IP Library Granted Patent US 10,375,056
Granted Patent B2
US 10,375,056 · App. 15/291,886 · Granted Aug 6, 2019

Providing a secure communication channel during active directory disaster recovery

Inventors: Sergey Alexandrovich Kalitin (St. Petersburg, RU); Sergey Romanovich Vartanov (St. Petersburg, RU)
Assignee: Quest Software Inc.
H04L63/0823G06F11/1464H04L69/40G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,375,056
App. No.
15/291,886
Granted
Aug 6, 2019
Kind
B2
Abstract

A secure communication channel can be established between a recovery console and a recovery agent during an Active Directory disaster recovery. This secure channel can be established without employing the Kerberos or NT LAN Manager (NTLM) authentication protocols. Therefore, the recovery console and recovery agent will be able to establish a secure channel even when the domain controller is in Directory Services Restore Mode (DSRM) and NTLM is disabled. A secure channel can be established between the recovery console and the recovery agent based on the Microsoft Secure Channel (Schanel) Security Support Provider (SSP). The Schannel implementation can be modified in a manner that allows the client to be authenticated within the Schannel architecture.

Claims (48)

1. A method, performed by a recovery agent executing on a server, for establishing a secure connection between a recovery console executing on a client and the recovery agent, the method comprising:

receiving, from the recovery console, a console certificate;

storing the console certificate to enable the recovery agent to access the console certificate during subsequent attempts to establish a secure connection with the recovery agent;

installing a hook on a function that is called by a security support provider to accept a certificate context received from a client;

intercepting a call to the function that is made as part of a particular client's attempt to establish a secure connection with the recovery agent; and

as part of intercepting the call, verifying a certificate context obtained from the intercepted call against the console certificate that was previously received from the recovery console and stored, wherein when the certificate context is verified, the recovery agent allows the intercepted call to complete, whereas when the certificate context is not verified, the recovery agent causes the intercepted call to fail.

2. The method of claim 1 , wherein the function is the AcceptSecurityContext function.

3. The method of claim 1 , wherein the console certificate is not stored in a trusted certificate store, and wherein verifying the certificate context against the console certificate comprises performing a binary comparison.

4. The method of claim 1 , wherein the server is a domain controller and the method is performed while the domain controller is in Directory Services Restore Mode.

5. The method of claim 1 , wherein the server is a domain controller and the method is performed when Kerberos authentication is not available.

6. The method of claim 1 , wherein the console certificate is stored in a virtual certificate store.

7. The method of claim 6 , further comprising:

intercepting a call to a function to open a collection certificate store;

adding the virtual certificate store to the collection certificate store.

8. The method of claim 7 , wherein the function to open the collection certificate store is the CertOpenStore function.

9. The method of claim 7 , wherein verifying the certificate context against the console certificate comprises verifying the certificate context against the console certificate that is included in the collection certificate store.

10. The method of claim 1 , wherein the security support provider is Schannel.

11. A method for establishing a secure connection between a recovery console executing on a client and a recovery agent executing on a server, the method comprising:

sending, by the recovery console, a console certificate to the recovery agent;

storing, by the recovery agent, the console certificate to enable the recovery agent to access the console certificate during subsequent attempts to establish a secure connection with the recovery agent;

installing, by the recovery agent, a hook on a first function that is called by a server-side security support provider to accept a certificate context received from a client;

requesting, by the recovery console, that a client-side security support provider establish a secure connection between the recovery console and the recovery agent thereby causing the client-side security support provider to send a security token containing a console certificate context to the server-side security support provider;

in response to the server-side security support provider receiving the security token and calling the first function, intercepting, by the recovery agent, the call to thereby obtain access to the security token;

accessing, by the recovery agent, the stored console certificate received from the recovery console; and

verifying, by the recovery agent, the console certificate context obtained from the security token against the stored console certificate.

12. The method of claim 11 , further comprising:

installing, by the recovery console, a hook on a second function that is called by the client-side security support provider to accept a certificate context received from a server.

13. The method of claim 12 , further comprising:

in response to the client-side security support provider receiving a security token containing an agent certificate context and calling the second function, intercepting, by the recovery console, the call such that the recovery console obtains access to the security token containing the agent certificate context;

obtaining, by the recovery console, an agent certificate stored on the client; and

verifying, by the recovery console, the agent certificate context obtained from the security token against the agent certificate.

14. The method of claim 11 , wherein verifying the console certificate context against the console certificate comprises performing a binary comparison.

15. The method of claim 11 , wherein the recovery agent stores the console certificate in a virtual certificate store, the method further comprising:

intercepting a call to a function to open a collection certificate store; and

adding the virtual certificate store to the collection certificate store.

16. The method of claim 11 , wherein the recovery agent executes on a domain controller in an Active Directory environment.

17. The method of claim 11 , wherein the security support provider is Schannel.

18. One or more non-transitory computer storage media storing computer executable instructions which implement a method for establishing a secure channel, the method comprising:

receiving, by a recovery agent executing on a domain controller, a console certificate from a recovery console executing on a client;

storing the console certificate on the domain controller to enable the recovery agent to access the console certificate during subsequent attempts to establish a secure connection with the recovery agent;

installing a hook on a function that is called by a security support provider to accept a certificate context received from a client;

intercepting a call to the function that is made as part of a particular client's attempt to establish a secure connection with the recovery agent; and

as part of intercepting the call, verifying a certificate context obtained from the intercepted call against the console certificate that was previously received from the recovery console and stored, wherein when the certificate context is verified, the recovery agent allows the intercepted call to complete, whereas when the certificate context is not verified, the recovery agent causes the intercepted call to fail.

19. The non-transitory computer storage media of claim 18 , wherein verifying the certificate context against the console certificate comprises performing a binary comparison.

20. The non-transitory computer storage media of claim 18 , further comprising:

storing the console certificate in a virtual certificate store;

intercepting a call to a function to open a collection certificate store; and

adding the virtual certificate store to the collection certificate store.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
CHANGE OF NAME Recorded Sep 13, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043834/0852 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2016
From: KALITIN, SERGEY ALEXANDROVICH; VARTANOV, SERGEY ROMANOVICH
To: DELL SOFTWARE, INC.
Reel/Frame 040000/0635 →
Continuity (1)
Related Publication 20180103033A1 · Apr 12, 2018