Tenantless access orchestration engine in a cloud access management system

By configuring temporary identities for remote client devices on the cloud platform through a tenantless access orchestration engine, the inefficiency of adding devices to the consumer context in existing cloud access management systems is solved, enabling seamless consumer identity management and flexible access in DaaS scenarios.

CN122460049APending Publication Date: 2026-07-24MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480081946.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-24
Filing Date
2024-12-10
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing cloud access management systems fail to effectively support the addition of remote client devices in the consumer context, resulting in inefficiency and availability issues, and lacking adaptation and customization capabilities for consumer use cases.

Method used

Employing a tenantless access orchestration engine, it simplifies the device joining process by configuring temporary identities for remote client devices on the cloud platform and installing boot tokens using secure channels in the cloud provider's management environment, while also supporting tenantless identity management within the consumer context.

Benefits of technology

It enables seamless integration into the cloud platform within the consumer context, improving the flexibility and efficiency of computing operations and interfaces, and supporting tenantless access for remote client devices in DaaS scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122460049A_ABST
    Figure CN122460049A_ABST
Patent Text Reader

Abstract

Methods, systems, and computer storage media for providing cloud access management using a tenantless access orchestration engine. Cloud access management supports tenantless access orchestration operations that allow a user to use a remote client device in a consumer context. In particular, the remote client device can have an identity that operates on a cloud platform without having a tenant instance associated with the remote client device. In operation, a request is communicated to an identity provider to create identity provider data for a remote client device of the cloud platform. Based on communicating the request, a bootstrap token containing a remote client identifier is received. The remote client device is configured based on creating a set of cloud resources for the remote client device and installing the bootstrap token onto a virtual machine associated with the remote client device. The virtual machine is associated with a cloud provider management environment of the cloud platform.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Users rely on computing environments with applications and services to complete computing tasks. Distributed computing systems (or cloud computing platforms) host and support different types of applications and services within managed computing environments. Specifically, a cloud computing platform can implement a cloud access management system that provides access management functionality for different types of cloud computing products. For example, a cloud access management system can support organizational onboarding of different types of cloud computing products—including managed desktop services, which include virtual machines assigned to individual users as virtual desktop devices configured with productivity, security, and collaboration tools. Summary of the Invention

[0002] The various aspects of the technology described herein generally relate to systems, methods, and computer storage media for providing cloud access management using a tenantless access orchestration engine. Cloud access management supports access orchestration operations that allow users to use remote client devices (or remote clients) in a consumer context. Specifically, a remote client device can have a remote client device identity for operation on a cloud platform without having a tenant associated with it.

[0003] The tenantless access orchestration engine operates based on a tenantless access orchestration workflow designed for the identity of remote client devices targeting consumers. As described, the tenantless access orchestration workflow includes access orchestration operations that support Desktop-as-a-Service (DaaS) scenarios, where a cloud platform hosts cloud resources in a cloud provider-managed environment (also known as "HOBO" hosting). The cloud platform can register remote client devices without associating them with tenant information. The cloud platform configures the remote client device using cloud resources associated with the cloud provider-managed environment. The cloud platform also installs a bootstrap token as a temporary identity on the remote client device via a secure channel of the cloud provider-managed environment. This tenantless access orchestration workflow simplifies the onboarding process for remote client devices and provides the flexibility to assign the remote client device to a tenant or consumer user after it has been onboarded.

[0004] Typically, cloud access management systems are not configured with comprehensive computing logic and infrastructure to effectively support the addition of remote client devices from consumer users to the cloud platform (without tenant information). In some examples, cloud-driven productivity platforms or cloud computing platforms (“cloud platforms”) can be designed to provide productivity applications. For example, cloud-driven tools and services can be provided by Microsoft 365. Cloud platforms and productivity applications can be implemented via PCs, Macs, tablets, and phones. Cloud platforms can provide applications and services designed to help individuals, businesses, and organizations collaborate, communicate, and complete tasks more efficiently.

[0005] The cloud platform was initially designed to support business use cases, or "business contexts" (e.g., small businesses and organizations). Therefore, the existing architecture lacks the adaptation and customization capabilities for consumer use cases, or "consumer contexts." Specifically, while the existing architecture meets the specific needs and requirements of users in the business context, inbound users for the consumer context require different features, capabilities, and user interactions. This inconsistency between the initial architecture of the cloud platform and the unique needs and expectations of extended contexts leads to potential inefficiencies, usability issues, and mismatches between business and consumer context requirements. Therefore, adaptation and customization are necessary to ensure improved performance (e.g., operations and interfaces) and enhanced user satisfaction for computing capabilities in diverse settings for extended uses.

[0006] Technical solutions to address the limitations of conventional cloud access management systems can include providing tenantless access orchestration operations and interfaces via a tenantless access orchestration engine that supports cloud access management within the cloud access management system. Tenantless access orchestration operations can include managing remote client devices that are not associated with a tenant. In a business context, remote client devices are associated with a tenant; however, in a consumer context, remote client devices are not associated with a tenant. Specifically, for the consumer context, no tenant information is available for consumer identity and for remote client devices to join the cloud platform. The cloud platform can operate with a cloud-based identity provider or access management service (e.g., MICROSOFTENTRA ID or AZURE ACTIVE DIRECTORY) but does not require tenant information (e.g., tenant instance) corresponding to the remote client device to join the identity. In this way, the tenantless access orchestration engine supports tenantless access orchestration workflows to manage the identities of remote client devices for consumers. In this way, the cloud platform can support DaaS scenarios and tenantless access orchestration engines that support the identities of remote client devices for consumers not associated with a tenant, while maintaining the same level of security.

