IP Library › Granted Patent US 10,187,426
Granted Patent B2
US 10,187,426 · App. 15/278,124 · Granted Jan 22, 2019

Provisioning systems for installing credentials

Inventor: Tatu J. Ylonen (Espoo, FI)
Assignee: SSH Communications Security OYJ
H04L63/20G06F21/575H04L9/083H04L9/0891H04L9/14H04L9/30H04L9/321H04L9/3263H04L9/3268H04L61/1523H04L63/0428H04L63/0435H04L63/0442H04L63/061H04L63/062H04L63/065H04L63/08H04L63/0807H04L63/10H04L63/101H04L63/166H04L67/42H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,426
App. No.
15/278,124
Granted
Jan 22, 2019
Kind
B2
Abstract

Certain embodiments provide means for managing automated access to computers, e.g., using SSH user keys and other kinds of trust relationships. Certain embodiments also provide for managing certificates, Kerberos credentials, and cryptographic keys. Certain embodiments provide for remediating legacy SSH key problems and for automating configuration of SSH keys, as well as for continuous monitoring.

Claims (29)

1. A method for creating a new virtual data processing instance, comprising:

creating and starting the new virtual data processing instance at a host via a communication network in a virtualization environment, wherein the host comprises memory, one or more processors and an interface for communication with a management system via the communication network; and

enrolling the new virtual data processing instance into the management system, the enrolling comprising installing at least one credential via the communication network on the new virtual data processing instance at the host for use by the new virtual data processing instance in securing communications with the management system.

2. The method according to claim 1 , further comprising installing a certificate on the new virtual data processing instance.

3. The method according to claim 1 , further comprising installing at least one configuration object on the new virtual data processing instance.

4. The method according to claim 1 , further comprising inserting the new virtual data processing instance into a host group.

5. The method according to claim 1 , further comprising installing at least one of an identity key, a host key and an authorized key on the new virtual data processing instance before booting thereof.

6. The method according to claim 1 , further comprising installing the at least one credential on the new virtual data processing instance during a boot process thereof.

7. The method according to claim 1 , further comprising inserting credential management system credentials into a virtual machine image for use in booting of the new virtual data processing instance.

8. The method according to claim 1 , further comprising configuring the new virtual data processing instance, based on the at least one credential, for at least one of: authentication to a credential management system, use of a host key for at least one other host in the virtualization environment, enabling an account in another data processing instance to log into the new virtual data processing instance, and logging into at least one other data processing instance.

9. The method according to claim 1 , wherein parts of a kernel are shared by multiple instances.

10. An apparatus for a host in a virtualization environment system for creating a new virtual data processing instance in the host, the apparatus comprising:

an interface for communication with a management system via a communication network for creation and starting new virtual data processing instances;

one or more processors; and

memory storing executable instructions that, when executed by the one or more processors, cause the host to:

create and start the new virtual data processing instance based on information communicated via the communication network; and

enroll the new virtual data processing instance into the management system, the enrolling comprising installing at least one credential on the new virtual data processing instance for use by the new virtual data processing instance in securing communications with the management system.

11. The apparatus according to claim 10 , wherein the instructions, when executed by the one or more processors, cause performance of at least one of the following:

install a certificate on the new virtual data processing instance;

install at least one configuration object on the new virtual data processing instance; or

insert the new virtual data processing instance into a host group.

12. The apparatus according to claim 10 , wherein the instructions, when executed by the one or more processors, cause installing of at least one key on the new virtual data processing instance before or during booting thereof.

13. The apparatus according to claim 10 , wherein the instructions, when executed by the one or more processors, cause insertion of credential management system credentials into a virtual machine image for use in booting of the new virtual data processing instance.

14. The apparatus according to claim 10 , wherein the instructions, when executed by the one or more processors, cause configuring of the new virtual data processing instance, based on the at least one credential, for at least one of: authentication to a credential management system, use of a host key for at least one other host in the virtualized environment, enabling an account in another data processing instance to log into the new virtual data processing instance, and logging into at least one other data processing instance.

15. The apparatus according to claim 10 , wherein parts of a kernel of the host are shared by multiple virtual data processing instances.

16. A non-transitory computer readable media comprising program code for causing an apparatus operable in a virtualized environment and comprising a processor to perform instructions for:

creating a new virtual data processing instance on a host, wherein the creating comprises:

creating and starting the new virtual data processing instance in the virtualized environment based on communications by the host via a communication network; and

enrolling the new virtual data processing instance into a management system, the enrolling comprising installing at least one credential on the new virtual data processing instance based on communications by the host via the communication network for use by the new virtual data processing instance in securing communications with the management system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2016
From: YLONEN, TATU J.
To: SSH COMMUNICATIONS SECURITY OYJ
Reel/Frame 039873/0551 →
Continuity (7)
Continuation 14367462
Provisional Application 61578389 · Dec 21, 2011
Provisional Application 61646978 · May 15, 2012
Provisional Application 61693278 · Aug 25, 2012
Provisional Application 61697768 · Sep 6, 2012
Provisional Application 61721278 · Nov 1, 2012
Related Publication 20170019387A1 · Jan 19, 2017