IP Library Granted Patent US 9,838,366
Granted Patent B2
US 9,838,366 · App. 14/603,197 · Granted Dec 5, 2017

Secure shell public key audit system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,366
App. No.
14/603,197
Granted
Dec 5, 2017
Kind
B2
Abstract

A system for auditing authorized key files associated with secure shell (SSH) servers is disclosed. In an example, the system may include a purpose-built SSH audit server. The SSH audit server may be configured to receive an authorized key file and a list of users. The SSH audit sever may generate and provide unique registration codes for each of the users in the list. The SSH audit server may associate particular users with particular public keys as each of the users accesses the SSH audit server using a public key and inputs a registration code.

Claims (72)

1. An audit server comprising:

one or more communication interfaces to communicate with one or more client devices;

one or more hardware processors; and

computer-readable storage media storing computer-executable instructions, which when executed by the one or more hardware processors, cause the one or more processors to perform operations comprising:

receiving an authorized key file associated with a secure shell (SSH) server, the authorized key file including a plurality of public keys;

receiving contact information associated with each of a plurality of individuals;

generating a plurality of registration codes, each of the plurality of registration codes corresponding to and uniquely identifying a particular individual of the plurality of individuals;

providing each of the plurality of registration codes to the corresponding particular individual of the plurality of individuals;

receiving a request to open a secure communication channel from a client device associated with an individual of the plurality of individuals, the request including information generated based at least in part on a private key associated with the individual;

authenticating the information based at least in part on a particular public key of the plurality of public keys;

opening the secure communication channel;

receiving a particular registration code from the client device;

identifying the individual associated with the particular public key;

identifying one or more registration codes of the plurality of registration codes that were not received; and

automatically removing or disabling, from the authorized key file, one or more public keys of the plurality of public keys that correspond to the one or more registration codes that were not received.

2. The audit server as recited in claim 1 , wherein, before receiving the particular registration code from the client device, the operations further comprise:

opening the secure communication channel; and

requesting input of one of the plurality of registration codes.

3. The audit server as recited in claim 1 , wherein the operations further comprise:

matching the particular registration code to a registration code of the plurality of registration codes; and

determining that the particular registration code is valid.

4. The audit server as recited in claim 1 , wherein the operations further comprise:

failing to match the particular registration code with any of the plurality of registration codes;

determining that the particular registration code is invalid; and

marking the public key corresponding to the particular registration code for further investigation.

5. The audit server as recited in claim 1 , wherein the operations further comprise:

failing to match the particular registration code with any of the plurality of registration codes;

identifying the particular registration code as invalid; and

removing the public key from the authorized key file.

6. The audit server as recited in claim 1 , wherein receiving the particular registration code from the client device comprises receiving an email that includes the particular registration code.

7. A method performed by an audit server comprising one or more processors configured with operating instructions, the method comprising:

receiving a plurality of public keys associated with a secure shell (SSH) server;

generating, by the audit server, a unique registration code, the unique registration code corresponding to and uniquely identifying a particular user;

associating the unique registration code with the user;

providing the unique registration code to a location accessible to a client device of the user;

receiving a request to open a communication channel from the client device, the request including information generated based at least in part on a private key associated with the user;

establishing the communication channel based at least in part on a public key of the plurality of public keys;

receiving, via the communication channel, the unique registration code from the client device;

identifying that the user is associated with the public key;

identifying one or more registration codes of the plurality of registration codes that were not received; and

automatically removing or disabling, one or more public keys of the plurality of public keys that correspond to the one or more registration codes that were not received.

8. The method as recited in claim 7 , further comprising:

generating a second unique registration code;

associating the second unique registration code with a second user;

providing the second unique registration code to a second location accessible to a second client device of the second user;

receiving a second request to open a second communication channel from the second client device;

establishing the second communication channel based at least in part on a second public key;

receiving a second input of the second unique registration code from the second client device; and

associating the second user with the second public key based at least in part on receiving the second unique registration code via the second communication channel.

9. The method as recited in claim 7 , wherein the location is an email account.

10. The method as recited in claim 7 , further comprising providing a login credential to establish the communication channel with the audit server.

11. The method as recited in claim 7 , wherein the communication channel is a secure shell.

12. The method as recited in claim 7 , further comprising:

receiving, prior to generating the unique registration code, an authorized key file associated with a server being audited, the authorized key file including the public key; and

receiving, prior to generating the unique registration code, contact information associated with a plurality of individuals authorized to access the server, the plurality of individuals including the user.

13. A non-transitory computer-readable storage media storing computer-executable instructions, which when executed by one or more processors, cause the one or more processors to:

receiving a plurality of public keys associated with a secure shell (SSH) server;

generate a plurality of registration codes, a particular registration code of the plurality of registration codes associated with and uniquely identifying a user;

associating the particular registration code with the user;

provide the particular registration code to a location accessible to a client device of the user;

receive a request to open a communication channel from the client device, the request including information generated based at least in part on a private key associated with the user;

establish the communication channel based at least in part on a public key of the plurality of public keys;

receive the particular unique registration code over a communication channel that is established based in part on the public key;

identifying that the user is associated with the public key;

identifying one or more registration codes of the plurality of registration codes that were not received; and

automatically removing or disabling, from an authorized key file, one or more public keys of the plurality of public keys that correspond to the one or more registration codes that were not received.

14. The non-transitory computer-readable storage media as recited in claim 13 , wherein the location is at least one of an email account associated with the user or an instant message account associated with the user.

15. The non-transitory computer-readable storage media as recited in claim 13 , wherein the computer-executable instructions, when executed by the one or more processors, further cause the processors to receive, prior to generating the unique registration code, contact information associated with a plurality of individuals authorized to access a server being audited, the plurality of individuals including the user.

16. The non-transitory computer-readable storage media as recited in claim 13 , wherein the computer-executable instructions, when executed by the one or more processors, further cause the processors to receive, prior to generating the plurality of registration codes, an authorized key file associated with a server being audited, the authorized key file including the public key.

17. The non-transitory computer-readable storage media as recited in claim 13 , wherein the computer-readable storage media is a resource associated with a secure shell audit server.

18. The non-transitory computer-readable storage media as recited in claim 13 , wherein the instructions, when executed by the one or more processors, further cause the processors to generate a list of registered public keys, the list of registered public keys including the public key and an indication of the user as an owner of the public key.

19. The non-transitory computer-readable storage media as recited in claim 18 , wherein the instructions, when executed by the one or more processors, further cause the processors to provide the list of registered public keys to an administrator system after a predetermined period of time has elapsed.

Assignments (29)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 942. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY LLC
Reel/Frame 070678/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY LLC
Reel/Frame 070194/0942 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Mar 21, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045660/0755 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2018
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE INC.
Reel/Frame 045355/0817 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2015
From: PETERSON, MATTHEW TODD
To: DELL PRODUCTS L.P.
Reel/Frame 035100/0554 →