IP Library Granted Patent US 10,841,093
Granted Patent B2
US 10,841,093 · App. 16/119,992 · Granted Nov 17, 2020

Access management to instances on the cloud

Inventors: Hui Li (Chengdu, CN); Fangyuan Lin (Chengdu, CN); Rui Guo (Chengdu, CN); Ou Zhang (Chengdu, CN); Xiaohui Wang (Chengdu, CN); Min Han (Chengdu, CN)
Assignee: EMC IP HOLDING COMPANY LLC
H04L9/3073H04L9/0861H04L9/14H04L9/3228H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,093
App. No.
16/119,992
Granted
Nov 17, 2020
Kind
B2
Abstract

Managing access to instances on a public cloud can include in responding to a request from a user to create a support account for a target instance on a public network. A process can include generating a key pair including a public key and a private key, creating, in the target instance, a support account, and associating the public key with the target instance. Access to the private key can be provided to facilitate a connection to the target instance through the support account. Temporary credentials can be generated and associated with the target instance. Upon expiration of the temporary credentials, the support account can be disabled by removing the support account from the target instance and disassociating the public key with the target instance.

Claims (40)

1. A method performed by a computing device comprising:

in response to a request from a user to create a support account for a target instance on a public network:

generating a key pair including a public key and a private key;

creating, in the target instance, the support account;

associating the public key with the target instance, including storing the public key in an authorized key list associated with the target instance;

providing access to the private key, wherein the key pair can facilitate a connection to the target instance through the support account;

generating temporary credentials associated with the target instance, wherein the request from the user includes permissions associated with the support account and an expiration time of the temporary credentials; and

upon expiration of the temporary credentials, removing the support account from the target instance and disassociating the public key with the target instance, resulting in termination of current connections and barring future connections to the target instance through the key pair.

2. The method according to claim 1 , wherein generating the temporary credentials includes setting a timer and the expiration of the temporary credentials is triggered by an expiration of the timer.

3. The method according to claim 1 , wherein the expiration of the temporary credentials is forced as a response to a user pre-emption request to discontinue the support account.

4. The method according to claim 1 , wherein:

disassociating the public key with the target instance includes removing the public key from the authorized key list.

5. The method according to claim 1 , further comprising retrieving, from the instance, a system log, the system log containing actions performed on the instance through the support account.

6. The method according to claim 1 , wherein the connection to the target instance is through a network using a secure socket shell (SSH) protocol.

7. The method according to claim 1 , wherein the key pair is based on a cryptographic algorithm.

8. The method according to claim 1 , further comprising repeating each process to manage access to a plurality of target instances.

9. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations, the operations comprising:

in response to a request from a user to create a support account for a target instance on a public network:

generating a key pair including a public key and a private key;

creating, in the target instance, the support account;

associating the public key with the target instance, including storing the public key in an authorized key list associated with the target instance;

providing access to the private key, wherein the key pair can facilitate a connection to the target instance through the support account;

generating temporary credentials associated with the target instance, wherein the request from the user includes permissions associated with the support account and an expiration time of the temporary credentials; and

upon expiration of the temporary credentials, removing the support account from the target instance and disassociating the public key with the target instance, resulting in termination of current connections and barring future connections to the target instance through the key pair.

10. The non-transitory machine-readable medium according to claim 9 , wherein generating the temporary credentials includes setting a timer and the expiration of the temporary credentials is triggered by an expiration of the timer.

11. The non-transitory machine-readable medium according to claim 9 , wherein the expiration of the temporary credentials is forced as a response to a user pre-emption request to discontinue the support account.

12. The non-transitory machine-readable medium according to claim 9 , wherein:

disassociating the public key with the target instance includes removing the public key from the authorized key list.

13. The non-transitory machine-readable medium according to claim 9 , wherein the operations further comprise: retrieving, from the instance, a system log, the system log containing actions performed on the instance through the support account.

14. The non-transitory machine-readable medium according to claim 9 , wherein the connection to the target instance is through a network using a secure socket shell (SSH) protocol.

15. The non-transitory machine-readable medium according to claim 9 , wherein the key pair is based on a cryptographic algorithm.

16. A system comprising:

a processing system having at least one hardware processor, the processing system coupled to a memory programmed with executable instructions that, when executed by the processing system, perform operations comprising:

in response to a request from a user to create a support account for a target instance on a public network:

generating a key pair including a public key and a private key;

creating, in the target instance, the support account;

associating the public key with the target instance, including storing the public key in an authorized key list associated with the target instance;

providing access to the private key to an administrator or technical support user, wherein the key pair can facilitate a connection to the target instance through the support account;

generating temporary credentials associated with the target instance, wherein the request from the user includes permissions associated with the support account and an expiration time of the temporary credentials; and

upon expiration of the temporary credentials, removing the support account from the target instance and disassociating the public key with the target instance, resulting in termination of current connections and barring future connections to the target instance through the key pair.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2018
From: LI, HUI; LIN, FANGYUAN; GUO, RUI; ZHANG, OU; WANG, XIAOHUI; HAN, MIN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046820/0067 →
Priority Claims (1)
CN 2018 1 0879335 · Aug 3, 2018 · national
Continuity (1)
Related Publication 20200044847A1 · Feb 6, 2020
Cited By (1)
US 12,739,098