US2016366143A1PendingUtilityA1

System and method for virtual image security in a cloud environment

Assignee: CA INCPriority: Feb 27, 2012Filed: Aug 24, 2016Published: Dec 15, 2016
Est. expiryFeb 27, 2032(~5.6 yrs left)· nominal 20-yr term from priority
G06F 2009/45587G06F 9/45558G06F 9/468H04W 4/60H04L 63/10H04L 63/101H04L 63/0823G06F 2009/45595G06F 21/60
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods enabling secure virtual image access in a virtual or cloud computing environment. The systems and methods include assigning a status to indicator to guest virtual machines (virtual images) that provide applications and other services to cloud consumers in the cloud environment. A virtual appliance machine in the cloud environment maintains the status of the guest virtual machines and makes decisions based on the status as to whether to allow access to the guest virtual machines. These decisions are transmitted to local elements on the guest virtual machines, which enforce access control on a local level. In this manner, unauthorized virtual image access is prevented providing increased security and data integrity.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method to provide secure access in a virtual computing environment, the method executed by a processor comprising hardware, the processor configured to perform a plurality of operations, the operations comprising:
 sending, from a guest virtual machine to a virtual access control machine of a virtual computing environment, information representative of an attempted use of the guest virtual machine, wherein the guest virtual machine supports a service and is accessible to a user through a network and the virtual access control machine assigns a status to the guest virtual machine;   sending, from the guest virtual machine to the virtual access control machine, a request for the status of the guest virtual machine; and   receiving, at the guest virtual machine from the virtual access control machine, information regarding the (i) status of the guest virtual machine in response to the request, or (ii) an action to take based on the status, or (iii) both (i) and (ii).   
     
     
         22 . The method of  claim 21 , wherein the status indicates that the guest virtual machine, after the guest virtual machine is created and ready for use, is able to be accessed by an authorized user, and further comprising allowing the attempted use of the guest virtual machine to an authorized user. 
     
     
         23 . The method of  claim 21 , wherein the status indicates that the guest virtual machine is not to be used by anyone, and further comprising preventing the attempted use of the guest virtual machine. 
     
     
         24 . The method of  claim 21 , further comprising changing the status of the guest virtual machine from a status indicating that the guest virtual machine is able to be accessed by an authorized user to a status indicating that the guest virtual machine is not to be used by anyone, and comprising preventing the attempted use of the guest virtual machine. 
     
     
         25 . The method of  claim 21 , wherein the request includes a certificate identifying the guest virtual machine or an authorized user of the guest virtual machine. 
     
     
         26 . The method of  claim 21 , further comprising sending a signal from the guest virtual machine to the virtual access control machine to set or update the status of the guest virtual machine at the virtual access control machine. 
     
     
         27 . The method of  claim 21 , further comprising sending a certificate associated with an authorized user of the guest virtual machine to the virtual access control machine. 
     
     
         28 . The method of  claim 21 , further comprising causing deactivation of the guest virtual machine responsive to the status or action. 
     
     
         29 . A system to provide secure access in a virtual computing environment, the system comprising:
 a processor comprising hardware, the processor configured to:
 send, from a guest virtual machine to a virtual access control machine of a virtual computing environment, information representative of an attempted use of the guest virtual machine, wherein the guest virtual machine supports a service and is accessible to a user through a network and the virtual access control machine assigns a status to the guest virtual machine; 
 send, from the guest virtual machine to the virtual access control machine, a request for the status of the guest virtual machine; and 
 receive, at the guest virtual machine from the virtual access control machine, information regarding the (i) status of the guest virtual machine in response to the request, or (ii) an action to take based on the status, or (iii) both (i) and (ii). 
   
     
     
         30 . The system of  claim 29 , wherein the status indicates that the guest virtual machine, after the guest virtual machine is created and ready for use, is able to be accessed by an authorized user, and the processor is further configured to allow the attempted use of the guest virtual machine to an authorized user. 
     
     
         31 . The system of  claim 29 , wherein the status indicates that the guest virtual machine is not to be used by anyone, and the processor is further configured to prevent the attempted use of the guest virtual machine. 
     
     
         32 . The system of  claim 29 , wherein the processor is further configured to change the status of the guest virtual machine from a status indicating that the guest virtual machine is able to be accessed-by an authorized user to a status indicating that the guest virtual machine is not to be used by anyone, and the processor is further configured to prevent the attempted use of the guest virtual machine. 
     
     
         33 . The system of  claim 29 , wherein the request includes a certificate identifying the guest virtual machine or an authorized user of the guest virtual machine. 
     
     
         34 . The system of  claim 29 , wherein the processor is further configured to send a signal from the guest virtual machine to the virtual access control machine to set or update the status of the guest virtual machine at the virtual access control machine. 
     
     
         35 . The system of  claim 29 , wherein the processor is further configured to send a certificate associated with an authorized user of the guest virtual machine to the virtual access control machine. 
     
     
         36 . The system of  claim 29 , wherein the processor is further configured to cause the guest virtual machine to be deactivated responsive to the status or action. 
     
     
         37 . A non-transitory computer-readable medium including computer-executable instructions thereon, the computer-executable instructions, when executed, causing a processor to:
 send, from a guest virtual machine to a virtual access control machine of a virtual computing environment, information representative of an attempted use of the guest virtual machine, wherein the guest virtual machine supports a service and is accessible to a user through a network and the virtual access control machine assigns a status to the guest virtual machine:   send, from the guest virtual machine to the virtual access control machine, a request for the status of the guest virtual machine; and   receive, at the guest virtual machine from the virtual access control machine, information regarding the (i) status of the guest virtual machine in response to the request, or (ii) an action to take based on the status, or (iii) both (i) and (ii).   
     
     
         38 . The system of  claim 37 , wherein the status indicates that the guest virtual machine, after the guest virtual machine is created and ready for use, is able to be accessed by an authorized user, and the instructions further include instructions to allow the attempted use of the guest virtual machine to an authorized user, 
     
     
         39 . The system of  claim 37 , wherein the status indicates that the guest virtual machine is not to be used by anyone, and the instructions further include instructions to prevent the attempted use of the guest virtual machine. 
     
     
         40 . The system of  claim 37 , wherein the instructions further include instructions to change the status of the guest virtual machine from a status indicating that the guest virtual machine is able to be accessed by an authorized user to a status indicating that the guest virtual machine is not to be used by anyone, and the instructions further include instructions to prevent the attempted use of the guest virtual machine.

Join the waitlist — get patent alerts

Track US2016366143A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.