IP Library Granted Patent US 12,603,890
Granted Patent B2
US 12,603,890 · App. 18/539,881 · Granted Apr 14, 2026

Method for sensitive infrastructure protection

Inventors: Arn Hyndman (Ottawa, CA); Nicholas Sauriol (Ottawa, CA)
Assignee: International Business Machines Corporation
H04L63/102G06F8/77H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,890
App. No.
18/539,881
Granted
Apr 14, 2026
Kind
B2
Abstract

Managing access to computing environments is provided. A number of infrastructure as code (IAC) configurations are configured, wherein the IAC configurations are related to a same project. The IAC configurations are grouped into a number of environments, wherein the environments represent project stages or deployment situations, and wherein the environments have respective access privileges and allowed modifications for the respective IAC configurations within each environment. A number of user trusted profiles are automatically created that are linked to the access privileges and allowed modifications for the environments, wherein each trusted profile is specific to one of the environments. Modification are be deployed in an environment only after those modifications have been successfully deployed in a prerequisite environment.

Claims (39)

1 . A computer-implemented method of managing access to computing environments, the method comprising:

using a number of processors to perform:

configuring a number of infrastructure as code (IAC) configurations, wherein the IAC configurations are related to a same project;

grouping the IAC configurations into a number of environments, wherein the environments represent project stages or deployment situations, and wherein the environments have respective access privileges and allowed modifications for the respective IAC configurations within each environment, and wherein the IAC configuration has no prerequisite environment, or the IAC configuration has been successfully deployed in a prerequisite environment; and

automatically creating a number of user trusted profiles that are linked to the access privileges and allowed modifications for the environments, wherein each trusted profile is specific to one of the environments.

2 . The method of claim 1 , wherein a modification cannot be deployed in an environment unless that modification has been successfully deployed in a prerequisite environment.

3 . The method of claim 1 , further comprising searching all IAC configurations in a prerequisite environment for a match of a target IAC configuration version with a successful deployment.

4 . The method of claim 1 , wherein the project development stages comprise at least one of:

development;

testing; or

production.

5 . The method of claim 1 , wherein the access privileges specify session time duration limits.

6 . The method of claim 1 , wherein the access privileges limit access to the specific environment to which access privileges and allowed modifications are linked.

7 . The method of claim 1 , wherein a deployment of the IAC configuration to a selected environment is denied unless a user has assumed a trusted profile corresponding to the selected environment prior to the deployment.

8 . A system for managing access to computing environments, the system comprising:

a storage device that stores program instructions;

one or more processors operably connected to the storage device and configured to execute the program instructions to cause the system to:

configure a number of infrastructure as code (IAC) configurations, wherein the IAC configurations are related to a same project;

group the IAC configurations into a number of environments, wherein the environments represent project stages or deployment situations, and wherein the environments have respective access privileges and allowed modifications for the respective IAC configurations within each environment, and wherein the IAC configuration has no prerequisite environment, or the IAC configuration has been successfully deployed in a prerequisite environment; and

automatically create a number of user trusted profiles that are linked to the access privileges and allowed modifications for the environments, wherein each trusted profile is specific to one of the environments.

9 . The system of claim 8 , wherein a modification cannot be deployed in an environment unless that modification has been successfully deployed in a prerequisite environment.

10 . The system of claim 8 , wherein the program instructions further cause the system to search all IAC configurations in a prerequisite environment for a match of a target IAC configuration version with a successful deployment.

11 . The system of claim 8 , wherein the project development stages comprise at least one of:

development;

testing; or

production.

12 . The system of claim 8 , wherein the access privileges specify session time duration limits.

13 . The system of claim 8 , wherein the access privileges limit access to the specific environment to which access privileges and allowed modifications are linked.

14 . The system of claim 8 , wherein a deployment of the IAC configuration to a selected environment is denied unless a user has assumed a trusted profile corresponding to the selected environment prior to the deployment.

