Techniques for establishing a trusted cloud service

US2016352779A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016352779-A1
Application numberUS-201615180365-A
CountryUS
Kind codeA1
Filing dateJun 13, 2016
Priority dateMay 4, 2011
Publication dateDec 1, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for establishing a trusted cloud service are provided. Packages are created for services that include certificates, configuration information, trust information, and images for deploying instances of the services. The packages can be used to deploy the services in trusted environments and authenticated to deploy in sub environments of un-trusted environments. The sub environments are trusted by the trusted environments. Also, clouds are prospected for purposes of identifying desirable clouds and creating the packages for deployment.

First claim

Opening claim text (preview).

1 . (canceled) 2 . A method, comprising: creating a package for a migrating service based at least in part on a processing environment specification for a target processing environment of the migrating service; establishing a trust configuration for the target processing environment based on the specification; adding the trust configuration to the package; deploying the package to the target processing environment; and validating the migrating service was initiated and is executing within the target processing environment. 3 . The method of claim 2 , wherein creating further includes encrypting the package as an encrypted package. 4 . The method of claim 2 , wherein creating further includes defining in the package a mechanism for the target processing environment to authenticate the package in the target processing environment. 5 . The method of claim 4 , wherein defining further includes providing as the mechanism at least one key for securely communicating with the method. 6 . The method of claim 5 , wherein providing further includes providing at least pme certificate for securely communicating with the method. 7 . The method of claim 4 , wherein defining further includes providing the mechanism as a technique for generating keys for the migrating service that is included within the package. 8 . The method of claim 7 , wherein defining further includes providing another technique for obtaining certificates for the migrating service that is included within the package. 9 . The method of claim 8 further comprising, obtaining at least one of the generated keys and at least one of the certificates from the target processing environment for secure communication with the migrating service once initiated in the target processing environment. 10 . The method of claim 2 , wherein deploying further includes instructing the target processing environment to instantiate the migrating service within the target processing environment once the target processing environment as validated the package and authenticated the migrating service 11 . A method, comprising: obtaining a specification for a target cloud environment; configuring a package that includes a service image for a service based on the specification; providing the package to the target cloud environment; and interact with the service when deployed from the service image within the target cloud environment. 12 . The method of claim 11 , wherein obtaining further includes obtaining the specification as a hardware configuration and software configuration for the target cloud environment. 13 . The method of claim 12 , wherein obtaining further includes requesting the specification from the target cloud environment. 14 . The method of claim 12 , wherein configuring further includes providing keys and certificates within the package for security processing by the service once initiated within the target cloud environment. 15 . The method of claim 12 , wherein configuring further includes providing instructions for generating keys and certificates for security processing by the service once initiated within the target cloud environment. 16 . The method of claim 12 , wherein providing further includes authenticating the target cloud environment. 17 . The method of claim 16 , wherein interacting further includes authenticating the service from the target cloud environment. 18 . The method of claim 12 , wherein interacting further includes interacting with one or more sub services of the service from the target cloud environment. 19 . A system, comprising: a processor; and a service deployer configured to: i) execute on the processor, ii) create a package for a service image of a service with the package customized for a target cloud environment, iii) configure the package with security for authenticating the service within the target cloud environment, and iv) cause the service to be deployed from the service image of the package within the target cloud environment. 20 . The system of claim 19 , wherein the service deployer is further configured to: v) authenticate the service once initiated within the target cloud environment based at least in part on information included in the package. 21 . The system of claim 19 , wherein the service deployer is further configured to: v) interact with the service and sub services of the service once initiated within the target cloud environment.

Assignees

Inventors

Classifications

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016352779A1 cover?
Techniques for establishing a trusted cloud service are provided. Packages are created for services that include certificates, configuration information, trust information, and images for deploying instances of the services. The packages can be used to deploy the services in trusted environments and authenticated to deploy in sub environments of un-trusted environments. The sub environments are…
Who is the assignee on this patent?
Novell Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 01 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).