IP Library Granted Patent US 11,784,999
Granted Patent B1
US 11,784,999 · App. 18/091,895 · Granted Oct 10, 2023

Credential management for distributed services

Inventors: William Craig Jones (Cedar Park, TX); Justin Allan McCarthy (Redwood City, CA); Patrick David Stephen (Minneapolis, MN); Evan Michael Todd (Culver City, CA)
Assignee: strongDM, Inc.
H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,784,999
App. No.
18/091,895
Granted
Oct 10, 2023
Kind
B1
Abstract

Embodiments are directed to credential management for distributed services. A plurality of mesh agents for an overlay network may be provided such that the overlay network may be employed to provide a secure tunnel between a client and a resource server. If client request that requires user credentials is provided to a mesh agent associated with the resource server, credential instructions may be provided to the mesh agent and the credential instructions may be employed to determine credential information that enables access to the resource server. The mesh agent may be employed to communicate the client request and the credential information to the resource server; determining a response to the client request from the resource server; employing the mesh agent to receive a response to the client request from the resource server and forwarded to the client over the overlay network.

Claims (59)

1. A method for managing access to network resources in a network using one or more processors that are configured to execute instructions, wherein the execution of the instructions enables performance of actions, comprising:

determining credential information to access a resource server based on credential instructions and a client request received by a mesh agent on an overlay network that includes a plurality of mesh agents;

communicating the client request and the credential information to the resource server via the mesh agent; and

in a response to the client request generated by the resource server, forwarding the response to the client over the overlay network via the mesh agent.

2. The method of claim 1 , wherein the plurality of mesh agents further comprises:

hosting one or more of the mesh agents on one or more network computers.

3. The method of claim 1 , wherein communicating the client request further comprises:

generating a secure tunnel over the overlay network for communication between the client and the resource server.

4. The method of claim 1 , wherein determining the credential information, further comprises:

determining an interpretation of the credential instructions based on one or more of a grammar or a ruleset based on the credential instructions and the client request;

determining one or more actions to access the credential information based on the interpretation of the credential instructions, wherein the one or more actions are executed to determine the credential information.

5. The method of claim 1 , further comprising:

determining actions on how to activate credential information to gain access to the resource server based on the credential instructions.

6. The method of claim 1 , further comprising:

determining one or more application protocols employed for communication between the client and the resource server based on network traffic; and

generating one or more application models to provide instructions for credential management for distributed services based on the one or more application protocols.

7. The method of claim 1 , further comprising:

generating one or more application models that include information for determining one or more fields to modify for injection of credential secrets in application protocol network traffic between the client and the resource server.

8. A system for method for managing access to network resources, comprising:

a network computer, comprising:

memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

determining credential information to access a resource server based on credential instructions and a client request received by a mesh agent on an overlay network that includes a plurality of mesh agents;

communicating the client request and the credential information to the resource server via the mesh agent; and

in a response to the client request generated by the resource server, forwarding the response to the client over the overlay network via the mesh agent; and

a client computer, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that enable performance of actions, including:

providing the client request.

9. The system of claim 8 , wherein the plurality of mesh agents further comprises:

hosting one or more of the mesh agents on one or more network computers.

10. The system of claim 8 , wherein communicating the client request further comprises:

generating a secure tunnel over the overlay network for communication between the client and the resource server.

11. The system of claim 8 , wherein determining the credential information, further comprises:

determining an interpretation of the credential instructions based on one or more of a grammar or a ruleset based on the credential instructions and the client request;

determining one or more actions to access the credential information based on the interpretation of the credential instructions, wherein the one or more actions are executed to determine the credential information.

12. The system of claim 8 , further comprising:

determining actions on how to activate credential information to gain access to the resource server based on the credential instructions.

13. The system of claim 8 , further comprising:

determining one or more application protocols employed for communication between the client and the resource server based on network traffic; and

generating one or more application models to provide instructions for credential management for distributed services based on the one or more application protocols.

14. The system of claim 8 , further comprising:

generating one or more application models that include information for determining one or more fields to modify for injection of credential secrets in application protocol network traffic between the client and the resource server.

15. A processor readable non-transitory storage media that includes instructions for managing access to network resources over a network, wherein execution of the instructions by one or more processors on one or more network computers performs actions, comprising:

determining credential information to access a resource server based on credential instructions and a client request received by a mesh agent on an overlay network that includes a plurality of mesh agents;

communicating the client request and the credential information to the resource server via the mesh agent; and

in a response to the client request generated by the resource server, forwarding the response to the client over the overlay network via the mesh agent.

16. The processor readable non-transitory storage media of claim 15 , wherein the plurality of mesh agents further comprises:

hosting one or more of the mesh agents on one or more network computers.

17. The processor readable non-transitory storage media of claim 15 , wherein communicating the client request further comprises:

generating a secure tunnel over the overlay network for communication between the client and the resource server.

18. The processor readable non-transitory storage media of claim 15 , wherein determining the credential information, further comprises:

determining an interpretation of the credential instructions based on one or more of a grammar or a ruleset based on the credential instructions and the client request;

determining one or more actions to access the credential information based on the interpretation of the credential instructions, wherein the one or more actions are executed to determine the credential information.

19. The processor readable non-transitory storage media of claim 15 , further comprising:

determining one or more application protocols employed for communication between the client and the resource server based on network traffic; and

generating one or more application models to provide instructions for credential management for distributed services based on the one or more application protocols.

20. The processor readable non-transitory storage media of claim 15 , further comprising:

generating one or more application models that include information for determining one or more fields to modify for injection of credential secrets in application protocol network traffic between the client and the resource server.

Assignments (2)
MERGER Recorded May 26, 2026
From: STRONGDM, INC.
To: DELINEA INC.
Reel/Frame 074757/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2022
From: JONES, WILLIAM CRAIG; MCCARTHY, JUSTIN ALLAN; STEPHEN, PATRICK DAVID; TODD, EVAN MICHAEL
To: STRONGDM, INC.
Reel/Frame 062246/0587 →
Continuity (1)
Continuation 17889788 · Aug 17, 2022
Cited By (9)
US 12,242,599 US 12,284,224 US 12,348,519 US 12,355,770 US 12,423,418 US 12,432,242 US 12,603,921 US 12,670,246 US 12,695,793