IP Library › Granted Patent US 12,375,478
Granted Patent B2
US 12,375,478 · App. 17/855,887 · Granted Jul 29, 2025

Quorum-based authorization to secure sensitive cloud assets

Inventors: Wayne Reed (Kemptville, CA); Robert Burns (Gainesville, FL); Marc Boillot (Plantation, FL); Hugot Didier (Le Plessis Robinson, FR)
Assignee: THALES DIS CPL USA, INC.
H04L63/0846G06F9/547G06F21/40H04L63/107H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,478
App. No.
17/855,887
Filed
Jul 1, 2022
Granted
Jul 29, 2025
Kind
B2
Art Unit
2409
USPC
726/6
Abstract

Provided is a system and method to authenticate multiple users in order to secure sensitive cloud assets. The system comprises a user device, a service provider, and an identify provider. The service provider provides services for producing and consuming data. The identify provider authenticates and authorizes multiple authorizors for providing user access to the resources and data. A device app communicates with the service provider and identify provider. The device app polls votes and determines when a quorum approval for utilizing data is met within a constraint. It authorizes the user temporary access to the data for use by one of the services upon quorum approval, and enforces temporal and physical conditions on it. The access can be granted via a push action or a pull notification. Other embodiments are disclosed.

Claims (55)

1. A system to authenticate multiple users to secure sensitive cloud assets, the system comprising:

a Hardware Security Module (HSM) that produces or consumes data, wherein access to the HSM and the data requires multi-user authentication from multiple authorizors by way of

a service provider communicatively coupled to the HSM to provide services for the producing and consuming the data, and

an identity provider communicatively coupled to the service provider to authenticate and authorize the multiple authorizors for providing the access to the HSM;

an user device executing a device app that in response to a user requesting access to the HSM or the data:

authenticates the user and multiple authorizors,

polls votes from the multiple authorizors and determines when a quorum approval for utilizing the data is met within a constraint,

authorizes the user with a temporary access to the data for use by one of the services upon the quorum approval in accordance with temporal and physical conditions; and

enforces the temporal conditions and the physical conditions on the temporary access to the HSM;

a bridge device communicatively coupled to an in-band network and an out-of-band network connected to the HSM that transfers data there between; and

a process daemon that is configurable via the device app and controls an air-gapped switching of data between the secure in-band network and the out-of-band network responsive to the quorum approval,

wherein the HSM comprises a quorum web service Applications Programming Interface (API) to enforce quorum policy and handle quorum requests related to the quorum approval,

wherein the process daemon by way of the bridge device transfers an image from a dev-ops platform to the HSM responsive to the device app receiving the quorum approval for the user performing a code signing ceremony,

wherein the HSM securely signs the image using private keys thereon to produce a signed image during the code signing ceremony,

and thereafter, the process daemon by way of the bridge device transfers the signed image from the HSM back to the dev-ops platform;

wherein

a build server provides out-of-band resources on the out-of-band network comprising code, artifacts, audit logs, configuration files, and the image,

the dev-ops platform sourcing the image provides out-of-band services on the out-of-band network; and

the HSM hosting the code signing ceremony provides in-band resources and services on the in-band network to provide a secure computing environment with controlled ingress and egress of the image, data or artifacts.

2. The system of claim 1 , wherein the constraint comprises

a temporal constraint with a time window having a fixed start point and either an end point or duration, and

the quorum approval is achieved when a predetermined number of authorizors have been authenticated and have authorized access to data, service or the HSM requested by the user in accordance with the temporal constraint.

3. The system of claim 1 , wherein the constraint comprises

a physical constraint based on a geographic point at a precise location on the earth or within a configurable radius from a precise location on earth; and

the quorum approval is achieved when a predetermined number of authorizors have been authenticated and have authorized access to data, service or the HSM requested by the user in accordance with the physical constraint.

4. The system of claim 1 , wherein authorizing temporary access is via a push action or a pull notification.

5. The system of claim 1 , wherein the bridge device is configurable via a back-end cloud integration RESTful quorum API offered by the service provider.

6. The system of claim 1 , wherein the bridge device is configurable via a gRPC quorum API offered by the service provider.

7. The system of claim 1 , wherein the bridge device interchangeably couples the app to either of the in-band resources or the out-of-band resources indirectly via TCP/IP connection.

8. The system of claim 1 , wherein the HSM includes one among a secure console, a Key Management System (KMS), another Hardware Security Module, or other secure device.

