US2024007470A1PendingUtilityA1

Secure access management for tools within a secure environment

Assignee: IBMPriority: Oct 19, 2017Filed: Sep 15, 2023Published: Jan 4, 2024
Est. expiryOct 19, 2037(~11.2 yrs left)· nominal 20-yr term from priority
H04L 63/10H04L 67/06G06F 21/62G06F 21/6218H04L 63/0435H04L 63/0442H04L 63/061H04L 63/126G06F 2221/2107
73
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system and computer program product for secure access management for tools within a secure environment. A virtual file system for a user in memory on a server side in the secure environment is accessed as part of an authenticated user session including a user command instigated by a user. At the virtual file system, an encrypted file stored in the secure environment is obtained, where the file is encrypted using a public key of a user. A read operation at the virtual file system of the encrypted file is intercepted and the encrypted file is sent to a client at a user system external to the secure environment over a secure connection for decryption by a remote cryptography device of the user system using the user's private key. The decrypted file is then received at the virtual file system enabling the user to run the required user command.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for secure access management for tools within a secure environment, the method comprising:
 obtaining at a virtual file system an encrypted file stored in the secure environment;   sending the encrypted file to a client at a user system external to the secure environment over a secure connection for decryption; and   receiving the decrypted file at the virtual file system enabling a user to run a user command.   
     
     
         2 . The method as recited in  claim 1 , wherein the file holds sensitive data and is encrypted using a public key of the user. 
     
     
         3 . The method as recited in  claim 1  further comprising:
 intercepting a read operation at the virtual file system of the encrypted file. 
 
     
     
         4 . The method as recited in  claim 3  further comprising:
 receiving the user command from the user system external to the secure environment to carry out the read operation of the encrypted file, wherein the user command is directed to a server from a tool to which the command is directed. 
 
     
     
         5 . The method as recited in  claim 1 , wherein the encrypted file is sent to the client at the user system external to the secure environment over the secure connection for decryption by a remote cryptography device of the user system using the user's private key. 
     
     
         6 . The method as recited in  claim 1 , wherein the virtual file system is generated for each user session or is a central virtual file system that is user aware and is provided by a software interface for a computer operating system for creating virtual file systems in user space. 
     
     
         7 . The method as recited in  claim 1  further comprising:
 verifying access permissions of the user according to stored access permissions in the secure environment, wherein the access permissions for the encrypted file are stored and accessed in association with the encrypted file. 
 
     
     
         8 . A computer program product for secure access management for tools within a secure environment, the computer program product comprising one or more computer readable storage mediums having program code embodied therewith, the program code comprising programming instructions for:
 obtaining at a virtual file system an encrypted file stored in the secure environment;   sending the encrypted file to a client at a user system external to the secure environment over a secure connection for decryption; and   receiving the decrypted file at the virtual file system enabling a user to run a user command.   
     
     
         9 . The computer program product as recited in  claim 8 , wherein the file holds sensitive data and is encrypted using a public key of the user. 
     
     
         10 . The computer program product as recited in  claim 8 , wherein the program code further comprises the programming instructions for:
 intercepting a read operation at the virtual file system of the encrypted file.   
     
     
         11 . The computer program product as recited in  claim 10 , wherein the program code further comprises the programming instructions for:
 receiving the user command from the user system external to the secure environment to carry out the read operation of the encrypted file, wherein the user command is directed to a server from a tool to which the command is directed.   
     
     
         12 . The computer program product as recited in  claim 8 , wherein the encrypted file is sent to the client at the user system external to the secure environment over the secure connection for decryption by a remote cryptography device of the user system using the user's private key. 
     
     
         13 . The computer program product as recited in  claim 8 , wherein the virtual file system is generated for each user session or is a central virtual file system that is user aware and is provided by a software interface for a computer operating system for creating virtual file systems in user space. 
     
     
         14 . The computer program product as recited in  claim 8 , wherein the program code further comprises the programming instructions for:
 verifying access permissions of the user according to stored access permissions in the secure environment, wherein the access permissions for the encrypted file are stored and accessed in association with the encrypted file.   
     
     
         15 . A system, comprising:
 a memory for storing a computer program for secure access management for tools within a secure environment; and   a processor connected to the memory, wherein the processor is configured to execute program instructions of the computer program comprising:
 obtaining at a virtual file system an encrypted file stored in the secure environment; 
 sending the encrypted file to a client at a user system external to the secure environment over a secure connection for decryption; and 
 receiving the decrypted file at the virtual file system enabling a user to run a user command. 
   
     
     
         16 . The system as recited in  claim 15 , wherein the file holds sensitive data and is encrypted using a public key of the user. 
     
     
         17 . The system as recited in  claim 15 , wherein the program instructions of the computer program further comprise:
 intercepting a read operation at the virtual file system of the encrypted file.   
     
     
         18 . The system as recited in  claim 17 , wherein the program instructions of the computer program further comprise:
 receiving the user command from the user system external to the secure environment to carry out the read operation of the encrypted file, wherein the user command is directed to a server from a tool to which the command is directed.   
     
     
         19 . The system as recited in  claim 15 , wherein the encrypted file is sent to the client at the user system external to the secure environment over the secure connection for decryption by a remote cryptography device of the user system using the user's private key. 
     
     
         20 . The system as recited in  claim 15 , wherein the virtual file system is generated for each user session or is a central virtual file system that is user aware and is provided by a software interface for a computer operating system for creating virtual file systems in user space.

Join the waitlist — get patent alerts

Track US2024007470A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.