IP Library Granted Patent US 9,838,382
Granted Patent B2
US 9,838,382 · App. 15/400,769 · Granted Dec 5, 2017

Establishing trust within a cloud computing system

Inventors: Wesley Leggette (Chicago, IL); Jason K. Resch (Chicago, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/0823H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,382
App. No.
15/400,769
Granted
Dec 5, 2017
Kind
B2
Abstract

A cloud computing system includes a cloud system managing unit, a plurality of sets of devices, where a set of devices includes one or more devices having a common aspect, and a plurality of authentication servers, where an authentication server is associated with one of the plurality of sets of devices based on the common aspect. The cloud computing system functions to establish trust between a corresponding one of the plurality of authentication servers and the one or more devices of one of the plurality of sets of devices, between the corresponding one of the plurality of authentication servers and the cloud system managing unit, and between the cloud system managing unit and the one or more devices. The cloud system managing unit configures the cloud computing system based on the trust between the cloud system managing unit and devices of the plurality of sets of devices.

Claims (93)

1. A cloud computing system comprises:

a cloud system managing unit having a system level manager trusted certificate;

a set of devices includes one or more devices having a common aspect; and

an authentication server associated with the set of devices based on the common aspect, wherein the authentication server has a unique device level server trusted certificate and a unique system level server trusted certificate; wherein:

the authentication servers and the one or more devices of the set of devices establishes trust therebetween based on the unique device level server trusted certificate of the authentication server;

the authentication server and the cloud system managing unit establishes trust therebetween based on at least one of the unique system level server trusted certificate and the system level manager trusted certificate;

the cloud system managing unit and the one or more devices of the set of devices establish trust therebetween based on the trust between the authentication server and the one or more device of the set of devices and the trust between the authentication servers and the cloud system managing unit; and

the cloud system managing unit configures the cloud computing system based on the trust between the cloud system managing unit and the one or more devices of the set of devices, wherein the configuring includes facilitating subsequent operation of a device of the one or more devices of the set of devices in accessing another set of devices of the cloud computing system using a signed certificate from the cloud system managing unit.

2. The cloud computing system of claim 1 , wherein the common aspect comprises at least one of:

a vendor identifier;

a device type identifier;

a version identifier;

a functionality identifier; and

an assigned identifier.

3. The cloud computing system of claim 1 further comprises:

a plurality of certificate authorities, wherein one of the plurality of certificate authorities is affiliated with the authentication server based on the common aspect and wherein the one of the plurality of certificate authorities generates the unique device level server trusted certificate for the authentication server.

4. The cloud computing system of claim 1 further comprises:

a cloud system certificate authority operable to:

generate the system level manager trusted certificate for the cloud system managing unit; and

generate the unique system level server trusted certificate for the authentication server.

5. The cloud computing system of claim 1 , wherein the authentication server and the one or more devices of the set of devices establishing trust therebetween comprises:

sending, by a device of the one or more devices, an authentication request to the authentication server, wherein the device is programmed with the unique device level server trusted certificate and wherein the authentication request references the unique device level server trusted certificate;

generating, by the authentication server, an authentication response based on the authentication request;

when the authentication response is verified, sending, by the device, device configuration information to the authentication server; and

receiving, by the device, manager information regarding the cloud system managing unit.

6. The cloud computing system of claim 1 , wherein the cloud system managing unit and the one or more devices of the set of devices establishing trust therebetween comprises:

sending, by a device of the one or more devices, a manager authentication request to the cloud system managing unit based on manager information, wherein the manager authentication request references the system level manager trusted certificate;

generating, by the cloud system managing unit, a manager authentication response based on the manager authentication request;

sending, by the device, a certificate signing request to the cloud system managing unit; and

sending, by the cloud system managing unit, a signed certificate to the device in response to the certificate signing request.

7. The cloud computing system of claim 1 further comprises:

the authentication server and the one or more devices of the set of devices establishes trust therebetween based on the common aspect and the unique device level server trusted certificate of the authentication server.

8. The cloud computing system of claim 1 further comprises:

the cloud system managing unit and the one or more devices of the set of devices establish trust therebetween based on the trust between each of a plurality of other authentication servers and the one or more devices of the set of devices and the trust between each of the plurality of other authentication servers and the cloud system managing unit.

9. A method comprises:

storing a system level manager trusted certificate for a cloud system managing unit that includes a processor;

storing a unique device level server trusted certificate and a unique system level server trusted certificate for a plurality of authentication servers;

establishing trust, via a corresponding one of the plurality of authentication servers, between the corresponding one of the plurality of authentication servers and one or more devices of one of a plurality of sets of devices based on the unique device level server trusted certificate of the corresponding one of the plurality of authentication servers, wherein a set of devices of the plurality of sets of devices includes the one or more devices having a common aspect;

establishing trust, via the cloud system managing unit, between the corresponding one of the plurality of authentication servers and the cloud system managing unit based on at least one of the unique system level server trusted certificate and the system level manager trusted certificate;

establishing trust, via the cloud system managing unit, between the cloud system managing unit and the one or more devices of the one of the plurality of sets of devices based on the trust between the corresponding one of the plurality of authentication servers and the one or more devices of the one of the plurality of sets of devices and the trust between the corresponding one of the plurality of authentication servers and the cloud system managing unit; and

configuring, via the cloud system managing unit, a cloud computing system based on the trust between the cloud system managing unit and devices of the plurality of sets of devices, wherein the configuring includes facilitating subsequent operation of a device of the plurality of sets of devices in accessing another of the plurality of sets of devices of the cloud computing system using a signed certificate from the cloud system managing unit.