[0007] In operation, in the first embodiment, a request is transmitted from the cloud-based service engine to the identity provider to create identity provider data for a remote client device on the cloud platform. Based on the transmission of this request, a bootstrap token containing a new remote client device identifier is received. The remote client device is configured, wherein configuring the remote client device includes creating a set of cloud resources and installing the bootstrap token onto a virtual machine associated with the remote client device. The virtual machine is associated with a cloud provider management environment and a secure channel of the cloud provider management environment, which supports the installation of the bootstrap token on the virtual machine. The remote client device is configured to use the bootstrap token to request a signing certificate from the identity provider, wherein the signing certificate enables the remote client device to access applications and services on the cloud platform.

[0008] In the second embodiment, a first request for an identity provider for a remote client device to create a cloud platform is received from the cloud-based service engine. Identity provider data including a bootstrap token is generated. The bootstrap token contains a new remote client device identifier. The bootstrap token containing the new remote client device identifier is transmitted. A second request for a signing certificate from the remote client device is received. The signing certificate is transmitted to the remote client device to enable the remote client device to access applications and services on the cloud platform.

[0009] In the third embodiment, a request for a signing certificate is transmitted from a remote client device. The signing certificate is associated with identity provider data on the remote client device. The signing certificate is received from the identity provider, and this signing certificate is associated with identity provider data. Based on this signing certificate, applications or services of the cloud platform are accessed at the remote client device.

[0010] This summary provides a simplified overview of some concepts that will be further described in the following detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter. Attached Figure Description

[0011] The techniques described herein are described in detail below with reference to the accompanying drawings, in which:

[0012] Figure 1A and Figure 1B This is a block diagram of an exemplary cloud access management system, including a tenantless access orchestration engine, based on various aspects of the technologies described herein.

[0013] Figure 1C and Figure 1D This is a schematic diagram relating to an exemplary cloud access management system, including a tenantless access orchestration engine, based on various aspects of the technologies described herein.

[0014] Figure 2A and 2B This is a block diagram of an exemplary cloud access management system, including a tenantless access orchestration engine, based on various aspects of the technologies described herein.

[0015] Figure 3 This paper provides a first exemplary method for providing cloud access management using a tenantless access orchestration engine, based on various aspects of the technologies described herein.

[0016] Figure 4 A second exemplary method for providing cloud access management using a tenantless access orchestration engine, based on various aspects of the technologies described herein, is provided.

[0017] Figure 5 A third exemplary method for providing cloud access management using a tenantless access orchestration engine, based on various aspects of the technologies described herein, is provided.

[0018] Figure 6 Block diagrams are provided for exemplary distributed computing environments suitable for implementing various aspects of the techniques described herein; and

[0019] Figure 7 This is a block diagram of an exemplary computing environment applicable to implementing various aspects of the techniques described herein. Detailed Implementation

[0020] Overview

[0021] The cloud access management system supports identity and access management in the cloud. It provides on-site and remote employees with seamless access to their organization's resources, secure and seamless access to applications, and protection and governance of access. For example, it efficiently manages identities by ensuring the right people have the right access to the right resources. The system also supports access to different types of cloud products. For instance, it can support organizational onboarding for different types of cloud computing products—including managed desktop services, which consist of virtual machines assigned to individual users as virtual desktop devices configured with productivity, security, and collaboration tools.

[0022] Typically, cloud access management systems are not configured with comprehensive computing logic and infrastructure to effectively support the onboarding of remote client devices of consumer users to the cloud platform (without tenant information). The cloud platform may initially be designed to cater to the needs of enterprises (specifically, small businesses and organizations). However, the platform's design is not suited to consumer use cases. In this way, cloud access management can be tailored to the "business context"—the originally intended users and their requirements—rather than the "consumer context"—the broader audience that includes individual consumers with varying needs and expectations. The existing architecture of the cloud platform is customized to support user onboarding in the business context and optimized for the specific needs and requirements of the business. However, when it comes to user onboarding in the consumer context, there are different requirements in terms of characteristics, capabilities, and user interactions. The current architecture is inconsistent with the unique needs of consumers, leading to potential inefficiencies and usability issues. Therefore, a more comprehensive cloud access management system with alternative foundations for performing cloud access management operations can improve the computing operations and interfaces within the cloud access management system.

[0023] Embodiments of this technical solution relate to systems, methods, and computer storage media for providing cloud access management using a tenantless access orchestration engine. Cloud access management supports access orchestration operations that allow users to operate remote client devices (or remote clients) within a consumer context. Specifically, a remote client device can operate on a cloud platform with a remote client device identity without having a tenant (e.g., tenant information) associated with it. Cloud access management is provided using a tenantless access orchestration engine operatively integrated into a cloud access management system.

[0024] The tenantless access orchestration engine operates based on a tenantless access orchestration workflow designed for the identity of remote client devices targeting consumers. As described, the tenantless access orchestration workflow includes access orchestration operations that support Desktop-as-a-Service (DaaS) scenarios, where the cloud platform hosts cloud resources in a cloud provider-managed environment (also known as "HOBO" hosting). The cloud platform can register a remote client device without associating it with tenant information. The cloud platform configures the cloud resources associated with the cloud provider-managed environment for the remote client device and installs a bootstrap token as a temporary identity via a secure channel within the cloud provider-managed environment. The tenantless access orchestration workflow simplifies the onboarding process for remote client devices and provides the flexibility to assign the remote client device to a tenant or consumer user after it has been onboarded.

