IP Library › Granted Patent US 12,744,679
Granted Patent B2
US 12,744,679 · App. 17/947,957 · Granted Sep 22, 2026

Managing unique secrets in distributed systems

Inventors: Param Sharma (Haymarket, VA); Todd Cignetti (Ashburn, VA); Trevor Freeman (Sammamish, WA)
Assignee: Amazon Technologies, Inc.
H04L9/3268H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,679
App. No.
17/947,957
Granted
Sep 22, 2026
Kind
B2
Abstract

Approaches presented herein relate to the management of secure secrets in a distributed environment. In particular, various embodiments provide for the management of unique digital identities across multiple regions, where each region can include its own certificate authority. While these certificate authorities may operate independently, they can be part of a multi-primary system where unique identities and keys are stored redundantly across environments. In the event of a failure of a certificate authority in one region, another certificate authority in another region can continue security and authentication management, without a need to issue new identities or change operation of any of the regions. Parties to secure communications, such as application containers, can each receive their own unique identity which can be shared across various regions to allow related tasks (e.g., certificate issuance or revocation) to be performed identically from any of those regions.

Claims (50)

1 . A method, comprising:

generating, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;

providing the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;

initiating, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;

issuing, using the first secure token authority in the first region or the second secure token authority in the second region, a certificate associated with the unique identity; and

performing an authentication action on behalf of the resource instance using the certificate.

2 . The method according to claim 1 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.

3 . The method according to claim 2 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.

4 . The method according to claim 1 , wherein the resource instance is an application container in the first region.

5 . The method according to claim 1 , further comprising:

receiving, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;

authenticating, using a second certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and

storing information for the secure communication to a log in the second region that is available from the first region.

6 . The method according to claim 1 , further comprising:

sending the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein the transaction serial number will be unique both within and across regions.

7 . The method according to claim 1 , further comprising:

providing an interface to allow a user to specify one or more regions for which the unique identity is to be redundantly stored.

8 . The method according to claim 1 , wherein the first secure token authority and the second secure token authority operate independently as part of a multi-primary system, and are able to use the unique identity to perform one or more secure tasks in the first region and the second region.

9 . The method according to claim 1 , wherein the second secure token authority is able to revoke the certificate whether the certificate is issued by the first secure token authority or the second secure token authority.

10 . A system, comprising:

a processor; and

memory including instructions that, when executed by the processor, cause the system to:

generate, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;

provide the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;

initiate, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;

issue, using the first secure token authority in the first region, a certificate corresponding to the unique identity; and

revoke the certificate using the first secure token authority or the second secure token authority in the second region.

11 . The system according to claim 10 , wherein the instructions when executed further cause the system to:

receive, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;

authenticate, using a certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and

write information for the secure communication to a log in the second region that is available from the first region.

12 . The system according to claim 11 , wherein the resource instance is an application container in the first region.

13 . The system according to claim 11 , wherein the instructions when executed further cause the system to:

send the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein transaction serial numbers will be unique both within and across regions.

14 . The system according to claim 10 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.

15 . The system according to claim 14 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.

16 . A non-transitory computer-readable storage medium storing instructions that, when executed by a processor of a computing device, cause the computing device to:

generate, by a first secure token authority in a first region of a plurality of geographic regions, a unique identity for a resource instance in the first region, wherein the first secure token authority generates one or more unique identities for one or more resource instances in the first region and a second region of the plurality of geographic regions;

provide the unique identity to the resource instance, wherein the resource instance is authenticated using the unique identity;

initiate, by the first secure token authority, a transaction identified by a unique serial number to provide the unique identity to at least a second secure token authority in the second region;

issue, using the first secure token authority in the first region, a certificate corresponding to the unique identity; and

revoke the certificate using the first secure token authority or the second secure token authority in the second region.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein the instructions when executed further cause the computing device to:

receive, by the second secure token authority in the second region, a request to initiate a secure communication between the first resource instance in the first region and a second resource instance in the second region;

authenticate, using a certificate issued by the second secure token authority, the first resource instance using the unique identity stored redundantly in the second region; and

write information for the secure communication to a log in the second region that is available from the first region.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions when executed further cause the computing device to:

send the unique identity from the first region to the secure token authority in the second region using the transaction with the unique serial number dependent, at least in part, upon the first region from which the transaction was initiated, wherein transaction serial numbers will be unique both within and across regions.

19 . The non-transitory computer-readable storage medium of claim 16 , wherein the first secure token authority is a certificate authority, and wherein the unique identity is generated using a cryptographic key associated with the resource instance.

20 . The non-transitory computer-readable storage medium of claim 19 , wherein the cryptographic key is stored redundantly in at least the first region and the second region.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: SHARMA, PARAM; CIGNETTI, TODD; FREEMAN, TREVOR
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 061141/0006 →
Continuity (1)
Related Publication 20240097918A1 · Mar 21, 2024
References Cited (11)
US 9960923B2 · Zombik · 2018 [cited by applicant]
US 10063382B1 · Mehta et al. · 2018 [cited by applicant]
US 20040144840A1 · Lee · 2004 [cited by examiner]
US 20090210703A1 · Epstein · 2009 [cited by examiner]
US 20110078304A1 · Lee · 2011 [cited by examiner]
US 20140282922A1 · Iwanski · 2014 [cited by examiner]
US 20140359281A1 · Saboori · 2014 [cited by examiner]
US 20170012967A1 · Holloway · 2017 [cited by examiner]
US 20180287804A1 · Geisbush · 2018 [cited by examiner]
US 20230269099A1 · Medvinsky · 2023 [cited by examiner]
International Search Report and Written Opinion issued Sep. 20, 2023 in PCT Application No. PCT/US2023/067611. [cited by applicant]