IP Library Granted Patent US 8,341,708
Granted Patent B1
US 8,341,708 · App. 11/468,255 · Granted Dec 25, 2012

Systems and methods for authenticating credentials for management of a client

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,341,708
App. No.
11/468,255
Granted
Dec 25, 2012
Kind
B1
Abstract

A method and system for authenticating credentials for management of a client is disclosed. The credentials are provided to a verification application. The credentials are authenticated to an authentication application. A connection between the authentication application and a security server is established. An authenticator is invoked. Administrative rights associated with the credentials are verified. An authentication certificate indicating the administrative rights is sent to the client.

Claims (51)

1. A method for authenticating credentials for management of a node, the method being implemented by a computer system, the method comprising:

providing the credentials to a verification application on a managed node;

establishing a secure connection between the managed node and an authentication application located remotely from the managed node;

sending the credentials via the secure connection;

authenticating the credentials to the authentication application via basic authentication, wherein the credentials are sent via the secure connection before they are authenticated;

establishing a connection between the authentication application and a security server using an authentication procedure that is different from the authentication used with the secure connection;

invoking an authenticator on the security server;

receiving the credentials at the authenticator from the authentication application;

verifying administrative rights associated with the credentials using the authenticator on the security server; and

sending, from the authenticator, an authentication certificate indicating the administrative rights associated with the credentials to the managed node,

wherein both the secure connection and the connection are used for authenticating the managed node such that the managed node does not have direct access to the authenticator.

2. The method of claim 1 , wherein verifying the administrative rights is performed using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure comprises the authenticator using a challenge/response authentication protocol.

3. The method of claim 1 , wherein verifying the administrative rights is performed using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure comprises the authenticator implementing an operating system based authentication protocol.

4. The method of claim 1 , wherein verifying the administrative rights is performed using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure comprises the authenticator using a hyper-text transfer protocol authentication mechanism.

5. The method of claim 1 , wherein the authenticator comprises a web service.

6. The method of claim 1 , wherein the authenticator is implemented on a domain controller.

7. The method of claim 1 , wherein the credentials comprise a username and a password.

8. The method of claim 7 , further comprising associating the username and the password with the administrative rights of a system administrator.

9. The method of claim 1 , further comprising sending the certificate to a management agent.

10. The method of claim 1 , further comprising issuing a limited rights authentication certificate to the managed node indicating the limited administrative rights associated with the credentials.

11. The method of claim 1 , wherein establishing a connection comprises implementing an internet based management gateway application.

12. The method of claim 1 , wherein establishing a secure connection comprises implementing a secure sockets layer connection and an internet based management gateway application.

13. The method of claim 1 , wherein the administrative rights are verified by a web service using a domain controller using a challenge/response authentication protocol, and wherein the authentication certificate is sent to the managed node.

14. The method of claim 13 , wherein communications between the managed node and the domain controller are sent via a network that comprises a management gateway.

15. A computer system that is configured for authenticating credentials for management of a client, the computer system comprising:

a processor; memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

authenticate credentials at an authentication application via basic authentication, wherein the credentials are received via a secure connection before they are authenticated;

establish a connection between the authentication application located remotely from the client and a security server on the computer system, wherein the security server comprises an authenticator, wherein the connection is established using an authentication procedure that is different from the authentication used with the secure connection;

invoke the authenticator on the computer system;

receive credentials at the authenticator from the authentication application, wherein the credentials were previously received from the client and were sent from the authentication application to the authenticator;

verify administrative rights associated with the credentials using the authenticator on the security server; and

send an authentication certificate indicating the administrative rights associated with the credentials to the client, wherein both the secure connection and the connection are used for authenticating the client such that the client does not have direct access to the authenticator.

16. The system of claim 15 , wherein the verification of the credentials is performed using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure comprises a challenge/response authentication protocol.

17. The system of claim 15 , wherein the verification of the credentials is performed using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure comprises a hyper-text transfer protocol authentication mechanism.

18. The system of claim 15 , wherein the secure connection implements a secure sockets layer connection and an internet based management gateway application.

19. The system of claim 15 , wherein the authenticator comprises a web service.

20. The system of claim 15 , wherein the authenticator is implemented on a domain controller.

21. A non-transitory computer-readable medium comprising executable instructions for authenticating credentials for management of a client, the executable instructions being executable to:

provide credentials to a verification application on the client;

establish a secure connection between the client and an authentication application located remotely from the client;

send the credentials via the secure connection;

authenticate the credentials to the authentication application via basic authentication, wherein the credentials are sent via the secure connection before they are authenticated;

establish a connection between the authentication application and a security server using an authentication procedure that is different from the authentication used with the secure connection, wherein the security server comprises an authenticator;

invoke the authenticator on the security server;

receive credentials at the authenticator from the authentication application, wherein the credentials were previously received from the client and were sent from the authentication application to the authenticator;

verify administrative rights associated with the credentials using the authenticator on the security server; and

issue, by the security server, an authentication certificate indicating the administrative rights associated with the credentials to the client,

wherein both the secure connection and the connection are used for authenticating the client such that the client does not have direct access to the authenticator.

22. The non-transitory computer-readable medium of claim 21 , wherein the executable instructions that are executable to authenticate the credentials comprise executable instructions that are executable to authenticate using the authentication procedure that is different from the authentication used with the secure connection, wherein this different authentication procedure uses a challenge/response authentication protocol.

23. The non-transitory computer-readable medium of claim 21 , wherein the executable instructions that are executable to establish a secure connection comprise executable instructions that are executable to implement a secure sockets layer connection and an internet based management gateway application.

Assignments (22)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →