US2020259809A1PendingUtilityA1

Efficient centralized credential storage for remotely managed networks

Assignee: SERVICENOW INCPriority: May 4, 2017Filed: Feb 14, 2020Published: Aug 13, 2020
Est. expiryMay 4, 2037(~10.8 yrs left)· nominal 20-yr term from priority
H04L 63/083H04L 63/062G06F 21/44H04L 63/045H04L 63/10G06F 2221/2129G06F 2221/2115H04L 63/0281G06F 21/602
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An example embodiment may involve receiving, by a server device that stores a plurality of access credentials for computing devices that are disposed within a managed network, a request containing a label and an indication of an application service. The server device may be disposed within a remote network management platform that remotely manages the managed network. The example embodiment may further involve mapping, by the server device, the label and the application service to an endpoint identifier of a target computing device that is disposed within the managed network. The endpoint identifier may be associated with particular access credentials that are usable to access the application service executing on the target computing device. The example embodiment may further involve transmitting, by the server device, the endpoint identifier and the particular access credentials.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A system comprising:
 a processor;   a memory storing instructions that, when executed by the processor, cause the processor to perform operations comprising:
 receiving, from a server, a request containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within a managed network; 
 storing, in a configuration management database (CMDB), the association between the application service and the endpoint identifier; 
 determining that an access credential is required to access the application service executing on the computing device; 
 retrieving the access credential from the CMDB based on the endpoint identifier; and 
 transmitting the endpoint identifier and the access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device. 
   
     
     
         22 . The system of  claim 21 , wherein the endpoint identifier is an IP address or uniform resource locator. 
     
     
         23 . The system of  claim 21 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service. 
     
     
         24 . The system of  claim 23 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network. 
     
     
         25 . The system of  claim 21 , wherein the application service is a remote login service. 
     
     
         26 . The system of  claim 21 , wherein the access credential is obtained via an orchestration script executed on a proxy server. 
     
     
         27 . The system of  claim 26 , wherein the orchestration script is configured to automatically run on a predetermined time schedule. 
     
     
         28 . A method comprising:
 receiving, via a processor, a request from a server containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within a managed network;   storing, via a processor, the association between the application service and the endpoint identifier in a configuration management database (CMDB);   determining, via the processor, that an access credential is required to access the application service executing on the computing device;   retrieving, via the processor, the access credential from the CMDB based on the endpoint identifier; and   transmitting, via the processor, the endpoint identifier and the access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device.   
     
     
         29 . The method of  claim 28 , wherein the endpoint identifier is an IP address or uniform resource locator. 
     
     
         30 . The method of  claim 28 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service. 
     
     
         31 . The method of  claim 30 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network. 
     
     
         32 . The method of  claim 28 , wherein the application service is a remote login service. 
     
     
         33 . The method of  claim 28 , wherein the access credential is obtained via an orchestration script executed on a proxy server. 
     
     
         34 . The method of  claim 33 , orchestration script is configured to automatically run on a predetermined time schedule. 
     
     
         35 . A non-transitory computer-readable medium, having stored thereon program instructions that, upon execution by a server that is disposed within a remote network management platform that remotely manages a managed network, cause the server to perform operations comprising:
 receiving, from the server, a request containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within the managed network;   storing, in a configuration management database (CMDB), the association between the application service and the endpoint identifier;   determining that an access credential is required to access the application service executing on the computing device;   retrieving the access credential from the CMDB based on the endpoint identifier; and   transmitting the endpoint identifier and access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device.   
     
     
         36 . The non-transitory computer-readable medium of  claim 35 , wherein the endpoint identifier is an IP address or uniform resource locator. 
     
     
         37 . The non-transitory computer-readable medium of  claim 35 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service. 
     
     
         38 . The non-transitory computer-readable medium of  claim 37 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network. 
     
     
         39 . The non-transitory computer-readable medium of  claim 35 , wherein the application service is a remote login service. 
     
     
         30 . The non-transitory computer-readable medium of  claim 35 , wherein the access credential is obtained via an orchestration script executed on a proxy server.

Join the waitlist — get patent alerts

Track US2020259809A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.