IP Library Granted Patent US 9,819,661
Granted Patent B2
US 9,819,661 · App. 14/025,560 · Granted Nov 14, 2017

Method of authorizing an operation to be performed on a targeted computing device

Inventor: Allon Joseph Stern (Leesburg, VA)
Assignee: THE BOEING COMPANY
H04L63/06G06F21/305G06F21/335
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,819,661
App. No.
14/025,560
Granted
Nov 14, 2017
Kind
B2
Abstract

A method of authorizing an operation to be performed on a targeted computing device is provided. The method includes generating a request to perform an operation on the targeted computing device, signing the request with a private key of a first private, public key pair, transmitting the request to an authentication server, receiving an authorization response from the authentication server that includes the request and an authorization token, and transmitting the authorization response to the targeted computing device.

Claims (29)

1. A method of requesting an operation be performed on a targeted computing device, said method comprising:

generating a request to perform the operation on the targeted computing device, the request including a geographic location of the targeted computing device, the operation to be performed on the targeted computing device, and a time period in which the operation will be performed;

signing the request with a private key of a first private, public key pair;

transmitting the request to an authentication server;

receiving, in response to the request, an authorization response from the authentication server that includes the request and an authorization token, wherein the authorization token includes at least one of a predetermined authorization period, an authorization to perform the operation on a predetermined targeted computing device, and an authorization to perform predetermined operations on the targeted computing device; and

transmitting the authorization response to the targeted computing device.

2. The method in accordance with claim 1 , wherein generating a request comprises generating the request to further include an identification of the targeted computing device.

3. The method in accordance with claim 1 further comprising verifying the authorization response with a public key of a second private, public key pair, wherein the authorization response is signed with a private key of the second private, public key pair.

4. The method in accordance with claim 3 , wherein transmitting the authorization response comprises transmitting the authorization response upon verification of the authorization response with the public key of the second private, public key pair.

5. The method in accordance with claim 1 further comprising signing the authorization response with the private key of the first private, public key pair.

6. The method in accordance with claim 1 , wherein receiving the authorization response comprises determining whether the authorization token authorizes the operation requested to be performed on the targeted computing device.

7. The method in accordance with claim 1 , wherein transmitting the request comprises transmitting the request to the authentication server via a removable media.

8. A method of authorizing an operation to be performed on a targeted computing device, said method comprising:

receiving, at an authentication server, a request from a requesting device to perform the operation on the targeted computing device, the request including parameters that include a geographic location of the targeted computing device, the operation to be performed on the targeted computing device, and a time period in which the operation will be performed;

verifying, at the authentication server, the request with a public key of a first private, public key pair, wherein the request is signed by a private key of the first private, public key pair;

forming, at the authentication server in response to the request, an authorization response that includes the request and an authorization token, wherein the authorization token includes at least one of a predetermined authorization period, an authorization to perform the operation on a predetermined targeted computing device, and an authorization to perform predetermined operations on the targeted computing device; and

transmitting, at the authentication server, the authorization response to the requesting device.

9. The method in accordance with claim 8 further comprising determining whether to grant the request based on the parameters and a security policy for the targeted computing device.

10. The method in accordance with claim 9 , wherein determining whether to grant the request comprises determining whether the parameters for the operation to be performed align with the security policy for the targeted computing device.

11. The method in accordance with claim 8 further comprising creating the authorization token either prior to receiving the request to perform the operation on the targeted computing device or in response to verification of the request to perform the operation on the targeted computing device.

12. The method in accordance with claim 8 further comprising signing the authorization response with a private key of a second private, public key pair.

13. The method in accordance with claim 8 , wherein transmitting the authorization response comprises transmitting the authorization response to the requesting device via a removable media.

14. The method in accordance with claim 8 , wherein receiving a request comprises receiving the request wherein the parameters further include an identification of the targeted computing device.

15. A method of carrying out an operation on a targeted computing device, said method comprising:

receiving, at a requesting device, an authorization response from an authorization server, the authorization response including a request to perform the operation on the targeted computing device, including parameters that include a geographic location of the targeted computing device, the operation to be performed on the targeted computing device, a time period in which the operation will be performed, and an authorization token, the authorization response generated by the authorization server in response to the request, wherein the authorization token includes at least one of a predetermined authorization period, an authorization to perform the operation on a predetermined targeted computing device, and an authorization to perform predetermined operations on the targeted computing device;

verifying, at the requesting device, the authorization response with a public key of a private, public key pair, wherein the authorization response is signed by a private key of the private, public key pair; and

granting, at the requesting device, authorization to perform the operation upon verification of the authorization response.

16. The method in accordance with claim 15 , wherein receiving an authorization response comprises receiving the authorization response including the request, wherein the parameters additionally include an identification of the targeted computing device.

17. The method in accordance with claim 15 , wherein verifying the authorization response comprises determining whether the parameters for the operation to be performed align with a security policy for the targeted computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2013
From: STERN, ALLON JOSEPH
To: THE BOEING COMPANY
Reel/Frame 031223/0843 →
Continuity (1)
Related Publication 20150074764A1 · Mar 12, 2015