IP Library Granted Patent US 9,923,888
Granted Patent B2
US 9,923,888 · App. 14/874,173 · Granted Mar 20, 2018

Single sign-on method for appliance secure shell

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,923,888
App. No.
14/874,173
Granted
Mar 20, 2018
Kind
B2
Abstract

A system and method for efficiently establishing a secure shell connection for accessing Web resources. A user attempts to establish a secure Hypertext Transfer Protocol (HTTP) session between a client computing device and a remote storage device. The storage device redirects the Web browser of the client computing device to a single sign-on (SSO) third-party identity provider for authorizing the user. After successful authorization, the client computing device receives information to use to maintain a secure HTTP session. This information is stored on the storage device. The user attempts to establish a text-based secure shell session. The user is not prompted for login credentials. However, the user is authenticated using the previously stored information and a text-based secure shell session is established.

Claims (38)

1. An authentication system comprising:

a third-party identity provider (IDP) configured to authenticate a plurality of users through a series of one or more Hypertext Transfer Protocol (HTTP) redirections;

a storage device hosting an application; and

a client device configured to:

send a first request to establish a secure HTTP session with the storage device in order to access the application; and

send a second request different from the first request to establish a secure shell (SSH) session, wherein the second request comprises at least an access token generated during establishing of the secure HTTP session using the third-party IDP, wherein the access token is to be used for both verifying subsequent accesses of the application from the client device via the secure HTTP session and establishing the SSH session; and

wherein in response to receiving the second request, the storage device is configured to authorize the client device to establish the SSH session although the second request lacks a password, in further response to verifying the access token corresponds to the previously established secure HTTP session.

2. The authentication system as recited in claim 1 , wherein the storage device is further configured to send at least the access token and a client device identifier (ID) to the client device responsive to receiving from the third-party IDP an indication of successful authentication for a given user of the plurality of users on the client device requesting to access the application through a secure HTTP session.

3. The authentication system as recited in claim 2 , wherein the storage device is further configured to store each of the access token and the client device ID to use for verifying subsequent accesses of the application from the client device via the secure HTTP session.

4. The authentication system as recited in claim 3 , wherein the client device ID comprises one or more of a session cookie, an Internet Protocol (IP) address, and a media access control (MAC) address.

5. The authentication system as recited in claim 2 , wherein the second request from the client device to establish the SSH session further comprises the client device ID.

6. The authentication system as recited in claim 3 , wherein to authorize the client device to establish the SSH session, the storage device is further configured to determine whether at least the access token and the client device ID in the request matches the stored access token and the stored client device ID.

7. The authentication system as recited in claim 3 , wherein to authorize the client device to establish the SSH session, the storage device is further configured to forego any HTTP redirections.

8. The authentication system as recited in claim 3 , wherein to authorize the client device to establish the SSH session, the storage device is further configured to forego using the third-party IDP.

9. A method for executing on a processor, the method comprising:

authenticating with a third-party identity provider (IDP) a plurality of users through a series of one or more Hypertext Transfer Protocol (HTTP) redirections;

hosting an application on a storage device;

sending a first request from a client device to establish a secure HTTP session with the storage device in order to access the application;

sending a second request different from the first request from the client device to the storage device to establish a secure shell (SSH) session, wherein the second request comprises at least an access token generated during establishing of the secure HTTP session using the third-party IDP, wherein the access token is to be used for both verifying subsequent accesses of the application from the client device via the secure HTTP session and establishing the SSH session; and

authorizing the client device to establish the SSH session although the second request lacks a password, in response to verifying the access token corresponds to the previously established secure HTTP session.

10. The method as recited in claim 9 , further comprising sending at least the access token and a client device identifier (ID) to the client device responsive to receiving from the third-party IDP an indication of successful authentication for a given user of the plurality of users on the client device requesting to access the application through a secure HTTP session.

11. The method as recited in claim 10 , further comprising storing each of the access token and the client device ID in the storage device to use for verifying subsequent accesses of the application from the client device via the secure HTTP session.

12. The method as recited in claim 11 , wherein the client device ID comprises one or more of a session cookie, an Internet Protocol (IP) address, and a media access control (MAC) address.

13. The method as recited in claim 10 , wherein the second request from the client device to establish the SSH session further comprises the client device ID.

14. The method as recited in claim 11 , wherein to authorize the client device to establish the SSH session, the method further comprises determining whether at least the access token and the client device ID in the request matches the stored access token and the stored client device ID.

15. The method as recited in claim 11 , wherein to authorize the client device to establish the SSH session, the method further comprises foregoing any HTTP redirections.

16. The method as recited in claim 11 , wherein to authorize the client device to establish the SSH session, the method further comprises foregoing using the third-party IDP.

17. A storage device comprising:

a processor; and

a memory configured to:

store an application; and

store program instructions executable by the processor to:

send requests to a third-party identity provider (IDP) configured to authenticate a plurality of users through a series of one or more Hypertext Transfer Protocol (HTTP) redirections;

receive a given request from a client device to establish a secure shell (SSH) session, wherein the given request comprises at least an access token generated during establishing of a secure HTTP session for the client device using the third-party IDP, wherein the access token is to be used for both verifying subsequent accesses of the application from the client device via the secure HTTP session and establishing the SSH session; and

authorize the client device to establish the SSH session although the given request lacks a password, in further response to verifying the access token corresponds to the previously established secure HTTP session.

18. The storage device as recited in claim 17 , wherein the program instructions are further executable by the processor to send at least the access token and a client device identifier (ID) to the client device responsive to receiving from the third-party IDP an indication of successful authentication for a given user of the plurality of users on the client device requesting to access the application through a secure HTTP session.

19. The storage device as recited in claim 18 , wherein the given request from the client device to establish the SSH session further comprises the client device ID.

20. The storage device as recited in claim 18 , wherein to authorize the client device to establish the SSH session, the program instructions are further executable to determine whether at least the first access token and the client device ID in the request matches stored values of the first access token and the stored client device ID.

Assignments (13)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038483/0203 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037693/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2015
From: GOEL, VIKAS; KOETEN, ROBERT
To: SYMANTEC CORPORATION
Reel/Frame 036720/0136 →