IP Library Granted Patent US 8,806,566
Granted Patent B2
US 8,806,566 · App. 12/727,048 · Granted Aug 12, 2014

Identity and policy enforced inter-cloud and intra-cloud channel

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,806,566
App. No.
12/727,048
Granted
Aug 12, 2014
Kind
B2
Abstract

Techniques for identity and policy enforced cloud communications are presented. Cloud channel managers monitor messages occurring within a cloud or between independent clouds. Policy actions are enforced when processing the messages. The policy actions can include identity-based restrictions and the policy actions are specific to the messages and/or clouds within which the messages are being processed.

Claims (38)

1. A method implemented in a non-transitory machine-readable storage medium and processed by one or more processors configured to perform the method, comprising:

configuring a first process within a first cloud computing environment to manage select messages occurring within a communication channel within the first cloud computing environment, the communication channel is constructed within the first cloud environment based on a particular identifier that is associated with the select messages, and the communication channel is defined, identified, and communicated via a different communication channel that is used for some communication other than the communication channel that is to be monitored;

instantiating the first cloud computing environment with the first process executing therein; and

enforcing, by the first process, selective policy restrictions based on the select messages that enter and exit the communication channel, the first policy enforces the selective policy restrictions by consulting an identity service to obtain the selective policy restrictions and the policy restrictions include particular policies for the first process to authenticate the select messages based on: identities of senders of the selective messages, identities of receivers of the selective messages, identities for the selective messages, identities for other cloud computing environments that the selective messages originate from or are being directed to, and an identity for the first process.

2. The method of claim 1 further comprising:

configuring a second process within a second cloud computing environment to manage other select messages occurring within a second communication channel within the second cloud computing environment;

instantiating the second cloud computing environment with the second process executing therein; and

the second process enforces other selective policy restrictions based on the other select messages that enter and exit the second communication channel.

3. The method of claim 2 further comprising, sending by the first process a particular message that exits the communication channel and is directed to the second communication channel, the particular message intercepted and handled by the second process.

4. The method of claim 3 , wherein sending further includes sending the particular message to the second cloud computing environment where the first and second cloud computing environments are independent and separate cloud computing environments.

5. The method of claim 3 , wherein sending further includes sending the particular message to the second cloud computing environment where the first and second cloud computing environments are different sub environments of a global cloud environment that includes both the first and second cloud computing environments.

6. The method of claim 1 further comprising, sending by the first process a particular message that exits the communication channel and is directed to a second communication channel, the particular message intercepted and handled by a second process that monitors the second communication channel within the first cloud computing environment.

7. The method of claim 1 , wherein enforcing further includes one of:

consulting the identity service to acquire the selective policy restrictions, the identity service acting as a Policy Decision Point (PDP) service for acquiring policy specifications and the selective policy restrictions and the first process act as a Policy Enforcement Point (PEP) for enforcing the one or more policy restrictions; and

consulting a PDP to acquire policy specifications for the selective policy restrictions and the first process acting as the PEP for enforcing the selective policy restrictions.

8. The method of claim 1 , wherein enforcing further includes logging the selective messages, the selective policy restrictions, and identities associated with senders and receivers of the selective messages in response to enforcing some of the selective policy restrictions.

9. A method implemented in a non-transitory machine-readable storage medium and processed by one or more processors configured to perform the method, comprising:

detecting within a first cloud computing environment an event that identifies a message to manage on behalf of the first cloud computing environment, a port defined for an event type that includes the event the port monitored for the event;

acquiring a policy in response to an identity assigned to the message, the policy acquired from an identity service; and

processing actions defined in the policy to authenticate the message based on: identities of senders of the selective messages, identities of receivers of the selective messages, the identity for the message, an identity for the first cloud computing environment, and identities for other cloud computing environments that the message originates from or are being directed to.

10. The method of claim 9 , wherein detecting further includes monitoring a configured event type that the event is assigned to within the first cloud computing environment, the monitoring of the configured event type defining a communication channel for the first cloud computing environment.

11. The method of claim 9 , wherein detecting further includes determining that the event originated from second independent and disparate cloud computing environment.

12. The method of claim 9 , wherein detecting further includes determining that event originated from with the first cloud computing environment and associated with a different communication channel within the first cloud computing environment.

13. The method of claim 9 , wherein acquiring further includes:

authenticating the policy; and

logging the message and the policy along with other metadata collected from the message.

14. The method of claim 9 , wherein processing further includes one or more of:

guaranteeing a sender of the message of message delivery to a receiver;

backing up and/or mirroring the message to a second cloud computing environment that is independent and disparate from the first cloud computing environment; and

performing message sequencing for the message within the first cloud computing environment when the message is one of many messages associated with a transaction processing through the first cloud computing environment.

15. The method of claim 9 , wherein processing further includes detecting in response to a particular action that the message originated from a message service within the first cloud computing environment and is to be sent to a second disparate and independent cloud computing environment, the message service is incompatible with and unaware of the second disparate and independent cloud computing environment and believes the message is being processed by another message service that the message service believes to be within the first cloud computing environment.

16. A multi-processor implemented system, comprising:

a first processor configured to execute a cloud configurator; and

a plurality of second processors, each second processor configured to execute one or more cloud channel managers;

the cloud configurator configured to instantiate cloud computing environments, each cloud computing environment processing on one or more the second processors, and each cloud computing environment having one or more of the cloud channel managers, each cloud channel manager configured to handle inbound and outbound messages occurring over a particular communication channel and within that cloud channel manager's cloud computing environment and enforcing policy and identity restrictions for each of the inbound and outbound messages processed, the cloud channel manager configured to enforce the identity restrictions based on a policy acquired from an identity service and the enforcement for authentication of: identities of senders of the outbound messages, identities of receivers of the inbound messages, identities for the inbound and outbound messages, identities for the cloud computing environments that the inbound messages originate from or that the outbound messages are being directed to, and wherein each particular communication channel is constructed within each cloud computing environment based on a particular events of defined types that are associated with the inbound and outbound messages.

17. The system of claim 16 , wherein the cloud configurator is configured to instantiate each cloud computing environment in response to global configuration restrictions global to all the cloud computing environments and in response to local configuration restrictions specific to each particular cloud computing environment.

18. The system of claim 16 , wherein the cloud configurator is configured to instantiate each cloud computing environment with its own independent identity service that performs authentication services within that cloud computing environment.

19. The system of claim 18 , wherein each cloud channel manager is configured to monitor, log, and audit the inbound and outbound messages occurring within that cloud channel manager's communication channel.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2010
From: BERGESON, BRUCE L.; MCCLAIN, CAROLYN B.; CARTER, STEPHEN R; HOLM, VERNON ROGER
To: NOVELL, INC.
Reel/Frame 024116/0344 →