首页> 外国专利> Securing an injection of a workload into a virtual network hosted by a cloud-based platform

Securing an injection of a workload into a virtual network hosted by a cloud-based platform

机译:将重新注入由基于云的平台托管的虚拟网络

摘要

The disclosed system implements techniques to secure communications for injecting a workload (e.g., a container) into a virtual network hosted by a cloud-based platform. Based on a delegation instruction received from a tenant, a virtual network of the tenant can connect to and execute a workload via a virtual machine that is part of a virtual network that belongs to a resource provider. To secure calls and authorize access to the tenant's virtual network, authentication information provided in association with a call from the virtual network of the resource provider may need to match authorization information made available via a publication service of the cloud-based platform. Moreover, an identifier of a NIC used to make a call may need to correspond to a registered name of the resource provider for the call to be authorized. These checks provide increased security by preventing unauthorized calls from accessing the tenant's virtual network.
机译:所公开的系统实现了用于保护用于将工作量(例如,容器)注入由基于云的平台托管的虚拟网络的通信的技术。基于从租户收到的委托指令,租户的虚拟网络可以通过属于资源提供者的虚拟网络的一部分来连接和执行工作负载。为了保护呼叫和授权访问租户的虚拟网络,与来自资源提供者的虚拟网络的呼叫相关联的认证信息可能需要匹配通过基于云的平台的发布服务可用的授权信息。此外,用于进行呼叫的NIC的标识符可能需要对应于要授权的呼叫的资源提供商的注册名称。这些检查通过防止未经授权的呼叫访问租户的虚拟网络来提供更高的安全性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号