10. The method of claim 9 , wherein the common aspect comprises at least one of:

a vendor identifier;

a device type identifier;

a version identifier;

a functionality identifier; and

an assigned identifier.

11. The method of claim 9 further comprises:

generating the unique device level server trusted certificate for the corresponding one of the plurality of authentication servers based on the common aspect.

12. The method of claim 9 further comprises:

generating the system level manager trusted certificate for the cloud system managing unit; and

generating the unique system level server trusted certificates for each of the plurality of authentication servers.

13. The method of claim 9 , wherein establishing the trust between the corresponding one of the plurality of authentication servers and one or more devices of one of a plurality of sets of devices includes:

sending, from a device of the one or more devices of the one of the plurality of sets of devices, an authentication request to the corresponding one of the plurality of authentication servers, wherein the device is programmed with the unique device level server trusted certificate of the corresponding one of the plurality of authentication servers and wherein the authentication request references the unique device level server trusted certificate;

generating an authentication response based on the authentication request;

when the authentication response is verified, sending, device configuration information to the corresponding one of the plurality of authentication servers; and

receiving, manager information regarding the cloud system managing unit.

14. The method of claim 9 , wherein establishing trust between the cloud system managing unit and the one or more devices of the one of the plurality of sets of devices includes:

sending a manager authentication request to the cloud system managing unit based on manager information, wherein the manager authentication request references the system level manager trusted certificate;

generating a manager authentication response based on the manager authentication request;

sending a certificate signing request to the cloud system managing unit; and

sending a signed certificate to the device in response to the certificate signing request.

15. A cloud computing system set up unit comprises:

memory for storing:

a system level manager trusted certificate of a cloud system managing unit;

a unique device level server trusted certificate for each of a plurality of authentication servers; and

a unique system level server trusted certificate for the each of the plurality of authentication servers; and

a processor having processing hardware, the processor operable to:

establish trust between a corresponding one of the plurality of authentication servers and one or more devices of one of a plurality of sets of devices based on the unique device level server trusted certificate of the corresponding one of the plurality of authentication servers, wherein a set of devices of the plurality of sets of devices includes one or more devices having a common aspect;

establish trust between the corresponding one of the plurality of authentication servers and the cloud system managing unit based on at least one of the unique system level server trusted certificate and the system level manager trusted certificate;

establish trust between the cloud system managing unit and the one or more devices of the one of the plurality of sets of devices based on the trust between the corresponding one of the plurality of authentication servers and the one or more devices of the one of the plurality of sets of devices and the trust between the corresponding one of the plurality of authentication servers and the cloud system managing unit; and

configure the cloud computing system based on the trust between the cloud system managing unit and devices of the plurality of sets of devices wherein the configuring includes facilitating subsequent operation of a device of the plurality of sets of devices in accessing another of the plurality of sets of devices of the cloud computing system using a signed certificate from the cloud system managing unit.

16. The cloud computing system set up unit of claim 15 , wherein the common aspect comprises at least one of:

a vendor identifier;

a device type identifier;

a version identifier;

a functionality identifier; and

an assigned identifier.

17. The cloud computing system set up unit of claim 15 , wherein the processor is further operable to:

generate the unique device level server trusted certificate for the corresponding one of the plurality of authentication servers based on the common aspect.

18. The cloud computing system set up unit of claim 15 , wherein the processor is further operable to:

generate the system level manager trusted certificate for the cloud system managing unit; and

generate the unique system level server trusted certificates for the each of the plurality of authentication servers.

19. The cloud computing system set up unit of claim 15 , wherein the processor is further operable to:

send, as a device of the one or more devices, an authentication request to the corresponding one of the plurality of authentication servers, wherein the device is programmed with the unique device level server trusted certificate of the corresponding one of the plurality of authentication servers and wherein the authentication request references the unique device level server trusted certificate;

generate, as the corresponding one of the plurality of authentication servers, an authentication response based on the authentication request;

when the authentication response is verified, send, as the device, device configuration information to the corresponding one of the plurality of authentication servers; and

receive, as the device, manager information regarding the cloud system managing unit.

20. The cloud computing system set up unit of claim 15 , wherein the processor is further operable to:

send, as a device of the one or more devices, a manager authentication request to the cloud system managing unit based on manager information, wherein the manager authentication request references the system level manager trusted certificate;

generate, as the cloud system managing unit, a manager authentication response based on the manager authentication request;

send, as the device, a certificate signing request to the cloud system managing unit; and

send, as the cloud system managing unit, a signed certificate to the device in response to the certificate signing request.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 9992063 AND 10334045 LISTED IN ERROR PREVIOUSLY RECORDED ON REEL 049556 FRAME 0012. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNOR HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 052205/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2017
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041326/0229 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2017
From: LEGGETTE, WESLEY; RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 040904/0055 →
Continuity (3)
Continuation 13868988 · Apr 23, 2013
Provisional Application 61655736 · Jun 5, 2012
Related Publication 20170118200A1 · Apr 27, 2017