Access configuration in hybrid network environments

US12301583B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12301583-B2
Application numberUS-202217662242-A
CountryUS
Kind codeB2
Filing dateMay 6, 2022
Priority dateMay 6, 2022
Publication dateMay 13, 2025
Grant dateMay 13, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Method, systems, and computer program products for access configuration in hybrid network environments are disclosed. According to the method, an access configuration request is received from a client device in a first network environment, wherein the access configuration request is associated with an access to a network resource in a second network environment and comprises first authentication information associated with the client device. Further, second authentication information associated with the network resource is obtained. The first and second authentication information is further used to determine whether the access configuration request is verified. If the access configuration request is verified, connectivity between the client device and the network resource can be automatically established.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method comprising: receiving, by a configuration server, an access configuration request from a client device in a first network environment, the access configuration request including a request for access to an identified network resource in a second network environment, the access configuration request including first authentication information associated with the client device, the access configuration request being a hypertext transfer protocol (HTTP) request having an encrypted token in a message body of the request, the first network environment being a different computing environment than the second network environment; responsive to receiving the access configuration request, obtaining, by the configuration server, second authentication information associated with the identified network resource; initiating, by the configuration server, a validation container for determining whether the access configuration request is verified based on the first and second authentication information; responsive to determining the access configuration request is verified, communicating with a controller of the second network environment to determine availability of the network resource; responsive to the network resource becoming available and, based on a security level of the network resource being below a security threshold, receiving, from the controller, a secret key associated with the network resource; automatically establishing connectivity between the client device and the identified network resource using the secret key; and causing, by the configuration server, an addition of the client device to a permission list based on the access configuration request being verified. 2. The method of claim 1 , wherein: a header of the HTTP request indicates an access mode of the requested access to the identified network resource. 3. The method of claim 1 , wherein obtaining the second authentication information comprises: determining the second authentication information from a set of network resource information corresponding to a set of network resources, the second authentication information being determined by cross-referencing the identified network resource in the set of network resources with corresponding authentication information. 4. The method of claim 1 , wherein: the access configuration request further includes an access mode of the requested access to the identified network resource, and obtaining the second authentication information includes: determining the second authentication information from a set of network resource information by cross-referencing the identified network resource and the access mode with corresponding authentication information. 5. The method of claim 1 , wherein obtaining the second authentication information comprises: determining the second authentication information from a set of network resource information corresponding to a set of network resources, the set of network resource information including a set of security levels associated with the set of network resources by: determining the security level associated with the identified network resource in the set of network resource information; and comparing the security level with the security threshold. 6. The method of claim 1 , wherein: the identified network resource comprises a first network resource having a first identity, and the second authentication information is associated with the identified network resource by a set of network resource information in which a set of network resources are associated by identity with corresponding authentication information; and the method further comprising: obtaining a notification indicating an initiation of a second network resource in a third network environment, wherein the third network environment is different from the second network environment, and the notification comprises third authentication information associated with the second network resource; and updating the set of network resource information by adding additional network resource information corresponding to the second network resource, the additional network resource information comprising a second identity of the second network resource and the third authentication information. 7. The method of claim 1 , wherein the first authentication information comprises a client token associated with the client device. 8. The method of claim 7 , further comprising: determining whether the client token matches with the secret key. 9. The method of claim 1 , wherein the first network environment comprises a public cloud, and the second network environment comprises a private cloud. 10. A system comprising: a processing unit; and a memory coupled to the processing unit and storing instructions thereon, the instructions, when executed by the processing unit, performing acts including: receiving, by a configuration server, an access configuration request from a client device in a first network environment, the access configuration request including a request for access to an identified network resource in a second network environment, the access configuration request including first authentication information associated with the client device, the access configuration request being a hypertext transfer protocol (HTTP) request having an encrypted token in a message body of the request, the first network environment being a different computing environment than the second network environment; responsive to receiving the access configuration request, obtaining, the configuration server, second authentication information associated with the identified network resource; initiating, by the configuration server, a validation container for determining whether the access configuration request is verified based on the first and second authentication information; responsive to determining the access configuration request is verified, communicating with a controller of the second network environment to determine availability of the network resource; responsive to the network resource becoming available and, based on a security level of the network resource being below a security threshold, receiving, from the controller, a secret key associated with the network resource; automatically establishing connectivity between the client device and the identified network resource using the secret key; and causing, by the configuration server, an addition of the client device to a permission list based on the access configuration request being verified. 11. The system of claim 10 , wherein: a header of the HTTP request indicates an access mode of the requested access to the identified network resource. 12. The system of claim 10 , wherein obtaining the second authentication information comprises: determining the second authentication information from a set of network resource information corresponding to a set of network resources, the second authentication information being determined by cross-referencing the identified network resource in the set of network resources with corresponding authentication information. 13. The system of claim 10 , wherein: the access configuration request further includes an access mode of the requested access to the identified network resource, and obtaining the second authentication information includes: determining the second authentication information from a set of network resource information by cross-referencing the identified network resource and the access mode with corresponding authentication information. 14. The system of claim 10 , wherein

Assignees

Inventors

Classifications

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • H04L63/105Primary

    Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12301583B2 cover?
Method, systems, and computer program products for access configuration in hybrid network environments are disclosed. According to the method, an access configuration request is received from a client device in a first network environment, wherein the access configuration request is associated with an access to a network resource in a second network environment and comprises first authenticatio…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/105. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 13 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).