IP Library Granted Patent US 12,549,527
Granted Patent B2
US 12,549,527 · App. 17/802,909 · Granted Feb 10, 2026

Multi-factor authentication of cloud-managed services

Inventor: Scott Wilson (Golden, CO)
Assignee: Nvidia Corporation
H04L63/0442H04L63/067H04L63/123H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,527
App. No.
17/802,909
Granted
Feb 10, 2026
Kind
B2
Abstract

A cloud management system ( 180 ) only instructs a storage platform ( 100 ) in a private domain to implement an operation that reveals, modifies, or destroys data if an administrator ( 163 ) both provides valid credentials and is able to direct a services processing unit or SPU ( 120 ) in the private domain to send a message with valid contents and signature. An SPU ( 120 ) only performs operations that reveal, modify, or destroy data if signed instructions from the cloud management system ( 180 ) have originated or been relayed through a component ( 120 ) in the private domain. An attacker with access to the cloud management system ( 180 ) that does not also have access to a component ( 120 ) in the private domain is prevented from tampering with the storage platform ( 100 ).

Claims (62)

1 . A process comprising:

receiving, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;

verifying, by the management system, the credentials of the administrator;

sending, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;

causing the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;

receiving, by the management system, a second message from the first SPU, the second message containing the first message;

verifying, by the management system, that the first SPU signed the second message and that the second message contains the first message; and

in response to the verification succeeding, sending, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.

2 . The process of claim 1 , wherein the first message is sent through a public network to the private network.

3 . The process of claim 2 , wherein the public network comprises the Internet.

4 . The process of claim 1 , further comprising:

constructing the instruction for the identified first SPU.

5 . The process of claim 4 , further comprising:

implementing the instruction in response to a validation process succeeding, the validation process comprising:

validating that the management system signed the third message;

extracting the second message from the third message; and

validating that the first SPU signed the second message.

6 . The process of claim 5 , wherein:

the first message contains a one-time code; and

the validation process further comprises extracting the first message from the extracted second message and verifying that the one-time code differs from prior one-time codes associated with operations the storage platform completed.

7 . The process of claim 5 , wherein:

the second message contains a time stamp; and

the validation process further comprises verifying that the time stamp corresponds to a time that differs from a current time by less than a threshold time difference.

8 . The process of claim 1 , wherein the storage platform is instructed to perform the operation only if the second message is verified to contain the first message signed by the management system.

9 . At least one processor comprising:

one or more processing units configured to:

receive, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;

verify, by the management system, the credentials of the administrator;

send, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;

cause the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;

receive, by the management system, a second message from the first SPU, the second message containing the first message;

verify, by the management system, that the first SPU signed the second message and that the second message contains the first message; and

in response to the verification succeeding, send, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.

10 . The at least one processor of claim 9 , wherein the first message is sent through a public network to the private network.

11 . The at least one processor of claim 10 , wherein the public network comprises the Internet.

12 . The at least one processor of claim 9 , wherein the one or more processing units are further configured to:

construct the instruction for the identified first SPU.

13 . The at least one processor of claim 12 , wherein the one or more processing units are further configured to:

implement the instruction in response to a validation process succeeding, the validation process comprising:

validating that the management system signed the third message;

extracting the second message from the third message; and validating that the first SPU signed the second message.

14 . The at least one processor of claim 13 , wherein:

the first message contains a one-time code; and

the validation process further comprises extracting the first message from the extracted second message and verifying that the one-time code differs from prior one-time codes associated with operations the storage platform completed.

15 . The at least one processor of claim 13 , wherein:

the second message contains a time stamp; and

the validation process further comprises verifying that the time stamp corresponds to a time that differs from a current time by less than a threshold time difference.

16 . The at least one processor of claim 9 , wherein the storage platform is instructed to perform the operation only if the second message is verified to contain the first message signed by the management system.

17 . A system comprising:

at least one processor; and

a memory coupled to the at least one processor, the memory storing instructions that, when executed by the at least one processor, cause the system to perform steps comprising:

receiving, from an administrator, and by a management system, credentials and a request to implement an operation on a storage platform comprising a plurality of services processing units (SPUs) within a private network, the management system being outside of the private network;

verifying, by the management system, the credentials of the administrator;

sending, by the management system, a first message to the administrator, the first message signed by the management system using a private key of the management system, the first message including a command for the request to implement the operation;

causing the first message to be forwarded to an identified first SPU of the plurality of SPUs within the private network to fulfill the operation;

receiving, by the management system, a second message from the first SPU, the second message containing the first message;

verifying, by the management system, that the first SPU signed the second message and that the second message contains the first message; and

in response to the verification succeeding, sending, to the first SPU, a third message, signed by the management system using the private key of the management system, containing an instruction and the second message.

18 . The system of claim 17 , wherein the first message is sent through a public network to the private network.

19 . The system of claim 18 , wherein the public network comprises the Internet.

20 . The system of claim 17 , wherein the memory storing instructions that, when executed by the at least one processor, further cause the system to perform steps comprising:

constructing the instruction for the identified first SPU.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: NEBULON, INC.; NEBULON LTD
To: NVIDIA CORPORATION
Reel/Frame 067005/0154 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: WILSON, SCOTT
To: NEBULON, INC.
Reel/Frame 061330/0688 →
Continuity (2)
Provisional Application 62983293 · Feb 28, 2020
Related Publication 20230123159A1 · Apr 20, 2023
References Cited (24)
US 10402090B1 · Tsaur · 2019 [cited by examiner]
US 11374903B1 · Li · 2022 [cited by examiner]
US 20090228525A1 · Fridrich · 2009 [cited by examiner]
US 20090276623A1 · Jevans · 2009 [cited by examiner]
US 20130046976A1 · Rosati · 2013 [cited by examiner]
US 20130132504A1 · Kohli · 2013 [cited by examiner]
US 20140009366A1 · Chang · 2014 [cited by examiner]
US 20140181948A1 · Mazur et al. · 2014 [cited by applicant]
US 20150163206A1 · McCarthy · 2015 [cited by examiner]
US 20150339401A1 · Baldwin · 2015 [cited by examiner]
US 20160359684A1 · Rizqi · 2016 [cited by examiner]
US 20170005944A1 · Agrawal · 2017 [cited by examiner]
US 20180026984A1 · Maker · 2018 [cited by examiner]
US 20180063096A1 · Rogson · 2018 [cited by examiner]
US 20190310791A1 · Kasturi · 2019 [cited by examiner]
US 20190327223A1 · Kumar et al. · 2019 [cited by applicant]
US 20190377886A1 · Roy · 2019 [cited by applicant]
US 20200145499A1 · Kaplan · 2020 [cited by examiner]
US 20200274778A1 · Lecuyer · 2020 [cited by examiner]
US 20210165759A1 · Bar-Nissan · 2021 [cited by examiner]
CA 3065058A1 · 2020 [cited by examiner]
CN 113806778A · 2021 [cited by examiner]
JP 2013137595A · 2013 [cited by examiner]
WO WO2016191639A1 · 2016 [cited by examiner]