[0025] Overall, the cloud access management system supports access orchestration operations that allow users to utilize remote client devices (or remote clients) within a consumer context. Within this context, a consumer identity can be an account or profile with credentials (e.g., username and password, time-based one-time passwords, numeric matching, notifications, biometrics, multi-factor authentication) used to grant access to computing resources. It is conceivable that a consumer identity can be associated with different types of authentication mechanisms that verify the user's identity to ensure that only authorized users gain access to protected resources. This consumer identity can be assigned to an account or profile on a cloud provider platform that supports various cloud computing products.

[0026] A consumer identity can be associated with one or more identity providers (e.g., external and / or internal identity providers) used for authentication and can be associated with an email service. A consumer identity can be an existing one or can be created in real-time. This consumer identity can be associated with consumer identity resources (e.g., personal user resources, cloud storage devices, email, applications, and services) accessible via a computing environment (e.g., a remote client workspace or a virtual machine workspace). In one example, a user can use their consumer identity (e.g., Outlook, Gmail, Hotmail, or a phone number) to register an account associated with a cloud computing provider (e.g., a Microsoft account). This account can be passwordless (e.g., using multi-factor authentication). The consumer identity associated with the account can be used to access remote clients associated with tenants of a tenantless consumer or organization. The organization can be a customer of the cloud computing platform. The consumer or organization can be provided with cloud computing platform services, including access to, management of, and development of applications and services.

[0027] A tenantless access orchestration engine can comprise three main components: a cloud-based service engine, remote client devices, and an identity provider. The cloud-based service engine provides management services for business resources and logic. For example, it configures remote client devices, monitors them, and enables users to restart and restore them. Remote client devices are cloud-hosted virtual desktops or DaaS (Data as a Service). They are virtual desktop environments hosted on a cloud platform rather than on a local physical computer or deployed locally. Specifically, remote client devices can be HOBO (i.e., cloud provider-managed environment) remote client devices, supported by the cloud platform provider. For example, the subscriptions associated with the remote client devices are owned and controlled by the cloud platform provider. The identity provider is built to provide identity support, including maintaining device identities, issuing tokens and device certificates, and providing metadata for token and certificate verification.

[0028] refer to Figure 1C , Figure 1C The diagram illustrates a sample process for a remote client device to join a tenantless identity system (i.e., a tenantless access orchestration engine). Figure 1C The diagram illustrates a cloud-based service engine 102C, an identity provider 104C, and a remote client device 106C. The remote client device 106C can be hosted on a cloud computing platform via a tenantless access orchestration engine. The hosting process can be in three stages: (1) remote client device pre-creation stage; (2) remote client device configuration stage; and (3) certificate signing stage.

[0029] During the remote client device pre-creation phase, the cloud-based service engine 102C creates a remote client device 106C in the identity provider 104C at step 1C, and at step 2C, the identity provider 104C returns a bootstrap token containing a remote client device identifier (e.g., a new remote client device identifier). The identity provider 104C stores the remote client device identity 104C, including the join status and assignment status of the remote client device 106C.

[0030] During the remote client device configuration phase, the cloud-based service engine 102C configures the remote client device 106C at step 3C by creating a set of cloud resources. The cloud-based service engine 102C also installs a boot token onto the virtual machine associated with the remote client device 106C. As described above, the cloud resources are associated with a cloud provider management environment (e.g., a subscription) owned and controlled by the cloud platform provider. The cloud provider management environment can utilize trusted or secure channels within the cloud provider management environment to securely install the boot token onto a specific virtual machine.

[0031] During the certificate signing phase, remote client device 106C requests a certificate using a bootstrap token at step 4C, and identity provider 104C signs the certificate at step 5C. After verifying the token, it updates the remote client device's identity joining status and remote client device allocation status. Once remote client device 106C has joined the cloud platform via the cloud provider's management environment, it can use the signed certificate as its identity to communicate with applications and services on the cloud platform. It is conceivable that identity provider 104C can assign remote client device 106C to tenant users or consumer users.

[0032] Using a tenantless access orchestration workflow to add remote client devices can offer improvements over tenant-based access orchestration workflows. With tenant-based access orchestration, the identity of a remote client device is meaningless without a corresponding tenant account as the owner. The identity provider requires tenant account information to add a remote client device. However, in a DaaS scenario, the cloud provider's management environment manages its cloud resources on behalf of the user, allowing the cloud provider's management environment to register remote client devices without tenant information. In this way, the tenantless access orchestration workflow simplifies the remote client device onboarding process and provides the flexibility to assign remote client devices to tenants or consumer users after onboarding.

[0033] As explained, IoT devices on public networks typically require user credentials as the primary identity to securely trigger remote client device joining. In a DaaS scenario, the cloud platform uses a cloud provider management environment with cloud resources to configure remote client devices and leverages a secure channel within the cloud provider management environment to install a bootstrap token as a temporary identity. This allows remote client devices to initiate remote client joining without requiring user credentials.

