IP Library Granted Patent US 9,094,217
Granted Patent B2
US 9,094,217 · App. 13/958,283 · Granted Jul 28, 2015

Secure credential store

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,094,217
App. No.
13/958,283
Granted
Jul 28, 2015
Kind
B2
Abstract

A credential store provides for secure storage of credentials. A credential stored in the credential store is encrypted with the public key of a user owning the credential. A first user may provide a credential owned by the first user to a second user. The first user may add credentials owned by the first user to the credential store. An administrator may manage users of the credential store without having the ability to provide credentials to those users.

Claims (71)

1. A computer program product, the computer program product being tangibly embodied on a non-transitory computer-readable medium and including instructions that, when executed by at least one processor, are configured to:

insert a credential in a credential store of a credential server computer, the credential encrypted with a public key corresponding to a first user of the credential store;

receive an instruction to provide the credential;

decrypt the first credential with a private key of the first user;

encrypt the first credential with a single-use key;

store the single-use key-encrypted credential at a location;

make the single use key-encrypted credential available at the location during a time window;

allow access to the stored single-use key-encrypted credential at the location during the time window including a time scheduled for an automated action, wherein the size of the time window and the time scheduled for the automated action have been specified by the first user; and

remove the single use key-encrypted credential from the location upon expiration of the time window.

2. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

provide the single use key to the first user;

receive the single use key during the time window;

decrypt the single use key encrypted credential with the single use key; and

provide the decrypted credential for an automated action.

3. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

configure the time window as instructed by the first user.

4. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

schedule access to the credential within the time window based on information provided by the first user.

5. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

generate the single-use key after decrypting the first credential with the private key of the first user, the single-use key including a single-use encryption key generated by using a symmetric encryption technique.

6. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

generate an encrypted copy of the single-use key-encrypted credential; and

store the encrypted copy at a location specified by the user.

7. The computer program product of claim 1 , wherein the location includes an address specified by the user.

8. The computer program product of claim 1 , further comprising instructions that, when executed by the at least one processor, are configured to:

return the single-use key to the first user.

9. The computer program product of claim 1 , wherein removing the single use key-encrypted credential from the location upon expiration of the time window includes permanently discarding or deleting the single-use key-encrypted credential at the location.

10. A computer system including instructions recorded on a non-transitory computer-readable medium and executable by at least one processor, the system comprising:

a credential server configured to cause the at least one processor to:

insert a credential in a credential store of a credential server computer, the credential encrypted with a public key corresponding to a first user of the credential store;

receive an instruction to provide the credential;

decrypt the first credential with a private key of the first user;

encrypt the first credential with a single-use key;

store the single-use key-encrypted credential at a location;

make the single use key-encrypted credential available at the location during a time window;

allow access to the stored single-use key-encrypted credential at the location during the time window, the time window including a time scheduled for an automated action, wherein the size of the time window and the time scheduled for the automated action have been specified by the first user; and

remove the single use key-encrypted credential from the location upon expiration of the time window.

11. The system of claim 10 , wherein the credential server is further configured to cause the at least one processor to:

provide the single use key to the first user;

receive the single use key during the time window;

decrypt the single use key encrypted credential with the single use key; and

provide the decrypted credential for an automated action.

12. The system of claim 10 , wherein the credential server is further configured to cause the at least one processor to:

configure the time window as instructed by the first user;

schedule access to the credential within the time window based on information provided by the user; and

return the single-use key to the first user.

13. The system of claim 10 , wherein the credential server is further configured to cause the at least one processor to:

generate the single-use key after decrypting the first credential with the private key of the first user, the single-use key including a single-use encryption key generated by using a symmetric encryption technique.

14. The system of claim 10 , wherein the location includes an address specified by the first user.

15. The system of claim 10 , wherein the credential server is further configured to cause the at least one processor to:

generate an encrypted copy of the single-use key-encrypted credential; and

store the encrypted copy at a location specified by the first user.

16. The system of claim 10 , wherein removing the single use key-encrypted credential from the location upon expiration of the time window includes permanently discarding or deleting the single-use key-encrypted credential at the location.

17. A computer-implemented method comprising:

inserting a credential in a credential store of a credential server computer, the credential encrypted with a public key corresponding to a first user of the credential store;

receiving an instruction to provide the credential;

decrypting the first credential with a private key of the first user;

encrypting the first credential with a single-use key;

storing the single-use key-encrypted credential at a location;

making the single use key-encrypted credential available at the location during a time window;

allowing access to the stored single-use key-encrypted credential at the location during the time window including a time scheduled for an automated action, wherein the size of the time window and the time scheduled for the automated action have been specified by the first user; and

removing the single use key-encrypted credential from the location upon expiration of the time window.

18. The method of claim 17 , further comprising:

providing the single use key to the first user;

receiving he single use key during the time window;

decrypting the single use key encrypted credential with the single use key; and

providing the decrypted credential for an automated action.

19. The method of claim 17 , further comprising:

configuring the time window as instructed by the first user;

scheduling access to the credential within the time window based on information provided by the user; and

returning the single-use key to the first user.

Assignments (15)
CHANGE OF NAME Recorded Jan 10, 2025
From: BLADELOGIC, INC.
To: BMC HELIX, INC.
Reel/Frame 069870/0796 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Jul 27, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043351/0189 →
SECURITY AGREEMENT Recorded Sep 11, 2013
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 031204/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2013
From: SOLIN, DAVID ALLEN; LIAO, RICHARD GUOYU
To: BLADELOGIC, INC.
Reel/Frame 031037/0262 →