IP Library › Granted Patent US 12,615,241
Granted Patent B2
US 12,615,241 · App. 18/140,205 · Granted Apr 28, 2026

Securing access to a virtual machine via a service processor using a key

Inventors: Kristian Doggett (Austin, TX); Douglas Griffith (Round Rock, TX); Walter Scott Scanlan (Edina, MN); Anil Kalavakolanu (Austin, TX); Hariganesh Muralidharan (B. Narayanapura, IN); Maisha Choudhury (Plano, TX)
Assignee: International Business Machines Corporation
H04L63/0435H04L63/0876H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,241
App. No.
18/140,205
Granted
Apr 28, 2026
Kind
B2
Abstract

A computer-implemented method, system and computer program product for securing access to a virtual machine via a service processor. A broadcasted request from a computing device of a user to establish a virtual session with the virtual machine through a service processor is received. Such a broadcasted request includes an identifier of the virtual machine as well as a key. A secure connection between the service processor and the computing device of the user is established in response to the broadcasted identifier of the virtual machine matching the identifier of the virtual machine in the service processor table. After establishing the secure connection between the service processor and the computing device of the user, a secure connection between the service processor and the virtual machine is established in response to the broadcasted key matching the key associated with the identifier of the virtual machine in the service processor table.

Claims (37)

1 . A computer-implemented method for securing access to a virtual machine, the method comprising:

receiving a broadcasted request from a computing device of a user to establish a virtual session with said virtual machine through a service processor, wherein said broadcasted request comprises an identifier of said virtual machine and a key;

establishing a secure connection between said service processor and said computing device of said user in response to matching said broadcasted identifier of said virtual machine with an identifier of said virtual machine in a table; and

establishing a secure connection between said service processor and said virtual machine in response to matching said broadcasted key with a key associated with said identifier of said virtual machine in said table.

2 . The method as recited in claim 1 further comprising:

determining if a key-value pair in firmware of said virtual machine matches said broadcasted key and said broadcasted identifier of said virtual machine, respectively, prior to or after booting of said virtual machine where said virtual machine is in a pre-operating system state.

3 . The method as recited in claim 2 further comprising:

establishing said secure connection between said service processor and said virtual machine in response to said key-value pair in said firmware of said virtual machine matching said broadcasted key and said broadcasted identifier of said virtual machine, respectively.

4 . The method as recited in claim 1 , wherein said secure connection between said service processor and said computing device of said user is established via a secure shell protocol.

5 . The method as recited in claim 1 , wherein said secure connection between said service processor and said virtual machine is established via a virtual universal asynchronous receiver-transmitter connection.

6 . The method as recited in claim 1 , wherein said broadcasted request is broadcasted via transmission control protocol/Internet protocol.

7 . The method as recited in claim 1 , wherein said broadcasted identifier of said virtual machine corresponds to a universally unique identifier.

8 . A computer program product for securing access to a virtual machine, the computer program product comprising one or more computer readable storage mediums having program code embodied therewith, the program code comprising programming instructions for:

receiving a broadcasted request from a computing device of a user to establish a virtual session with said virtual machine through a service processor, wherein said broadcasted request comprises an identifier of said virtual machine and a key;

establishing a secure connection between said service processor and said computing device of said user in response to matching said broadcasted identifier of said virtual machine with an identifier of said virtual machine in a table; and

establishing a secure connection between said service processor and said virtual machine in response to matching said broadcasted key with a key associated with said identifier of said virtual machine in said table.

9 . The computer program product as recited in claim 8 , wherein the program code further comprises the programming instructions for:

determining if a key-value pair in firmware of said virtual machine matches said broadcasted key and said broadcasted identifier of said virtual machine, respectively, prior to or after booting of said virtual machine where said virtual machine is in a pre-operating system state.

10 . The computer program product as recited in claim 9 , wherein the program code further comprises the programming instructions for:

establishing said secure connection between said service processor and said virtual machine in response to said key-value pair in said firmware of said virtual machine matching said broadcasted key and said broadcasted identifier of said virtual machine, respectively.

11 . The computer program product as recited in claim 8 , wherein said secure connection between said service processor and said computing device of said user is established via a secure shell protocol.

12 . The computer program product as recited in claim 8 , wherein said secure connection between said service processor and said virtual machine is established via a virtual universal asynchronous receiver-transmitter connection.

13 . The computer program product as recited in claim 8 , wherein said broadcasted request is broadcasted via transmission control protocol/Internet protocol.

14 . The computer program product as recited in claim 8 , wherein said broadcasted identifier of said virtual machine corresponds to a universally unique identifier.

15 . A system, comprising:

a memory for storing a computer program for securing access to a virtual machine; and

a processor connected to said memory, wherein said processor is configured to execute program instructions of the computer program comprising:

receiving a broadcasted request from a computing device of a user to establish a virtual session with said virtual machine through a service processor, wherein said broadcasted request comprises an identifier of said virtual machine and a key;

establishing a secure connection between said service processor and said computing device of said user in response to matching said broadcasted identifier of said virtual machine with an identifier of said virtual machine in a table; and

establishing a secure connection between said service processor and said virtual machine in response to matching said broadcasted key with a key associated with said identifier of said virtual machine in said table.

16 . The system as recited in claim 15 , wherein the program instructions of the computer program further comprise:

determining if a key-value pair in firmware of said virtual machine matches said broadcasted key and said broadcasted identifier of said virtual machine, respectively, prior to or after booting of said virtual machine where said virtual machine is in a pre-operating system state.