[0034] refer to Figure 1D , Figure 1DThe illustration depicts example steps for assigning an identity to a remote client device using a tenantless access orchestration engine associated with a cloud-based service engine 102D, an identity provider 104D, and a remote client device 106D. In step 1D, the cloud-based service engine 102D transmits a request to create a new remote client device. In step 2D, the identity provider 104D receives the request and generates a remote client device identifier for the remote client device 106D based on the request. In step 3D, the identity provider 104D issues a bootstrap token containing the remote client device identifier and returns the token to the cloud-based service engine. In step 4D, the cloud-based service engine 102D configures the remote client device 106D by creating a set of cloud resources and installing an agent in a virtual machine with the bootstrap token. In step 5D, the remote client device 106D generates a Certificate Signing Request (CSR) containing the remote client device identifier and sends the CSR to the identity provider 104D using the bootstrap token. In step 6D, the identity provider verifies the bootstrap token and the associated remote client device identifier, then issues a certificate containing the remote client device identifier and marks the device as registered. In step 7D, the identity provider returns the certificate to the remote client device 106D, and the remote client device 106D installs the certificate.

[0035] Examples and references are available. Figures 1A to 1B To describe various aspects of the technical solution. Figure 1A The diagram illustrates a cloud computing environment (system) 100 and a cloud access management system 100A. The cloud access management system 100A includes a network 110B, a tenantless access orchestration engine 110, remote clients 140 and 142, a cloud access management client 160, and a cloud access management client 170.

[0036] Cloud computing environment 100 provides computing system resources for different types of managed computing environments. For example, the cloud computing platform supports the delivery of computing services—including computing, servers, storage devices, databases, networking, and intelligence. Multiple cloud access management clients (e.g., cloud access management client 160 and cloud access management client 170) include hardware or software for accessing resources in cloud computing environment 100. Cloud access management client 160 and cloud access management client 170 may each include applications that support client-side functionality associated with the cloud computing environment. For example, cloud access management client 160 may represent a consumer client associated with remote client 140 in a consumer context; and cloud access management client 170 may be associated with remote client 142 in a business context. Multiple cloud access management clients can access the computing components of cloud computing environment 100 via a network (e.g., network 100B) to perform computing operations.

[0037] The cloud access management system 100A is designed to provide access management using a tenantless access orchestration engine 110. The cloud access management system 100A provides an integrated operating environment based on a tenantless access orchestration framework associated with providing tenantless access to the cloud platform to remote client devices. Specifically, the tenantless access orchestration engine 110 includes tenantless access orchestration operations that support consumer users accessing remote clients (e.g., remote client 140) in a consumer context (i.e., without tenant information) and support organization users accessing remote clients (e.g., remote client 142) in a business context (i.e., with tenant information).

[0038] refer to Figure 1B , Figure 1B The diagram illustrates a cloud access management system 100A and a tenantless access orchestration engine 110, which includes a cloud-based service engine 120, an identity provider 130, remote clients 140 and 142, a cloud provider management environment 150, tenants 152, a cloud access management client 160, and a cloud access management client 170.

[0039] The tenantless access orchestration engine 110 includes a cloud-based service engine 120, an identity provider 130, and remote clients 140 (or 142). The cloud-based service engine 120 provides management services for business resources and logic. For example, the cloud-based service engine 120 configures remote client devices (e.g., remote client 140 or remote client 142), monitors remote client devices, and enables users to restart and restore remote client devices (e.g., via cloud access management client 160 or cloud access management client 170).

[0040] Remote client device 140 is a cloud-hosted virtual desktop or DaaS. Remote client device 140 is a virtualized desktop environment hosted in a cloud platform rather than hosted on a local physical computer or deployed locally. Remote client device 140 can specifically be a HOBO (e.g., cloud provider-managed environment 150) remote client device supported by a cloud platform provider. For example, cloud provider-managed environment 150 can be a subscription associated with the remote client device and owned and controlled by the cloud platform provider. The remote device (e.g., remote client device 150) can be supported by a tenant (e.g., tenant 152), which is a reserved cloud infrastructure instance that an organization receives, owns, and controls once it registers for cloud computing services via the cloud platform. Identity provider 130 is configured to provide identity support (including maintaining device identity, issuing tokens and device certificates), and to provide metadata for token and certificate verification.

[0041] Remote client device 140 can be hosted on a cloud computing platform via a tenantless access orchestration engine 110. The hosting process can be in three phases: (1) remote client device pre-creation phase; (2) remote client device configuration phase; and (3) certificate signing phase. In the remote client device pre-creation phase, the cloud-based service engine 110 creates remote client device 140 in identity provider 130, and identity provider 120 returns a bootstrap token containing the remote client device identifier. Identity provider 130 stores identity provider data, including the joining status and allocation status of remote client device 140.

[0042] During the remote client device configuration phase, the cloud-based service engine 120 configures the remote client device 140 by creating a set of cloud resources. The cloud-based service engine 120 also installs a boot token onto the virtual machine associated with the remote client device 140. As described above, the cloud resources are associated with a cloud provider management environment 150 owned and controlled by the cloud platform provider. The cloud provider management environment 150 can utilize a trusted or secure channel (not shown) within it to securely install the boot token onto a specific virtual machine.

[0043] During the certificate signing phase, remote client device 140 uses a bootstrap token to request a certificate, and identity provider 130 signs the certificate and updates the remote client device's identity joining and assignment states after verifying the token. After remote client device 140 has joined the cloud platform via cloud provider management environment 150, remote client device 150 can use the signed certificate as its identity to communicate with applications and services on the cloud platform. It is conceivable that identity provider 130 can assign remote client device 142 to tenant users (e.g., tenant 152).

