Nova Patents
EP2328107B1

Identity controlled data center

Abstract

This record has no abstract on file.

EP2328107B1, drawing sheet 1
Sheet 1 of 6

Term

1 yearleft in the term

Expires 27 September 2027.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

5 claims: 2 independent, 3 dependent

  1. 1
    A computer-implemented method, comprising:sending (110) data to a remote identity service associated with a remote processing environment;receiving (120) an encrypted version of the data from the remote identity service;decrypting (130) the encrypted version to verify the data;establishing (140) a secure channel with the remote identity service when the encrypted version is verified;acquiring (150) operating metadata unique to the remote processing environment via the secure channel;and generating (160) an identity for the remote processing environment that is unique to the remote processing environment based on the operating metadata that is unique to the remote processing environment, wherein the operating metadata includes an Internet Protocol (IP) subnet for the remote processing environment, an IP address for the remote processing environment, and disk or storage subsystem configuration settings for the remote processing environment, and wherein the identity for the remote processing environment is unique to a resource across a given context that the resource may engage in over a network, including a given service interaction, a given processing environment, or a given virtual processing environment, and transmitting (160) the unique identity to the remote identity service associated with the remote processing environment for subsequent authentication and deployment of policy restrictions within the remote processing environment, wherein decrypting (130) further comprises using (131) a public key associated with a secure device, which is located in the remote processing environment, to decrypt the encrypted version, wherein the private key is known to just the secure device and previously used by the secure device to produce the encrypted version, and the private key is not transmitted or communicated from the secure device to the remote identity service, and wherein the secure device supplies the encrypted version to the remote identity service for delivery, wherein transmitting further includes using the policy restrictions within the remote processing environment to distribute, clone, move, or terminate a virtual processing environment, the virtual processing environment is a software constructed sub processing environment that is carved from a portion of the remote processing environment.
  2. 5
    A computer program which when executing on a computer or computer network performs the steps of any one of claims 1 to 4.