9. A method for authenticating multiple users to secure sensitive cloud assets, by way of a device app executing on a user device, that in response to a user requesting access to a Hardware Security Module (HSM) or data within a computing environment, performs the steps of:

authenticating the user requesting access to the HSM producing or consuming the data within the computing environment, wherein access to the HSM and data requires multi-user authentication from multiple authorizors; and

authorizing the user with a temporary access to data for use by a service within the computing environment upon determining a quorum approval in accordance with temporal and physical conditions,

where the device app:

authenticates the user and the multiple authorizors,

polls votes from the multiple authorizors to determines when the quorum approval for utilizing data is met within a constraint; and

enforces the temporal conditions and physical conditions on the temporary access to the HSM,

wherein the HSM comprises a quorum web service Applications Programming Interface (API) to enforce quorum policy and handle quorum requests related to the quorum approval, that by way of

a bridge device communicatively coupled to an in-band network and an out-of-band network connected to the HSM transfers data there between, and

a process daemon that is configurable via the device app controls an air-gapped switching of data between the secure in-band network and the out-of-band network responsive to the quorum approval,

wherein the process daemon by way of the bridge device transfers an image from a dev-ops platform to the HSM responsive to the device app receiving the quorum approval for the user performing a code signing ceremony,

wherein the HSM securely signs the image using private keys thereon to produce a signed image during the code signing ceremony,

and thereafter, the process daemon by way of the bridge device transfers the signed image from the HSM back to the dev-ops platform;

wherein

a build server provides out-of-band resources on the out-of-band network comprising code, artifacts, audit logs, configuration files, and the image,

the dev-ops platform sourcing the image provides out-of-band services on the out-of-band network; and

the HSM hosting the code signing ceremony provides in-band resources and services on the in-band network to provide a secure computing environment with controlled ingress and egress of the image, data or artifacts.

10. The method of claim 9 , wherein the constraint comprises

a temporal constraint with a time window having a fixed start point and either an end point or duration,

a physical constraint based on a geographic point at a precise location on the earth or within a configurable radius from a precise location on earth; and

the quorum approval is achieved when a predetermined number of authorizors have been authenticated and have authorized access to data, service or the HSM requested by the user,

in accordance with the temporal constraint and the physical constraint.

11. The method of claim 10 , wherein the method includes

notifying, by way of the device app, the authorizors that a request for using the HSM or accessing data is pending, and

