IP Library Granted Patent US 10,142,325
Granted Patent B2
US 10,142,325 · App. 15/250,496 · Granted Nov 27, 2018

Systems and methods for credentials distribution

Inventors: Mark Tempel (Minneapolis, MN); Andrew Moravec (Hugo, MN)
Assignee: Ivanti, Inc.
H04L63/0823H04L63/045H04L63/0428H04L63/0464H04L63/06H04L63/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,142,325
App. No.
15/250,496
Filed
Aug 29, 2016
Granted
Nov 27, 2018
Kind
B2
Art Unit
2439
USPC
713/156
Abstract

A method by a management server is described. The method includes receiving a credentials request from a requesting management node. The credentials request includes a public key of the requesting management node. The method also includes determining whether the management server has credentials encrypted for the requesting management node in a local cache. The credentials are encrypted using the public key of the requesting management node and cannot be decrypted by the management server. The method further includes sending the encrypted credentials to the requesting management node when the management server has the encrypted credentials. The requesting management node can decrypt the encrypted credentials using a private key.

Claims (44)

1. A method by a management server, comprising:

receiving a credentials request from a requesting management node, wherein the credentials request includes a public key of the requesting management node;

determining whether the management server has credentials encrypted for the requesting management node in a local cache, wherein the credentials are encrypted using the public key of the requesting management node and cannot be decrypted by the management server;

sending the encrypted credentials to the requesting management node when the management server has the encrypted credentials, wherein the requesting management node can decrypt the encrypted credentials using a private key; and

when the management server determines that the management server does not have the encrypted credentials:

sending a multicast request to one or more peer management nodes, the multicast request including the public key of the requesting management node;

receiving a unicast response from a responding management node that includes the encrypted credentials for the requesting management node; and

sending the encrypted credentials received from the responding management node to the requesting management node.

2. The method of claim 1 , wherein the requesting management node sends the credentials request upon determining that credentials required to perform a task cannot be resolved or acquired at the requesting management node.

3. The method of claim 1 , wherein upon receiving the multicast request, the responding management node resolves the credentials from a local store of the responding management node, decrypts the credentials using a private key of the responding management node, and re-encrypts the credentials using the public key of the requesting management node.

4. The method of claim 1 , wherein the responding management node validates that the requesting management node is trusted to receive credentials by testing a certificate of the requesting management node with a certificate chain.

5. The method of claim 1 , further comprising:

storing the encrypted credentials received from the responding management node in the local cache of the management server.

6. The method of claim 1 , wherein the requesting management node and the one or more peer management nodes are part of a same tenancy.

7. The method of claim 1 , wherein the requesting management node sends the credentials request as part of an automated recovery process that does not require a user to re-enter credentials.

8. The method of claim 1 , wherein the management server is a cloud-based server.

9. The method of claim 1 , wherein when the credentials are initially set, the management server uses a public key infrastructure (PKI) to encrypt the credentials in a manner in which only a management node for which the credentials are encrypted can decrypt the credentials.

10. A management server, comprising:

a processor;

memory in electronic communication with the processor; and

instructions stored in the memory, the instructions being executable to:

receive a credentials request from a requesting management node, wherein the credentials request includes a public key of the requesting management node;

determine whether the management server has credentials encrypted for the requesting management node in a local cache, wherein the credentials are encrypted using the public key of the requesting management node and cannot be decrypted by the management server;

send the encrypted credentials to the requesting management node when the management server has the encrypted credentials, wherein the requesting management node can decrypt the encrypted credentials using a private key; and

when the management server determines that the management server does not have the encrypted credentials:

send a multicast request to one or more peer management nodes, the multicast request including the public key of the requesting management node;

receive a unicast response from a responding management node that includes the encrypted credentials for the requesting management node; and

send the encrypted credentials received from the responding management node to the requesting management node.

11. The management server of claim 10 , wherein the requesting management node sends the credentials request upon determining that credentials required to perform a task cannot be resolved or acquired at the requesting management node.

12. The management server of claim 10 , wherein the instructions are further executable to:

store the encrypted credentials received from the responding management node in the local cache of the management server.

13. The management server of claim 10 , wherein the management server is a cloud-based server.

14. The management server of claim 10 , wherein the management server uses a public key infrastructure (PKI) to encrypt the credentials when the credentials are initially set in a manner in which only a management node for which the credentials are encrypted can decrypt the credentials.

15. A method by a responding management node, comprising:

receiving a multicast request from a management server in response to a credentials request sent by a requesting management node and when the management server determines that the management server does not store credentials requested by the requesting management node, wherein the multicast request includes a public key of the requesting management node;

resolving the credentials from a local store;

encrypting the credentials using the public key of the requesting management node; and

sending a unicast response to the management server that includes the encrypted credentials for the requesting management node.

16. The method of claim 15 , further comprising decrypting, before encrypting the credentials using the public key of the requesting management node, the credentials from the local store using a private key of the responding management node if the credentials are encrypted.

17. The method of claim 15 , further comprising:

testing a certificate of the requesting management node with a certificate chain of the responding management node; and

validating that the requesting management node is trusted to receive credentials.

18. The method of claim 15 , wherein the requesting management node and the responding management node are part of a same tenancy.

19. The method of claim 15 , wherein the management server is a cloud-based server.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: TEMPEL, MARK; MORAVEC, ANDREW
To: CRIMSON CORPORATION
Reel/Frame 039612/0675 →
Continuity (1)
Related Publication 20180063123A1 · Mar 1, 2018