[0044] Examples and references are available. Figure 2A and Figure 2B To describe various aspects of the technical solution. Figure 2A This is a block diagram of an exemplary technical solution environment, based on a reference. Figure 6 and Figure 7 An example environment for implementing the described technical solution is shown. Typically, the technical solution environment includes a technical solution system suitable for providing an example cloud access management system 100A, wherein the methods of this disclosure can be employed. Specifically, Figure 2A The high-level architecture of a cloud access management system 100A according to an implementation of this disclosure is shown. Except for other engines, managers, generators, selectors, or components (collectively referred to herein as "components") not shown, the technical solution environment of the cloud access management system 100A corresponds to... Figure 1A and Figure 1B .

[0045] refer to Figure 2A , Figure 2A The diagram illustrates a cloud access management system 100A with a tenantless access orchestration engine 110, which has a cloud-based service engine 120, an identity provider 130, a remote client 140, a cloud provider management environment 150, and a cloud access management client 160, wherein the cloud provider management environment 150 includes a virtual machine 150A and a secure channel 150B.

[0046] Tenantless access orchestration engine 110 includes access orchestration operations that allow users to use remote client devices (e.g., remote client 140) in a consumer context without requiring tenant information. Cloud-based service engine 120 transmits a request to identity provider 130 to create identity provider data for the remote client device on the cloud platform. Based on transmitting this request, cloud-based service engine 120 receives a bootstrap token containing a remote client device identifier, which is generated and transmitted by identity provider 130.

[0047] The cloud-based service engine 120 configures the remote client device 140. Configuring the remote client device 140 includes creating a set of cloud resources for the remote client device 140 and installing a boot token onto the virtual machine 150A associated with the remote client device 140. The remote client device 140 is configured to use the boot token to request a signing certificate from the identity provider 130, which enables the remote client device 140 to access applications and services on the cloud platform.

[0048] Virtual machine 150A is associated with cloud provider management environment 150. Cloud provider management environment 150 includes a secure channel 150B, which supports the installation of a boot token on virtual machine 150A within cloud provider management environment 150. The boot token can be a temporary identity, operable with remote client device 140 in a consumer context associated with cloud provider management environment 150. Tenantless access orchestration engine 140 provides tenantless access orchestration operations to allow users to use remote client devices in a consumer context when they are not associated with tenant information. Tenantless access orchestration operations support the DaaS (Daily as a Service) features of cloud platforms hosting cloud resources within cloud provider management environment 150.

[0049] Remote client device 140 sends a request for a signing certificate to identity provider 130. This signing certificate is generated based on identity provider data for remote client device 140. Remote client device 140 receives the signing certificate associated with the identity provider data. Based on this signing certificate, remote client device 140 accesses applications or services on the cloud platform.

[0050] Identity provider 130 receives a first request from cloud-based service engine 120 to create identity provider data for remote client device 140. Identity provider 130 transmits a bootstrap token containing the remote client device identifier. Identity provider 130 receives a second request from remote client 140 for a signing certificate and transmits the signing certificate to remote client device 140. The signing certificate enables the remote client device to access applications and services on the cloud platform. Identity provider 130 stores identity provider data, which includes the remote client device's join and assignment status.

[0051] refer to Figure 2B , Figure 2B The illustration depicts a cloud-based service engine 120, an identity provider 130, and a remote client device 140 according to an embodiment of the present technical solution. At box 10, the cloud-based service engine 120 transmits a request to create identity provider data for a remote client device on a cloud platform. At box 12, the identity provider receives a request to create identity provider data for the remote client device. At box 14, the identity provider 140 generates identity provider data including a boot token containing a client device identifier; and at box 16, a boot token containing the remote client device identifier is transmitted. At box 18, the cloud-based service engine receives the boot token containing the remote client device identifier; and at box 20, the remote client device is configured based on creating a set of cloud resources for the remote client device and installing the boot token onto a virtual machine associated with the remote client device.

[0052] At box 22, a virtual machine in the cloud provider's management environment is used to initialize remote client 14; and at box 24, remote client device 140 transmits a request for a signing certificate associated with the identity provider data of the remote client device. At box 26, identity provider 140 receives the request for the signing certificate; and at box 28, identity provider 140 transmits the signing certificate to enable the remote client device to access applications and services of the cloud platform. At box 30, the remote client device receives the signing certificate associated with the identity provider data; and at box 32, based on the signing certificate, remote client device 140 accesses applications or services of the cloud platform.

[0053] Example Method

[0054] refer to Figure 3 , Figure 4 and Figure 5A flowchart illustrating a method for providing cloud access management using a tenantless access orchestration engine is provided. This method can be executed using the cloud access management system described herein. In embodiments, one or more computer storage media have computer-executable or computer-usable instructions thereon that, when executed by one or more processors, can cause one or more processors to perform the method (e.g., a computer-implemented method) within the cloud access management system (e.g., a computer system or computing system).

[0055] Go to Figure 3 The document provides a flowchart illustrating method 300 for providing cloud access management using a tenantless access orchestration engine in a cloud access management system. At box 302, a request is sent to an identity provider to create identity provider data for a remote client device on the cloud platform. At box 304, based on sending the request, a bootstrap token containing a new remote client device identifier is received. At box 306, the remote client device is configured based on creating a set of cloud resources for the remote client device and installing the bootstrap token onto the virtual machine associated with the remote client device.

[0056] Go to Figure 4 This document provides a flowchart illustrating a method 400 for providing cloud access management using a tenantless access orchestration engine within a cloud access management system. At box 402, a first request is received from a cloud-based service engine to create identity provider data for a remote client device on the cloud platform. At box 404, identity provider data including a bootstrap token containing a new remote device identifier is generated. At box 406, the bootstrap token containing the new remote client device identifier is transmitted. At box 408, a second request for a signing certificate is received from the remote client. At box 410, the signing certificate is transmitted to the remote client device. The remote client device uses this signing certificate to access applications and services on the cloud platform.

