-
公开(公告)号:US20250068762A1
公开(公告)日:2025-02-27
申请号:US18946433
申请日:2024-11-13
Applicant: Google LLC
Inventor: Atul Goel , Diganta Paladhi , Manoj Sharma , Maurilio Cometto
IPC: G06F21/62
Abstract: The present disclosure describes an architecture and design of Unauthorized-Blocking-Role (UAB). UAB is a mechanism which prevents higher privileged users of cloud-hosted software from performing unauthorized activities on protected objects, such as management objects. UAB works by periodically monitoring the permissions of customer users on key management objects in an object hierarchy in management software. If a customer user is detected to have privileges higher than the user should have on those objects, UAB applies restrictive role-based access controls (RBACs) on the user. Similarly, UAB also monitors protected principals and protected roles to ensure that their privileges are not modified by a customer user.
-
公开(公告)号:US12175277B2
公开(公告)日:2024-12-24
申请号:US18517896
申请日:2023-11-22
Applicant: Google LLC
Inventor: Ilya Beyer , Manoj Sharma , Gururaj Pangal , Maurilio Cometto
Abstract: In one embodiment, a system includes first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines includes a resource manager that provides a public-cloud resource interface through which one or more public-cloud clients interact with one or more virtual machines, and second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines includes one or more private-cloud virtual machines, wherein at least one of the first host machines further includes a private-cloud VM resource provider through which the resource manager interacts with the private-cloud virtual machines, wherein the VM resource provider translates requests to perform virtual machine operations from a public-cloud-resource interface to a private-cloud virtual machine interface, and the private-cloud virtual machines perform the requested virtual machine operations in response to receiving the translated requests from the VM resource provider.
-
公开(公告)号:US11463306B2
公开(公告)日:2022-10-04
申请号:US17230920
申请日:2021-04-14
Applicant: Google LLC
Inventor: Manoj Sharma , Choudhury Sarada Prasanna Nanda , Gururaj Pangal , Maurilio Cometto , Ilya Beyer
Abstract: In one embodiment, a method includes a method for provisioning private-cloud server nodes by receiving a request to provision a specified number of server nodes for a private cloud, wherein the request is associated with a user, identifying a plurality of server nodes including (a) the specified number of hypervisor server nodes from a first pool that includes prepared hypervisor server nodes, each of which includes a previously-installed hypervisor, and (b) a management server node from a second pool that includes prepared management server nodes, each of which includes a previously-installed hypervisor and one or more previously-installed management components, configuring the identified server nodes to use a network associated with the user, creating a private cloud that includes the identified server nodes, and providing, to the user, permission to access the identified server nodes.
-
公开(公告)号:US20250094204A1
公开(公告)日:2025-03-20
申请号:US18964430
申请日:2024-11-30
Applicant: Google LLC
Inventor: Ilya Beyer , Manoj Sharma , Gururaj Pangal , Maurilio Cometto
Abstract: A system includes first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines includes a resource manager that provides a public-cloud resource interface through which one or more public-cloud clients interact with one or more virtual machines, and second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines includes one or more private-cloud virtual machines, wherein at least one of the first host machines further includes a private-cloud VM resource provider through which the resource manager interacts with the private-cloud virtual machines, wherein the VM resource provider translates requests to perform virtual machine operations from a public-cloud-resource interface to a private-cloud virtual machine interface, and the private-cloud virtual machines perform the requested virtual machine operations in response to receiving the translated requests from the VM resource provider.
-
公开(公告)号:US12158964B2
公开(公告)日:2024-12-03
申请号:US17497386
申请日:2021-10-08
Applicant: Google LLC
Inventor: Atul Goel , Diganta Paladhi , Manoj Sharma , Maurilio Cometto
Abstract: The present disclosure describes an architecture and design of Unauthorized-Blocking-Role (UAB). UAB is a mechanism which prevents higher privileged users of cloud-hosted software from performing unauthorized activities on protected objects, such as management objects. UAB works by periodically monitoring the permissions of customer users on key management objects in an object hierarchy in management software. If a customer user is detected to have privileges higher than the user should have on those objects, UAB applies restrictive role-based access controls (RBACs) on the user. Similarly, UAB also monitors protected principals and protected roles to ensure that their privileges are not modified by a customer user.
