×

Virtual network pairs

  • US 9,619,662 B1
  • Filed: 01/11/2012
  • Issued: 04/11/2017
  • Est. Priority Date: 01/13/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method implemented by data processing apparatus, the method comprising:

  • maintaining, by a virtual machine registry service, a distinct secret key for each of a plurality of virtual machines executing on a plurality of host machines, wherein the secret key for each of the virtual machines (i) is known to a communication process that executes on the same host machine as the virtual machine and that manages network communication for the virtual machine, (ii) is not known to any of the plurality of virtual machines, and (iii) is used by the virtual machine registry service to authorize pairwise communications between the virtual machine and other virtual machines of the plurality of virtual machines;

    maintaining, by the virtual machine registry service, data identifying pairs of virtual machines that are allowed to communicate with one another;

    receiving, by the virtual machine registry service, a plurality of requests, each request being received from a respective source communication process that manages network communication for a respective source virtual machine, and each request being a request for a token that authenticates the respective source virtual machine as being authorized to communicate with a respective destination virtual machine to a respective destination communication process that manages network communication for the respective destination virtual machine;

    for each request of the plurality of requests;

    determining, by the virtual machine registry service, that the respective source virtual machine is authorized to communicate with the respective destination virtual machine by consulting the data identifying pairs of virtual machines that are allowed to communicate with one another;

    determining, by the virtual machine registry service, a host machine network address for the respective destination virtual machine;

    generating, by the virtual machine registry service, a token based at least partly on the host machine network address and the secret key of the respective destination virtual machine; and

    sending, by the virtual machine registry service, the selected host machine network address and generated token to the respective source communication process for the respective source virtual machine for transmission to the respective destination communication process as evidence that the respective source virtual machine is authorized to communicate with the respective destination virtual machine.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×