confirming a vote via a push action or a pull notification responsive to the notifying in accordance with the temporal constraint and the physical constraint.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2025
From: THALES DIS FRANCE SAS
To: THALES DIS CPL USA, INC.
Reel/Frame 071492/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2024
From: THALES DIS CPL CANADA, INC
To: THALES DIS CPL USA, INC
Reel/Frame 068809/0600 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: BURNS, ROBERT; BOILLOT, MARC
To: THALES DIS CPL USA, INC.
Reel/Frame 060791/0575 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: REED, WAYNE
To: THALES DIS CPL CANADA, INC.
Reel/Frame 060791/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2022
From: HUGOT, DIDIER
To: THALES DIS FRANCE SAS
Reel/Frame 060791/0779 →
Continuity (1)
Related Publication 20240007461A1 · Jan 4, 2024
References Cited (74)
US 5825880A · Sudia · 1998 [cited by examiner]
US 5867578A · Brickell · 1999 [cited by examiner]
US 6775668B1 · Goel · 2004 [cited by examiner]
US 7136489B1 · Madhusudhana · 2006 [cited by examiner]
US 7975288B2 · Viavant · 2011 [cited by examiner]
US 8365258B2 · Dispensa · 2013 [cited by examiner]
US 8474028B2 · Kulkarni · 2013 [cited by examiner]
US 8745379B2 · Orsini et al. · 2014 [cited by applicant]
US 9547847B2 · Ristock · 2017 [cited by examiner]
US 9785510B1 · Madhavarapu · 2017 [cited by examiner]
US 9807610B2 · Rasheed · 2017 [cited by examiner]
US 9866392B1 · Campagna · 2018 [cited by examiner]
US 10171457B2 · Moore · 2019 [cited by examiner]
US 10216949B1 · McKelvie · 2019 [cited by examiner]
US 10223184B1 · McKelvie · 2019 [cited by examiner]
US 10291622B1 · Rossman · 2019 [cited by examiner]
US 10341313B2 · Kojima · 2019 [cited by examiner]
US 10455025B2 · Burch · 2019 [cited by examiner]
US 10482231B1 · Harding · 2019 [cited by examiner]
US 10581924B2 · Gaddam et al. · 2020 [cited by applicant]
US 10606994B2 · Kurian · 2020 [cited by examiner]
US 10728038B2 · Tomlinson · 2020 [cited by examiner]
US 10771444B2 · Schiffman · 2020 [cited by examiner]
US 10834063B2 · Hancock · 2020 [cited by examiner]
US 10885220B2 · Sharma et al. · 2021 [cited by applicant]
US 10887110B2 · Wainblat · 2021 [cited by examiner]
US 10992670B1 · Drooger · 2021 [cited by examiner]
US 11019068B2 · Rossman et al. · 2021 [cited by applicant]
US 11082235B2 · Monica et al. · 2021 [cited by applicant]
US 11096052B2 · Gaudet et al. · 2021 [cited by applicant]
US 11468435B1 · Cheng · 2022 [cited by examiner]
US 11568038B1 · Kulkarni · 2023 [cited by examiner]
US 11914696B1 · Saxe · 2024 [cited by examiner]
US 20050204129A1 · Sudia · 2005 [cited by examiner]
US 20050271067A1 · King et al. · 2005 [cited by applicant]
US 20050278536A1 · Canard · 2005 [cited by examiner]
US 20060184787A1 · Sandhu · 2006 [cited by examiner]
US 20070250920A1 · Lindsay · 2007 [cited by applicant]
US 20100325441A1 · Laurie · 2010 [cited by examiner]
US 20110321131A1 · Austel · 2011 [cited by examiner]
US 20130081114A1 · Bell · 2013 [cited by examiner]
US 20130291056A1 · Gaudet · 2013 [cited by examiner]
US 20130347089A1 · Bailey · 2013 [cited by examiner]
US 20150378842A1 · Tomlinson et al. · 2015 [cited by applicant]
US 20160125412A1 · Cannon · 2016 [cited by applicant]
US 20160337344A1 · Johansson · 2016 [cited by examiner]
US 20160359838A1 · Dasgupta et al. · 2016 [cited by applicant]
US 20170054756A1 · Jones · 2017 [cited by examiner]
US 20170118025A1 · Shastri · 2017 [cited by examiner]
US 20170142579A1 · Gaudet et al. · 2017 [cited by applicant]
US 20170264430A1 · Robertson · 2017 [cited by examiner]
US 20170366556A1 · Pemmaraju · 2017 [cited by examiner]
US 20190036934A1 · Pitchaimani · 2019 [cited by examiner]
US 20190268165A1 · Monica et al. · 2019 [cited by applicant]
US 20190058700A1 · Kurian · 2019 [cited by examiner]
US 20190068563A1 · Kurian · 2019 [cited by examiner]
US 20190079504A1 · Wu · 2019 [cited by examiner]
US 20190147152A1 · Kurian · 2019 [cited by examiner]
US 20190173853A1 · Hasek et al. · 2019 [cited by applicant]
US 20190266576A1 · McCauley · 2019 [cited by examiner]
US 20190268342A1 · Rossman · 2019 [cited by examiner]
US 20190312858A1 · Johansson · 2019 [cited by examiner]
US 20200066072A1 · Galvez · 2020 [cited by examiner]
US 20200196145A1 · Gaudet et al. · 2020 [cited by applicant]
US 20210409217A1 · Maley · 2021 [cited by examiner]
US 20210409945A1 · Gaudet · 2021 [cited by examiner]
US 20220166605A1 · Suurkivi et al. · 2022 [cited by applicant]
US 20220198043A1 · Kozlowski · 2022 [cited by examiner]
US 20220200990A1 · Madej · 2022 [cited by examiner]
US 20220231861A1 · Maley · 2022 [cited by examiner]
US 20230328106A1 · Johnson · 2023 [cited by examiner]
US 20230328107A1 · Johnson · 2023 [cited by examiner]
EP 3429156A1 · 2019 [cited by applicant]
International Search Report (PCT/ISA/2010) & Written Opinion (PCT/ISA/237) mailed by ISA/EP on Sep. 27, 2023 for corresponding International Application pursuant to the PCT, NºPCT/US2023/025930 (14 pages). [cited by applicant]