IP Library Granted Patent US 12,664,315
Granted Patent B2
US 12,664,315 · App. 17/746,269 · Granted Jun 23, 2026

Managing privilege delegation on a server device

Inventors: John Goodridge (Cheshire, GB); Thomas Couser (Lancashire, GB)
Assignee: Avecto Limited
G06F21/629G06F9/44526G06F9/468G06F21/126G06F21/53H04L63/105H04L67/564G06F2221/2141G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,664,315
App. No.
17/746,269
Granted
Jun 23, 2026
Kind
B2
Abstract

A server device for managing privilege delegation to control execution of commands thereon is described. Execution of a command, according to first privileges, by a remote management (RM) server on the server device is requested from a RM client on a client device. An agent plug-in, chained to a command execution plug-in of the RM server, intercepts the request and forwards related information to an agent service cooperating with an operating system of the server device. The agent service determines whether to execute the command according to second privileges, different from the first privileges and if permitted, delegates the second privileges to the command, and causes, via the agent plug-in chained to the command execution plug-in, the command to be executed according to the second privileges.

Claims (47)

1 . A system, comprising:

a memory; and

a remote management (RM) server comprising a processing circuit, wherein the processing circuit is configured to:

intercept a request, via an agent plug-in installed on the RM server, originating from a first user account of a logged-in user on a client device to execute a command by the RM server and as a second user account on the RM server, wherein the first user account is assigned first privileges, the second user account is assigned second privileges, the request is transmitted over a network from the client device to the RM server, and the request is intercepted by the agent plug-in prior to receipt by an intended recipient on the RM server;

obtain information related to the request to execute the command;

determine whether to execute the command on the RM server by applying a policy to the information related to the request; and

in response to determining to execute the command, cause the command to be executed according to the second privileges in the second user account.

2 . The system of claim 1 , wherein the policy comprises a plurality of rules and the processing circuit is further configured to evaluate the information against the plurality of rules.

3 . The system of claim 1 , wherein the processing circuit is further configured to delegate the second privileges to a thread executing the command by providing the thread with a token, wherein the second privileges are assigned to the token.

4 . The system of claim 1 , wherein the agent plug-in is configured to be executed by the processing circuit and cause the processing circuit to intercept the request.

5 . A method, comprising:

intercepting, via an agent plug-in installed on an RM server, a request originating from a first user account of a logged-in user on a client device to execute a command by the RM server and as a second user account on the RM server, wherein the first user account is assigned first privileges, the second user account is assigned second privileges, the request is transmitted over a network from the client device to the RM server, and the request is intercepted by the agent plug-in prior to receipt by an intended recipient on the RM server;

obtaining, via the RM server, information related to the request to execute the command;

determining, via the RM server, whether to execute the command on the RM server by applying a policy to the information related to the request; and

in response to determining to execute the command, causing, via the RM server, the command to be executed according to the second privileges in the second user account.

6 . The method of claim 5 , further comprising:

capturing, via the RM server, a set of identities associates with the request; and

requesting, via the RM server, the policy based on the set of identities.

7 . The method of claim 6 , wherein the set of identities comprises at least one of: a user identity of the first user account, a user identity of the second user account, a group identity, and a process identity.

8 . The method of claim 5 , further comprising:

generating, via the RM server, a custom message based on the policy; and

causing, via the RM server, the custom message to be rendered on a display of the client device.

9 . The method of claim 5 , further comprising:

exposing, via the RM server, a function corresponding to a command execution plug-in function; and

receiving, via the RM server, the request via the exposed function.

10 . The method of claim 5 , further comprising providing a token to a thread executing the command, wherein the second privileges are assigned to the token.

11 . The method of claim 5 , further comprising:

calling a command execution plug-in function;

delegating the second privileges to the command; and

passing the command to the command execution plug-in function.

12 . The method of claim 5 , further comprising passive handling of the request based on the policy.

13 . A non-transitory computer-readable medium embodying a program that, when executed by a processing circuit of a remote management (RM) server, causes the processing circuit to:

intercept a request, via an agent plug-in installed on the RM server, originating from a first user account of a logged-in user on a client device to execute a command by the RM server and as a second user account on the RM server, wherein the first user account is assigned first privileges, the second user account is assigned second privileges, the request is transmitted over a network from the client device to the RM server, and the request is intercepted by the agent plug-in prior to receipt by an intended recipient on the RM server;

obtain information related to the request to execute the command;

determine whether to execute the command on the RM server by applying a policy to the information related to the request; and

in response to determining to execute the command, cause the command to be executed according to the second privileges in the second user account.

