IP Library Granted Patent US 10,771,469
Granted Patent B1
US 10,771,469 · App. 15/419,874 · Granted Sep 8, 2020

Cloud service account management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,771,469
App. No.
15/419,874
Granted
Sep 8, 2020
Kind
B1
Abstract

A cloud service account management method identifies unauthorized or unmanaged accounts making administration console access or API access at a cloud computing service and triggers a work flow to place the accounts under management. In one embodiment, the user device is directed to a registration portal to provide credentials of the unauthorized account. Once the accounts are made managed, the cloud service account management method can monitor the activities of the accounts and can apply compliance or security policies to the managed accounts.

Claims (56)

1. A method of implementing cloud service account management by an enterprise, the method comprising:

identifying, using a hardware processor, traffic, wherein the traffic is associated with an access at a cloud computing service, the access made using an unmanaged account that is not managed by the enterprise;

generating, using the hardware processor, a request to obtain credentials associated with the unmanaged account;

receiving the credentials associated with the unmanaged account;

in response to receiving the credentials associated with the unmanaged account, placing, using the hardware processor, the unmanaged account in a management mode so that the unmanaged account becomes a managed account; and

monitoring, using the hardware processor, the managed account at the cloud computing service.

2. The method of claim 1 , further comprising:

storing, using the hardware processor, an account identifier associated with the managed account and the credentials in a managed account database.

3. The method of claim 2 , wherein identifying, using the hardware processor, the traffic associated with the access at the cloud computing service using the unmanaged account comprises:

comparing the account identifier to a list of managed accounts in the managed account database.

4. The method of claim 1 , wherein identifying, using the hardware processor, the traffic associated with the access at the cloud computing service using the unmanaged account comprises:

identifying, using the hardware processor, an administration console access at the cloud computing service using the unmanaged account.

5. The method of claim 1 , wherein identifying, using the hardware processor, the traffic associated with the access at the cloud computing service using the unmanaged account comprises:

identifying, using the hardware processor, an application program interface (API) access at the cloud computing service using the unmanaged account.

6. The method of claim 1 , wherein generating, using the hardware processor, the request to obtain credentials associated with the unmanaged account comprises:

generating, using the hardware processor, a request to obtain a security key associated with the unmanaged account.

7. The method of claim 1 , wherein generating, using the hardware processor, the request to obtain credentials associated with the unmanaged account comprises:

generating, using the hardware processor, a request to obtain an access token associated with the unmanaged account.

8. The method of claim 1 , wherein generating, using the hardware processor, the request to obtain credentials associated with the unmanaged account comprises:

providing, using the hardware processor, a registration portal requesting the credentials associated with the unmanaged account; and

receiving the credentials entered onto the registration portal.

9. The method of claim 1 , wherein monitoring, using the hardware processor, the managed account at the cloud computing service comprises:

using the credentials of the managed account to access the managed account at the cloud computing service; and

performing an audit of the managed account at the cloud computing service.

10. The method of claim 9 , wherein performing the audit of the managed account at the cloud computing service comprises:

performing a configuration audit to assess the configuration of application instances created by the managed account at the cloud computing service to determine compliance with security policies of the enterprise.

11. The method of claim 9 , wherein performing the audit of the managed account at the cloud computing service comprises:

performing a user activity audit at the cloud computing service to assess user activities associated with the managed account to determine compliance with security policies of the enterprise.

12. The method of claim 1 , further comprising:

in response to the credentials associated with the unmanaged account not being received, generating an alert to the enterprise concerning the access by the unmanaged account.

13. A system for implementing cloud service account management by an enterprise, the system comprising:

a hardware processor; and

a memory coupled with the hardware processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

identify traffic, wherein the traffic is associated with an access at a cloud computing service, the access made using an unmanaged account that is not managed by the enterprise;

generate a request to obtain credentials associated with the unmanaged account;

receive the credentials associated with the unmanaged account;

in response to receiving the credentials associated with the unmanaged account, place the unmanaged account in a management mode so that the unmanaged account becomes a managed account; and

monitor the managed account at the cloud computing service.

14. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

store an account identifier associated with the managed account and the credentials in a managed account database.

15. The system of claim 14 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

compare the account identifier to a list of managed accounts in the managed account database.

16. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

identify an administration console access or an application program interface (API) access at the cloud computing service using the unmanaged account.

17. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

generate a request to obtain a security key or an access token associated with the unmanaged account.

18. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

provide a registration portal requesting the credentials associated with the unmanaged account; and

receiving the credentials entered onto the registration portal.

19. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

monitor the managed account at the cloud computing service by using the credentials to access the account at the cloud computing service and performing an audit at the cloud computing service.

20. The system of claim 19 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

perform a configuration audit at the cloud computing service to assess the configuration of application instances created by the managed account.

21. The system of claim 19 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to:

perform a user activity audit at the cloud computing service to determine user activities associated with the managed account are in compliance with security policies of the enterprise.

22. The system of claim 13 , wherein the memory is further configured to provide the processor with instructions which when executed cause the processor to: in response to the credentials associated with the unmanaged account not being received, generating an alert to the enterprise concerning the administration console access by the unmanaged account.

Assignments (16)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047988/0159 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2017
From: SARUKKAI, SEKHAR; NARAYAN, KAUSHIK; GUPTA, RAJIV
To: SKYHIGH NETWORKS, INC.
Reel/Frame 041532/0631 →