IP Library › Granted Patent US 12,204,669
Granted Patent B2
US 12,204,669 · App. 17/584,996 · Granted Jan 21, 2025

Extending private cloud security model to public cloud

Inventors: Michael G. Varteresian (Lexington, MA); Muzhar S. Khokhar (Shrewsbury, MA); Wenfeng Li (Shanghai, CN); Donald Mace (Hopkinton, MA)
Assignee: Dell Products L.P.
G06F21/6218G06F16/258G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,669
App. No.
17/584,996
Granted
Jan 21, 2025
Kind
B2
Abstract

Methods and systems disclosed herein extend an entity's private cloud security model to the entity's public cloud. Public cloud access permissions are defined, in accordance with a security model implemented in the entity's private cloud, for one or more of the entity's public cloud resources. The public cloud permissions are pushed or otherwise provided to an access module within the private cloud. Upon receiving a request to access a public cloud resource, the private cloud access module is invoked to grant or deny the access request in accordance with the public cloud access permissions. Similarly, upon receiving a request to access a private cloud resource, the private cloud access module is invoked to process the access request in accordance with private cloud access permissions, thereby beneficially enabling users to interact with a single access interface regardless of whether the resource reside within the entity's cloud platform.

Claims (28)

1. A method for managing access security in a cloud environment, wherein the method comprises:

defining public cloud access permissions for one or more public cloud resources associated with an entity, wherein the public cloud access permissions are in accordance with a security model implemented in a private cloud of the entity;

providing the public cloud permissions to a private cloud access module;

responsive to an access request to access a public cloud resource, invoking the private cloud access module to process the access request in accordance with the public cloud access permissions;

responsive to an access request to access a private cloud resource, invoking the private cloud access module to process the access request in accordance with private cloud access permissions;

managing the private cloud access permissions and the public cloud access permissions from within the private cloud; and

responsive to managing a public cloud access permission from within the private cloud, forwarding the public cloud access permission to the public cloud via a secure channel between the private cloud and public cloud.

2. The method of claim 1 , wherein providing the public cloud permissions comprises pushing the public cloud access permissions from the public cloud to the private cloud access module.

3. The method of claim 1 , wherein the private cloud security model comprises a role-based access model wherein an access permission is associated with a resource, indicates one or more authorized users to which the permission pertains, and identifies a role, comprising one or more access privileges, accorded to the one or more authorized users with respect to the resource.

4. An information handling system, comprising:

a central processing unit (CPU); and

a computer readable memory, accessible to the CPU, including process executable program instructions that, when executed by the CPU, cause the CPU to perform operations for managing access security in a cloud environment, wherein the operations include:

defining public cloud access permissions for one or more public cloud resources associated with an entity, wherein the public cloud access permissions are in accordance with a security model implemented in a private cloud of the entity;

providing the public cloud permissions to a private cloud access module;

responsive to an access request to access a public cloud resource, invoking the private cloud access module to process the access request in accordance with the public cloud access permissions;

responsive to an access request to access a private cloud resource, invoking the private cloud access module to process the access request in accordance with private cloud access permissions;

managing the private cloud access permissions and the public cloud access permissions from within the private cloud; and

responsive to managing a public cloud access permission from within the private cloud, forwarding the public cloud access permission to the public cloud via a secure channel between the private cloud and public cloud.

5. The information handling system of claim 4 , wherein providing the public cloud permissions comprises pushing the public cloud access permissions from the public cloud to the private cloud access module.

6. The information handling system of claim 4 , wherein the private cloud security model comprises a role-based access model wherein an access permission is associated with a resource, indicates one or more authorized users to which the permission pertains, and identifies a role, comprising one or more access privileges, accorded to the one or more authorized users with respect to the resource.

7. A non-transitory computer readable memory including process executable program instructions that, when executed by a processor of an information handing system, cause the system to perform operations for managing access security in a cloud environment, wherein the operations include:

defining public cloud access permissions for one or more public cloud resources associated with an entity, wherein the public cloud access permissions are in accordance with a security model implemented in a private cloud of the entity;

providing the public cloud permissions to a private cloud access module;

responsive to an access request to access a public cloud resource, invoking the private cloud access module to process the access request in accordance with the public cloud access permissions;

managing the private cloud access permissions and the public cloud access permissions from within the private cloud; and

responsive to managing a public cloud access permission from within the private cloud, forwarding the public cloud access permission to the public cloud via a secure channel between the private cloud and public cloud.

8. The non-transitory computer readable medium of claim 7 , wherein providing the public cloud permissions comprises pushing the public cloud access permissions from the public cloud to the private cloud access module.

9. The non-transitory computer readable medium of claim 7 , wherein the private cloud security model comprises a role-based access model wherein an access permission is associated with a resource, indicates one or more authorized users to which the permission pertains, and identifies a role, comprising one or more access privileges, accorded to the one or more authorized users with respect to the resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2022
From: VARTERESIAN, MICHAEL G.; KHOKHAR, MUZHAR S.; LI, WENFENG; MACE, DONALD
To: DELL PRODUCTS L.P.
Reel/Frame 059051/0644 →
Continuity (1)
Related Publication 20230237181A1 · Jul 27, 2023
References Cited (15)
US 8813174B1 · Koeten · 2014 [cited by examiner]
US 11445009B1 · Ji · 2022 [cited by examiner]
US 12101320B2 · Khokhar · 2024 [cited by examiner]
US 20120101995A1 · Agetsuma · 2012 [cited by examiner]
US 20130007845A1 · Chang · 2013 [cited by examiner]
US 20160012182A1 · Golay · 2016 [cited by examiner]
US 20170163644A1 · Horii · 2017 [cited by examiner]
US 20180026985A1 · Pogrebinsky · 2018 [cited by examiner]
US 20180027050A1 · Pogrebinsky · 2018 [cited by examiner]
US 20190213104A1 · Qadri · 2019 [cited by examiner]
US 20220141189A1 · Flavel · 2022 [cited by examiner]
US 20230239298A1 · Khokhar · 2023 [cited by examiner]
CN 112424818A · 2021 [cited by examiner]
EP 3765985B1 · 2022 [cited by examiner]
WO WO2021137138A1 · 2021 [cited by examiner]