Multi-factor authentication of cloud-managed services
A cloud management system ( 180 ) only instructs a storage platform ( 100 ) in a private domain to implement an operation that reveals, modifies, or destroys data if an administrator ( 163 ) both provides valid credentials and is able to direct a services processing unit or SPU ( 120 ) in the private domain to send a message with valid contents and signature. An SPU ( 120 ) only performs operations that reveal, modify, or destroy data if signed instructions from the cloud management system ( 180 ) have originated or been relayed through a component ( 120 ) in the private domain. An attacker with access to the cloud management system ( 180 ) that does not also have access to a component ( 120 ) in the private domain is prevented from tampering with the storage platform ( 100 ).
1 . A process comprising:
receiving, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;
verifying, by the management system, the credentials of the administrator;
sending, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;
causing the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;
receiving, by the management system, a second message from the first SPU, the second message containing the first message;
verifying, by the management system, that the first SPU signed the second message and that the second message contains the first message; and
in response to the verification succeeding, sending, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.
2 . The process of claim 1 , wherein the first message is sent through a public network to the private network.
3 . The process of claim 2 , wherein the public network comprises the Internet.
4 . The process of claim 1 , further comprising:
constructing the instruction for the identified first SPU.
5 . The process of claim 4 , further comprising:
implementing the instruction in response to a validation process succeeding, the validation process comprising:
validating that the management system signed the third message;
extracting the second message from the third message; and
validating that the first SPU signed the second message.
6 . The process of claim 5 , wherein:
the first message contains a one-time code; and
the validation process further comprises extracting the first message from the extracted second message and verifying that the one-time code differs from prior one-time codes associated with operations the storage platform completed.
7 . The process of claim 5 , wherein:
the second message contains a time stamp; and
the validation process further comprises verifying that the time stamp corresponds to a time that differs from a current time by less than a threshold time difference.
8 . The process of claim 1 , wherein the storage platform is instructed to perform the operation only if the second message is verified to contain the first message signed by the management system.
9 . At least one processor comprising:
one or more processing units configured to:
receive, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;
verify, by the management system, the credentials of the administrator;
send, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;
cause the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;
receive, by the management system, a second message from the first SPU, the second message containing the first message;
verify, by the management system, that the first SPU signed the second message and that the second message contains the first message; and
in response to the verification succeeding, send, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.
10 . The at least one processor of claim 9 , wherein the first message is sent through a public network to the private network.
11 . The at least one processor of claim 10 , wherein the public network comprises the Internet.
12 . The at least one processor of claim 9 , wherein the one or more processing units are further configured to:
construct the instruction for the identified first SPU.
13 . The at least one processor of claim 12 , wherein the one or more processing units are further configured to:
implement the instruction in response to a validation process succeeding, the validation process comprising:
validating that the management system signed the third message;
extracting the second message from the third message; and validating that the first SPU signed the second message.
14 . The at least one processor of claim 13 , wherein:
the first message contains a one-time code; and
the validation process further comprises extracting the first message from the extracted second message and verifying that the one-time code differs from prior one-time codes associated with operations the storage platform completed.
15 . The at least one processor of claim 13 , wherein:
the second message contains a time stamp; and
the validation process further comprises verifying that the time stamp corresponds to a time that differs from a current time by less than a threshold time difference.
16 . The at least one processor of claim 9 , wherein the storage platform is instructed to perform the operation only if the second message is verified to contain the first message signed by the management system.
17 . A system comprising:
at least one processor; and
a memory coupled to the at least one processor, the memory storing instructions that, when executed by the at least one processor, cause the system to perform steps comprising:
receiving, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;
verifying, by the management system, the credentials of the administrator;
sending, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;
causing the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;
receiving, by the management system, a second message from the first SPU, the second message containing the first message;
verifying, by the management system, that the first SPU signed the second message and that the second message contains the first message; and
in response to the verification succeeding, sending, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.
18 . The system of claim 17 , wherein the first message is sent through a public network to the private network.
19 . The system of claim 18 , wherein the public network comprises the Internet.
20 . The system of claim 17 , wherein the memory storing instructions that, when executed by the at least one processor, further cause the system to perform steps comprising:
constructing the instruction for the identified first SPU.