发明名称 Identity and policy enforced inter-cloud and intra-cloud channel
摘要 Techniques for identity and policy enforced cloud communications are presented. Cloud channel managers monitor messages occurring within a cloud or between independent clouds. Policy actions are enforced when processing the messages. The policy actions can include identity-based restrictions and the policy actions are specific to the messages and/or clouds within which the messages are being processed.
申请公布号 US8806566(B2) 申请公布日期 2014.08.12
申请号 US201012727048 申请日期 2010.03.18
申请人 Novell, Inc. 发明人 Bergeson Bruce L.;McClain Carolyn B.;Carter Stephen R;Holm Vernon Roger
分类号 G06F17/00 主分类号 G06F17/00
代理机构 Schwegman, Lundberg & Woessner, P.A. 代理人 Schwegman, Lundberg & Woessner, P.A.
主权项 1. A method implemented in a non-transitory machine-readable storage medium and processed by one or more processors configured to perform the method, comprising: configuring a first process within a first cloud computing environment to manage select messages occurring within a communication channel within the first cloud computing environment, the communication channel is constructed within the first cloud environment based on a particular identifier that is associated with the select messages, and the communication channel is defined, identified, and communicated via a different communication channel that is used for some communication other than the communication channel that is to be monitored; instantiating the first cloud computing environment with the first process executing therein; and enforcing, by the first process, selective policy restrictions based on the select messages that enter and exit the communication channel, the first policy enforces the selective policy restrictions by consulting an identity service to obtain the selective policy restrictions and the policy restrictions include particular policies for the first process to authenticate the select messages based on: identities of senders of the selective messages, identities of receivers of the selective messages, identities for the selective messages, identities for other cloud computing environments that the selective messages originate from or are being directed to, and an identity for the first process.
地址 St. Paul MN US