发明名称 Securely connecting virtual machines in a public cloud to corporate resource
摘要 Securely connecting a virtual machine in a public cloud to corporate resources. A cloud computing system is coupled to an enterprise computing system via a network. The enterprise computing system includes a management server, an authentication server and a virtual private network (VPN) server. A cloud engine runs on the management server. The cloud engine starts an exchange with the authentication server that leads to a state in which both parties know a one-time password (OTP) and an identifier (ID) of a virtual machine (VM) hosted by the cloud computing system. The cloud engine sends the OTP and the ID to the VM. The VPN server then receives credentials from the VM. If the credentials are successfully authenticated against the OTP and the ID, a secure connection is established between the enterprise computing system and the VM.
申请公布号 US8863257(B2) 申请公布日期 2014.10.14
申请号 US201113045061 申请日期 2011.03.10
申请人 Red Hat, Inc. 发明人 Pal Dmitri V.
分类号 G06F7/04;H04L29/06;G06F21/44;H04L9/32 主分类号 G06F7/04
代理机构 Lowenstein Sandler LLP 代理人 Lowenstein Sandler LLP
主权项 1. A method, comprising: generating a one-time password (OTP) by one of a cloud engine of a private enterprise computing system or an authentication server, wherein the cloud engine is executable by a processing device; passing the OTP to the other one of the cloud engine and the authentication server; starting, by the cloud engine, an exchange with the authentication server to lead to a state in which both the cloud engine and the authentication server comprise an identifier (ID) of a virtual machine (VM), the VM hosted by a public cloud computing system coupled to the private enterprise computing system via a network; sending, by the private enterprise computing system, the OTP and the ID to the VM; creating an account at an account creation time before starting the VM; associating the OTP and the ID for the VM with the account; enabling the account at an account enablement time that is after the account creation time; receiving credentials of the VM and a request to access a virtual private network (VPN) server of the private enterprise computing system; authenticating the credentials of the VM against the OTP and the ID; and establishing, by the private enterprise computing system, a secure connection between the VPN server and the VM when the credentials received from the VM comprise the OTP and the ID.
地址 Raleigh NC US