IP Library Granted Patent US 9,172,688
Granted Patent B2
US 9,172,688 · App. 13/886,787 · Granted Oct 27, 2015

Secure shell authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,688
App. No.
13/886,787
Granted
Oct 27, 2015
Kind
B2
Abstract

A first information handling system receives a security challenge and forwards it to a second information handling system. The second information handling system retrieves a private key from a public/private encryption key pair and satisfies the challenge with the private key. The second information handling system forwards the satisfied challenge without divulging the private key. The second information handling system is in a more secure environment than the first information handling system. The challenge may be satisfied by signing the challenge with the private key. Satisfying the challenge may be a step in creating a secure shell connection between the first information handling system and an organization maintaining the first information handling system and the second information handling system.

Claims (36)

1. A method comprising:

receiving at a first information handling system a security challenge;

forwarding the security challenge to a second information handling system;

retrieving by the second information handling system a private key;

producing by the second information handling system by use of the private key a satisfied security challenge;

sending the satisfied security challenge from the second information handling system to the first information handling system; and

establishing a secure shell (SSH) connection between a third information handling system and the first information handling system through use of the satisfied security challenge without the second information handling system divulging the private key, wherein the satisfied security challenge comprises signing the security challenge with the private key and wherein the first information handling system or the second information handling system comprising at least one hardware processor.

2. The method of claim 1 , wherein:

the method further comprises the first information handling system sending to the third information handling system a request to establish an SSH connection and a public key, wherein the public key and the private key form a private/public key Pair;

the receiving comprises receiving the security challenge from the third information handling system in response to sending the request and the public key; and

the establishing the SSH connection comprises establishing the SSH connection between the first information handling system and the third information handling.

3. The method of claim 1 , wherein the producing the satisfied security challenge comprises signing the security challenge with the private key.

4. The method of claim 1 , further comprising authenticating the first information handling system by the second information handling system.

5. The method of claim 1 , wherein the forwarding comprises forwarding the challenge to the second information handling system utilizing Transport Layer Security.

6. The method of claim 1 , wherein network access of the second information handling system is more restricted than network access of the first information handling system according to a policy of an organization controlling the first information handling system and the second information handling system.

7. The method of claim 6 , wherein a firewall governing network access of the second information handling system implements the policy.

8. The method of claim 7 , wherein:

the first information handling system is on a first network;

the second information handling system is on a second network;

the first network is separate from the second network; and

the second network is a segmented network.

9. The method of claim 8 , wherein network access of information handling systems on the second network is limited to information handling systems on the first network.

10. A system of an organization comprising:

a first information handling system to receive a security challenge referring to a public key of a public/private key pair and to forward the security challenge to a second information handling system;

the second information handling system to retrieve from the key store private key of the public/private key pair and to produce a satisfied challenge by use of the private key, wherein the satisfied challenge demonstrates proof of possession of the private key; and

the key store to store the public/private key pair and to provide to the second information handling system the private key, wherein the second information handling system is in a more secure environment than the first information handling system and the system is to establish an SSH connection between a third information handling system and the first information handling system through use of the satisfied security challenge without the second information handling system divulging the private key, wherein the first information handling system or the second information handling system comprising at least one hardware processor.

11. The system of claim 10 , wherein:

the first information handling system is to send to the third information handling system a request to establish an SSH connection and the public key;

the receiving the security challenge comprises receiving the security challenge from the third information handling system in response to sending the request and the public key;

the producing the satisfied security challenge comprises the second information handling system signing the security challenge with the private key; and

the establishing the SSH connection comprises establishing the SSH connection with a fourth information handling system outside the organization by transmitting the signed security challenge to the fourth information handling system.

12. The system of claim 10 , wherein network access of the second information handling system is limited to information handling systems within the organization according to a policy of the organization.

13. The system of claim 10 , further comprising a firewall to implement the policy.

14. The method of claim 3 , further comprising:

transmitting the signed security challenge to the third information handling system; and

the third information handling system decrypting the signed security challenge with the public key.

Assignments (14)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2025
From: VINCENT, MICHAEL
To: DELL PRODUCTS, LP
Reel/Frame 072778/0913 →
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
ENTITY CONVERSION WITH NAME CHANGE Recorded Dec 8, 2015
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 037243/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2015
From: DELL PRODUCTS L.P.
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 036262/0417 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0490 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0509 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0525 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2013
From: DUBY, CAROLYN; KING, MARK B.; LEDELL, ARIC; OREN, ELCHANAN; VINCENT, MICHAEL
To: DELL PRODUCTS, LP
Reel/Frame 030612/0604 →