IP Library Granted Patent US 12,010,112
Granted Patent B2
US 12,010,112 · App. 17/706,165 · Granted Jun 11, 2024

Remote secured console over a secured connection for inoperable virtual machine

Inventors: Alexandru Cozma (Bucharest, RO); Jeffery J Van Heuklon (Rochester, MN); Ioana Voicu (Bucharest, RO); Ionut Dobre (Bucharest, RO)
Assignee: Lenovo Global Technology (United States) Inc.
H04L63/0853G06F9/45558H04L63/083G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,112
App. No.
17/706,165
Granted
Jun 11, 2024
Kind
B2
Abstract

A method for creation of a secured connection for an inoperable virtual machine includes receiving a token at an on-host service running on an inoperable virtual machine (“VM”) on a server. The token is generated by a remote service person. The method includes receiving a user generated password from a user having direct access to the on-host service. The method includes creating a secured connection, using the token and password, between the on-host service and a remote server of the service person. The method includes transmitting a VM identifier of the inoperable VM to the user and receiving communications from the remote server. The communications include commands for the inoperable VM. The service person accesses the on-host service and inoperable VM using the VM identifier and the password. The password and VM identifier are transmitted to the service person by the user via a channel separate from the secured connection.

Claims (43)

1. A method comprising:

receiving a token at an on-host service running on an inoperable virtual machine (“VM”) running on a server, the token generated by a service person located remote from the server;

receiving, at the on-host service, a password from a user, the user having direct access to the on-host service;

creating, by the on-host service, a secured connection between the on-host service and a remote server accessible to the service person, the secured connection created using the token and the password;

transmitting a VM identifier of the inoperable VM to the user; and

receiving communications from the remote server, the communications comprising one or more commands directed to the inoperable VM,

wherein the service person accesses the on-host service and the inoperable VM using the VM identifier and the password, the password and the VM identifier transmitted to the service person by the user via a channel separate from the secured connection,

wherein the channel separate from the secured connection comprises a voice connection and/or an electronic message, and

wherein the service person transmits the token to the user and the user inputs the token to the on-host service, wherein the service person transmits the token using a voice connection and/or an electronic message.

2. The method of claim 1 , wherein creating the secured connection further comprises using web proxy information regarding a web proxy between the inoperable VM and the remote server to create the secured connection.

3. The method of claim 1 , wherein the secured connection comprises a WebSocket.

4. The method of claim 1 , wherein the token is unique to the secured connection and the on-host service and the remote server use the token to encrypt communications over the secured connection.

5. The method of claim 1 , further comprising storing a hash of previous passwords and rejecting the password generated by the user in response to a hash of the password matching a hash of a previous password.

6. The method of claim 1 , wherein the service person accesses the remote server via a web browser accessing a webpage hosted by the remote server.

7. The method of claim 1 , further comprising terminating the secured connection in response to reaching a time limit and/or reaching a time limit after a period inactivity on the secured connection.

8. The method of claim 1 , wherein the user accesses the on-host service via a user interface through the server.

9. An apparatus comprising:

a processor; and

non-transitory computer readable storage media storing code, the code being executable by the processor to perform operations comprising:

receiving a token at an on-host service running on an inoperable virtual machine (“VM”) running on a server, the token generated by a service person located remote from the server;

receiving, at the on-host service, a password from a user, the user having direct access to the on-host service;

creating, by the on-host service, a secured connection between the on-host service and a remote server accessible to the service person, the secured connection created using the token and the password;

transmitting a VM identifier of the inoperable VM to the user; and

receiving communications from the remote server, the communications comprising one or more commands directed to the inoperable VM,

wherein the service person accesses the on-host service and the inoperable VM using a VM identifier and the password, the password and the VM identifier transmitted to the service person by the user via a channel separate from the secured connection,

wherein the channel separate from the secured connection comprises a voice connection and/or an electronic message, and

wherein the service person transmits the token to the user and the user inputs the token to the on-host service, wherein the service person transmits the token using a voice connection and/or an electronic message.

10. The apparatus of claim 9 , wherein creating the secured connection further comprises using web proxy information regarding a web proxy between the inoperable VM and the remote server to create the secured connection.

11. The apparatus of claim 9 , wherein the secured connection comprises a WebSocket.

12. The apparatus of claim 9 , wherein the token is unique to the secured connection and the on-host service and the remote server use the token to encrypt communications over the secured connection.

13. The apparatus of claim 9 , the operations further comprising storing a hash of previous passwords and rejecting the password generated by the user in response to a hash of the password matching a hash of a previous password.

14. The apparatus of claim 9 , wherein the service person accesses the remote server via a web browser accessing a webpage hosted by the remote server.

15. The apparatus of claim 9 , the operations further comprising terminating the secured connection in response to reaching a time limit and/or reaching a time limit after a period inactivity on the secured connection.

16. A non-transitory computer readable storage medium storing code, the code being configured to be executable by a processor to perform operations comprising:

receiving a token at an on-host service running on an inoperable virtual machine (“VM”) running on a server, the token generated by a service person located remote from the server;

receiving, at the on-host service, a password from a user, the user having direct access to the on-host service;

creating, by the on-host service, a secured connection between the on-host service and a remote server accessible to the service person, the secured connection created using the token and the password;

transmitting a VM identifier of the inoperable VM to the user; and

receiving communications from the remote server, the communications comprising one or more commands directed to the inoperable VM,

wherein the service person accesses the on-host service and the inoperable VM using the VM identifier and the password, the password and the VM identifier transmitted to the service person by the user via a channel separate from the secured connection,

wherein the channel separate from the secured connection comprises a voice connection and/or an electronic message, and

wherein the service person transmits the token to the user and the user inputs the token to the on-host service, wherein the service person transmits the token using a voice connection and/or an electronic message.

17. The non-transitory computer readable storage medium of claim 16 , wherein creating the secured connection further comprises using web proxy information regarding a web proxy between the inoperable VM and the remote server to create the secured connection.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LIMITED
To: LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 070269/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
To: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LTD.
Reel/Frame 070269/0252 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2022
From: COZMA, ALEXANDRU; VAN HEUKLON, JEFFERY J; VOICU, IOANA; DOBRE, IONUT
To: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
Reel/Frame 059418/0147 →
Continuity (1)
Related Publication 20230308434A1 · Sep 28, 2023