Techniques for secure access management in virtual environments
    1.
    发明授权
    Techniques for secure access management in virtual environments 有权
    在虚拟环境中进行安全访问管理的技术

    公开(公告)号:US08984621B2

    公开(公告)日:2015-03-17

    申请号:US12714452

    申请日:2010-02-27

    摘要: Techniques for secure access management to virtual environments are provided. A user authenticates to a portal for purposes of establishing a virtual machine (VM). The portal interacts with a cloud server and an identity server to authenticate the user, to acquire an Internet Protocol (IP) address and port number for the VM, and to obtain a secure token. The user then interacts with a secure socket layer virtual private network (SSL VPN) server to establish a SSL VPN session with the VM. The SSL VPN server also authenticates the token through the identity server and acquires dynamic policies to enforce during the SSL VPN session between the user and the VM (the VM managed by the cloud server).

    摘要翻译: 提供了对虚拟环境进行安全访问管理的技术。 为了建立虚拟机(VM),用户认证到门户。 门户与云服务器和身份服务器进行交互以验证用户,获取虚拟机的互联网协议(IP)地址和端口号,并获取安全令牌。 然后,用户与安全套接字层虚拟专用网(SSL VPN)服务器交互,以与VM建立SSL VPN会话。 SSL VPN服务器还通过身份服务器对令牌进行身份验证,并获取动态策略,以在用户与VM(由云端服务器管理的虚拟机)之间的SSL VPN会话期间执行。

    Techniques for managing a secure communication session
    2.
    发明授权
    Techniques for managing a secure communication session 有权
    用于管理安全通信会话的技术

    公开(公告)号:US08799640B2

    公开(公告)日:2014-08-05

    申请号:US12714451

    申请日:2010-02-27

    IPC分类号: H04L29/06 G06F9/00

    摘要: Techniques for managing a secure communication session are provided. A non-browser application utilizes a browser to establish a secure communication session with a server. The session cookie set in the browser is mapped by the server to a secret token that is supplied via the browser to the non-browser application. The browser is then closed and the secure communication session between the server and the non-browser application continues unabated via the secret token.

    摘要翻译: 提供了用于管理安全通信会话的技术。 非浏览器应用程序利用浏览器与服务器建立安全通信会话。 在浏览器中设置的会话cookie被服务器映射到通过浏览器提供给非浏览器应用程序的秘密令牌。 浏览器然后关闭,并且服务器和非浏览器应用程序之间的安全通信会话通过秘密令牌继续有增无减。

    DYNAMIC SERVICE ACCESS
    3.
    发明申请
    DYNAMIC SERVICE ACCESS 失效
    动态服务访问

    公开(公告)号:US20110296486A1

    公开(公告)日:2011-12-01

    申请号:US12787727

    申请日:2010-05-26

    IPC分类号: G06F21/00 G06F11/00 G06F15/16

    摘要: Apparatus, systems, and methods may operate to authenticate a desktop client to an identity service (IS), to receive a request, from an application, at the IS via the desktop client for a virtual service internet protocol (IP) address associated with a service. The IS may operate to build a routing token that includes an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the desktop client. After the routing token is validated, the application may be connected to the service via the desktop client. The application may comprise an e-mail application or a remote control application, such as a virtual network computing (VNC) application. Additional apparatus, systems, and methods are disclosed.

    摘要翻译: 装置,系统和方法可以操作以将身份服务(IS)的桌面客户端认证为从IS应用程序经由桌面客户端接收与一个虚拟服务网际协议(IP)地址相关联的虚拟服务网际协议(IP)地址的请求 服务。 当与IS相关联的策略允许通过与桌面客户端相关联的用户身份访问服务时,IS可以操作以构建包括与服务相关联的原始物理IP地址的路由令牌。 在验证路由令牌之后,应用程序可能通过桌面客户端连接到服务。 应用可以包括电子邮件应用或诸如虚拟网络计算(VNC)应用的远程控制应用。 公开了附加装置,系统和方法。

    IDENTITY DRIVEN PEER-TO-PEER (P2P) VIRTUAL PRIVATE NETWORK (VPN)
    4.
    发明申请
    IDENTITY DRIVEN PEER-TO-PEER (P2P) VIRTUAL PRIVATE NETWORK (VPN) 失效
    身份认同对等(P2P)虚拟私有网络(VPN)

    公开(公告)号:US20100154050A1

    公开(公告)日:2010-06-17

    申请号:US12334809

    申请日:2008-12-15

    IPC分类号: G06F9/00

    摘要: Techniques for identity-based Peer-to-Peer (P2P) Virtual Private Networks (VPN's) are provided. First and second principals authenticate to a trusted third party. The first principal subsequently requests a P2P VPN with the second principal. The second principal is contacted on behalf of the first principal and permission is acquired. The first and second principals are then sent commands to directly establish a P2P VPN communication session with one another.

    摘要翻译: 提供了基于身份的对等(P2P)虚拟专用网(VPN)技术。 第一位和第二位负责人向受信任的第三方进行身份验证。 随后,第一个主体向第二个委托人请求了一个P2P VPN。 第二名委托人代表第一委托人联系,并获得许可。 然后发送第一和第二主体以直接建立彼此的P2P VPN通信会话命令。

    Identity driven peer-to-peer (P2P) virtual private network (VPN)
    6.
    发明授权
    Identity driven peer-to-peer (P2P) virtual private network (VPN) 失效
    身份驱动的对等(P2P)虚拟专用网(VPN)

    公开(公告)号:US08683574B2

    公开(公告)日:2014-03-25

    申请号:US12334809

    申请日:2008-12-15

    IPC分类号: H04L29/00

    摘要: Techniques for identity-based Peer-to-Peer (P2P) Virtual Private Networks (VPN's) are provided. First and second principals authenticate to a trusted third party. The first principal subsequently requests a P2P VPN with the second principal. The second principal is contacted on behalf of the first principal and permission is acquired. The first and second principals are then sent commands to directly establish a P2P VPN communication session with one another.

