首页> 外国专利> Enforcing a segmentation policy using cryptographic proof of identity

Enforcing a segmentation policy using cryptographic proof of identity

机译:使用Cryptography证明身份执行分割策略

摘要

A segmentation server defines a segmentation policy and distributes the segmentation policy to be enforced by a plurality of operating system (OS) instances. The segmentation policy includes rules controlling which workloads executing on the OS instances can communicate with other workloads and controlling how the workloads may communicate. When a connection between two OS instances is requested, each OS instance provides an identity and a cryptographic proof of the identity. The OS instances each authenticate the identity received from the other OS instance, and once authenticated, determines based on the authenticated identities if the rules permit the communication. If the rules permit the communication, the OS instances obtain session parameters that enable the OS instances to validate integrity of the messages communicated between the workloads and optionally encrypt the messages.
机译:分段服务器定义分段策略并分发由多个操作系统(OS)实例强制执行的分段策略。 分割策略包括控制在操作系统实例上执行的工作负载的规则可以与其他工作负载通信并控制工作负载如何通信。 当请求两个OS实例之间的连接时,每个操作系统实例提供身份和身份的加密证明。 操作系统实例每个验证从其他操作系统实例接收的身份,并且一旦验证,基于规则允许通信,基于经过身份验证的身份确定。 如果规则允许通信,操作系统实例可以获得会话参数,使操作系统实例能够验证在工作负载之间传送的消息的完整性,并可选地加密消息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号