15 . A computer program product for managing access to computing environments, the computer program product comprising:

a computer readable storage medium having program instructions configured to cause one or more processors to:

configure a number of infrastructure as code (IAC) configurations, wherein the IAC configurations are related to a same project;

group the IAC configurations into a number of environments, wherein the environments represent project stages or deployment situations, and wherein the environments have respective access privileges and allowed modifications for the respective IAC configurations within each environment, and wherein the IAC configuration has no prerequisite environment, or the IAC configuration has been successfully deployed in a prerequisite environment; and

automatically create a number of user trusted profiles that are linked to the access privileges and allowed modifications for the environments, wherein each trusted profile is specific to one of the environments.

16 . The computer program product of claim 15 , wherein a modification cannot be deployed in an environment unless that modification has been successfully deployed in a prerequisite environment.

17 . The computer program product of claim 15 , further comprising instructions for searching all IAC configurations in a prerequisite environment for a match of a target IAC configuration version with a successful deployment.

18 . The computer program product of claim 15 , wherein the access privileges specify session time duration limits.

19 . The computer program product of claim 15 , wherein the access privileges limit access to the specific environment to which access privileges and allowed modifications are linked.

20 . The computer program product of claim 15 , wherein a deployment of the IAC configuration to a selected environment is denied unless a user has assumed a trusted profile corresponding to the selected environment prior to the deployment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2023
From: HYNDMAN, ARN; SAURIOL, NICHOLAS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065871/0637 →
Continuity (1)
Related Publication 20250202901A1 · Jun 19, 2025
References Cited (20)
US 11372626B2 · White et al. · 2022 [cited by applicant]
US 11550567B2 · Copty et al. · 2023 [cited by applicant]
US 11770398B1 · Erlingsson et al. · 2023 [cited by applicant]
US 11785104B2 · Erlingsson et al. · 2023 [cited by applicant]
US 12445495B2 · Hyndman · 2025 [cited by applicant]
US 12461738B1 · Christensen · 2025 [cited by examiner]
US 20220200869A1 · Erlingsson · 2022 [cited by examiner]
US 20220222354A1 · Agarwwal · 2022 [cited by applicant]
US 20220272163A1 · Schuller et al. · 2022 [cited by applicant]
US 20230036145A1 · Ramachandran · 2023 [cited by examiner]
US 20230161614A1 · Herzberg et al. · 2023 [cited by applicant]
US 20250030722A1 · Ragula · 2025 [cited by examiner]
US 20250047709A1 · Arla · 2025 [cited by examiner]
Anonymous, “Fully Decentralized Cloud using Generalized Trusted Execution Environments and Distributed Hash Tables (Without Blockchain),” Feb. 5, 2021, 7 pages, ip.com, accessed on Nov. 30, 2023, https://ip.com/IPCOM/00… [cited by applicant]
Anonymous, “Infrastructure as Code for automated self service AWS environments,” 21 pages, AWS Marketplace, DevOps Institute, accessed on Nov. 20, 2023, https://pages.awscloud.com/rs/112-TZM-766/images/Infrastructure-as… [cited by applicant]
Anonymous, “Method and system for protection of sensitive data in infrastructure management services,” Jul. 28, 2015, 11 pages, ip.com, accessed on Nov. 30, 2023, https://ip.com/IPCOM/000242582. [cited by applicant]
Dahir et al, “Dynamic Trust and Risk Scoring Using Last-Known-Profile Learning,” Cisco Systems, Inc., Aug. 31, 2016, 13 pages, ip.com, accessed on Dec. 1, 2023, https://www.researchgate.net/publication/374754529_DYNAMIC… [cited by applicant]
Joseph et al., “Infrastructure As Code,” 2021, 11 pages, Dell Inc., accessed on Nov. 22, 2023, https://education.dell.com/content/dam/dell-emc/documents/en-us/2021KS_Joseph-Infrastructure_as_Code.pdf. [cited by applicant]
Klein et al., “Infrastructure as Code-Final Report,” Dec. 2018, 19 pages, Carnegie Mellon University Software Engineering Institute, Pittsburgh, accessed on Nov. 22, 2023, https://insights.sei.cmu.edu/library/infrastruc… [cited by applicant]
Prisma Cloud, “The DevSecGuide to Infrastructure as Code,” Bridgecrew by Prisma Cloud, 2021, 12 pages, Palo Alto Networks, accessed on Nov. 20, 2023, https://bridgecrew.io/wp-content/uploads/devsecguide-iac-security.pdf. [cited by applicant]