication indicator for confirming that the software application is valid.
7 . The system of claim 1 , comprising a plurality of applications that communicate with each other, the at least one software application controlling communications with a second one of the applications based on whether the second one of the applications provides a valid authentication indicator.
8 . The system of claim 1 , wherein the server is configured to:
provide the application with a key on a preselected schedule; and
verify an authenticity of the application based on whether the application provides a heartbeat message to the server that includes an indication based on the key.
9 . The system of claim 8 , wherein
each key provided by the server is different than a most recently provided key; and
the server provides an indication that the application is not authentic if the heartbeat message from the application does not include a proper indication based on the key.
10 . The system of claim 9 , wherein the server is configured to generate at least some of the keys using a random number generation process.
11 . A computing method, comprising:
generating an authentication indicator having a content based on at least two identifiers that are distinct from a hardware identifier of a device on which a software application is running; and
providing the authentication indicator to the software application for enabling the software application to provide at least one computing feature.
12 . The method of claim 11 , wherein the at least two identifiers are selected from
an Internet Protocol address of the device,
a domain name associated with the device,
a customer identifier associated with the device,
metadata associated with the device,
an Internet Protocol address associated with another application, and
a domain name associated with another application.
13 . The method of claim 11 , wherein the device is part of a cloud computing system.
14 . The method of claim 13 , comprising running the software application on at least one virtual machine instance on the device.
15 . The method of claim 11 , wherein the device comprises a plurality of computing devices.
16 . The method of claim 11 , comprising the software application using the authentication indicator for confirming that the software application is valid.
17 . The method of claim 11 , comprising
communicating between the at least one software application and at least a second application;
the at least one software application controlling communications with the second application based on whether the second application provides a valid authentication indicator; and
the second application controlling communications with the at least one software application based on whether the application provides a valid authentication indicator.
18 . The method of claim 11 , comprising:
providing the application with a key on a preselected schedule; and
verifying an authenticity of the application based on whether the application provides a heartbeat message to the server that includes an indication based on the key.
19 . The method of claim 18 , comprising
generating a new key that is different than a most recently provided key;
providing the new key to the application; and
providing an indication that the application is not authentic if the heartbeat message from the application does not include a proper indication of the provided new key.
20 . The method of claim 19 , comprising generating at least the new key using a random number generation process.
21 . The method of claim 11 , comprising
using a predetermined algorithm for generating the authentication indicator; and
using the two identifiers as an input to the predetermined algorithm.
22 . The method of claim 21 , wherein the predetermined algorithm includes using a concatenation of the two identifiers.
23 . The method of claim 11 , wherein
at least a portion of the two identifiers are within the authentication indicator;
at least a portion of the two identifiers are used for the authentication indicator; or
the authentication indicator includes at least a portion of the two identifiers.
24 . The computing system of claim 1 , wherein
the server is configured to use a predetermined algorithm for generating the authentication indicator; and
the server is configured to use the two identifiers as an input to the predetermined algorithm.
25 . The computing system of claim 24 , wherein the predetermined algorithm includes using a concatenation of the two identifiers.
26 . The computing system of claim 1 , wherein
at least a portion of the two identifiers are within the authentication indicator;
at least a portion of the two identifiers are used for the authentication indicator; or
the authentication indicator includes at least a portion of the two identifiers.