The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 13, 2017

Filed:

Sep. 08, 2014
Applicant:

Cyber-ark Software Ltd., Petach-Tikva, IL;

Inventors:

Yair Sade, Herzlia, IL;

Roy Adar, Kiryat-Tivon, IL;

Yossi Dantes, Petach-Tikva, IL;

Tzippi Yitzhack, Ramat-Gan, IL;

Andrey Dulkin, Herzlia, IL;

Assignee:

Cyber-Ark Software Ltd., Petach-Tikva, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06Q 10/06 (2012.01);
U.S. Cl.
CPC ...
H04L 63/08 (2013.01); G06Q 10/06 (2013.01);
Abstract

A method of credential provisioning on a target service utilizes three credential sets: authentication credentials, privileged credentials and provisioned credentials. An intermediate element receives a request from a user client to establish a session with a target service. The request includes authentication credentials. The intermediate element creates provisioned credentials using privileged credentials which are authorized for creating provisioned credentials for accessing the target service. Once provisioned credentials have been created, a dual session communication channel is established between the user client and the target service. The session between the user client and intermediate element is established using the authentication credentials and the session between the intermediate element and the target service is established using the provisioned credentials. Optionally, user authorization to establish a session with the target service is determined prior to creating the provisioned credentials.


Find Patent Forward Citations

Loading…