IP Library Granted Patent US 9,794,224
Granted Patent B2
US 9,794,224 · App. 14/850,408 · Granted Oct 17, 2017

System and method for creating a trusted cloud security architecture

Inventors: Andrew E. S. MacKay (Carp, CA); Kyle Fransham (Ottawa, CA)
Assignee: SUPERNA INC.
H04L63/0245G06F21/57H04L41/12H04L43/0864H04L43/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,794,224
App. No.
14/850,408
Granted
Oct 17, 2017
Kind
B2
Abstract

The present invention provides a method for providing a computer implemented method and system for creating a trusted cloud security architecture having the following steps: a primary agent communicating with two or more secondary agents creating a trust ring or other shape of agent communications, the primary agent operating on a primary guest OS and two or more secondary agents operating on two or more secondary guest OSs; implementing a latency based topology for the trust ring having a network of links between disparate IP addresses, the disparate IP addresses corresponding with the primary agent and two or more secondary agents; the primary agent and two or more secondary agents exchanging data packets between the latency based topology within the trust ring; and outputting the exchanged data packets to a processing engine, the processing engine determining a trust status for the trust ring, the trust status based on the data packets between the latency based topology.

Claims (14)

1. A computer implemented method for creating a trusted cloud security architecture comprising the following steps:

a primary agent communicating with two or more secondary agents creating a trust ring, the primary agent operating on a primary guest Operating System (OS) and two or more secondary agents operating on two or more secondary guest Operating Systems (OSs);

implementing a latency based topology for the trust ring comprising a network of links between disparate IP addresses, the disparate IP addresses corresponding with the primary agent and two or more secondary agents;

the primary agent and two or more secondary agents exchanging data packets between the latency based topology within the trust ring; and

outputting the exchanged data packets to a processing engine, the processing engine determining a trust status for the trust ring, the trust status based on the data packets between the latency based topology.

2. The method of claim 1 wherein each of the primary agent and each of the two or more secondary agents may simultaneously serve as an agent for one or more other trust rings, the one or more other trust rings having its own respective latency based topology.

3. The method of claim 1 wherein the data packets between the latency based topology comprise ping data or alternate round trip based protocol, having latency measurements of distance traveled between source and destination.

4. The method of claim 1 wherein each of the primary agent and each two or more secondary agents provides for authentication prior to communication.

5. The method of claim 4 wherein authentication further comprises each of the primary agent and each two or more secondary agents to synchronize with a network time protocol source.

6. The method of claim 1 wherein communication and data packet exchange includes encryption.

7. The method of claim 1 wherein the latency based topology is selected by an assignment methodology.

8. The method of claim 7 wherein the assignment methodology comprises Ethernet mac address priority, IP address hash, and similar latency based priority schemes.

9. The method of claim 1 wherein the latency based topology is determined by a system administrator, wherein the system administrator determines the shape, number of agents and latency between agents.

10. The method of claim 1 wherein the primary guest OS and two or more secondary guest OSs implement Trusted Execution Technology (TXT) and Trusted Platform Module (TPM) enabled hosts.

Assignments (4)
SECURITY INTEREST Recorded Mar 9, 2022
From: SUPERNA INC.
To: BAIN CAPITAL CREDIT, LP
Reel/Frame 059213/0749 →
CHANGE OF NAME Recorded Sep 6, 2017
From: SUPERNA BUSINESS CONSULTING INC.
To: SUPERNA INC.
Reel/Frame 043773/0049 →
CHANGE OF NAME Recorded May 31, 2017
From: SUPERNA BUSINESS CONSULTING, INC.
To: SUPERNA BUSINESS CONSULTING INC.
Reel/Frame 042642/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2016
From: MACKAY, ANDREW E.S.; FRANSHAM, KYLE
To: SUPERNA BUSINESS CONSULTING, INC.
Reel/Frame 038740/0331 →
Continuity (2)
Provisional Application 62049060 · Sep 11, 2014
Related Publication 20160080323A1 · Mar 17, 2016