IP Library Granted Patent US 8,584,210
Granted Patent B2
US 8,584,210 · App. 13/085,127 · Granted Nov 12, 2013

Multiple server access management

Inventors: Robert E. Walsh (Foster City, CA); Varun Goel (Diamond Bar, CA)
Assignee: Visa U.S.A. Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,584,210
App. No.
13/085,127
Granted
Nov 12, 2013
Kind
B2
Abstract

An access management system receives an access request for a target computer from a client computer. The access request comprises a digital certificate belonging to a user. The access management system verifies the identity of the user by validating the digital certificate. When so verified, the user receives access privileges from a policy database. The access privileges contain one or more access attributes. The access management system evaluates the access request based the one or more access attributes and grants the user access to the target computer if all the one or more access attributes are satisfied.

Claims (19)

1. A computer implemented method of establishing a Secure Shell (SSH) connection with a target server computer, the method comprising:

receiving, at the target server computer, a request message from a user at a client computer to establish the Secure Shell (SSH) connection using an account, wherein the request message is generated using a private key;

retrieving a public key of the user from an authorized key store;

using the public key of the user to decrypt the request message, wherein the account is authenticated when the request message is successfully decrypted;

obtaining source identification information for the client computer;

retrieving, from a policy database, access rules for the account, wherein the access rules comprise a set of account attributes limiting the client computer from which access is requested;

verifying the identity of the user as being authorized when the source identification information satisfies the set of account attributes limiting the client computer; and

establishing the Secure Shell (SSH) connection between the client computer and the target server computer when the user's identity is verified.

2. A non-transitory computer readable medium comprising instructions which, when executed by a computing apparatus, performs the method of claim 1 .

3. The method of claim 1 , wherein the public key and the private key are generated by an algorithm.

4. The method of claim 3 , wherein the public key and private key are mathematically linked, wherein the private key is used to encrypt a message, and the public key is used to decrypt the message.

5. The method of claim 1 , wherein the access rules for the account govern permissions for the user to access the target server computer.

6. The method of claim 1 , wherein the set of account attributes includes a table of one or more accounts or groups and one or more sources from which the one or more accounts or groups can access the target server computer.

7. The method of claim 1 , wherein the request message to establish the Secure Shell (SSH) connection is rejected when the authorized key store does not include the public key of the user.

8. The method of claim 1 , wherein the request message to establish the Secure Shell (SSH) connection is rejected when the decryption of the request message using the public key of the user fails.

9. The method of claim 1 , wherein the authorized key store is maintained by the target server computer.

10. The method of claim 1 , wherein the set of account attributes includes one or more of: user information, account or user group membership, target service type, number of access attempts, time of day, or day of week.

11. The method of claim 10 , wherein the user information includes at least a user account name.

12. The method of claim 1 , wherein verifying the identity of the user as being authorized further comprises comparing the set of account attributes to the request message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2011
From: WALSH, ROBERT E.; GOEL, VARUN
To: VISA USA INC.
Reel/Frame 026128/0350 →
Continuity (2)
Provisional Application 61323077 · Apr 12, 2010
Related Publication 20110252459A1 · Oct 13, 2011