发明名称 IDENTITY AND ACCESS MANAGEMENT-BASED ACCESS CONTROL IN VIRTUAL NETWORKS
摘要 Methods and apparatus for providing identity and access management-based access control for connections between entities in virtual (overlay) network environments. At the encapsulation layer of the overlay network, an out-of-band connection creation process may be leveraged to enforce access control and thus allow or deny overlay network connections between sources and targets according to policies. For example, resources may be given identities, identified resources may assume roles, and policies may be defined for the roles that include permissions regarding establishing connections to other resources. When a given resource (the source) attempts to establish a connection to another resource (the target), role(s) may be determined, policies for the role(s) may be identified, and permission(s) checked to determine if a connection from the source to the target over the overlay network is to be allowed or denied.
申请公布号 CA2933056(A1) 申请公布日期 2015.06.18
申请号 CA20142933056 申请日期 2014.12.11
申请人 AMAZON TECHNOLOGIES, INC. 发明人 RYLAND, MARK
分类号 G06F15/173;G06F9/455 主分类号 G06F15/173
代理机构 代理人
主权项
地址