Patent · US Active

Tag-based policy architecture

US10356128B1 · kind B1 · utility

16Cited by
10References
15Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 27, 2017
Grant dateJul 16, 2019
Priority date
Expiry dateJul 27, 2037

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F9/455
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A tag-based policy architecture enforces information technology (IT) policy in a virtualized computing environment using cryptographically-verifiable metadata to authenticate compute resources coupled to a computer network and to authorize access to protected resources of the network. The compute resources are illustratively virtual machine instances (VMIs) provided by a virtual data center (VDC) of the environment, whereas the protected resources are illustratively virtualized storage, network and/or other compute resources of the VDC. Each VMI includes an intermediary manager, e.g., metavisor. The tag-based policy architecture includes an infrastructure having a centralized policy decision end point (e.g., a control plane of the VDC) and distributed policy enforcement endpoints (e.g., metavisors of the VMIs) to provide end-to-end passing of the cryptographically-verifiable metadata to (i) authorize instantiation of the VM is at the control plane, and (ii) enforce access to the virtualized resources at the metavisors.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.