Managing unique secrets in distributed systems
Approaches presented herein relate to the management of secure secrets in a distributed environment. In particular, various embodiments provide for the management of unique digital identities across multiple regions, where each region can include its own certificate authority. While these certificate authorities may operate independently, they can be part of a multi-primary system where unique identities and keys are stored redundantly across environments. In the event of a failure of a certificate authority in one region, another certificate authority in another region can continue security and authentication management, without a need to issue new identities or change operation of any of the regions. Parties to secure communications, such as application containers, can each receive their own unique identity which can be shared across various regions to allow related tasks (e.g., certificate issuance or revocation) to be performed identically from any of those regions.
1 . A method, comprising:
generating, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;
providing the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;
initiating, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;
issuing, using the first secure token authority in the first region or the second secure token authority in the second region, a certificate associated with the unique identity; and
performing an authentication action on behalf of the resource instance using the certificate.
2 . The method according to claim 1 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.
3 . The method according to claim 2 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.
4 . The method according to claim 1 , wherein the resource instance is an application container in the first region.
5 . The method according to claim 1 , further comprising:
receiving, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;
authenticating, using a second certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and
storing information for the secure communication to a log in the second region that is available from the first region.
6 . The method according to claim 1 , further comprising:
sending the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein the transaction serial number will be unique both within and across regions.
7 . The method according to claim 1 , further comprising:
providing an interface to allow a user to specify one or more regions for which the unique identity is to be redundantly stored.
8 . The method according to claim 1 , wherein the first secure token authority and the second secure token authority operate independently as part of a multi-primary system, and are able to use the unique identity to perform one or more secure tasks in the first region and the second region.
9 . The method according to claim 1 , wherein the second secure token authority is able to revoke the certificate whether the certificate is issued by the first secure token authority or the second secure token authority.
10 . A system, comprising:
a processor; and
memory including instructions that, when executed by the processor, cause the system to:
generate, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;
provide the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;
initiate, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;
issue, using the first secure token authority in the first region, a certificate corresponding to the unique identity; and
revoke the certificate using the first secure token authority or the second secure token authority in the second region.
11 . The system according to claim 10 , wherein the instructions when executed further cause the system to:
receive, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;
authenticate, using a certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and
write information for the secure communication to a log in the second region that is available from the first region.
12 . The system according to claim 11 , wherein the resource instance is an application container in the first region.
13 . The system according to claim 11 , wherein the instructions when executed further cause the system to:
send the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein transaction serial numbers will be unique both within and across regions.
14 . The system according to claim 10 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.
15 . The system according to claim 14 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.
16 . A non-transitory computer-readable storage medium storing instructions that, when executed by a processor of a computing device, cause the computing device to:
generate, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;
provide the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;
initiate, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;
issue, using the first secure token authority in the first region, a certificate corresponding to the unique identity; and
revoke the certificate using the first secure token authority or the second secure token authority in the second region.
17 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions when executed further cause the computing device to:
receive, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;
authenticate, using a certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and
write information for the secure communication to a log in the second region that is available from the first region.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions when executed further cause the computing device to:
send the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein transaction serial numbers will be unique both within and across regions.
19 . The non-transitory computer-readable storage medium of claim 16 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.