14 . The non-transitory computer-readable medium of claim 13 , wherein the program further causes the processing circuit to delegate the second privileges to an agent service and the agent service executes the command.

15 . The non-transitory computer-readable medium of claim 13 , wherein the program further causes the processing circuit to intercept the request from the first user account of the logged-in user on the client device by exposing a function corresponding to a command execution plug-in function and receiving the request via the exposed function.

16 . The non-transitory computer-readable medium of claim 13 , wherein the request originating from the first user account of the logged-in user on the client device to execute the command by the RM server is received from a terminal.

17 . The non-transitory computer-readable medium of claim 13 , wherein the program further causes the processing circuit to relay the command to a command execution plug-in provided by an operating system of the RM server.

18 . The non-transitory computer-readable medium of claim 13 , wherein the program further causes the processing circuit to:

intercept a connection request, from the client device, to connect to the RM server; and

control connection of the logged-in user on the client device to the RM server.

19 . The non-transitory computer-readable medium of claim 13 , wherein the program further causes the processing circuit to:

generate a custom message comprising a challenge-response based on the policy; and

receive a validation code to authenticate the first user account.

20 . The non-transitory computer-readable medium of claim 13 , wherein RM server is configured to generate responses for requests as the intended recipient unless the request is intercepted.

Assignments (5)
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: AVECTO LTD
Reel/Frame 065696/0980 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: AVECTO LTD
Reel/Frame 065697/0239 →
SECURITY INTEREST Recorded Oct 18, 2022
From: AVECTO LTD
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 061456/0209 →
SECURITY INTEREST Recorded Oct 18, 2022
From: AVECTO LTD
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 061456/0980 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: GOODRIDGE, JOHN; COUSER, THOMAS
To: AVECTO LIMITED
Reel/Frame 059932/0408 →
Priority Claims (1)
GB 1801568 · Jan 31, 2018 · national
Continuity (2)
Continuation 16259113 · Jan 28, 2019
Related Publication 20220277092A1 · Sep 1, 2022
References Cited (83)
US 5881225A · Worth · 1999 [cited by applicant]
US 5991542A · Han et al. · 1999 [cited by applicant]
US 6233618B1 · Shannon · 2001 [cited by applicant]
US 7133904B1 · Soyha et al. · 2006 [cited by applicant]
US 7219354B1 · Huang et al. · 2007 [cited by applicant]
US 8368640B2 · Dardinski et al. · 2013 [cited by applicant]
US 8677446B2 · De Peuter · 2014 [cited by examiner]
US 9158662B1 · Hanes et al. · 2015 [cited by applicant]
US 9769131B1 · Hartley · 2017 [cited by applicant]
US 10803499B1 · Davis et al. · 2020 [cited by applicant]
US 12101376B2 · Maheshwari · 2024 [cited by examiner]
US 20020040366A1 · Lahr · 2002 [cited by examiner]
US 20020144137A1 · Harrah et al. · 2002 [cited by applicant]
US 20020174256A1 · Bonilla et al. · 2002 [cited by applicant]
US 20040133801A1 · Pastorelli et al. · 2004 [cited by applicant]
US 20040210771A1 · Wood et al. · 2004 [cited by applicant]
US 20050188370A1 · Kouznetsov et al. · 2005 [cited by applicant]
US 20060089834A1 · Mowatt et al. · 2006 [cited by applicant]
US 20060294103A1 · Wood · 2006 [cited by examiner]
US 20070180502A1 · Yadav et al. · 2007 [cited by applicant]
US 20070198933A1 · Van Der Bogert et al. · 2007 [cited by applicant]
US 20080060051A1 · Barton et al. · 2008 [cited by applicant]
US 20080127322A1 · McCall · 2008 [cited by examiner]
US 20080189544A1 · Raghunath et al. · 2008 [cited by applicant]
US 20080289026A1 · Abzarian et al. · 2008 [cited by applicant]
US 20090070442A1 · Kacin et al. · 2009 [cited by applicant]
US 20090249448A1 · Choi · 2009 [cited by examiner]
US 20090260050A1 · George · 2009 [cited by examiner]
US 20100274366A1 · Fata et al. · 2010 [cited by applicant]
