发明授权
- 专利标题: Authentication and authorization methods for cloud computing security
- 专利标题(中): 云计算安全的认证和授权方法
-
申请号: US13173563申请日: 2011-06-30
-
公开(公告)号: US08769622B2公开(公告)日: 2014-07-01
- 发明人: David Yu Chang , Messaoud Benantar , John Yow-Chun Chang , Vishwanath Venkataramappa
- 申请人: David Yu Chang , Messaoud Benantar , John Yow-Chun Chang , Vishwanath Venkataramappa
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; David H. Judson
- 主分类号: H04L9/08
- IPC分类号: H04L9/08
摘要:
An authentication and authorization plug-in model for a cloud computing environment enables cloud customers to retain control over their enterprise information when their applications are deployed in the cloud. The cloud service provider provides a pluggable interface for customer security modules. When a customer deploys an application, the cloud environment administrator allocates a resource group (e.g., processors, storage, and memory) for the customer's application and data. The customer registers its own authentication and authorization security module with the cloud security service, and that security module is then used to control what persons or entities can access information associated with the deployed application. The cloud environment administrator, however, typically is not registered (as a permitted user) within the customer's security module; thus, the cloud environment administrator is not able to access (or release to others, or to the cloud's general resource pool) the resources assigned to the cloud customer (even though the administrator itself assigned those resources) or the associated business information. To further balance the rights of the various parties, a third party notary service protects the privacy and the access right of the customer when its application and information are deployed in the cloud.
公开/授权文献
信息查询