-
公开(公告)号:US12052254B2
公开(公告)日:2024-07-30
申请号:US17446751
申请日:2021-09-02
Applicant: Google LLC
Inventor: Manoj Sharma , Choudhury Sarada Prasanna Nanda , Ilya Beyer , Maurilio Cometto
CPC classification number: H04L63/102 , G06F11/3438 , G06F21/6281 , H04L63/108 , G06F2221/2141
Abstract: In one embodiment, a system includes a computing device providing a computing environment including a number of user accounts, where each of the user accounts is assigned specified privileges to execute particular commands or programs, receiving a request to temporarily escalate privileges for one of the user accounts during a specified duration, where the request includes an identifier of the user account, requested privileges, and the specified duration, granting the requested privileges for the specified duration in conjunction with specific restrictions on one or more prohibited activities that are normally permitted for user accounts with the requested privileges, monitoring, during the specified duration, for any indication that the user account has attempted a prohibited activity, detecting an indication that the user account attempted one of the prohibited activities, and initiating an automated remediation corresponding to the indication.
-
公开(公告)号:US20220129575A1
公开(公告)日:2022-04-28
申请号:US17497386
申请日:2021-10-08
Applicant: Google LLC
Inventor: Atul Goel , Diganta Paladhi , Manoj Sharma , Maurilio Cometto
IPC: G06F21/62
Abstract: The present disclosure describes an architecture and design of Unauthorized-Blocking-Role (UAB). UAB is a mechanism which prevents higher privileged users of cloud-hosted software from performing unauthorized activities on protected objects, such as management objects. UAB works by periodically monitoring the permissions of customer users on key management objects in an object hierarchy in management software. If a customer user is detected to have privileges higher than the user should have on those objects, UAB applies restrictive role-based access controls (RBACs) on the user. Similarly, UAB also monitors protected principals and protected roles to ensure that their privileges are not modified by a customer user.
-
公开(公告)号:US20240372870A1
公开(公告)日:2024-11-07
申请号:US18777146
申请日:2024-07-18
Applicant: Google LLC
Inventor: Manoj Sharma , Choudhury Sarada Prasanna Nanda , Ilya Beyer , Maurilio Cometto
Abstract: In one embodiment, a system includes a computing device providing a computing environment including a number of user accounts, where each of the user accounts is assigned specified privileges to execute particular commands or programs, receiving a request to temporarily escalate privileges for one of the user accounts during a specified duration, where the request includes an identifier of the user account, requested privileges, and the specified duration, granting the requested privileges for the specified duration in conjunction with specific restrictions on one or more prohibited activities that are normally permitted for user accounts with the requested privileges, monitoring, during the specified duration, for any indication that the user account has attempted a prohibited activity, detecting an indication that the user account attempted one of the prohibited activities, and initiating an automated remediation corresponding to the indication.
-
公开(公告)号:US20240086227A1
公开(公告)日:2024-03-14
申请号:US18517896
申请日:2023-11-22
Applicant: Google LLC
Inventor: Ilya Beyer , Manoj Sharma , Gururaj Pangal , Maurilio Cometto
CPC classification number: G06F9/45558 , G06F8/60 , G06F9/5072 , G06F9/5077 , G06F2009/45583 , G06F2209/5011
Abstract: In one embodiment, a system includes first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines includes a resource manager that provides a public-cloud resource interface through which one or more public-cloud clients interact with one or more virtual machines, and second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines includes one or more private-cloud virtual machines, wherein at least one of the first host machines further includes a private-cloud VM resource provider through which the resource manager interacts with the private-cloud virtual machines, wherein the VM resource provider translates requests to perform virtual machine operations from a public-cloud-resource interface to a private-cloud virtual machine interface, and the private-cloud virtual machines perform the requested virtual machine operations in response to receiving the translated requests from the VM resource provider.
-
公开(公告)号:US20230090171A1
公开(公告)日:2023-03-23
申请号:US18058597
申请日:2022-11-23
Applicant: Google LLC
Inventor: Ilya Beyer , Manoj Sharma , Gururaj Pangal , Maurilio Cometto
Abstract: In one embodiment, a system includes first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines includes a resource manager that provides a public-cloud resource interface through which one or more public-cloud clients interact with one or more virtual machines, and second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines includes one or more private-cloud virtual machines, wherein at least one of the first host machines further includes a private-cloud VM resource provider through which the resource manager interacts with the private-cloud virtual machines, wherein the VM resource provider translates requests to perform virtual machine operations from a public-cloud-resource interface to a private-cloud virtual machine interface, and the private-cloud virtual machines perform the requested virtual machine operations in response to receiving the translated requests from the VM resource provider.
-
-
-
-
-
-
-
-
-