US 20110030045A1 · Beauregard et al. · 2011 [cited by applicant]
US 20110173251A1 · Sandhu et al. · 2011 [cited by applicant]
US 20110196842A1 · Timashev et al. · 2011 [cited by applicant]
US 20110239275A1 · De Peuter · 2011 [cited by examiner]
US 20110239288A1 · Cross et al. · 2011 [cited by applicant]
US 20110251992A1 · Bethlehem et al. · 2011 [cited by applicant]
US 20120047259A1 · Krasser et al. · 2012 [cited by applicant]
US 20120054744A1 · Singh et al. · 2012 [cited by applicant]
US 20120066512A1 · Kass et al. · 2012 [cited by applicant]
US 20120222083A1 · Vaha-Sipila · 2012 [cited by examiner]
US 20120226742A1 · Mornchilov et al. · 2012 [cited by applicant]
US 20130057561A1 · Nave et al. · 2013 [cited by applicant]
US 20130339313A1 · Blaine et al. · 2013 [cited by applicant]
US 20140164774A1 · Nord · 2014 [cited by examiner]
US 20140189808A1 · Mahaffey · 2014 [cited by examiner]
US 20140279600A1 · Chait · 2014 [cited by applicant]
US 20140281528A1 · Dubey et al. · 2014 [cited by applicant]
US 20150040181A1 · Cook et al. · 2015 [cited by applicant]
US 20150058839A1 · Madanapalli et al. · 2015 [cited by applicant]
US 20150074828A1 · Beauregard et al. · 2015 [cited by applicant]
US 20150128250A1 · Lee et al. · 2015 [cited by applicant]
US 20160057254A1 · Arcese et al. · 2016 [cited by applicant]
US 20160203313A1 · El-Moussa et al. · 2016 [cited by applicant]
US 20160217159A1 · Dahan et al. · 2016 [cited by applicant]
US 20160378962A1 · Austin · 2016 [cited by applicant]
US 20170011220A1 · Efremov et al. · 2017 [cited by applicant]
US 20170048259A1 · Dodge et al. · 2017 [cited by applicant]
US 20170054760A1 · Barton et al. · 2017 [cited by applicant]
US 20170111368A1 · Hibbert et al. · 2017 [cited by applicant]
US 20180024895A1 · Kumarasamy et al. · 2018 [cited by applicant]
US 20180302409A1 · Hope · 2018 [cited by applicant]
US 20190121631A1 · Hua et al. · 2019 [cited by applicant]
US 20200021670A1 · Agerstam · 2020 [cited by examiner]
EP 2750035A1 · 2014 [cited by applicant]
GB 2486528B · 2016 [cited by applicant]
GB 2538518A · 2016 [cited by applicant]
GB 2563066A · 2018 [cited by applicant]
KR 101308859B1 · 2013 [cited by applicant]
WO 2006101549A2 · 2006 [cited by applicant]
WO 2007089786A2 · 2007 [cited by applicant]
WO 2015183493A1 · 2015 [cited by applicant]
WO 2018174990A1 · 2018 [cited by applicant]
Motiee, “Do Windows Users Follow the Principle of Least Privilege? Investigating User Account Control Practices”, 2010, Proceedings on Usable Privacy and Security, pp. 1-13 (Year: 2010). [cited by examiner]
Perez-Botero, Charaterizing hypervisor vulnerabilities in cloud computing servers, 2013, Proceedings of the 2013 International workshop on Security in cloud computing, pp. 3-10 (Year: 2013). [cited by examiner]
Subashini S., et al., “A Survey on Security Issues in Service Delivery Models of Cloud Computing,” JNCA, Jul. 2010, pp. 1-11. [cited by applicant]
Chris Hoffman and Justin Pot; “How to Install Applications On a Mac: Everything You Need to Know”; HowToGeek.com website [full url in ref.]; Jul. 20, 2017 (Year: 2017). [cited by applicant]
Chris Hoffman; “How to Disable System Integrity Protection on a Mac (and Why You Shouldn't)”; HowToGeek.com website [full url in ref.]; Jul. 5, 2017 (Year: 2017). [cited by applicant]
Examination Report dated Apr. 29, 2020 for United Kingdom Patent Application No. GB1715628.2. [cited by applicant]
Examination Report dated Jun. 14, 2019 for United Kingdom Patent Application No. GB1600738.7. [cited by applicant]
Combined Examination & Search Report dated Feb. 6, 2018 for United Kingdom Patent Application No. GB1714489.0. [cited by applicant]
Combined Examination & Search Report dated Aug. 1, 2018 for United Kingdom Patent Application No. GB1802241.8. [cited by applicant]
Combined Examination & Search Report dated Nov. 16, 2018 for United Kingdom Patent Application No. GB1808380.8. [cited by applicant]
Combined Examination & Search Report dated Mar. 6, 2019 for United Kingdom Patent Application No. GB1814798.3. [cited by applicant]
Combined Examination & Search Report dated Dec. 1, 2017 for United Kingdom Patent Application No. GB1708824.6. [cited by applicant]