Methods for selectively controlling access to resources in a multi-node system
Methods are disclosed for selectively controlling access to a resource that is accessible to multiple nodes in a multi-node system or multiple processors in a multi-processor system to prevent hackers, malware, and ransomware attacks. The multi-node or multi-processor systems receive both matching and non-duplicated requests. In operation, each node or processor receives either a matching or non-duplicated request to access the resource. For the matching request, indicia of the request to access the resource is computed at each node or processor and is then compared between nodes or processors. Access to the resource is given to a node or processor when the computed indicia matches. For the non-duplicated request, a determination is made as to whether direct access to the resource is authorized for the request, and, if direct access is authorized, access to the resource is given to a node or processor.
1 . A method for selectively controlling access to resources in a multi-node system that receives both matching and non-duplicated requests, each node including (i) a processor and (ii) an indicia engine, each node having access to a resource that is accessible to the processor, the method comprising:
(a) receiving at at least one of the nodes a request to access the resource, wherein the request to access the resource is either:
(i) a matching request received by two or more nodes, or
(ii) a non-duplicated request received by at least one of the nodes to access the resource;
(b) when the request to access the resource is a non-duplicated request, determining whether direct access to the resource is authorized for the request;
(c) when the request to access the resource is a matching request, the indicia engine at each node:
(i) computes indicia of the request to access the resource,
(ii) exchanges its computed indicia of the request to access the resource with at least one other node, and
(iii) compares its computed indicia of the request to access the resource with the computed indicia of the request to access the resource received from the at least one other node; and
(d) processing in the processor in at least one of the nodes the request to access the resource when direct access is authorized for the request in step (b), or the result of the comparison in step
(c) indicates that the computed indicia of the request to access the resource matches the computed indicia of the request to access the resource received from at least one other node,
wherein the request to access to the resource is blocked when the request to access the resource in a non-duplicated request is determined to not be authorized for direct access, or when the request to access the resource is a matching request and the result of the comparison in step (c) indicates that the computed indicia of the request to access the resource does not match the computed indicia of the request to access the resource received from at least one other node.
2 . The method of claim 1 wherein the resource is a database.
3 . The method of claim 2 wherein the request to access the database is an open or read request.
4 . The method of claim 2 wherein the receiving in step (a) is via a before trigger on the database.
5 . The method of claim 1 further comprising:
(e) responding to the request to access the resource by taking an action other than processing the request to access the resource when the request to access the resource is a non-duplicated request and when direct access is not authorized for the request in step (c).
6 . The method of claim 5 wherein the action is one or more of responding with null data, responding with redacted data, responding with intentionally corrupted data, shutting down one or more of the nodes or databases, or redirecting the request to access the resource to another resource.
7 . The method of claim 1 wherein the multi-node system consists of two nodes.
8 . The method of claim 1 wherein the resource is a shared resource that is external to the multi-node system.
9 . The method of claim 1 wherein the resource is a hardware device.
10 . The method of claim 1 wherein matching requests either include or lack an indicator identifying the request as a matching request, and non-duplicated requests either include or lack an indicator identifying the request as a non-duplicated request, the method further comprising:
(e) the nodes using the indicator or lack thereof to determine whether to process a received request as either a matching request or a non-duplicated request.
11 . The method of claim 1 wherein each of the nodes further include (iii) a gateway having a first access method for receiving requests to access a resource from the transaction distributor, and a second access method for receiving requests to access a resource from sources other than the transaction distributor, the method further comprising:
(e) the nodes using a detected access method of the gateway to determine whether to process a received request as either a matching request or a non-duplicated request.
12 . A method for selectively controlling access to resources in a multi-node system that receives both matching and non-duplicated requests, the nodes including processing nodes and a comparison node, each processing node including (i) a processor, a program executing in the processor, and (ii) an indicia engine, each processing node having access to a resource that is accessible to the processor, the method comprising:
(a) receiving at at least one of the processing nodes a request to access the resource, wherein the request to access the resource is either:
(i) a matching request received by two or more processing nodes to access the resource, or
(ii) a non-duplicated request received by at least one of the processing nodes to access the resource;
(b) when the request to access the resource is a non-duplicated request, determining whether direct access to the resource is authorized for the request;
(c) when the request to access the resource is a matching request, the indicia engine at each processing node:
(i) computes indicia of the request to access the resource, and
(ii) shares its computed indicia of the request to access the resource with the comparison node;
(d) comparing in a comparator at the comparison node the computed indicia of the request to access the resource from one of the processing nodes with the computed indicia of the request to access the resource received from the at least one other processing nodes; and
(e) processing in the program executing in the processor in at least one of the processing nodes the request to access the resource when direct access is authorized for the request in step (c), or the result of the comparison in step (d) indicates that the computed indicia of the request to access the resource from one of the processing nodes matches the computed indicia of the request to access the resource received from at least one other processing node,
wherein the request to access to the resource is blocked when the request to access the resource in a non-duplicated request is determined to not be authorized for direct access, or when the request to access the resource is a matching request and the result of the comparison in step (d) indicates that the computed indicia of the request to access the resource from one of the processing nodes does not match the computed indicia of the request to access the resource received from at least one other processing node.
13 . The method of claim 12 wherein the resource is a database.
14 . The method of claim 13 wherein the request to access the database is an open or read request.
15 . The method of claim 13 wherein the receiving in step (a) is via a before trigger on the database.
16 . The method of claim 12 further comprising:
(f) responding to the request to access the resource by taking an action other than processing the request to access the resource when the request to access the resource is a non-duplicated request and when direct access is not authorized for the request in step (b).
17 . The method of claim 16 wherein the action is one or more of responding with null data, responding with redacted data, responding with intentionally corrupted data, shutting down one or more of the nodes or databases, or redirecting the request to access the resource to another resource.
18 . The method of claim 12 wherein the multi-node system consists of two processing nodes and one comparison node.
19 . The method of claim 12 wherein the resource is a shared resource that is external to the multi-node system.
20 . The method of claim 12 wherein the resource is a hardware device.
21 . The method of claim 12 wherein matching requests either include or lack an indicator identifying the request as a matching request, and non-duplicated requests either include or lack an indicator identifying the request as a non-duplicated request, the method further comprising:
(f) the nodes using the indicator or lack thereof to determine whether to process a received request as either a matching request or a non-duplicated request.
22 . The method of claim 12 wherein each of the nodes further include (iii) a gateway having a first access method for receiving requests to access a resource from the transaction distributor, and a second access method for receiving requests to access a resource from sources other than the transaction distributor, the method further comprising:
(f) the nodes using a detected access method of the gateway to determine whether to process a received request as either a matching request or a non-duplicated request.