WO2016183066A1

Password encryption for hybrid cloud services

Abstract

Methods, systems, computer-readable media, and apparatuses may provide password encryption for hybrid cloud services. A workspace cloud connector internally residing with an entity may intercept user credentials associated with an internal application being transmitted to an external cloud service. The workspace cloud connector may generate an encryption key and encrypt the user credentials via a reversible encryption methodology. The workspace cloud connector may encrypt the encryption key using an irreversible encryption methodology (e.g., use a hashing function to produce a first hash). The workspace cloud connector may transmit the encrypted user credentials and the first hash to a virtual delivery agent via a first path (e.g., via the external cloud service). In response, the workspace cloud connector may receive an address of the virtual delivery agent and, using the address, may send the encryption key to the virtual delivery agent via a second path different from the first path.

WO2016183066A1, drawing sheet 1
Sheet 1 of 9

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    We Claim:1. A system comprising: a gateway, within an internal cloud, configured to receive messages from a user device and configured to forward the messages to a computing device associated with an external cloud;and a workspace cloud connector communicatively coupled to the gateway, the workspace cloud connector configured to: intercept a first message of the messages being forwarded to the computing device associated with the external cloud, said intercepting based on the first message including user identity credentials for an internal application;generate an encryption key;encrypt the user identity credentials using the encryption key;generate a first hash of the encryption key;transmit a second message including the encrypted user identity credentials and the first hash of the encryption key to the computing device associated with the external cloud;in response to transmitting the second message including the encrypted user identity credentials and the first hash of the encryption key to the computing device associated with the external cloud, receive a routing address of a virtual delivery agent from the computing device associated with the external cloud;and transmit a third message including the encryption key and the routing address of the virtual delivery agent to the user device.
  2. 13
    An apparatus, within an internal cloud, comprising:a processor;and a computer readable medium storing instructions that, when executed by the processor, configure the apparatus to: intercept a first message being sent from a user device and to a computing device associated with an external cloud, said intercepting based on the first message including user identity credentials associated with an application;generate an encryption key;encrypt the user identity credentials using the encryption key;generate a first hash of the encryption key;transmit a second message including the encrypted user identity credentials and the first hash of the encryption key to the computing device associated with the external cloud;in response to transmitting the second message including the encrypted user identity credentials and the first hash of the encryption key to the computing device associated with the external cloud, receive a routing address of a virtual delivery agent from the computing device associated with the external cloud;and transmit a third message including the encryption key and the routing address of the virtual delivery agent to the user device.
  3. 17
    A method comprising:intercepting, by a computing device associated with an internal cloud, a first message being sent from a user device and to a computing device associated with an external cloud, said intercepting being based on the first message including user identity credentials associated with an internal application;extracting, by the computing device associated with the internal cloud, the user identity credentials included in the first message;generating, by the computing device associated with the internal cloud, a random logon ticket;encrypting, by the computing device associated with the internal cloud, the user identity credentials using the random logon ticket;generating, by the computing device associated with the internal cloud, a first hash of the random logon ticket;transmitting, by the computing device associated with the internal cloud and to the computing device associated with the external cloud, a second message including the encrypted user identity credentials and the first hash of the random logon ticket;in response to the transmitting, receiving, by the computing device associated with the internal cloud and from the computing device associated with the external cloud, a routing address of a virtual delivery agent;and transmitting, from the computing device associated with the internal cloud and to the user device, a third message including the random logon ticket and the routing address of the virtual delivery agent.