[0057] Go to Figure 5 The document provides a flowchart illustrating a method 500 for providing cloud access management using a tenantless access orchestration engine within a cloud access management system. At box 502, a request for a signing certificate is transmitted from a remote client device to an identity provider, the signing certificate being generated based on the remote client device's identity provider data. At box 504, a signing certificate associated with the identity provider data is received from the identity provider. At box 506, based on the signing certificate, access is granted to applications or services on the cloud platform.

[0058] Technological improvements

[0059] Advantageously, embodiments of this technical solution include several inventive features (e.g., operations, systems, engines, and components) associated with a cloud access management system having a tenantless access orchestration engine. The inventive features are described with reference to operations for providing consumer-identity-based access to remote clients using a tenantless access orchestration engine in a cloud access management system. The functionality of embodiments of this technical solution has been described through implementations and examples to demonstrate that the tenantless access orchestration operation is a solution to specific problems in cloud access management, improving the computational operations and interfaces of the cloud access management system. For example, in a DaaS scenario, a cloud provider management environment manages cloud resources on behalf of users, allowing the cloud provider management environment to register remote client devices without tenant information. In this way, the tenantless access orchestration workflow simplifies the remote client device onboarding process and provides the flexibility to assign the remote client device to a tenant user or consumer user after onboarding.

[0060] Additional support for specific implementation methods

[0061] Example Distributed Computing System Environment

[0062] Now for reference Figure 6 , Figure 6 The illustration shows an example distributed computing environment 600 that can adopt the implementation of this disclosure. Specifically, Figure 6 A high-level architecture of an example cloud computing platform 610 that can host a technology solution environment or a portion thereof (e.g., a data trustee environment) is shown. It should be understood that this and other arrangements described herein are presented as examples only. For instance, many of the elements described herein can be implemented as discrete or distributed components, or in combination with other components, and in any suitable combination and location, as described above. Other arrangements and elements (e.g., machines, interfaces, functions, sequences, and functional groups) may be used in addition to or in lieu of those shown.

[0063] The data center can support a distributed computing environment 600, which includes a cloud computing platform 610, racks 620, and nodes 630 (e.g., computing devices, processing units, or blade servers) within the racks 620. The cloud computing platform 610 can be used to implement a technology solution environment that runs cloud services across different data centers and geographic regions. The cloud computing platform 610 can implement a fabrication controller 640 component for configuring and managing the resource allocation, deployment, upgrades, and management of cloud services. Typically, the cloud computing platform 610 stores data or runs service applications in a distributed manner. The cloud computing infrastructure 610 in the data center can be configured to host and support the operation of endpoints for specific service applications. The cloud computing infrastructure 610 can be a public cloud, a private cloud, or a dedicated cloud.

[0064] Node 630 may be configured with host 650 (e.g., operating system or runtime environment) on which a defined software stack runs on node 630. Node 630 may also be configured to perform specialized functions (e.g., compute node or storage node) within cloud computing platform 610. Node 630 is assigned to run one or more parts of a tenant's service application. A tenant may be a customer utilizing the resources of cloud computing platform 610. The service application components of cloud computing platform 610 that support a particular tenant may be referred to as multi-tenant infrastructure or tenant architecture. The terms service application, application, or service are used interchangeably herein and, broadly, refer to any software or part of software that runs or accesses storage and computing device locations within a data center.

[0065] When more than one individual service application is supported by node 630, node 630 can be partitioned into virtual machines (e.g., virtual machine 652 and virtual machine 654). Physical machines can also run individual service applications concurrently. Virtual machines or physical machines can be configured as personalized computing environments supported by resources 660 (e.g., hardware and software resources) in the cloud computing platform 610. It is conceivable that resources can be configured for specific service applications. Furthermore, each service application can be partitioned into functional parts, allowing each functional part to run on a separate virtual machine. In the cloud computing platform 610, multiple servers can be used to run service applications and perform data storage operations in a cluster. Specifically, servers can perform data operations independently but are exposed as a single device (referred to as a cluster). Each server in the cluster can be implemented as a node.

[0066] Client device 680 can be linked to service applications in cloud computing platform 610. Client device 680 can be any type of computing device, which can correspond to the reference... Figure 6The described computing device 600, for example, client device 680, can be configured to issue commands to cloud computing platform 610. In embodiments, client device 680 can communicate with service applications via Virtual Internet Protocol (IP) and load balancers or other means of directing communication requests to designated endpoints in cloud computing platform 610. Components of cloud computing platform 610 can communicate with each other via a network (not shown), which may include, but is not limited to, one or more local area networks (LANs) and / or wide area networks (WANs).

[0067] Example computing environment

[0068] Having briefly described an overview of embodiments of the present technical solution, the following describes an example operating environment in which embodiments of the present technical solution may be implemented, in order to provide a general context for various aspects of the present technical solution. Reference is made first, particularly to... Figure 6 The illustration shows an example operating environment for implementing an embodiment of the present technical solution, which is generally designated as computing device 600. Computing device 600 is merely an example of a suitable computing environment and is not intended to imply any limitation on the scope or functionality of the present technical solution. Computing device 600 should also not be construed as having any dependency or requirement in relation to any one or combination of the illustrated components.

