IP Library Granted Patent US 11,442,755
Granted Patent B1
US 11,442,755 · App. 16/591,335 · Granted Sep 13, 2022

Secure access to a corporate application using a facade

Inventors: David Patimer (Tel Aviv, IL); Lior Lev-Tov (Tel Aviv, IL); Eldad Rudich (Tel Aviv, IL); Leonid Belkind (Tel Aviv, IL)
Assignee: CA, Inc.
G06F9/452G06F21/305G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,442,755
App. No.
16/591,335
Granted
Sep 13, 2022
Kind
B1
Abstract

Secure access to a corporate application using a facade. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate application that is deployed in a corporate datacenter. The method may also include creating, at the secure access cloud PoD, a facade representing the corporate application. The method may further include forwarding, from the facade, to a connector that is also deployed in the corporate datacenter, the request. The method may also include brokering, by the connector and the facade, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate application via the facade, with the client application being unaware that the secure communication session is brokered by the connector and the facade.

Claims (37)

1. A computer-implemented method comprising:

receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate application that is deployed in a corporate datacenter, wherein the secure access cloud PoD is isolated from the corporate datacenter;

creating, at the secure access cloud PoD, a facade representing the corporate application, wherein the façade replicates, at least in part, portions of the corporate application;

forwarding, from the facade at the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate application; and

brokering, by the connector and the facade at the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate application via the facade, with no corresponding agent being installed at the client device, and with the client application being unaware that the secure communication session is brokered by the connector and the facade at the secure access cloud PoD, wherein brokering the secure communication session between the client application and the corporate application includes establishing a communication channel between the facade at the secure access cloud PoD and the connector, and wherein communication between the client application and the corporate application is conducted via the facade at the secure access cloud PoD and the connector at the corporate datacenter over the communication channel.

2. The method of claim 1 , wherein the facade poses as the corporate application and behaves similarly to the corporate application.

3. The method of claim 1 , wherein the facade includes a DNS name and port resolving thereto that are unknown to the client application.

4. The method of claim 3 , wherein when the client application connects to the facade, the client application believe it is connected to the corporate application.

5. The method of claim 1 , further comprising volumetric logging, by the facade at the secure access cloud PoD, of the secure communication session.

6. The method of claim 1 , further comprising auditing, by the façade at the secure access cloud PoD, of the secure communication session.

7. The method of claim 1 , further analyzing and modifying, by the facade at the secure access cloud PoD, a request or a response of the secure communication session.

8. The method of claim 1 , further analyzing and delaying, by the facade at the secure access cloud PoD, a request or a response of the secure communication session.

9. The method of claim 1 , further analyzing and dropping, by the facade at the secure access cloud PoD, a request or a response of the secure communication session.

10. The method of claim 1 , further comprising:

identifying, by the facade at the secure access cloud PoD, a sensitive command about to be executed by the client application, and

sending, by the facade at the secure access cloud PoD, a notification to an IT administrator regarding the sensitive command.

11. The method of claim 1 , wherein the secure communication session employs Hypertext Transfer Protocol Secure (HTTPS), Secure Shell (SSH), Remote Desktop Protocol (RDP), Secure Copy Protocol (SCP), or SSH File Transfer Protocol (SFTP).

12. A computer-implemented method comprising:

receiving, at a secure access cloud point of delivery (PoD), from an SSH client application on a client device, a request to access a corporate SSH server that is deployed in a corporate datacenter, wherein the secure access cloud PoD is isolated from the corporate datacenter;

creating, at the secure access cloud PoD, a facade representing the corporate SSH server, wherein the façade replicates, at least in part, portions of the corporate application;

forwarding, from the facade at the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate SSH server; and

brokering, by the connector and the facade at the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the SSH client application and the corporate SSH server via the facade, with no corresponding agent being installed at the client device, and with the SSH client application being unaware that the secure communication session is brokered by the connector and the facade at the secure access cloud PoD, wherein brokering the secure communication session between the client application and the corporate SSH server includes establishing a communication channel between the facade at the secure access cloud PoD and the connector, and wherein communication between the client application and the corporate SSH server is conducted via the facade at the secure access cloud PoD and the connector at the corporate datacenter over the communication channel.

13. The method of claim 12 , wherein a public certificate authority (CA) certificate is deployed on the corporate SSH server.

14. The method of claim 13 , wherein the corporate SSH server is configured to validate session certificates of the secure communication session.

15. The method of claim 13 , wherein no active agent is present at the corporate SSH server.

16. The method of claim 12 , further comprising causing, by the facade at the secure access cloud PoD, a certificate authority (CA) to generate a unique short-lived certificate for the secure communication session that has specific session parameters embedded therein.

17. The method of claim 12 , further comprising enforcing, by the facade at the secure access cloud PoD:

a local access policy to decide whether to provide access to the corporate SSH server;

specified authentication types; and/or

4-eyes access and operations approval.

18. The method of claim 12 , further comprising controlling, by the facade at the secure access cloud PoD:

specific shell commands;

output data;

Secure Copy Protocol (SCP) files; and/or

SSH File Transfer Protocol (SFTP) files.

19. The method of claim 12 , further comprising deceiving, by the facade at the secure access cloud PoD, a potentially malicious user by providing the potentially malicious user with false data and/or a false indication on a result of a performed operation.

20. The method of claim 12 , further comprising detecting and logging, by the SSH client application, sensitive information being input by the user to avoid the sensitive information being logged in an audit log by replacing the sensitive information with benign characters in the audit log.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 056398/0100 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2020
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 052700/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051933/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: PATIMER, DAVID; LEV-TOV, LIOR; RUDICH, ELDAD; BELKIND, LEONID
To: SYMANTEC CORPORATION
Reel/Frame 050607/0701 →
Cited By (2)
US 12,238,145 US 12,563,072