17 . The system as recited in claim 16 , wherein the program instructions of the computer program further comprise:

establishing said secure connection between said service processor and said virtual machine in response to said key-value pair in said firmware of said virtual machine matching said broadcasted key and said broadcasted identifier of said virtual machine, respectively.

18 . The system as recited in claim 15 , wherein said secure connection between said service processor and said computing device of said user is established via a secure shell protocol.

19 . The system as recited in claim 15 , wherein said secure connection between said service processor and said virtual machine is established via a virtual universal asynchronous receiver-transmitter connection.

20 . The system as recited in claim 15 , wherein said broadcasted request is broadcasted via transmission control protocol/Internet protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: DOGGETT, KRISTIAN; GRIFFITH, DOUGLAS; SCANLAN, WALTER SCOTT; KALAVAKOLANU, ANIL; MURALIDHARAN, HARIGANESH; CHOUDHURY, MAISHA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063464/0079 →
Continuity (1)
Related Publication 20240364665A1 · Oct 31, 2024
References Cited (62)
US 8607054B2 · Ramarathinam et al. · 2013 [cited by applicant]
US 8782398B2 · Mirashrafi · 2014 [cited by examiner]
US 8880882B2 · Kulkarni · 2014 [cited by examiner]
US 8977867B2 · Rangegowda et al. · 2015 [cited by applicant]
US 9130824B2 · Bhatia et al. · 2015 [cited by applicant]
US 9300640B2 · Pate · 2016 [cited by applicant]
US 9311483B2 · Kurien et al. · 2016 [cited by applicant]
US 9385997B2 · Okimoto · 2016 [cited by examiner]
US 9483639B2 · Sliwa et al. · 2016 [cited by applicant]
US 9513947B2 · Hiebert et al. · 2016 [cited by applicant]
US 9678780B2 · Singh et al. · 2017 [cited by applicant]
US 9866553B2 · Brossard et al. · 2018 [cited by applicant]
US 9880867B2 · Delco · 2018 [cited by applicant]
US 10021077B1 · Brown · 2018 [cited by examiner]
US 10686779B2 · Glozman · 2020 [cited by examiner]
US 10742403B2 · Schubert · 2020 [cited by examiner]
US 10826905B2 · Gujarathi · 2020 [cited by applicant]
US 10972452B2 · Mathaiyan et al. · 2021 [cited by applicant]
US 11038954B2 · Cochran · 2021 [cited by examiner]
US 11100209B2 · Anjali et al. · 2021 [cited by applicant]
US 11182192B2 · Heller et al. · 2021 [cited by applicant]
US 11233787B2 · Clark et al. · 2022 [cited by applicant]
US 11323274B1 · Bowen et al. · 2022 [cited by applicant]
US 11601434B1 · Hornsby et al. · 2023 [cited by applicant]
US 11843604B2 · Prunier et al. · 2023 [cited by applicant]
US 11886565B2 · Kim et al. · 2024 [cited by applicant]
US 11889314B2 · Yokum · 2024 [cited by examiner]
US 12223337B2 · Levin et al. · 2025 [cited by applicant]
US 12259958B2 · Shear et al. · 2025 [cited by applicant]
US 20090125901A1 · Swanson · 2009 [cited by applicant]
US 20100318993A1 · Goud et al. · 2010 [cited by applicant]
US 20130145179A1 · Rangegowda et al. · 2013 [cited by applicant]
US 20130179558A1 · Lin · 2013 [cited by examiner]
US 20130268757A1 · Kulkarni · 2013 [cited by examiner]
US 20130346740A1 · Mirashrafi · 2013 [cited by examiner]
US 20140059680A1 · Kurien et al. · 2014 [cited by applicant]
US 20140149492A1 · Ananthanarayanan et al. · 2014 [cited by applicant]
US 20140278623A1 · Martinez et al. · 2014 [cited by applicant]
US 20150003607A1 · Choi · 2015 [cited by examiner]
US 20150081909A1 · Cochran et al. · 2015 [cited by applicant]
US 20150318986A1 · Novak · 2015 [cited by examiner]
US 20160277372A1 · Shah · 2016 [cited by examiner]
US 20170026174A1 · Pang · 2017 [cited by examiner]
US 20170201375A1 · Amin · 2017 [cited by examiner]
US 20180159856A1 · Gujarathi · 2018 [cited by applicant]
US 20200067914A1 · Glozman · 2020 [cited by examiner]
US 20200285499A1 · Heller et al. · 2020 [cited by applicant]
US 20210034734A1 · Rohde et al. · 2021 [cited by applicant]
US 20210200864A1 · Rudnik · 2021 [cited by applicant]
US 20210226937A1 · Mathaiyan · 2021 [cited by examiner]
US 20210258265A1 · Bernat et al. · 2021 [cited by applicant]
US 20210377287A1 · Shua · 2021 [cited by applicant]
US 20220329412A1 · McGee · 2022 [cited by examiner]
US 20220345483A1 · Shua · 2022 [cited by examiner]
US 20230104368A1 · Miriyala et al. · 2023 [cited by applicant]
US 20230344716A1 · Yarvis et al. · 2023 [cited by applicant]
US 20230418651A1 · Prabhu et al. · 2023 [cited by applicant]
CA 2898908C · 2014 [cited by applicant]
CN 103605536B · 2017 [cited by applicant]
CN 104883277B · 2018 [cited by applicant]
CN 106201646B · 2020 [cited by applicant]
KR 102474989B1 · 2022 [cited by applicant]