IP Library Patent Application 19393161
Patent Application
App. No. 19/393,161

METHOD AND APPARATUS FOR CREDENTIAL HANDLING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/393,161
Abstract

A privilege access management (PAM) appliance can receive an access request from an accessor device via a web interface on a public IP address to access an endpoint device. The PAM appliance can establish a session via a secure connection between the accessor device and the endpoint device. The PAM appliance can inject a credential for an account to login the accessor device to the endpoint device.

Claims (34)

1 . A system, comprising:

a privilege access management (PAM) appliance comprising at least one computing device, wherein the at least one computing device is configured to:

receive an access request from an accessor device via a web interface on a public IP address to access an endpoint device;

establish a session via a secure connection between the accessor device and the endpoint device; and

inject a credential for an account to login the accessor device to the endpoint device.

2 . The system of claim 1 , wherein the endpoint device comprises an endpoint client configured to utilize an injection mechanism of the PAM appliance to inject the credential, wherein the PAM appliance is configured to host an interface to gain access to the PAM appliance for on-demand product use via the injection mechanism.

3 . The system of claim 2 , wherein the injection mechanism includes a programmatic method, a proxy-based credential injection into a protocol stream, an automatic keystroke entry, a copying of the credential information into corresponding log-in fields, or a combination thereof.

4 . The system of claim 1 , wherein the at least one computing device is further configured to receive identifying information for a set of credentials comprising the credential excluding full credentials for selection.

5 . The system of claim 1 , wherein the at least one computing device is further configured to determine a set of credentials that are available for the accessor device from a plurality of credentials, the set of credentials comprising the credential.

6 . The system of claim 5 , wherein the at least one computing device is further configured to apply a policy to the plurality of credentials to determine the set of credentials.

7 . The system of claim 5 , wherein the at least one computing device is further configured to receive a selection of the credential from the set of credentials from the accessor device.

8 . The system of claim 1 , wherein the at least one computing device is further configured to inject the credential by securely transmitting full credentials to the endpoint device.

9 . The system of claim 5 , wherein the at least one computing device is further configured to send an access console to the accessor device for remote access to the endpoint via the web interface.

10 . A method, comprising:

receiving, via a privilege access management (PAM) appliance, an access request from an accessor device via a web interface on a public IP address to access an endpoint device;

establishing, via the PAM appliance, a session via a secure connection between the accessor device and the endpoint device; and

injecting, via the PAM appliance, a credential for an account to login the accessor device to the endpoint device.

11 . The method of claim 10 , wherein the credentials are injected subsequent to the session being established by the PAM appliance.

12 . The method of claim 10 , further comprising determining, via the PAM appliance, the credential based on at least one credential selection criteria.

13 . The method of claim 12 , further comprising:

receiving, via at least one computing device, selection of the at least one credential selection criteria via a web application; and

assigning, via the at least one computing device, the at least one credential selection criteria to the endpoint.

14 . The method of claim 12 , wherein the at least one credential selection criteria is based on at least one of: a location of the endpoint, a location of the accessor, a method of access, a time of day, or a duration of the session.

15 . A non-transitory computer-readable medium embodying a program that, when executed by at least one computing device, causes the at least one computing device to:

receive an access request from an accessor device via a web interface on a public IP address to access an endpoint device;

establish a session via a secure connection between the accessor device and the endpoint device; and

inject a credential for an account to login the accessor device to the endpoint device.

16 . The non-transitory computer-readable medium of claim 15 , wherein the program further causes the at least one computing device to determine a set of credentials that are available for the accessor device from a plurality of credentials, the set of credentials comprising the credential.

17 . The non-transitory computer-readable medium of claim 16 , wherein the program further causes the at least one computing device to restrict the set of credentials based on a location of the accessor device.

18 . The non-transitory computer-readable medium of claim 15 , wherein the program further causes the at least one computing device to:

cause a user interface to be rendered comprising a set of credentials to the accessor device; and

receive a selection of one of the set of credentials from the accessor device.

19 . The non-transitory computer-readable medium of claim 15 , wherein the program further causes the at least one computing device to determine that the credential grants the accessor device access to resources of the endpoint device.

20 . The non-transitory computer-readable medium of claim 15 , wherein the session is established through the at least one computing device.