首页> 外国专利> Extending infrastructure security to services in a cloud computing environment

Extending infrastructure security to services in a cloud computing environment

机译:将基础架构安全性扩展到云计算环境中的服务

摘要

A cloud deployment appliance (or other platform-as-a-service (IPAS) infrastructure software) includes a mechanism to deploy a product as a “shared service” to the cloud, as well as to enable the product to establish a trust relationship between itself and the appliance or IPAS. The mechanism further enables multiple products deployed to the cloud to form trust relationships with each other (despite the fact that each deployment and each product typically, by the nature of the cloud deployment, are intended to be isolated from one another). In addition, once deployed and provisioned into the cloud, a shared service can become part of a single sign-on (SSO) domain automatically. SSO is facilitated using a token-based exchange. Once a product registers with a token service, it can participate in SSO. This approach enables enforcement of consistent access control policy across product boundaries, and without requiring a user to perform any configuration.
机译:云部署设备(或其他平台即服务(IPAS)基础结构软件)包括一种机制,用于将产品作为“共享服务”部署到云中,并使产品能够在以下两种情况之间建立信任关系:本身以及设备或IPAS。该机制还使部署到云的多个产品能够彼此形成信任关系(尽管事实上,根据云部署的性质,每个部署和每个产品通常都打算相互隔离)。此外,共享服务一旦部署并配置到云中,便可以自动成为单点登录(SSO)域的一部分。使用基于令牌的交换可以促进SSO。产品向令牌服务注册后,便可以参与SSO。这种方法可以跨产品边界实施一致的访问控制策略,而无需用户执行任何配置。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号