IP Library › Granted Patent US 12,204,631
Granted Patent B2
US 12,204,631 · App. 17/855,890 · Granted Jan 21, 2025

Distributed quorum authorization enforcement through an API gateway

Inventors: Devesh Kumar Tewari (Noida, IN); Amit Sinha (Pradesh, IN)
Assignee: THALES DIS CPL USA, INC.
G06F21/40G06F21/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,631
App. No.
17/855,890
Filed
Jul 1, 2022
Granted
Jan 21, 2025
Kind
B2
Art Unit
2439
USPC
726/4
Abstract

In one embodiment a Hardware Server Module (HSM) ( 10 ) implementing a distributed quorum authentication enforcement is provided, whereby user access to a resource ( 40 ) on the device ( 10 ) is enforced via an API gateway ( 16 ). The HSM comprises one or more resources, a separate resource manager API for accessing the one or more resources, an enforcement module for enforcing access to the one or more resources via the API gateway according to a quorum policy, and a quorum manager for generating and storing a quorum request in a database. The API gateway ( 16 ) can be a RESTful API using HTTP requests to produce and consume data related to quorum services via at least one of a GET, PUT, POST, PATCH and DELETE command type. Other embodiments are disclosed.

Claims (60)

1. A computer implemented method for distributed quorum authentication enforcement of a Hardware Security Module (HSM) device, whereby when a user accesses a resource on the HSM device that user's access is enforced within a quorum expiry period via the Applications Programming interface (API) gateway responsive to real time authentication of administrators remotely working in coherence with access to a shared secret for authorizing HSM operations needing simultaneous approval, characterized in that the method comprises the steps of,

in a quorum creation event stage:

creating a quorum request when an operation on said resource is attempted that requires quorum authorization, by:

inquiring a quorum policy if a quorum is required to access said resource;

generating the quorum request in accordance with said quorum policy and storing it in a database thereby attaching it to said resource,

generating a quorum identifier (ID) to associate with said resource included in the quorum request;

responsive to said creating of said quorum request, informing said administrators to each provide an approval status for said quorum request in real time via said API gateway;

in a quorum approval event stage:

responsive to receiving said approval status from said administrators working in coherence to complete the shared secret for said HSM operational requirements via said API gateway within said quorum expiry period, validating said administrators are authorized to approve said quorum request,

if validated, updating a voting count on the quorum request in a database; and

informing said user via said API gateway of said approval status, and enforcing an access to said resource in accordance with said quorum policy and updated quorum request,

wherein said quorum request includes said quorum ID, an approval threshold, a voting count, the quorum expiry period, and an approval status.

2. The method of claim 1 further comprising,

in a quorum data retrieval event stage, via said API gateway

checking whether said an administrators are allowed to access said quorum id; and

providing details of said quorum request to said administrators via said API gateway.

3. The method of claim 1 further comprising,

in a quorum application event stage, via said API gateway:

checking whether said administrators are allowed to access said quorum id;

retrieving details of said quorum request; and

if an approval threshold is met in view of said voting count and within said quorum expiry period, updating said approval status to indicate quorum is approved for said resource, and committing said approval status in said database for said quorum request.

4. The method of claim 1 is performed by a hardware processor executing computer program code instructions from an electronic memory to execute at least said method steps.

5. The method of claim 1 , wherein said operation on said resource comprises one among update, view, modify, copy or delete.

6. The method of claim 1 , wherein said API gateway is in an architectural style of a RESTful API using HTTP requests to produce and consume data related to quorum services via at least one of a GET, PUT, POST, PATCH and DELETE command type.

7. A Hardware Security Module (HSM) device implementing a distributed quorum authentication enforcement through a API gateway, whereby when a user accesses a resource on the HSM device, that user's access is enforced within a quorum expiry period via the Applications Programming interface (API) gateway responsive to real time authentication of administrators remotely working in coherence with access to a shared secret for authorizing HSM operations needing simultaneous approval, characterized in that the HSM comprises:

one or more resources;

a resource manager API for accessing said one or more resources;

an enforcement module for enforcing access to said one or more resources via said API gateway according to a quorum policy; and

a quorum manager for generating and storing a quorum request in a database,

wherein

in a quorum creation event stage:

said enforcement module inquires a quorum policy if a quorum is required to access said resource;

said quorum manager creates a quorum request when an operation on said resource 40 is attempted that requires quorum authorization, by:

generating the quorum request in accordance with said quorum policy and storing it in a database thereby attaching it to said resource,

generating a quorum identifier (ID) to associate with said resource included in the quorum request;

responsive to said creating of said quorum request, said resource manager API informs administrators to each provide an approval status for said quorum request via said API gateway;

in a quorum approval event stage:

responsive to receiving said approval status from said administrators working in coherence to complete the shared secret for said HSM operational requirements via said API gateway within said quorum expiry period, said quorum manager validates said administrators are authorized to approve said quorum request,

if validated, updates a voting count on the quorum request in a database; and

informs said user via said API gateway of said approval status, and enforcement module enforces an access to said resource in accordance with said quorum policy and updated quorum request,

wherein said quorum request includes said quorum ID, an approval threshold, a voting count, the quorum expiry period, and an approval status.

