Patent · US Active

Controlling permissions for remote management of computing resources

US10771337B1 · kind B1 · utility

22Cited by
0References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 25, 2018
Grant dateSep 8, 2020
Priority date
Expiry dateNov 24, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

This disclosure describes techniques for defining a set of permissions, or privileges, for users who manage resources of a network-based service provisioned in a network-based service platform managed by a service provider. The techniques may include mapping cloud identities of the users to operating system (OS) user groups defined local to the resources that specify the set of permissions for user group members. Systems-manager agents that execute locally on the resources may determine to which OS user group the user belongs based on their cloud identity, and launch shells that are restricted by the set of permissions. Using these shells, a network-based service platform may allow users to remotely manage resources of the network-based service in various ways, such as through batch run commands and/or remote user sessions, while ensuring that the users are unable to execute commands on the resources that are outside the set of permissions.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.