Nova Patents
US20080098457A1

Identity controlled data center

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Techniques for identity controlled data centers are provided. Remote processing environments are authenticated via identity associations. Virtual remote processing environments are subsequently installed and authenticated on the remote processing environments on which they are deployed and they receive unique virtual remote processing environment identities, which are locally and independently assigned within their remote processing environments. Applications deployed to the virtual remote processing environments are also authenticated and acquire identities for the virtual remote processing environments in which they are deployed. The processing of the remote virtual processing environments and the applications are circumscribed by independently acquired policies within the remote processing environments.

US20080098457A1, drawing sheet 1
Sheet 1 of 7

Term

4.1 yearsto projected expiry

Projected expiry 24 October 2030, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

29 claims: 4 independent, 25 dependent

  1. 1
    Broadest claimClaim Score 73, broad(NHIP)A method, comprising:sending data to a remote identity service associated with a remote processing environment;receiving an encrypted version of the data from the remote identity service;decrypting the encrypted version to verify the data;establishing a secure channel with the remote identity service when the encrypted version is verified;acquiring operating metadata unique to the remote processing environment via the secure channel;and transmitting a unique identity for the remote processing environment for subsequent authentication and deployment of policy restrictions within the remote processing environment.
  2. 12
    A method, comprising:requesting a temporary access token from an identity service;and sending a request to establish a remote virtual processing environment on an authenticated remote processing environment, wherein the request includes the temporary access token, and wherein the temporary access token is supplied to a remote identity service located on the remote processing environment and the remote identity service contacts the identity service to authenticate the temporary access token, and wherein when authenticated the remote identity service and a service provider of the remote virtual processing environment cooperate to establish a unique remote virtual processing environment identity for the remote virtual processing environment and to establish and enforce policy on the remote virtual processing environment within the remote processing environment.
  3. 15
    A method, comprising:receiving a temporary access token, wherein the temporary access token is associated with a request to establish a virtual processing environment within a processing environment;requesting verification of the temporary access token from a remote identity service;inspecting a processing configuration for the virtual processing environment when the temporary access token is verified by the remote identity service;and supplying a service provider of the virtual processing environment with a unique virtual processing environment identity to process within the processing environment.
  4. 24
    A system, comprising:an identity service;and an orchestration service, wherein the identity service is to establish trust with a remote identity service associated with a remote processing environment and is to provide a unique remote processing environment identity for the remote processing environment to use to communicate with the identity service, and wherein the orchestration service is to communicate with the identity service to acquire a temporary access token to establish a remote virtual processing environment within the remote processing environment, and wherein the remote identity service further interacts with the identity service using the temporary access token to locally establish a unique remote virtual processing environment identity for use within the remote processing environment.