Uniquely identifying and securely communicating with an appliance in an uncontrolled network
Abstract
A service consumer that utilizes a cloud-based access service provided by a service provider has associated therewith a network that is not capable of being controlled by the service provider. An enterprise connector is supported in this uncontrolled network, preferably as an appliance-based solution. According to this disclosure, the enterprise configures an appliance and then deploys it in the uncontrolled network. To this end, an appliance is required to proceed through a multi-stage approval protocol before it is accepted as a “connector” and is thus enabled for secure communication with the service provider. The multiple stages include a “first contact” (back to the service) stage, an undergoing approval stage, a re-generating identity material stage, and a final approved and configured stage. Unless the appliance passes through these stages, the appliance is not permitted to interact with the service as a connector. As an additional aspect, the service provides various protections for addressing scenarios wherein entities masquerade as approved appliances.
Claims
exact text as granted — not AI-modifiedHaving described our invention, what is claimed is set forth as follows:
1 . A method of preventing an instance of an sanctioned but uncontrolled appliance from being deploying in an untrusted network to interoperate with a cloud-based managed service providing secure enterprise access, comprising:
maintaining state information about the sanctioned but uncontrolled appliance, wherein the state information is one of: a stage of an approval process that the cloud-based managed service considers the appliance to be in, identity information presented by the appliance, and network information; receiving a request from an unknown entity, wherein the request is associated with the instance of the unsanctioned but uncontrolled appliance; and using the state information to determine whether the instance of the unsanctioned but uncontrolled appliance is permitted secure enterprise access.
2 . The method as described in claim 1 wherein the stage of the approval process is one of: first contact, undergoing approval, re-generating identity material, and approved and configured.
3 . The method as described in claim 1 wherein the identity information is one of: a Universally Unique Identifier (UUID), and a certificate.
4 . The method as described in claim 1 wherein the network information is one of: data derived from an incoming connection, and data maintained by the cloud-based managed service.
5 . The method as described in claim 1 wherein data maintained by the cloud-based managed service is a network range on which to expect incoming traffic from the appliance.
6 . The method as described in claim 1 wherein the sanctioned but uncontrolled appliance has not yet undergone a registration with the cloud-based managed service.
7 . The method as described in claim 1 wherein the sanctioned but uncontrolled appliance has undergone a registration with the cloud-based managed service.Join the waitlist — get patent alerts
Track US2023208653A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.