IP Library › Granted Patent US 12,341,779
Granted Patent B2
US 12,341,779 · App. 18/380,286 · Granted Jun 24, 2025

Session-centric access control for secure ephemeral shells

Inventor: John Ezra-Razi Jawed (Sunnyvale, CA)
Assignee: eBay Inc.
H04L63/10G06F21/45H04L9/321H04L9/3263H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,779
App. No.
18/380,286
Granted
Jun 24, 2025
Kind
B2
Abstract

Technologies are shown for session centric access control of a remote connection. A request for a remote connection is received from a client. A container is created for the remote connection, and an identifier for each of one or more endpoints authorized for the remote connection are stored in the container. A secure shell is initiated for the remote connection. Access is provided to the first endpoint from the one or more endpoints via the secure shell based on a first identifier for the first endpoint being stored in the container.

Claims (43)

1. A computer-implemented method comprising:

receiving, from a client, a request for a remote connection;

creating a container for the remote connection;

storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;

initiating a secure shell for the remote connection;

receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;

determining that a first identifier for the first endpoint is stored in the container; and

based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.

2. The computer-implemented method of claim 1 , wherein the method further comprises:

storing, in the container, a certificate and a public key for the remote connection.

3. The computer-implemented method of claim 2 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.

4. The computer-implemented method of claim 1 , wherein the one or more endpoints are authorized based on a profile or a role for the client.

5. The computer-implemented method of claim 1 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.

6. The computer-implemented method of claim 1 , wherein the identifier for the first endpoint comprises a private key.

7. One or more computer storage media storing computer-useable instructions that, when used by a computing device, cause the computing device to perform operations, the operations comprising:

receiving, from a client, a request for a remote connection;

creating a container for the remote connection;

storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;

initiating a secure shell for the remote connection;

receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;

determining that a first identifier for the first endpoint is stored in the container; and

based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.

8. The one or more computer storage media of claim 7 , wherein the operations further comprise:

storing, in the container, a certificate and a public key for the remote connection.

9. The one or more computer storage media of claim 8 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.

10. The one or more computer storage media of claim 7 , wherein the one or more endpoints are authorized based on a profile or a role for the client.

11. The one or more computer storage media of claim 7 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.

12. The one or more computer storage media of claim 7 , wherein the identifier for the first endpoint comprises a private key.

13. A computer system comprising:

a processor; and

a computer storage medium storing computer-useable instructions that, when used by the processor, causes the computer system to perform operations comprising:

receiving, from a client, a request for a remote connection;

creating a container for the remote connection;

storing, in the container, an identifier for each of one or more endpoints authorized for the remote connection;

initiating a secure shell for the remote connection;

receiving, from a first endpoint, a query in response to the first endpoint receiving an access request from the client;

determining that a first identifier for the first endpoint is stored in the container; and

based on determining the first identifier for the first endpoint is stored in the container, sending a message to the first endpoint indicating that the client is authorized to access the first endpoint.

14. The computer system of claim 13 , wherein the operations further comprise:

storing, in the container, a certificate and a public key for the remote connection.

15. The computer system of claim 14 , wherein the secure shell for the remote connection is initiated using the certificate, the public key, and single use credentials.

16. The computer system of claim 13 , wherein the one or more endpoints are authorized based on a profile or a role for the client.

17. The computer system of claim 13 , wherein the one or more endpoints are authorized based on a type of task requested for the remote connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: JAWED, JOHN EZRA-RAZI
To: EBAY INC.
Reel/Frame 065231/0445 →
Continuity (2)
Continuation 17349630 · Jun 16, 2021
Related Publication 20240039917A1 · Feb 1, 2024
References Cited (9)
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10764752B1 · Avetisov · 2020 [cited by examiner]
US 11444925B1 · Patimer · 2022 [cited by examiner]
US 11824860B2 · Jawed · 2023 [cited by applicant]
US 20160119306A1 · Matthews et al. · 2016 [cited by applicant]
US 20220407856A1 · Jawed · 2022 [cited by applicant]
What are Ephemeral Certificates, https://www.ssh.com/iam/ephemeral_access/, 2020, 4 Pages. [cited by applicant]
Miller,“SSH Agent Protocol”, Internet Engineering Task Force (IETF) draftmiller-ssh-agent-04, Retrieved from internet URL: https://www.ietf.org/archive/id/draft-miller-ssh-agent-04.txt, Dec. 10, 2019, 14 Pages. [cited by applicant]
Wang et al., “Session-based Access Control in Information-Centric Networks: Design and Analyses”, https://www.semanticscholar.org/paper/Session-based-access-control-in-information-centric-Wang-Xu/cbd837363443c606d3aec48… [cited by applicant]