    摘要翻译: 提供了基于身份的对等(P2P)虚拟专用网(VPN)技术。 第一位和第二位负责人向受信任的第三方进行身份验证。 随后,第一个主体向第二个委托人请求了一个P2P VPN。 第二名委托人代表第一委托人联系,并获得许可。 然后发送第一和第二主体以直接建立彼此的P2P VPN通信会话命令。

    SECURE NETWORK COMMUNICATIONS
    7.
    发明申请
    SECURE NETWORK COMMUNICATIONS 有权
    安全网络通信

    公开(公告)号:US20100211780A1

    公开(公告)日:2010-08-19

    申请号:US12388658

    申请日:2009-02-19

    IPC分类号: H04L9/00

    摘要: Apparatus, systems, and methods may operate to establish a secure communications tunnel between a server node and a client node, and to receive user requests from the client node at the server node via the secure communications tunnel. The user requests may be received in conjunction with a device verification token derived from nonces generated by the server node and transmitted to the client node as part of keep-alive response messages. The nonces may change according to a period of time established by the server node. Additional apparatus, systems, and methods are disclosed.

    摘要翻译: 设备,系统和方法可以操作以在服务器节点和客户机节点之间建立安全通信隧道,并且经由安全通信隧道从服务器节点处的客户端节点接收用户请求。 用户请求可以结合从由服务器节点生成的随机数导出的设备验证令牌被接收,并且作为保持活动响应消息的一部分被发送到客户端节点。 随机数可以根据由服务器节点建立的时间段而改变。 公开了附加装置,系统和方法。

    TECHNIQUES FOR NON REPUDIATION OF STORAGE IN CLOUD OR SHARED STORAGE ENVIRONMENTS
    8.
    发明申请
    TECHNIQUES FOR NON REPUDIATION OF STORAGE IN CLOUD OR SHARED STORAGE ENVIRONMENTS 有权
    无法在云存储或共享存储环境中存储的技术

    公开(公告)号:US20120297183A1

    公开(公告)日:2012-11-22

    申请号:US13108094

    申请日:2011-05-16

    IPC分类号: H04L9/32

    摘要: Techniques for non-repudiation of storage in cloud or shared storage environments are provided. A unique signature is generated within a cloud or shared storage environment for each file of the storage tenant that accesses the cloud or shared storage environment. Each signature is stored as part of the file system and every time a file is accessed that signature is verified. When a file is updated, the signature is updated as well to reflect the file update.

    摘要翻译: 提供了在云或共享存储环境中不可否认存储的技术。 在云或共享存储环境中为访问云或共享存储环境的存储租户的每个文件生成唯一的签名。 每个签名作为文件系统的一部分存储,并且每次访问该文件时,签名都被验证。 更新文件时,还会更新签名以反映文件更新。

    Techniques for secure network communication
    9.
    发明授权
    Techniques for secure network communication 有权
    安全网络通信技术

    公开(公告)号:US08301876B2

    公开(公告)日:2012-10-30

    申请号:US12121843

    申请日:2008-05-16

    IPC分类号: H04L29/06

    摘要: Techniques for secure network communication are provided. Credentials for a user along with a transparently generated secret are sent to a resource that the user desires to establish a secure communication session with. After successful authentication of the user, an initial sequence number for a first transaction of the session is set on a client of the user. Thereafter, with each transaction of the session the client supplies a new and unique sequence number to a server of the resource and uses the secret to encode and validate that transaction. The server of the resource does not permit any transaction that includes an invalid or previously used sequence number.

    摘要翻译: 提供了用于安全网络通信的技术。 将用户的凭证以及透明生成的秘密发送到用户希望与之建立安全通信会话的资源。 在用户成功认证之后,在用户的客户端上设置用于会话的第一事务的初始序列号。 此后,对于会话的每个事务,客户端向资源的服务器提供新的和唯一的序列号,并使用秘密对该事务进行编码和验证。 资源的服务器不允许包含无效或先前使用的序列号的任何事务。

    Techniques for non repudiation of storage in cloud or shared storage environments
    10.
    发明授权
    Techniques for non repudiation of storage in cloud or shared storage environments 有权
    在云或共享存储环境中不可否认存储的技术

    公开(公告)号:US08544070B2

    公开(公告)日:2013-09-24

    申请号:US13108094

    申请日:2011-05-16

    IPC分类号: G06F7/04

    摘要: Techniques for non-repudiation of storage in cloud or shared storage environments are provided. A unique signature is generated within a cloud or shared storage environment for each file of the storage tenant that accesses the cloud or shared storage environment. Each signature is stored as part of the file system and every time a file is accessed that signature is verified. When a file is updated, the signature is updated as well to reflect the file update.

    摘要翻译: 提供了在云或共享存储环境中不可否认存储的技术。 在云或共享存储环境中为访问云或共享存储环境的存储租户的每个文件生成唯一的签名。 每个签名作为文件系统的一部分存储,并且每次访问该文件时,签名都被验证。 更新文件时,还会更新签名以反映文件更新。