IP Library › Granted Patent US 12,627,653
Granted Patent B2
US 12,627,653 · App. 18/404,190 · Granted May 12, 2026

Secured direct access for customer service

Inventors: Rishabh Tiwari (Bangalore, IN); Vyankatesh Sawalapurkar (Bangalore, IN); Hao Wu (Santa Clara, CA); Falak Kansal (Bangalore, IN)
Assignee: Rubrik, Inc.
H04L63/0838H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,653
App. No.
18/404,190
Granted
May 12, 2026
Kind
B2
Abstract

Methods, systems, and devices for data management are described. Authorization may be received, from a user of a customer of an operator of a first computing system, to access an instance of a first application running at the first computing system for the customer via a user account for the customer. Based on receiving the authorization, a request from a user of the operator to access a second application associated with generating a one-time credential associated with the user account may be received. The second application may run at the first computing system. Based on authenticating the user of the operator for access to the second application, the one-time credential may be provided to the user of the operator, which may use the one-time credential to gain temporary access to the instance of the first application via the user account.

Claims (54)

1 . A method, comprising:

receiving, at a first computing system that is managed by an operator and separate from a second computing system that is managed by a customer of the operator, from a user of the customer, authorization to access an instance of a first application running at the first computing system for the customer via a user account for the customer;

receiving, based at least in part on the authorization, a request from a user of the operator to access a second application associated with generating a one-time credential associated with the user account, the second application running at the first computing system;

providing, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential associated with the user account to the user of the operator; and

granting, based at least in part on the one-time credential, the user of the operator temporary access to the instance of the first application via the user account.

2 . The method of claim 1 , further comprising:

creating, prior to receiving the authorization to access the instance of the first application, a first user group that has access to the second application and a second user group that is permitted to impersonate users of the customer.

3 . The method of claim 1 , further comprising:

authenticating the user of the operator for access to the second application based at least in part on the user of the operator being included in a first user group that has access to the second application and in a second user group that is permitted to impersonate users of the customer.

4 . The method of claim 1 , further comprising:

determining, based at least in part on authenticating the user of the operator for access to the second application, permissions for accessing the instance of the first application granted to the user of the operator by the user of the customer, wherein the user of the operator is granted temporary access to the instance of the first application via the user account in accordance with the permissions.

5 . The method of claim 1 , further comprising:

generating, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential, wherein the one-time credential comprises a unique string, a time the one-time credential was issued, a time the one-time credential expires, an identifier of the user of the customer, an identifier of the user of the operator, an identifier of the authorization to access the instance of the first application, or any combination thereof.

6 . The method of claim 1 , wherein the one-time credential is formatted as a JSON web token, the method further comprising:

signing the JSON web token with a private key associated with granting users of the operator temporary access to the instance of the first application.

7 . The method of claim 1 , further comprising:

receiving, at a portal that is associated with the instance of the first application, based at least in part on providing the one-time credential to the user of the operator, the one-time credential from the user of the operator, wherein access to the portal is limited to requests originating within a network of the first computing system.

8 . The method of claim 7 , further comprising:

verifying, based at least in part on receiving the one-time credential from the user of the operator, the one-time credential; and

generating, based at least in part on verifying the one-time credential, a token associated with accessing the user account.

9 . The method of claim 8 , wherein:

the customer supports a plurality of organizations, and

the token comprises a time the token was issued, a time the token expires, an identifier of the user of the customer, an identifier of the user of the operator, an identifier of the user account, an identifier of an organization of the plurality of organizations to which the user of the customer belongs, a connection type associated with accessing the instance of the first application using the token, or any combination thereof.

10 . The method of claim 1 , further comprising:

verifying, based at least in part on receiving the one-time credential from the user of the operator, the one-time credential; and

redirecting, based at least in part on verifying the one-time credential, the user of the operator to a landing page of a user portal for the user account, a configuration of the landing page of the user portal for the user account corresponding to a configuration of a landing page of a user portal for a second user account for the customer that is associated with the user of the customer.

