IP Library Granted Patent US 9,027,087
Granted Patent B2
US 9,027,087 · App. 13/829,781 · Granted May 5, 2015

Method and system for identity-based authentication of virtual machines

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,027,087
App. No.
13/829,781
Granted
May 5, 2015
Kind
B2
Abstract

A cloud computing system configured to run virtual machine instances is disclosed. The cloud computing system assigns an identity to each virtual machine instance. When the virtual machine instance accesses initial configuration resources, it provides this identity to the resources to authenticate itself. This allows for flexible and extensible initial configuration of virtual machine instances.

Claims (41)

1. A cloud computing system, the system comprising:

a resource having configuration information;

a virtual machine instance operably coupled to the resource, wherein the virtual machine instance has an identity; and

an authentication manager configured to authenticate the virtual machine instance based on the identity of the virtual machine instance, without storing credentials for authentication of the virtual machine instance with the virtual machine instance.

2. The cloud computing system of claim 1 , wherein the identity is a MAC address.

3. The cloud computing system of claim 1 , wherein the resource is a second virtual machine instance.

4. The cloud computing system of claim 1 , wherein the resource is a metadata service configured to store configuration information.

5. The cloud computing system of claim 1 , wherein the resource is a network controller configured to provide network configuration information to the virtual machine instance.

6. The cloud computing system of claim 1 , wherein the authentication manager is further configured to allow a user to setup permissions for the identity, and to control access by the virtual machine instance to the resource based on the permissions.

7. The cloud computing system of claim 1 , wherein the authentication manager is further configured to allow a user to setup permissions for a group of identities.

8. The cloud computing system of claim 1 , wherein the authentication manager is configured to permit access to the resource based on whether the virtual machine instance is authenticated.

9. A method for controlling access to a resource, the method comprising:

instantiating a virtual machine instance;

assigning an identity to the virtual machine instance;

receiving a request for access to the resource from the virtual machine instance, the request including the identity of the virtual machine instance;

determining whether to authenticate the virtual machine instance based on the identity in the request, and

authenticating, based on the determining, the virtual machine instance, without storing credentials for authentication of the virtual machine instance with the virtual machine instance.

10. The method of claim 9 , further comprising:

permitting the virtual machine to access the resource based on the result of the determining step.

11. The method of claim 9 , further comprising:

denying the virtual machine instance access to the resource based on the result of the determining step.

12. The method of claim 9 , further comprising:

receiving permission information from a user, the permission information defining access rights to the resource for the identity;

wherein the determining step further includes determining whether the virtual machine instance may access the resource based on the permissions information.

13. The method of claim 9 , wherein the step of assigning an identity to the virtual machine instance is performed before the step of instantiating the virtual machine.

14. The method of claim 9 , wherein the step of assigning an identity to the virtual machine instance is performed after the step of instantiating the virtual machine.

15. The method of claim 9 , wherein assigning the identity to the virtual machine instance includes assigning a MAC address to the virtual machine instance.

16. A method for controlling access of virtual machines to resources in a cloud computing system, the method comprising:

receiving a request to instantiate a virtual machine instance;

instantiating the virtual machine instance;

assigning the virtual machine instance a unique, immutable attribute;

performing an initial boot of the virtual machine instance;

receiving a request from the virtual machine instance to access a resource, the request including the unique, immutable attribute;

determining whether to authenticate the virtual machine instance based on permissions configured for the unique, immutable attribute assigned to the virtual machine instance;

authenticating, based on the determining, the virtual machine instance without storing credentials for authentication of the virtual machine instance with the virtual machine instance;

if the virtual machine is authenticated, transmitting a response to the virtual machine instance; and

if the virtual machine is not authenticated, transmitting an error response to the virtual machine instance.

17. The method of claim 16 , wherein assigning the unique, immutable attribute includes assigning a MAC address.

18. The method of claim 16 , wherein the step of assigning an identity to the virtual machine instance is performed after the step of instantiating the virtual machine.

19. The method of claim 16 , wherein the step of assigning an identity to the virtual machine instance is performed before the step of instantiating the virtual machine.

20. The method of claim 16 , wherein determining whether to authenticate includes determining whether a type of the request is included in a set of request types that are allowed for an access level associated with the unique, immutable attribute.

Assignments (7)
RELEASE OF PATENT SECURITIES Recorded Mar 13, 2024
From: CITIBANK, N.A.
To: RACKSPACE US, INC.
Reel/Frame 066795/0177 →
SECURITY AGREEMENT (FIRST LIEN) Recorded Mar 13, 2024
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066795/0282 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE PROPERTY NUMBER PREVIOUSLY RECORDED AT REEL: 40564 FRAME: 914. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 21, 2019
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 048658/0637 →
SECURITY AGREEMENT Recorded Nov 4, 2016
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 040564/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2015
From: ISHAYA, VISHVANANDA
To: RACKSPACE US, INC.
Reel/Frame 035313/0174 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2015
From: VOCCIO, PAUL
To: RACKSPACE US, INC.
Reel/Frame 035233/0909 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2014
From: CARLIN, ERIK
To: RACKSPACE US, INC.
Reel/Frame 033832/0612 →