IP Library Granted Patent US 10,681,026
Granted Patent B2
US 10,681,026 · App. 15/832,563 · Granted Jun 9, 2020

Secure shell public key audit system

Inventor: Matthew Todd Peterson (Lindon, UT)
Assignee: QUEST SOFTWARE INC.
H04L63/061H04L63/065H04L63/0823H04L63/101H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,681,026
App. No.
15/832,563
Granted
Jun 9, 2020
Kind
B2
Abstract

A system for auditing authorized key files associated with secure shell (SSH) servers is disclosed. In an example, the system may include a purpose-built SSH audit server. The SSH audit server may be configured to receive an authorized key file and a list of users. The SSH audit sever may generate and provide unique registration codes for each of the users in the list. The SSH audit server may associate particular users with particular public keys as each of the users accesses the SSH audit server using a public key and inputs a registration code.

Claims (62)

1. A system, comprising:

one or more communication interfaces to communicate with one or more client devices;

one or more hardware processors; and

computer-readable storage media storing computer-executable instructions, which when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:

receive a request to open a secure communication channel from a client device associated with an individual, the request including information generated based at least in part on a private key;

authenticate the request based at least in part on a public key associated with the individual;

receive a registration code from the client device corresponding to the individual;

attempt to validate the registration code by determining whether the registration code is valid for the individual;

mark the public key for further investigation responsive to determining that the registration code is invalid for the individual;

based on the further investigation, determining an identity of an owner of the private key;

based on the identity of the owner of the private key, permit a second registration code to be received from the client device; and

associate the individual with the public key based on the second registration code.

2. The system of claim 1 , the request includes a request to open a secure communication channel from the client device the operations further comprising:

open the secure communication channel;

request input of any registration code;

in response to requesting input of the any registration code, receiving the registration code from the client device; and

associate the individual with the public key.

3. The system of claim 2 , the operations further comprising identify the registration code as valid by matching the registration code with a predetermined registration code.

4. The system of claim 2 , the operations further comprising identify the registration code as invalid by failing to match the registration code with a predetermined registration code; and

remove the public key from an authorized key file.

5. A method, comprising:

generating, at an audit server, a unique registration code;

associating the unique registration code with a user;

sending the unique registration code to a client device of the user;

receiving a public key and a request to open a communication channel from the client device;

establishing the communication channel based at least in part on the public key;

receiving an input of a registration code from the client device;

attempting to validate the registration code by determining whether the registration code corresponds to the unique registration code;

marking the public key for further investigation responsive to determining that the registration code does not correspond to the unique registration code;

based on the further investigation of the public key, determining an identity of an owner of a private key that is associated with the client device;

based on the identity of the owner of the private key, permitting a second registration code to be received from the client device; and

associating the user with the public key based on the second registration code.

6. The method of claim 5 , further comprising:

generating a second unique registration code;

associating the second unique registration code with a second user;

sending the second unique registration code to a second client device of the second user;

receiving a second request to open a second communication channel from the second client device;

establishing the second communication channel based at least in part on a second public key;

receiving a second input of the second unique registration code from the second client device; and

associating the second user with the second public key based at least in part on receiving the second unique registration code via the second communication channel.

7. The method of claim 5 , further comprising sending a login credential to the client device to establish the communication channel with the audit server.

8. The method of claim 5 , wherein the communication channel includes a secure shell.

9. The method of claim 5 , further comprising:

receiving, prior to generating the unique registration code, an authorized key file associated with a server being audited, the authorized key file including the public key; and

receiving, prior to generating the unique registration code, contact information associated with a plurality of individuals authorized to access the server, the plurality of individuals including the user.

10. One or more non-transitory computer-readable storage media configured to store computer-executable instructions, which when executed by one or more processors, cause a system to perform operations comprising:

generate a plurality of registration codes, a registration code of the plurality of registration codes associated with a user;

send the registration code to a client device of the user;

receive an input of the registration code over a communication channel established based in part on a public key;

attempt to validate the registration code by determining whether the registration code is valid for the user;

mark the public key for further investigation responsive to determining that the registration code is invalid for the user;

based on the further investigation of the public key, determine an identity of an owner of a private key that is associated with the client device;

based on the identity of the owner of the private key, permit a second registration code to be received from the client device; and

associate the user with the public key based on the second registration code.

11. The one or more non-transitory computer-readable storage media of claim 10 , wherein execution of the instructions further cause the system to receive, prior to generating the registration code, contact information associated with a plurality of individuals authorized to access a server being audited, the plurality of individuals including the user.

12. The one or more non-transitory computer-readable storage media of claim 10 , wherein execution of the instructions further cause the system to receive, prior to generating the plurality of registration codes, an authorized key file associated with a server being audited, the authorized key file including the public key.

13. The one or more non-transitory computer-readable storage media of claim 10 , wherein execution of the instructions further cause the system to:

receive a request to open the communication channel from the client device; and

establish the communication channel based at least in part on the public key.

14. The one or more non-transitory computer-readable storage media of claim 10 , wherein the one or more non-transitory computer-readable storage media is a resource associated with a secure shell audit server.

15. The one or more non-transitory computer-readable storage media as recited in claim 10 , wherein execution of the instructions further cause the system to generate a list of registered public keys, the list of registered public keys including the public key and an indication of the user as an owner of the public key.

16. The one or more non-transitory computer-readable storage media as recited in claim 15 , wherein execution of the instructions further cause the system to provide the list of registered public keys to an administrator system after a predetermined period of time has elapsed.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 942. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY LLC
Reel/Frame 070678/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY LLC
Reel/Frame 070194/0942 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: PETERSON, MATTHEW TODD
To: DELL PRODUCTS L.P.
Reel/Frame 052560/0582 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE INC.
Reel/Frame 052561/0010 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 053146/0678 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
Continuity (2)
Continuation 14603197 · Jan 22, 2015
Related Publication 20180176199A1 · Jun 21, 2018