IP Library Granted Patent US 10,958,444
Granted Patent B2
US 10,958,444 · App. 15/360,337 · Granted Mar 23, 2021

Uniquely identifying and securely communicating with an appliance in an uncontrolled network

Inventors: Rupinder Singh Gill (Robina, AU); Shravan Kumar Mettu (Redwood City, CA); Seetharama Sarma Ayyadevara (San Jose, CA)
Assignee: Akamai Technologies, Inc.
H04L9/3263H04L9/006H04L9/007H04L9/14H04L9/30H04L9/3247H04L63/0272H04L63/06H04L63/0815H04L63/0823H04L63/101H04L63/126H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,958,444
App. No.
15/360,337
Granted
Mar 23, 2021
Kind
B2
Abstract

A service consumer that utilizes a cloud-based access service provided by a service provider has associated therewith a network that is not capable of being controlled by the service provider. An enterprise connector is supported in this uncontrolled network, preferably as an appliance-based solution. According to this disclosure, the enterprise configures an appliance and then deploys it in the uncontrolled network. To this end, an appliance is required to proceed through a multi-stage approval protocol before it is accepted as a “connector” and is thus enabled for secure communication with the service provider. The multiple stages include a “first contact” (back to the service) stage, an undergoing approval stage, a re-generating identity material stage, and a final approved and configured stage. Unless the appliance passes through these stages, the appliance is not permitted to interact with the service as a connector. As an additional aspect, the service provides various protections for addressing scenarios wherein entities masquerade as approved appliances.

Claims (25)

1. A method of deploying an appliance in an untrusted network to interoperate with a cloud-based managed service providing secure enterprise access, wherein the appliance has an assigned initial cryptographic identity, comprising the ordered steps:

with the appliance positioned within the untrusted network and in an un-provisioned and un-approved state, receiving, by the cloud-based managed service, a certificate issued by a trusted Public Key Infrastructure (PKI) that includes a cryptographic identity having a digital signature from the PKI that confirms that the appliance is permitted to access the managed service;

upon verifying, by the cloud-based managed service, that the cryptographic identity is associated with a list of one or more appliances that are expected to be deployed in the untrusted network, returning to the appliance an indication that the appliance is approved to connect to the managed service;

with the appliance in an approved state, receiving, by the cloud-based managed service, a new certificate issued by the PKI that includes a new cryptographic identity;

upon verifying, by the cloud-based managed service, that the new cryptographic identity is associated with the list of one or more appliances that are expected to be deployed in the untrusted network, providing to the appliance an indication that the appliance is configured to use the managed service;

wherein following configuration of the appliance to use the managed service, blocking access to the managed service from the appliance except via the new certificate.

2. The method as described in claim 1 wherein the new cryptographic identity is obtained by the appliance after receipt of the indication and following execution at the appliance of an additional approval protocol.

3. The method as described in claim 2 wherein the additional approval protocol is carried out either manually or in an automated or programmatic manner.

4. The method as described in claim 1 wherein the cryptographic identity is a first universally unique identifier (UUID), and wherein the new cryptographic identify is a second UUID that differs from the first UUID.

5. The method as described in claim 4 wherein the cryptographic identity is generated by the PKI by binding the first UUID to a public key, the public key having an associated private key.

6. The method as described in claim 1 wherein the certificate is received from the appliance over a first cryptographically-secure communication link.

7. The method as described in claim 6 wherein the new certificate is received from the appliance over a second cryptographically-secure communication link that differs from the first cryptographically-secure communication link.

8. The method as described in claim 1 further including maintaining information about the appliance.

9. The method as described in claim 8 further including managing connectivity of the appliance to the managed service using the information.

10. The method as described in claim 8 wherein the information includes state information that defines one of: a provisioning state of the appliance, identity information identifying the appliance, and network information associated with the uncontrolled network.

11. The method as described in claim 1 further including:

detecting whether an entity attempting to access the managed service with a third certificate that includes a universally unique identifier (UUID) is an approved appliance; and

taking a given action with respect to the entity attempting to access the managed service with the third certificate.

12. The method as described in claim 11 wherein the given action is one of: approving the entity as a duplicate of the appliance, terminating a connection associated with the entity, and blocking all instances of any entity that presents the UUID.

13. The method as described in claim 1 wherein the managed service is associated with a content delivery network (CDN).

14. The method as described in claim 1 wherein the appliance is a virtual machine (VM).

15. The method as described in claim 1 wherein the new cryptographic identity has an associated private key that is only available locally to the appliance.

16. The method as described in claim 1 further including establishing a mutually-authenticated TLS connection to the appliance from the managed service.

17. The method as described in claim 1 wherein the PKI is associated with the managed service.

18. The method as described in claim 1 further including restricting access to the managed service by the appliance presenting the new certificate except through a predetermined Internet Protocol (IP) address range.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2017
From: GILL, RUPINDER SINGH; METTU, SHRAVAN KUMAR; AYYADEVARA, SEETHARAMA SARMA
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 041759/0032 →
MERGER Recorded Jan 25, 2017
From: SOHA SYSTEMS, INC.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 041076/0381 →
Continuity (2)
Provisional Application 62260035 · Nov 25, 2015
Related Publication 20170170973A1 · Jun 15, 2017
Cited By (1)
US 12,401,620