Invention Grant
US09438506B2 Identity and access management-based access control in virtual networks
有权
基于身份和访问管理的虚拟网络中的访问控制
- Patent Title: Identity and access management-based access control in virtual networks
- Patent Title (中): 基于身份和访问管理的虚拟网络中的访问控制
-
Application No.: US14103628Application Date: 2013-12-11
-
Publication No.: US09438506B2Publication Date: 2016-09-06
- Inventor: Mark Ryland
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Meyertons, Hood, Kivlin, Kowert & Goetzel, P.C.
- Agent Robert C. Kowert
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L12/56 ; H04L12/66 ; H04L12/701 ; H04L12/24 ; H04L12/911

Abstract:
Methods and apparatus for providing identity and access management-based access control for connections between entities in virtual (overlay) network environments. At the encapsulation layer of the overlay network, an out-of-band connection creation process may be leveraged to enforce access control and thus allow or deny overlay network connections between sources and targets according to policies. For example, resources may be given identities, identified resources may assume roles, and policies may be defined for the roles that include permissions regarding establishing connections to other resources. When a given resource (the source) attempts to establish a connection to another resource (the target), role(s) may be determined, policies for the role(s) may be identified, and permission(s) checked to determine if a connection from the source to the target over the overlay network is to be allowed or denied.
Public/Granted literature
- US20150163158A1 IDENTITY AND ACCESS MANAGEMENT-BASED ACCESS CONTROL IN VIRTUAL NETWORKS Public/Granted day:2015-06-11
Information query