IP Library Granted Patent US 8,752,137
Granted Patent B2
US 8,752,137 · App. 12/790,426 · Granted Jun 10, 2014

Security context passing for stateless system management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,752,137
App. No.
12/790,426
Granted
Jun 10, 2014
Kind
B2
Abstract

Systems and methods for stateless system management are described. Examples include a method wherein a user sends the management system a request to act upon a managed system. The management system determines whether the user is authorized for the requested action. Upon authorization, the management system looks up an automation principal, which is a security principal native to the managed system. The management system retrieves connecting credentials for the automation principal, and connects to the managed system using the retrieved credentials. Once the managed system is connected, the management system performs the requested action on the managed system, and sends the result back to the user.

Claims (62)

1. A method for passing security context in an heterogeneous environment created by a plurality of diverse computer systems each having different respective native security principals, the method comprising;

implementing a centralized configuration management system by executing instructions on a central processing unit (CPU) coupled to a memory, the centralized configuration management system configured to manage the plurality of diverse computer systems each having different respective native security principals;

receiving a request at the centralized configuration management system, from a user for action on a particular managed computer system of the plurality of diverse computer systems each having different respective native security principals;

authorizing the user's access to the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals based on the user's security context;

detecting whether there is an automation principal associated with the user and the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals, wherein the automation principal is a native security principal of the particular managed computer system;

if no automation principal is found, reporting an error to the centralized configuration management system;

if an automation principal is found, retrieving the automation principal and a credential for the particular managed computer system;

connecting to the particular managed computer system using the automation principal and the credential;

executing the requested action on the particular managed computer system; and

returning a response to the user.

2. The method of claim 1 , wherein retrieving an automation principal and credential comprises:

retrieving an access control model of the particular managed computer system;

determining an automation principal for the particular managed computer system based on its access control model;

retrieving the automation principal; and

retrieving a credential associated with the automation principal.

3. The method of claim 2 , wherein determining an automation principal comprises:

retrieving a security context of the user; and

selecting, from a database, an automation principal based on the security context of the user and the access control model of the particular managed computer system.

4. The method of claim 3 , wherein the security context of the user comprises one or more roles assigned to the user.

5. The method of claim 3 , wherein the access control model of the particular managed computer system is a role-based access control model.

6. The method of claim 1 , wherein authorizing the user's access to the particular managed computer system comprises determining, via an access control system, whether the user has access to the particular managed computer system.

7. The method of claim 6 , wherein the access control system comprises a role based access control system.

8. The method of claim 7 , wherein determining whether the user has access to the particular managed computer system comprises:

retrieving an active role of the user;

determining whether there is an automation principal for the particular managed computer system associated with the user's active role; and

signaling positive authorization if an association is found.

9. A computer system for managing one or more computer resources, comprising:

a processor;

an operator display coupled to the processor;

a storage subsystem coupled to the processor; and

a software module stored in the storage subsystem, the software module comprising instructions that when executed by the processor cause the processor to:

implement a centralized configuration management system to manage a plurality of diverse computer systems each having different respective native security principals;

receive a request at the centralized configuration management system, from a user for action on a particular managed computer system of the plurality of diverse computer systems each having different respective native security principals;

authorize the user's access to the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals based on the user's security context;

detect whether there is an automation principal associated with the user and the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals, wherein the automation principal is a native security principal of the particular managed computer system;

if no automation principal is found, report an error to the centralized configuration management system;

if an automation principal is found, retrieve the automation principal and a credential for the particular managed computer system;

connect to the particular managed computer system using the automation principal and the credential;

execute the requested action on the particular manacled computer system;

and

return a response to the user.

10. A programmable storage device having programmed instructions stored thereon for causing a programmable control device to:

implement a centralized configuration management system to manage a plurality of diverse computer systems each having different respective native security principals;

receive a request at the centralized configuration management system, from a user for action on a particular managed computer system of the plurality of diverse computer systems each having different respective native security principals;

authorize the user's access to the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals based on the user's security context;

detect whether there is an automation principal associated with the user and the particular managed computer system of the plurality of diverse computer systems each having different respective native security principals, wherein the automation principal is a native security principal of the particular managed computer system;

if no automation principal is found, report an error to the centralized configuration management system;

if an automation principal is found, retrieve the automation principal and a credential for the particular managed computer system;

connect to the particular managed computer system using the automation principal and the credential;

execute the requested action on the particular managed computer system; and

return a response to the user.

11. The method of claim 1 , wherein the automation principal is an abstract object that contains a subject identifier and an associated credential.

12. The method of claim 1 , wherein the automation principal is a native security principal of the particular managed computer system but is not a security principal of the centralized configuration management system.

13. The method of claim 1 , wherein the credential is a Kerberos TGT or an X509 certificate with a corresponding key.

14. The method of claim 1 , wherein connecting to the particular managed computer system comprises:

sending a connection request from the centralized configuration management system to an agent running on the particular managed computer system;

passing the automation principal's credential to the agent running on the particular managed computer system; and

authentication, by the agent, of the connection request using the received automation principal's credential.

15. The method of claim 14 , wherein executing the requested action on the particular managed computer system comprises:

sending the requested action from the centralized configuration management system to an agent running on the particular managed computer system; and

executing the requested action, by the agent, on the particular managed computer system.

16. The method of claim 1 , further comprising, providing a user with an interface to interact with the centralized configuration management system.

Assignments (14)
CHANGE OF NAME Recorded Jan 10, 2025
From: BLADELOGIC, INC.
To: BMC HELIX, INC.
Reel/Frame 069870/0796 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY AGREEMENT Recorded Sep 11, 2013
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 031204/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: KNJAZIHHIN, DENIS; REILLY, PAUL A.; BIRGER, CHET; SOLIN, DAVID; ADAMS, CARL
To: BLADELOGIC, INC.
Reel/Frame 024458/0781 →