US2023336991A1PendingUtilityA1

System and method for establishing trust between multiple management entities with different authentication mechanisms

Assignee: VMWARE INCPriority: Apr 2, 2021Filed: Jun 26, 2023Published: Oct 19, 2023
Est. expiryApr 2, 2041(~14.7 yrs left)· nominal 20-yr term from priority
H04W 12/068H04W 12/69H04W 12/0431H04W 12/0433H04W 12/084H04L 63/0807H04W 12/043
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for establishing trust between management entities with different authentication mechanisms in a computing system utilizes a token exchange service to acquire a second security token used in a second management entity in exchange for a first security token used in a first management entity. When a request with the second security token is sent from the first management entity to the second management entity, the second security token is validated using a public key from the first management entity at the second management entity. After validation, the request is processed at the second management entity and a response is transmitted to the first management entity.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for establishing trust between management entities with different authentication mechanisms in a computing system, the method comprising:
 creating a first account in a first management entity and a corresponding second account in a second management entity, wherein the first management entity uses a first token-based authentication mechanism and the second management entity uses a second token-based authentication mechanism;   acquiring a first security token at the first management entity using the first account to access the second management entity;   acquiring a second security token from a token exchange service in exchange for the first security token;   sending a request with the second security token from the first management entity to the second management entity using the corresponding second account;   validating the second security token using a public key from the first management entity at the second management entity; and   after validating the second security token, sending a response to the request back to the first management entity from the second management entity.   
     
     
         2 . The method of  claim 1 , wherein acquiring the first security token at the first management entity includes acquiring a security assertion markup language (SAML) token for a user identification for the first account at the first management entity to access the second management entity. 
     
     
         3 . The method of  claim 2 , wherein acquiring the second security token from the token exchange service includes acquiring a JavaScript Object Notation (JSON) Web Token (JWT) token from the token exchange service at the first management entity in exchange for the SAML token. 
     
     
         4 . The method of  claim 1 , further comprising setting an endpoint at the first management entity as an authentication endpoint for the second management entity. 
     
     
         5 . The method of  claim 4 , further comprising retrieving the public key from the first management entity by the second management entity using the authentication endpoint. 
     
     
         6 . The method of  claim 1 , further comprising registering the second management entity with a lookup service of the first management entity as a service to connect with the first management entity and requesting an endpoint of the second management entity from the lookup service to send the request to the second management entity from the first management entity. 
     
     
         7 . The method of  claim 1 , further comprising restricting access to the second management entity using credentials, and after validating the second security token, authorizing the request using the credentials at the second management entity. 
     
     
         8 . The method of  claim 1 , further comprising:
 registering the second management entity with the first management entity as an extension of the first management entity; and   registering the first management entity with the second management entity as a compute manager of the second management entity.   
     
     
         9 . A non-transitory computer-readable storage medium containing program instructions for establishing trust between management entities with different authentication mechanisms in a computing system, wherein execution of the program instructions by one or more processors of a computer system causes the one or more processors to perform steps comprising:
 creating a first account in a first management entity and a corresponding second account in a second management entity, wherein the first management entity uses a first token-based authentication mechanism and the second management entity uses a second token-based authentication mechanism;   acquiring a first security token at the first management entity using the first account to access the second management entity;   acquiring a second security token from a token exchange service in exchange for the first security token;   sending a request with the second security token from the first management entity to the second management entity using the corresponding second account;   validating the second security token using a public key from the first management entity at the second management entity; and   after validating the second security token, sending a response to the request back to the first management entity from the second management entity.   
     
     
         10 . The non-transitory computer-readable storage medium of  claim 9 , wherein acquiring the first security token at the first management entity includes acquiring a security assertion markup language (SAML) token for a user identification for the first account at the first management entity to access the second management entity. 
     
     
         11 . The non-transitory computer-readable storage medium of  claim 10 , wherein acquiring the second security token from the token exchange service includes acquiring a JavaScript Object Notation (JSON) Web Token (JWT) token from the token exchange service at the first management entity in exchange for the SAML token. 
     
     
         12 . The non-transitory computer-readable storage medium of  claim 9 , wherein the steps further comprise setting an endpoint at the first management entity as an authentication endpoint for the second management entity. 
     
     
         13 . The non-transitory computer-readable storage medium of  claim 12 , wherein the steps further comprise retrieving the public key from the first management entity by the second management entity using the authentication endpoint. 
     
     
         14 . The non-transitory computer-readable storage medium of  claim 9 , wherein the steps further comprise registering the second management entity with a lookup service of the first management entity as a service to connect with the first management entity and requesting an endpoint of the second management entity from the lookup service to send the request to the second management entity from the first management entity. 
     
     
         15 . The non-transitory computer-readable storage medium of  claim 9 , wherein the steps further comprise restricting access to the second management entity using credentials, and after validating the second security token, authorizing the request using the credentials at the second management entity. 
     
     
         16 . The non-transitory computer-readable storage medium of  claim 9 , wherein the steps further comprise:
 registering the second management entity with the first management entity as an extension of the first management entity; and   registering the first management entity with the second management entity as a compute manager of the second management entity.   
     
     
         17 . A system comprising:
 memory; and   at least one processor configured to:
 create a first account in a first management entity and a corresponding second account in a second management entity, wherein the first management entity uses a first token-based authentication mechanism and the second management entity uses a second token-based authentication mechanism; 
 acquire a first security token at the first management entity using the first account to access the second management entity; 
 acquire a second security token from a token exchange service in exchange for the first security token; 
 send a request with the second security token from the first management entity to the second management entity using the corresponding second account; 
 validate the second security token using a public key from the first management entity at the second management entity; and 
 after the second security token is validated, send a response to the request back to the first management entity from the second management entity. 
   
     
     
         18 . The system of  claim 17 , wherein the first security token is a security assertion markup language (SAML) token and the second security token is a JavaScript Object Notation (JSON) Web Token (JWT) token. 
     
     
         19 . The system of  claim 17 , wherein the at least one processor is configured to set an endpoint at the first management entity as an authentication endpoint for the second management entity and retrieve the public key from the first management entity by the second management entity using the authentication endpoint. 
     
     
         20 . The system of  claim 17 , wherein the at least one processor is configured to register the second management entity with a lookup service of the first management entity as a service to connect with the first management entity and request an endpoint of the second management entity from the lookup service to send the request to the second management entity from the first management entity.

Join the waitlist — get patent alerts

Track US2023336991A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.