[0069] This technical solution can be described in the general context of computer code or machine-usable instructions, including computer-executable instructions such as program modules, which are executed by a computer or other machine (such as a personal data assistant or other handheld device). Typically, program modules, including routines, programs, objects, components, data structures, etc., refer to code that performs a specific task or implements a specific abstract data type. This technical solution can be implemented in various system configurations, including handheld devices, consumer electronics, general-purpose computers, and more specialized computing devices. This technical solution can also be implemented in distributed computing environments, where tasks are performed by remote processing devices linked through a communication network.

[0070] refer to Figure 7 The computing device 700 includes a bus 710 that is directly or indirectly coupled to the following devices: a memory 712, one or more processors 714, one or more presentation components 716, an input / output port 718, an input / output component 720, and an exemplary power supply 722. The bus 710 may represent one or more buses (such as an address bus, a data bus, or a combination thereof). For clarity of concept, Figure 7The various boxes are shown with lines, and other arrangements of the described components and / or component functions are also envisioned. For example, a presentation component such as a display device can be considered an I / O component. Furthermore, the processor has memory. We recognize this as a matter of the art and reiterate... Figure 7 The schematic diagram illustrates only example computing devices that can be used in conjunction with one or more embodiments of this technical solution. No distinction is made between categories such as "workstation," "server," "laptop," and "handheld device," as all of these are envisioned for use in… Figure 7 Within that scope, it is referred to as a "computing device".

[0071] Computing device 700 typically includes a variety of computer-readable media. Computer-readable media can be any available media that can be accessed by computing device 700, and includes both volatile and non-volatile media, removable and non-removable media. By way of example and not limitation, computer-readable media can include computer storage media and communication media.

[0072] Computer storage media includes volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage devices, magnetic tape cassettes, magnetic tape, disk storage devices or other magnetic storage devices, or any other medium capable of storing desired information and accessible by the computing device 700. Computer storage media does not include the signal itself.

[0073] Communication media typically embody computer-readable instructions, data structures, program modules, or other data in the form of modulated data signals (such as carrier waves or other transmission mechanisms), and include any information delivery medium. The term "modulated data signal" means a signal whose characteristics are set or altered in a manner that encodes information in the signal. By way of example, and not limitation, communication media include wired media (such as wired networks or direct wired connections) and wireless media (such as acoustic, RF, infrared, and other wireless media). Any combination of the foregoing should also be included within the scope of computer-readable media.

[0074] Memory 712 includes computer storage media in the form of volatile and / or non-volatile memory. The memory may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disk drives, etc. Computing device 700 includes one or more processors that read data from various entities, such as memory 712 or I / O components 720. Multiple presentation components 716 present data indications to a user or other device. Exemplary presentation components include display devices, speakers, printing components, vibration components, etc.

[0075] I / O port 718 allows computing device 700 to be logically coupled to other devices (including I / O components 720), some of which may be built-in. Illustrative components include microphones, joysticks, game controllers, satellite antennas, scanners, printers, wireless devices, etc.

[0076] Additional structural and functional features of embodiments of this technical solution

[0077] Various components utilized herein have been identified, and it should be understood that any number of components and arrangements can be employed to achieve the desired functionality within the scope of this disclosure. For example, for clarity of concept, components in the embodiments depicted in the accompanying drawings are shown in lines. Other arrangements of these and other components can also be implemented. For example, although some components are depicted as single components, many of the elements described herein can be implemented as discrete or distributed components or in combination with other components, and implemented in any suitable combination and location. Some elements can be omitted entirely. Furthermore, the various functions described herein as being performed by one or more entities can be performed by hardware, firmware, and / or software. For example, various functions can be performed by a processor executing instructions stored in memory. Therefore, other arrangements and elements (e.g., machines, interfaces, functions, sequences, and groups of functions) may be used in addition to or in lieu of what is shown.

[0078] The embodiments described in the following paragraphs may be combined with one or more of the specifically described alternatives. Specifically, the claimed embodiments may include alternative references to more than one other embodiment. The claimed embodiments may specify further limitations on the claimed subject matter.

[0079] This document specifically describes embodiments of the technical solution to meet legal requirements. However, the specification itself is not intended to limit the scope of this patent. Rather, the inventors have envisioned that the claimed subject matter may also be embodied in other ways to include steps different from or similar combinations of steps described herein, and in combination with other current or future techniques. Furthermore, although the terms “step” and / or “box” may be used herein to indicate different elements of the method employed, these terms should not be construed as implying any particular order between the various steps disclosed herein, unless and only when the order of individual steps is explicitly described.

[0080] For the purposes of this disclosure, the word "including" has the same broad meaning as the word "comprising," and the word "access" includes "receive," "reference," or "retrieve." Furthermore, the word "transmit," facilitated by a software or hardware-based bus, receiver, or transmitter using the communication medium described herein, has the same broad meaning as the words "receive" or "transmit." Additionally, unless otherwise indicated, words such as "a" and "an" include both plural and singular forms. Thus, for example, in the presence of one or more features, it satisfies the constraint of "an feature." Furthermore, the term "or" includes conjunction, disjunction, and both (therefore, a or b includes either a or b, as well as a and b).

[0081] For the purposes of the detailed discussion above, embodiments of the present technical solution are described with reference to a distributed computing environment; however, the distributed computing environment depicted herein is merely exemplary. Components may be configured to perform novel aspects of the embodiments, wherein the term "configured to" may mean "programmed to" use code to perform a particular task or implement a particular abstract data type. Furthermore, while embodiments of the present technical solution may generally refer to the technical solution environment and schematic diagrams described herein, it should be understood that the described technology can be extended to other implementation contexts.

