IP Library › Granted Patent US 9,935,789
Granted Patent B2
US 9,935,789 · App. 14/742,239 · Granted Apr 3, 2018

Centralized pluggable authentication and authorization

Inventors: Andrew T. Fausak (San Jose, CA); Oleg Rombakh (Los Gatos, CA)
Assignee: Dell Products L.P.
H04L12/4679H04L9/3213H04L12/4641H04L63/0272H04L63/0807H04L63/10H04L63/102H04L67/025H04L67/08H04L67/1002H04L67/141H04L67/142H04L67/148H04L67/2814H04L67/38H04L67/42H04L69/04H04L69/14H04L63/08Y02B60/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,935,789
App. No.
14/742,239
Granted
Apr 3, 2018
Kind
B2
Abstract

In particular embodiments, a first computing device may receive a request from a second computing device to access a first entity of an infrastructure, the second computing device being coupled to the first computing device, then determining an eligibility of the second computing device to access as least the first entity of the infrastructure, and if the second computing device is determined to be eligible to access the first entity, then assigning a second ticket to the second computing device responsive to the received request.

Claims (31)

1. A method comprising, by a first computing device of an infrastructure:

receiving a request from a second computing device to access through a gateway a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least the first entity and a second entity of the infrastructure and one or more back-end services, wherein the first computing device comprises a centralized pluggable authentication and authorization (PAA) ticketing server that is coupled to the gateway and that provides the first ticket, wherein the PAA ticketing server, an HTTPS server and the gateway form a centralized PAA framework, wherein the first ticket is encrypted based at least on one or more of a connection as routed between the first computing device and at least one of the one or more back-end services, a user of the first computing device and data associated with the connection, wherein the first ticket comprises a list of redirection servers, wherein the first computing device is associated with a third-party encryption service, wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service, and wherein the first entity redirects the second computing device to the second entity;

determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity, wherein the first ticket is usable by the second computing device against one or more resources; and

assigning, by the PAA ticketing server, a second ticket to the second computing device responsive to the received request based on the eligibility determination, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure, wherein the second ticket is based on a relationship to the first ticket, and wherein assigning the second ticket to the second computing device comprises:

nullifying the first ticket previously assigned by the first computing device; and

sending the second ticket to the second computing device.

2. The method of claim 1 , wherein an entity comprises one or more of a computing device, a data, or software.

3. The method of claim 1 , wherein the infrastructure comprises an enterprise infrastructure.

4. The method of claim 1 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure.

5. The method of claim 1 , wherein determining the eligibility of the second computing device to access at least the first entity of the infrastructure comprises determining an eligibility of a user of the second computing device to access at least the first entity of the infrastructure.

6. The method of claim 1 , wherein the second entity comprises a remote desktop gateway of the infrastructure.

7. The method of claim 1 , wherein the access to the first entity comprises a modification to the first entity.

8. One or more computer-readable non-transitory storage media embodying logic that is operable when executed to:

by a first computing device of an infrastructure:

receiving a request from a second computing device to access through a gateway a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least the first entity and a second entity of the infrastructure and one or more back-end services, wherein the first computing device comprises a centralized pluggable authentication and authorization (PAA) ticketing server that is coupled to the gateway and that provides the first ticket, wherein the PAA ticketing server, an HTTPS server and the gateway form a centralized PAA framework, wherein the first ticket is encrypted based at least on one or more of a connection as routed between the first computing device and at least one of the one or more back-end services, a user of the first computing device and data associated with the connection, wherein the first ticket comprises a list of redirection servers, wherein the first computing device is associated with a third-party encryption service, wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service, and wherein the first entity redirects the second computing device to the second entity;

determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity, wherein the first ticket is usable by the second computing device against one or more resources; and

assigning, by the PAA ticketing server, a second ticket to the second computing device responsive to the received request based on the eligibility determination, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure through the gateway, wherein the second ticket is based on a relationship to the first ticket, and wherein assigning the second ticket to the second computing device comprises:

nullifying the first ticket previously assigned by the first computing device; and

sending the second ticket to the second computing device.

9. The media of claim 8 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure.

10. The media of claim 8 , wherein the second entity comprises a remote desktop gateway of the infrastructure.

11. An information handling system comprising: one or more processors; and

a memory coupled to the processors comprising instructions executable by the processors, the processors being operable when executing the instructions to:

by a first computing device of an infrastructure:

receiving a request from a second computing device to access through a gateway a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least the first entity and a second entity of the infrastructure and one or more back-end services, wherein the first computing device comprises a centralized pluggable authentication and authorization (PAA) ticketing server that is coupled to the gateway and that provides the first ticket, wherein the PAA ticketing server, an HTTPS server and the gateway form a centralized PAA framework, wherein the first ticket is encrypted based at least on one or more of a connection as routed between the first computing device and at least one of the one or more back-end services, a user of the first computing device and data associated with the connection, wherein the first ticket comprises a list of redirection servers, wherein the first computing device is associated with a third-party encryption service, wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service, and wherein the first entity redirects the second computing device to the second entity;

determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity, wherein the first ticket is usable by the second computing device against one or more resources; and

assigning, by the PAA ticketing server, a second ticket to the second computing device responsive to the received request based on the eligibility determination, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure, wherein the second ticket is based on a relationship to the first ticket, and wherein assigning the second ticket to the second computing device comprises:

nullifying the first ticket previously assigned by the first computing device; and

sending the second ticket to the second computing device.

12. The information handling system of claim 11 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure.

13. The information handling system of claim 11 , wherein the second entity comprises a remote desktop gateway of the infrastructure.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 036502 FRAME 0237 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0088 →
RELEASE OF REEL 036502 FRAME 0291 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0637 →
RELEASE OF REEL 036502 FRAME 0206 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0204 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036502/0291 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 036502/0237 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 036502/0206 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2015
From: FAUSAK, ANDREW T.; ROMBAKH, OLEG
To: DELL PRODUCTS L.P.
Reel/Frame 035854/0573 →
Continuity (2)
Provisional Application 62115047 · Feb 11, 2015
Related Publication 20160234196A1 · Aug 11, 2016