IP Library Granted Patent US 10,855,724
Granted Patent B2
US 10,855,724 · App. 15/928,344 · Granted Dec 1, 2020

Securely establishing key-based SSH communications between virtual machines during cloud marketplace provisioning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,855,724
App. No.
15/928,344
Granted
Dec 1, 2020
Kind
B2
Abstract

Virtual machines are launched in a public cloud software marketplace by a user purchasing a software product. The virtual machines are automatically provisioned and configured upon launching. One virtual machine generates a public/private key pair, and key-based SSH communications is securely established between the virtual machines without the necessity of insecurely transferring the private key over an insecure public communications channel.

Claims (24)

1. A method of automatically and securely establishing key-based Secure shell (SSH) communications between processing entities over an insecure network in a public cloud environment without insecurely transferring a private key of a public/private key pair over the network, comprising:

launching instances of first and second virtual machines in said public cloud environment using an initiation template that automatically provisions and configures simultaneously each said first and second virtual machine, said launching comprising providing by said initiation template corresponding first and second instance identifiers for said first and second virtual machine instances, respectively;

enabling temporarily upon said launching a password-based SSH communications channel on the second virtual machine using said second instance identifier as a password, and enabling key-based SSH only on said first virtual machine;

generating by said first virtual machine a public/private key pair of the first virtual machine for key-based SSH communications with said second virtual machine;

transferring to said second virtual machine over said password-based SSH communications channel the public key of said public/private key pair of the first virtual machine, and configuring the second virtual machine to use the first virtual machine's public key as a public key of the second virtual machine; and

establishing a key-based SSH communications channel between the first virtual machine and the second virtual machine using the public/private key pair of the first virtual machine.

2. The method of claim 1 , wherein said steps of the method are performed by a processor automatically to completion without user involvement upon launching said instances of said first and second virtual machines.

3. The method of claim 1 further comprising disabling said password-based SSH communications channel with said second virtual machine upon said transferring of said pubic key of the first virtual machine.

4. The method of claim 1 further comprising generating by said second virtual machine another public/private key pair that is unique to said second virtual machine, transferring the public key of said other public/private key pair over said key-based SSH channel to said first virtual machine; and re-establishing said key-based SSH communications channel using said other public key for the second virtual machine.

5. The method of claim 1 , wherein said initialization template that launches said first and second virtual machines comprises scripts to configure said first and second virtual machines based upon user data.

6. The method of claim 5 , wherein said scripts configure operating systems and software on said virtual machines for operation of a software product.

7. The method of claim 1 , wherein said method is performed in a cloud software vendor environment in response to a user selecting a software product, and wherein said first and second virtual machines are launched on a cloud server to run the selected software product.

8. Computer readable non-transitory media storing executable instructions for controlling a processor to perform a method of automatically and securely establishing key-based Secure shell (SSH) communications between processing entities over an insecure network in a public cloud environment without insecurely transferring a private key of a public/private key pair over the network, comprising:

launching instances of first and second virtual machines in said public cloud environment using an initiation template that automatically provisions and configures simultaneously each said first and second virtual machine, said launching comprising providing by said initiation template corresponding first and second instance identifiers for said first and second virtual machine instances, respectively;

enabling temporarily upon said launching a password-based SSH communications channel on the second virtual machine using said second instance identifier as a password, and enabling key-based SSH only on said first virtual machine;

generating by said first virtual machine a public/private key pair of the first virtual machine for key-based SSH communications with said second virtual machine;

transferring to said second virtual machine over said password-based SSH communications channel the public key of said public/private key pair of the first virtual machine, and configuring the second virtual machine to use the first virtual machines public key as a public key of the second virtual machine; and

establishing key-based SSH communications between the first virtual machine and the second virtual machine using the public/private key pair of the first virtual machine.

9. Computer readable non-transitory media of claim 8 , wherein the steps of said method are performed automatically to completion without user involvement upon launching said instances of said first and second virtual machines.

10. Computer readable non-transitory media of claim 8 further comprising disabling said password-based SSH communications channel with said second virtual machine upon said transferring of said pubic key of the first virtual machine.

11. Computer readable non-transitory media of claim 8 further comprising generating by said second virtual machine another public/private key pair that is unique to said second virtual machine, transferring the public key of said other public/private key pair over said key-based SSH channel to said first virtual machine; and re-establishing said key-based SSH communications channel using said other public key for the second virtual machine.

12. Computer readable non-transitory media of claim 8 , wherein said initialization template that launches said first and second virtual machines comprises scripts to configure said first and second virtual machines based upon user data.

13. Computer readable non-transitory media of claim 12 , wherein said scripts configure operating systems and software on said virtual machines for operation of a software product.

14. Computer readable non-transitory media of claim 8 , wherein said method is performed in a cloud software vendor environment in response to a user selecting a software product, and wherein said first and second virtual machines are launched on a cloud server to run the selected software product.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2018
From: YU, BIN, MR; ZHOU, ARTHUR, MR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045313/0922 →