IP Library Granted Patent US 10,878,119
Granted Patent B2
US 10,878,119 · App. 16/837,625 · Granted Dec 29, 2020

Secure and temporary access to sensitive assets by virtual execution instances

Inventors: Nimrod Stoler (Zoran, IL); Lavi Lazarovitz (Petach-Tikva, IL)
Assignee: CYBERARK SOFTWARE LTD.
G06F21/6218G06F9/45558G06F11/0772G06F11/301G06F21/31G06F2009/45562G06F2009/45587G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,878,119
App. No.
16/837,625
Granted
Dec 29, 2020
Kind
B2
Abstract

Disclosed embodiments relate to systems and methods for securely provisioning sensitive data elements to virtualized execution instances. The techniques may include: identifying a request to provision a new virtualized execution instance; determining, in association with the request, that the new virtualized execution instance will require a prohibited data element in order to communicate with a target network resource; without providing the new virtualized execution instance the prohibited data element, registering the new virtualized execution instance; identifying a request from the new virtualized execution instance to communicate with the target network resource; performing a verification process for the request to communicate with the target network resource; and conditional on the verification process, provisioning the prohibited data element to the new virtualized execution instance.

Claims (33)

1. A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for securely provisioning sensitive data elements to virtualized execution instances, the operations comprising:

identifying a request to provision a new virtualized execution instance;

determining, in association with the request, that the new virtualized execution instance will require a prohibited data element in order to communicate with a target network resource, the prohibited data element being a data element not presently provisioned to the new virtualized execution instance;

without providing the new virtualized execution instance the prohibited data element required to communicate with the target network resource, registering the new virtualized execution instance;

identifying a request from the new virtualized execution instance to communicate with the target network resource;

performing a verification process for the request to communicate with the target network resource, wherein the verification process includes verifying privileged access rights associated with the new virtualized execution instance; and

in response to a determination that the request to communicate with the target network resource is verified, provisioning the prohibited data element required to communicate with the target network resource to the new virtualized execution instance.

2. The non-transitory computer readable medium of claim 1 , wherein the identifying of the request to provision the new virtualized execution instance occurs as part of monitoring requests to instantiate new virtual execution instances.

3. The non-transitory computer readable medium of claim 1 , wherein the prohibited data element is at least one of: a secret, a file, a directory, or a device.

4. The non-transitory computer readable medium of claim 1 , wherein identifying the request from the new virtualized execution instance to communicate with the target network resource includes intercepting the request.

5. The non-transitory computer readable medium of claim 1 , wherein the verification process includes authenticating the new virtualized execution instance.

6. The non-transitory computer readable medium of claim 1 , wherein provisioning the prohibited data element to the new virtualized execution instance includes mounting the prohibited data element in the new virtualized execution instance.

7. The non-transitory computer readable medium of claim 1 , wherein the prohibited data element is provisioned to the new virtualized execution instance on a just-in-time basis.

8. The non-transitory computer readable medium of claim 7 , wherein the operations further comprise applying access controls to the new virtualized execution instance while the prohibited data element is provisioned for the new virtualized execution instance.

9. The non-transitory computer readable medium of claim 7 , wherein the operations further comprise:

detecting a termination of a session between the new virtualized execution instance and the target network resource; and

automatically deprovisioning the prohibited data element for the new virtualized execution instance.

10. A computer-implemented method for securely provisioning sensitive data elements to virtualized execution instances, the method comprising:

identifying a request to provision a new virtualized execution instance;

determining, in association with the request, that the new virtualized execution instance will require a prohibited data element in order to communicate with a target network resource, the prohibited data element being a data element not presently provisioned to the new virtualized execution instance;

without providing the new virtualized execution instance the prohibited data element required to communicate with the target network resource, registering the new virtualized execution instance;

identifying a request from the new virtualized execution instance to communicate with the target network resource;

performing a verification process for the request to communicate with the target network resource, wherein the verification process includes verifying privileged access rights associated with the new virtualized execution instance; and

in response to a determination that the request to communicate with the target network resource is verified, provisioning the prohibited data element required to communicate with the target network resource to the new virtualized execution instance.

11. The computer-implemented method of claim 10 , wherein determining that the new virtualized execution instance will require the prohibited data element includes inspecting parameters of the request to provision the new virtualized execution instance.

12. The computer-implemented method of claim 10 , wherein determining that the new virtualized execution instance will require the prohibited data element includes identifying an error associated with an attempt to provision the new virtualized execution instance with the prohibited data element.

13. The computer-implemented method of claim 10 , further comprising locking a memory associated with the new virtualized execution instance while the new virtualized execution instance has access to the prohibited data element.

14. The computer-implemented method of claim 10 , further comprising prohibiting the new virtualized execution instance from entering a debugging mode while the new virtualized execution instance has access to the prohibited data element.

15. The computer-implemented method of claim 10 , further comprising blocking other processes from accessing the new virtualized execution instance while the new virtualized execution instance has access to the prohibited data element.

16. The computer-implemented method of claim 10 , wherein the identifying of the request to provision the new virtualized execution instance occurs as part of a scanning process in a virtualized network environment.

17. The computer-implemented method of claim 10 , further comprising, upon detecting a termination of a session between the new virtualized execution instance and the target network resource, unmounting the prohibited data element from the new virtualized execution instance.

18. The computer-implemented method of claim 10 , further comprising, upon detecting a termination of a session between the new virtualized execution instance and the target network resource, denying access to the prohibited data element by the new virtualized execution instance.

19. The computer-implemented method of claim 10 , further comprising monitoring and auditing activities of the new virtualized execution instance while the new virtualized execution instance has access to the prohibited data element.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2020
From: STOLER, NIMROD; LAZAROVITZ, LAVI
To: CYBERARK SOFTWARE LTD.
Reel/Frame 052287/0616 →
Continuity (3)
Continuation In Part 16451680 · Jun 25, 2019
Continuation In Part 16390542 · Apr 22, 2019
Related Publication 20200334371A1 · Oct 22, 2020