11 . An apparatus, comprising:

one or more memories; and

one or more processors, wherein the one or more memories store code comprising instructions executable, individually or collectively, by the one or more processors to cause the apparatus to:

receive, at a first computing system that is managed by an operator and separate from a second computing system that is managed by a customer of the operator, from a user of the customer, authorization to access an instance of a first application running at the first computing system for the customer via a user account for the customer;

receive, based at least in part on the authorization, a request from a user of the operator to access a second application associated with generating a one-time credential associated with the user account, the second application running at the first computing system;

provide, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential associated with the user account to the user of the operator; and

grant, based at least in part on the one-time credential, the user of the operator temporary access to the instance of the first application via the user account.

12 . The apparatus of claim 11 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the apparatus to:

create, prior to receiving the authorization to access the instance of the first application, a first user group that has access to the second application and a second user group that is permitted to impersonate users of the customer.

13 . The apparatus of claim 11 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the apparatus to:

authenticate the user of the operator for access to the second application based at least in part on the user of the operator being included in a first user group that has access to the second application and in a second user group that is permitted to impersonate users of the customer.

14 . The apparatus of claim 11 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the apparatus to:

determine, based at least in part on authenticating the user of the operator for access to the second application, permissions for accessing the instance of the first application granted to the user of the operator by the user of the customer, wherein the user of the operator is granted temporary access to the instance of the first application via the user account in accordance with the permissions.

15 . The apparatus of claim 11 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the apparatus to:

generate, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential, wherein the one-time credential comprises a unique string, a time the one-time credential was issued, a time the one-time credential expires, an identifier of the user of the customer, an identifier of the user of the operator, an identifier of the authorization to access the instance of the first application, or any combination thereof.

16 . A non-transitory, computer readable medium storing code that comprises instructions that are executable, individually or collectively, by one or more processors of a device to cause the device to:

receive, at a first computing system that is managed by an operator and separate from a second computing system that is managed by a customer of the operator, from a user of the customer, authorization to access an instance of a first application running at the first computing system for the customer via a user account for the customer;

receive, based at least in part on the authorization, a request from a user of the operator to access a second application associated with generating a one-time credential associated with the user account, the second application running at the first computing system;

provide, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential associated with the user account to the user of the operator; and

grant, based at least in part on the one-time credential, the user of the operator temporary access to the instance of the first application via the user account.

17 . The non-transitory, computer readable medium of claim 16 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the device to:

create, prior to receiving the authorization to access the instance of the first application, a first user group that has access to the second application and a second user group that is permitted to impersonate users of the customer.

18 . The non-transitory, computer readable medium of claim 16 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the device to:

authenticate the user of the operator for access to the second application based at least in part on the user of the operator being included in a first user group that has access to the second application and in a second user group that is permitted to impersonate users of the customer.

19 . The non-transitory, computer readable medium of claim 16 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the device to:

determine, based at least in part on authenticating the user of the operator for access to the second application, permissions for accessing the instance of the first application granted to the user of the operator by the user of the customer, wherein the user of the operator is granted temporary access to the instance of the first application via the user account in accordance with the permissions.

20 . The non-transitory, computer readable medium of claim 16 , wherein the instructions are further executable, individually or collectively, by the one or more processors to cause the device to:

generate, based at least in part on authenticating the user of the operator for access to the second application, the one-time credential, wherein the one-time credential comprises a unique string, a time the one-time credential was issued, a time the one-time credential expires, an identifier of the user of the customer, an identifier of the user of the operator, an identifier of the authorization to access the instance of the first application, or any combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2024
From: TIWARI, RISHABH; SAWALAPURKAR, VYANKATESH; WU, HAO; KANSAL, FALAK
To: RUBRIK, INC.
Reel/Frame 067059/0519 →
Continuity (1)
Related Publication 20250227105A1 · Jul 10, 2025
References Cited (10)
US 9635028B2 · Shepard · 2017 [cited by examiner]
US 11665166B2 · Dynkin et al. · 2023 [cited by applicant]
US 20130074179A1 · Das · 2013 [cited by examiner]
US 20190102162A1 · Pitre et al. · 2019 [cited by applicant]
US 20190132307A1 · Pitchaimani · 2019 [cited by examiner]
US 20200302446A1 · Kledaras et al. · 2020 [cited by applicant]
US 20220294817A1 · Parekh et al. · 2022 [cited by applicant]
US 20220353266A1 · Ramamurthi et al. · 2022 [cited by applicant]
US 20240144269A1 · Szigeti et al. · 2024 [cited by applicant]
EP 3622427B1 · 2025 [cited by examiner]