IP Library Granted Patent US 10,621,314
Granted Patent B2
US 10,621,314 · App. 15/697,270 · Granted Apr 14, 2020

Secure deployment of a software package

Inventors: Daniel Fox (London, GB); Felix Mance (London, GB); Jelena Cvitanovic (London, GB)
Assignee: Palantir Technologies Inc.
G06F21/121G06F8/60G06F16/254G06F16/9566H04L67/02H04L67/146H04L67/34G06F2221/0711
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,621,314
App. No.
15/697,270
Granted
Apr 14, 2020
Kind
B2
Abstract

Techniques for easy and secure deployment of a software package from a server to a customer-controlled computing device are described. In an embodiment, a deployment engine running on a server can be used to generate a unique URL for deployment of the software package. The unique URL may include a restricted use token. The restricted use token may be generated based on a combination of a random selection of one or more dictionary words, numbers, and/or symbols. The restricted token is easily readable given the combination of dictionary words, numbers, and/or symbols that make up the restricted use token. The unique URL may then be entered into a customer-controlled computing device via a curl command. The curl command will use the unique URL to generate a secure channel to the deployment engine and automatically download the software package onto the customer-controlled computing device. Upon downloading and/or installing the software package on the customer-controlled computing device, the unique URL is invalidated so that it may not be reused.

Claims (47)

1. A method comprising:

receiving, at a server, a request to generate a software package;

in response to receiving the request to generate the software package, the server generating the software package;

in response to receiving the request to generate the software package, the server generating a unique URL for the software package, wherein the unique URL comprises a restricted use token string and a URL root string;

wherein the restricted use token string comprises one or more dictionary strings randomly selected from a dictionary comprising a plurality of candidate dictionary strings;

receiving, at the server, a deployment command from a client computing device, wherein the deployment command comprises the unique URL;

in response to receiving the deployment command, sending the software package to the client computing device over a secure channel;

deactivating the unique URL on the server;

wherein the method is performed using one or more processors.

2. The method of claim 1 , wherein each candidate dictionary string of the plurality of candidate dictionary strings comprises a dictionary word.

3. The method of claim 1 , wherein the one or more dictionary strings comprises a plurality of dictionary strings.

4. The method of claim 3 , wherein the number of dictionary strings in the plurality of dictionary strings is randomly determined.

5. The method of claim 3 , wherein the restricted use token comprises concatenating the plurality of dictionary strings with a delimiter between each of the plurality of dictionary strings.

6. The method of claim 1 , further comprising:

storing validity data regarding the restricted use token; and

determining whether the deployment command is valid by comparing an extracted portion of the deployment command with the validity data for the restricted use token.

7. The method of claim 6 , wherein the validity data comprises a threshold number of uses for the restricted use token and determining whether the deployment command is valid comprises:

determining that the extracted portion of the deployment command matches the restricted use token; and

determining whether the threshold number of uses for the restricted use token has been exceeded or not.

8. The method of claim 6 , wherein the validity data comprises a time range for the restricted use token and determining whether the deployment command is valid comprises:

determining that the extracted portion of the deployment command matches the restricted use token; and

determining whether the deployment command was received in the time range.

9. The method of claim 1 , wherein the deployment command is a curl command.

10. The method of claim 1 , wherein the software package comprises a data extraction agent that is programmed or configured to perform data extraction of data records from a data source.

11. One or more non-transitory computer readable storage media storing instruction, which when executed by one or more processors, cause:

receiving a request to generate a software package;

in response to receiving the request to generate the software package, generating the software package;

in response to receiving the request to generate the software package, generating a unique URL for the software package, wherein the unique URL comprises a restricted use token string and a URL root string;

wherein the restricted use token string comprises one or more dictionary strings randomly selected from a dictionary comprising a plurality of candidate dictionary strings;

receiving a deployment command from a client computing device, wherein the deployment command comprises the unique URL;

in response to receiving the deployment command, sending the software package to the client computing device over a secure channel; and

deactivating the unique URL.

12. The one or more non-transitory computer readable storage media of claim 11 , wherein each candidate dictionary string of the plurality of candidate dictionary strings comprises a dictionary word.

13. The one or more non-transitory computer readable storage media of claim 11 , wherein the one or more dictionary strings comprises a plurality of dictionary strings.

14. The one or more non-transitory computer readable storage media of claim 13 , wherein the number of dictionary strings in the plurality of dictionary strings is randomly determined.

15. The one or more non-transitory computer readable storage media of claim 13 , wherein the restricted use token comprises concatenating the plurality of dictionary strings with a delimiter between each of the plurality of dictionary strings.

16. The one or more non-transitory computer readable storage media of claim 11 , further comprising instructions, which when executed by the one or more processors, cause:

storing validity data regarding the restricted use token; and

determining whether the deployment command is valid by comparing an extracted portion of the deployment command with the validity data for the restricted use token.

17. The one or more non-transitory computer readable storage media of claim 16 , wherein the validity data comprises a threshold number of uses for the restricted use token and determining whether the deployment command is valid comprises:

determining that the extracted portion of the deployment command matches the restricted use token; and

determining whether the threshold number of uses for the restricted use token has been exceeded or not.

18. The one or more non-transitory computer readable storage media of claim 16 , wherein the validity data comprises a time range for the restricted use token and determining whether the deployment command is valid comprises:

determining that the extracted portion of the deployment command matches the restricted use token; and

determining whether the deployment command was received in the time range.

19. The one or more non-transitory computer readable storage media of claim 11 , wherein the deployment command is a curl command.

20. The one or more non-transitory computer readable storage media of claim 11 , wherein the software package comprises a data extraction agent that is programmed or configured to perform data extraction of data records from a data source.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2018
From: FOX, DANIEL; MANCE, FELIX; CVITANOVIC, JELENA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 045680/0434 →