8. The HSM of claim 7 wherein during said quorum creation event stage:

said API gateway sends access token to quorum manager to validate whether the user is authentic and exists;

said quorum manager validates said user and sends user identity to said API gateway, which checks internal rules to determine to which micro-service of said resource manager API to send the quorum request and invoke appropriate resource manager API with name of said user.

9. The HSM of claim 8 , wherein

said resource manager API consults Enforcement module to determine if the user is authorized to perform requested operation;

said enforcement module reads internal authorization policy from database, and determines from said quorum policy if the operation requires a quorum before a configuration change is committed on said resource; and

said resource manager API prepares a quorum request and sends request to Quorum manager to generate a quorum request along with required data to store in database.

10. The HSM of claim 9 , wherein

said Quorum manager creates said quorum identifier for said quorum request and stores data associated with the quorum request in the database;

said Quorum manager returns the generated quorum identifier to resource manager API to the user through API gateway.

11. The HSM of claim 7 wherein, during the quorum approval event stage, each administrator votes to approve or deny a quorum request if they are authorized, whereby:

said API gateway requests HSM to approve the quorum with quorum identifier and authorize a token that validates the administrator;

said API gateway forwards the request to quorum management module to determine if the user is allowed to invoke resources API and respond whether the user is authorized or not.

12. The HSM of claim 11 wherein

said quorum manager reads details of the quorum request from database, then consults enforcement module if the administrator has authorization to approve the request;

said enforcement module reads the authorization for the quorum policy 51 from database and responds back to quorum manager, and

if the administrator is authorized, the quorum manager increases an approval count of the quorum request and stores this information as an entry in database, and

responds back to the administrator through API gateway to confirm or deny the user approval, wherein once a required approval has been received, the user can invoke resources API to apply configuration changes on said HSM.

13. The HSM of claim 11 further comprising at least one hardware processor executing computer program code instructions from an electronic memory to execute processes of at least one microservice running in an operating system of said HSM to support operation of said resources, resource manager API, said enforcement module, and said quorum manager.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2024
From: THALES DIS TECHNOLOGY INDIA PRIVATE LIMITED
To: THALES DIS CPL USA, INC.
Reel/Frame 069547/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: TEWARI, DAVESH KUMAR; SINHA, AMIT
To: THALES DIS TECHNOLOGY INDIA PRIVATE LIMITED
Reel/Frame 060791/0926 →
Continuity (1)
Related Publication 20240004983A1 · Jan 4, 2024
References Cited (32)
US 8745379B2 · Orsini et al. · 2014 [cited by applicant]
US 9866392B1 · Campagna · 2018 [cited by examiner]
US 10291622B1 · Rossman · 2019 [cited by examiner]
US 10523716B1 · Stickle et al. · 2019 [cited by applicant]
US 10581924B2 · Gaddam et al. · 2020 [cited by applicant]
US 10693638B1 · Cignetti · 2020 [cited by examiner]
US 10747635B1 · Trachtman · 2020 [cited by examiner]
US 10885220B2 · Sharma et al. · 2021 [cited by applicant]
US 11019068B2 · Rossman et al. · 2021 [cited by applicant]
US 11082235B2 · Monica et al. · 2021 [cited by applicant]
US 11096052B2 · Gaudet et al. · 2021 [cited by applicant]
US 11568038B1 · Kulkarni · 2023 [cited by examiner]
US 11914696B1 · Saxe · 2024 [cited by examiner]
US 20070250920A1 · Lindsay · 2007 [cited by applicant]
US 20070261103A1 · Viavant · 2007 [cited by examiner]
US 20130291056A1 · Gaudet et al. · 2013 [cited by applicant]
US 20150378842A1 · Tomlinson et al. · 2015 [cited by applicant]
US 20160359838A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20170142579A1 · Gaudet et al. · 2017 [cited by applicant]
US 20180183810A1 · Jones · 2018 [cited by examiner]
US 20190173853A1 · Hasek et al. · 2019 [cited by applicant]
US 20190268165A1 · Monica et al. · 2019 [cited by applicant]
US 20190372779A1 · Monica · 2019 [cited by examiner]
US 20200196145A1 · Gaudet · 2020 [cited by examiner]
US 20200401325A1 · Lamba · 2020 [cited by examiner]
US 20210056540A1 · McCauley · 2021 [cited by examiner]
US 20220141014A1 · Britto · 2022 [cited by examiner]
US 20220164190A1 · Suurkivi et al. · 2022 [cited by applicant]
US 20220327525A1 · Tsitrin · 2022 [cited by examiner]
US 20230273726A1 · Jagannati · 2023 [cited by examiner]
EP 3429156A1 · 2019 [cited by applicant]
International Search Report (PCT/ISA/2010) & Written Opinion (PCT/ISA/237) mailed by ISA/EP on Oct. 19, 2023 2023 for corresponding International Application pursuant to the PCT, N°PCT/US2023/026391 (14 pages). [cited by applicant]