Scaling a trusted computing model in a globally distributed cloud environment

US9401954B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9401954-B2
Application numberUS-201314073234-A
CountryUS
Kind codeB2
Filing dateNov 6, 2013
Priority dateNov 6, 2013
Publication dateJul 26, 2016
Grant dateJul 26, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A distributed cloud environment system comprising: a repository; a plurality of cloud managed nodes with a client program interface; a plurality of service management components with a service management component interface; a central trusted computing platform service in communication with the repository, the plurality of cloud managed nodes and the plurality of service management components, comprising: a first interface for communication with the client program interface in each of the plurality of cloud managed nodes through a first single touch point; and a second interface for communication with the service management component interface for the plurality of service management components through a second single touch point. The central trusted computing platform service manages interaction of the plurality of service management components with the plurality of cloud managed nodes, and the interaction of the plurality of cloud managed nodes with the repository.

First claim

Opening claim text (preview).

What is claimed is: 1. A distributed cloud environment system comprising: a repository comprising data; a plurality of cloud managed nodes comprising a client program which receives and ends measurement data to the repository and a client program interface; a plurality of service management components comprising functions for managing service of the plurality of cloud managed nodes and a service management component interface; and a central trusted computing platform service in communication with the repository, the plurality of cloud managed nodes and the plurality of service management components, comprising: a first interface for communication with the client program interface in each of the plurality of cloud managed nodes through a first single touch point; and a second interface for communication with the service management component interface for the plurality of service management components through a second single touch point; wherein the central trusted computing platform service manages interaction of the plurality of service management components with the plurality of cloud managed nodes, and the interaction of the plurality of cloud managed nodes with the repository; wherein an interaction managed by the central trusted computing platform is registration of the client program of the plurality of cloud managed nodes and the plurality of service management components by the steps of: the central trusted computing platform service sending a command to the client program interface and the service management component interface to register the plurality of cloud managed nodes and the plurality of service management components; the central trusted computing platform service receiving data including at least a location, measurement data, and system data from the cloud managed nodes and the service management components; the central trusted computing platform service authenticating the data received from the plurality of cloud managed nodes and the data of the plurality of service management components by searching in the repository; if the data is authenticated, the central trusted computing platform service comparing the location data to the data in the repository to match the location of the plurality of cloud managed nodes and the plurality of service management components; and if the location matches, the central trusted computing platform registering the plurality of cloud managed nodes and the plurality of service management components as trusted and storing the data received from the plurality of cloud managed nodes and the plurality of service management components in the repository. 2. The system of claim 1 , further comprising an attestation service in communication with the central trusted computing platform service and the repository. 3. The system of claim 1 , wherein the plurality of service management components are selected from a group consisting of a ticketing system, a patch management system, an asset management system, a workflow system and a provisioning system. 4. The system of claim 1 , wherein the central trusted computing platform service further comprises: a security layer comprising at least one of an authentication component, an authorization component, an audit component, and a public-key infrastructure component; an interface layer comprising at least one of a protocol switch component, a delegation interface component, mediation component, and an user registry component; and a service layer comprising at least one of a first interface service implementation component, a second interface service implementation component, and a repository and analytics component.

Assignees

Inventors

Classifications

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • wherein the managed service relates to distributed or central networked applications · CPC title

  • H04L67/10Primary

    in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9401954B2 cover?
A distributed cloud environment system comprising: a repository; a plurality of cloud managed nodes with a client program interface; a plurality of service management components with a service management component interface; a central trusted computing platform service in communication with the repository, the plurality of cloud managed nodes and the plurality of service management components, …
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L67/10. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 26 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).