[0082] For the purposes of this disclosure, the term "support" refers to the configuration of functionality, services, or assistance by a computing component or through computing operations within the broader computing system. When a computing component or set of operations supports a specific function, it means that the computing component or set of operations plays a role in implementing or performing a specific aspect of the computing system. This support can manifest in various ways, including data processing, operation execution, resource management, and ensuring compatibility or interoperability with other components. Additionally, support can involve providing interfaces, APIs (Application Programming Interfaces), or protocols that allow seamless interaction and integration with other elements of the computing system. The concept of support extends beyond simple functional configuration to include maintenance, troubleshooting, and overall optimization of computing resources to ensure robust and efficient operation of the computing system.

[0083] Embodiments of the present technical solution have been described with reference to specific examples, which are intended to be illustrative rather than limiting in all respects. Alternative embodiments will be readily apparent to those skilled in the art to which this technical solution pertains without departing from the scope of the present technical solution.

[0084] As can be seen from the foregoing, this technical solution is well-suited to achieving all the goals and objectives set forth above, as well as other obvious advantages inherent in the structure.

[0085] It should be understood that certain features and sub-combinations are practical and can be adopted without reference to other features or sub-combinations. This is also contemplated within the scope of the claims.

Claims

1. A computerized system, comprising: One or more computer processors; as well as A computer memory storing computer-usable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations including: Send (302) request to the identity provider to create identity provider data for the remote client device of the cloud platform; Based on the transmission of the request, receive (304) a boot token containing a remote client device identifier; and Configure (306) the remote client device, wherein configuring the remote client device includes: Create a set of cloud resources for the remote client device; and The boot token is installed on a virtual machine associated with the remote client device, wherein the virtual machine is associated with a cloud provider management environment, and wherein the remote client device is configured to use the boot token to request a signing certificate from the identity provider, the signing certificate enabling the remote client device to access applications and services of the cloud platform.

2. The system of claim 1, wherein the cloud provider management environment is associated with a secure channel, the secure channel supporting the installation of the boot token on the virtual machine.

3. The system of claim 1, wherein the bootstrap is a temporary identity that is operable with the remote client device in a business context associated with a tenant or in a consumer context associated with the cloud provider's management environment.

4. The system of claim 1 further includes a tenantless access orchestration engine, the tenantless access orchestration engine providing tenantless access orchestration operations to allow users to use remote client devices in a consumer context, the remote client devices not associated with tenant information.

5. The system according to claim 4, wherein the tenantless access orchestration engine provides a cloud-based service engine, the remote client device, and the identity provider, and the cloud-based service engine provides management services for business resources and logic.

6. The system of claim 1, wherein the tenantless access orchestration operation supports the Desktop as a Service (DaaS) feature of the cloud platform hosting cloud resources in the cloud provider's management environment.

7. The system of claim 1, wherein the cloud platform supports a first set of remote client devices in a consumer context and a second set of remote client devices in a business context, the first set of remote client devices being associated with the cloud provider management environment of the cloud platform, and the second set of remote client devices being associated with an organization's tenants.

8. The system according to claim 1, wherein the operation further comprises: The request for the signature certificate from the identity provider is transmitted from the remote client device, wherein the signature certificate is generated based on the identity provider data for the remote client device; Receive the signature certificate associated with the identity provider data; as well as Based on the signature certificate, access the applications or services of the cloud platform.

9. The system according to claim 1, wherein the operation further comprises: Receive the first request from the cloud-based service engine to create identity provider data for the first remote client device on the cloud platform; Transmit a first boot token containing the identifier of the first remote client device; Receive a second request for the signing certificate from the first remote client; as well as The signing certificate is transmitted to the first remote client device, wherein the signing certificate enables the first remote client device to access the applications and services of the cloud platform.

10. The system according to claim 1, wherein the identity provider stores identity provider data, the identity provider data including the joining status and allocation status of remote client devices.

11. One or more computer storage media having computer-executable instructions thereon, the computer-executable instructions, when executed by a computing system having a processor and a memory, causing the processor to perform operations, the operations including: (502) A request for a signing certificate from an identity provider is transmitted from a remote client device, wherein the signing certificate is generated based on identity provider data for the remote client device, wherein the remote client device is associated with a cloud provider management environment of a cloud platform; Receive (504) the signature certificate associated with the identity provider data; as well as Based on the signature certificate, access the application or service of the cloud platform (506).

12. The medium of claim 11, wherein the remote client device is configured based on: Create a set of cloud resources for the remote client device; and The boot token is installed on a virtual machine associated with the remote client device, wherein the virtual machine is associated with the cloud provider's management environment.

13. The medium of claim 12, wherein the remote client device is configured to use the bootstrap token to request the signing certificate from the identity provider, the signing certificate enabling the remote client device to access applications and services of the cloud platform.

14. A computer-implemented method, the method comprising: Receive (402) a request from the cloud-based service engine to create identity provider data for remote client devices on the cloud platform; Transmit (406) a boot token containing the remote client device identifier; Receive (408) a second request for a signing certificate from the remote client; as well as (410) The signing certificate is transmitted to the remote client device, wherein the signing certificate enables the remote client device to access the applications and services of the cloud platform.

15. The method of claim 14, wherein the remote client device is configured based on: Create a set of cloud resources for the remote client device; and The boot token is installed on a virtual machine associated with the remote client device, wherein the virtual machine is associated with a cloud provider management environment.