Nova Patents
EP2328107A2

Identity controlled data center

Abstract

Techniques for identity controlled data centers are provided. Remote processing environments are authenticated via identity associations (160). Virtual remote processing environments are subsequently installed and authenticated (320) on the remote processing environments on which they are deployed and they receive unique virtual remote processing environment identities, which are locally and independently assigned within their remote processing environments (170). Applications deployed (171) to the virtual remote processing environments are also authenticated and acquire identities (540) for the virtual remote processing environments in which they are deployed. The processing of the remote virtual processing environments and the applications are circumscribed by independently acquired policies (162,550) within the remote processing environments.

Term

1 yearto projected expiry

Projected expiry 27 September 2027, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

16 claims: 5 independent, 11 dependent

  1. c-en-0001
    A computer-implemented method, comprising:sending (110) data to a remote identity service associated with a remote processing environment;receiving (120) an encrypted version of the data from the remote identity service;decrypting (130) the encrypted version to verify the data;establishing (140) a secure channel with the remote identity service when the encrypted version is verified;acquiring (150) operating metadata unique to the remote processing environment via the secure channel;and transmitting (160) a unique identity for the remote processing environment for subsequent authentication and deployment of policy restrictions within the remote processing environment, wherein decrypting (130) further comprises using (131) a public key associated with a secure device, which is located in the remote processing environment, to decrypt the encrypted version, wherein the private key is known to just the secure device and previously used by the secure device to produce the encrypted version, and the private key is not transmitted or communicated from the secure device to the remote identity service, and wherein the secure device supplies the encrypted version to the remote identity service for delivery.
  2. c-en-0006
    A computer-implemented method, comprising:requesting (310) a temporary access token from an identity service;and sending (320) a request to establish a remote virtual processing environment on an authenticated remote processing environment, wherein the request includes the temporary access token, and wherein the temporary access token is supplied to a remote identity service located on the remote processing environment and the remote identity service contacts the identity service to authenticate the temporary access token, and wherein when authenticated the remote identity service and a service provider of the remote virtual processing environment cooperate to establish a unique remote virtual processing environment identity for the remote virtual processing environment and to establish and enforce policy on the remote virtual processing environment within the remote processing environment.
  3. c-en-0008
    A computer-implemented method, comprising:receiving (510) a temporary access token, wherein the temporary access token is associated with a request to establish a virtual processing environment within a processing environment;requesting (520) verification of the temporary access token from a remote identity service;inspecting (520) a processing configuration for the virtual processing environment when the temporary access token is verified by the remote identity service;and supplying (540) a service provider of the virtual processing environment with a unique virtual processing environment identity to process within the processing environment.
  4. c-en-0015
    A system (600), comprising:an identity service (601);and an orchestration service (602), wherein the identity service is adapted to establish trust with a remote identity service associated with a remote processing environment and is adapted to provide a unique remote processing environment identity for the remote processing environment to use to communicate with the identity service, and wherein the orchestration service is adapted to communicate with the identity service to acquire a temporary access token to establish a remote virtual processing environment within the remote processing environment, and wherein the remote identity service further interacts with the identity service using the temporary access token to locally establish a unique remote virtual processing environment identity for use within the remote processing environment.
  5. c-en-0016
    A computer program which when executing on a computer or computer network performs the steps of any one of claims 1 to 5, 6 to 7 or 8 to 14.