System and method for as needed connection escalation

US9426226B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9426226-B2
Application numberUS-201313886798-A
CountryUS
Kind codeB2
Filing dateMay 3, 2013
Priority dateMay 3, 2013
Publication dateAug 23, 2016
Grant dateAug 23, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes selecting a first connection between a connection manager and a managed system, the first connection being associated with a first privilege level, communicating by the connection manager a first command to the managed system via the first connection, determining that a second command is executable on the managed system using a connection that is associated with a second privilege level, the second privilege level being a lower privilege level than the first privilege level, selecting a second connection between the connection manager and the managed system, the second connection being associated with the second privilege level, and communicating, by the connection manager, the second command to the managed system via the second connection.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving a first command associated with a first privilege level on a managed system; selecting a first connection between a connection manager and the managed system in response to receiving the first command, the first connection being associated with the first privilege level; communicating, by the connection manager, the first command to the managed system via the first connection; receiving a second command associated with a second privilege level on the managed system, the second privilege level being a lower privilege level than the first privilege level; selecting a second connection between the connection manager and the managed system in response to receiving the second command, the second connection being associated with the second privilege level; and communicating, by the connection manager, the second command to the managed system via the second connection. 2. The method of claim 1 , further comprising: receiving a third command associated with a third privilege level on the managed system, the third privilege level being a higher privilege level than the first privilege level; selecting a third connection between the connection manager and the managed system in response to receiving the third command, the third connection being associated with the third privilege level; and communicating, by the connection manager, the third command to the managed system via the third connection. 3. The method of claim 1 , wherein: the first connection and the second connection comprise pre-established connections between the connection manager and the managed system; and in response to selecting the second connection, the method further comprises maintaining the first connection between the connection manager and the managed system. 4. The method of claim 1 , further comprising: closing the first connection in response to selecting the second connection. 5. The method of claim 1 , further comprising: providing the first command from a first plurality of commands from a first script; and evaluating, by the connection manager, the first script to determine that a first highest privilege level associated with the first plurality of commands is the first privilege level; wherein selecting the first connection is in response to evaluating the first script. 6. The method of claim 5 , further comprising: providing the second command from a second plurality of commands from a second script; and evaluating, by the connection manager, the second script to determine that a second highest privilege level associated with the second plurality of commands is the second privilege level; wherein selecting the second connection is in response to evaluating the second script. 7. The method of claim 1 , further comprising: receiving the first command from an authenticated administrator associated with the managed system; and evaluating, by the connection manager, the first command to determine that a first command privilege level associated with the first command is the first privilege level; wherein selecting the first connection is in response to evaluating the first command. 8. The method of claim 7 , further comprising: receiving the second command from the administrator; and evaluating, by the connection manager, the second command to determine that a second command privilege level associated with the second command is the second privilege level; wherein selecting the second connection is in response to evaluating the second command. 9. A connection manager for a managed network, the connection manager comprising: a memory including code; and a processor operable to execute the code to: receive a first command associated with a first privilege level on a managed system; select a first connection between the connection manager and a managed system in response to receiving the first command, the first connection being associated with a first privilege level; communicate the first command to the managed system via the first connection; receive a second command associated with a second privilege level on the managed system, the second privilege level being a lower privilege level than the first privilege level; select a second connection between the connection manager and the managed system in response to receiving the second command, the second connection being associated with the second privilege level; communicate the second command to the managed system via the second connection; and close the first connection in response to selecting the second connection. 10. The connection manager of claim 9 , the processor further operable to execute the code to: receive a third command associated with a third privilege level on the managed system, the third privilege level being a higher privilege level than the first privilege level; select a third connection between the connection manager and the managed system in response to receiving the third command, the third connection being associated with the third privilege level; and communicate the third command to the managed system via the third connection. 11. The connection manager of claim 9 , the processor further operable to execute the code to: provide the first command from a first plurality of commands from a first script; and evaluate the first script to determine that a first highest privilege level associated with the first plurality of commands is the first privilege level; wherein selecting the first connection is in response to evaluating the first script. 12. The connection manager of claim 11 , the processor further operable to execute the code to: provide the second command from a second plurality of commands from a second script; and evaluate, by the connection manager, the second script to determine that a second highest privilege level associated with the second plurality of commands is the second privilege level; wherein selecting the second connection is in response to evaluating the second script. 13. The connection manager of claim 9 , the processor further operable to execute the code to: receive the first command from an authenticated administrator associated with the managed system; and evaluate, by the connection manager, the first command to determine that a first command privilege level associated with the first command is the first privilege level; wherein selecting the first connection is in response to evaluating the first command. 14. The connection manager of claim 13 , the processor further operable to execute the code to: receive the second command from the administrator; and evaluate, by the connection manager, the second command to determine that a second command privilege level associated with the second command is the second privilege level; wherein selecting the second connection is in response to evaluating the second command. 15. A non-transitory computer-readable medium including code for performing a method, the method comprising: receiving a first command associated with a first privilege level on a managed system of a managed network; selecting a first connection between a connection manager and the managed system in response to receiving the first command, the first connection being associated with a first logged session between the connection manager and the managed system, the first logged session being at a first privilege level; communicating, by the connection manager, a first command to the managed system via the first connection; receiving a second command associated with a second privilege level on the managed s

Assignees

Inventors

Classifications

  • H04L67/141Primary

    Setup of application sessions (admission control or resource allocation in data switching networks H04L47/70) · CPC title

  • Access control lists [ACL] · CPC title

  • Multiple levels of security · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Session establishment or de-establishment · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9426226B2 cover?
A method includes selecting a first connection between a connection manager and a managed system, the first connection being associated with a first privilege level, communicating by the connection manager a first command to the managed system via the first connection, determining that a second command is executable on the managed system using a connection that is associated with a second privi…
Who is the assignee on this patent?
Dell Products Lp, Secureworks Corp
What technology area does this patent fall under?
Primary CPC classification H04L67/141. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).