IP Library Granted Patent US 9,240,988
Granted Patent B1
US 9,240,988 · App. 14/038,929 · Granted Jan 19, 2016

Computer system employing dual-band authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,240,988
App. No.
14/038,929
Granted
Jan 19, 2016
Kind
B1
Abstract

A first machine (e.g., server VM) authenticates an untrusted second machine (e.g., new client VM) as a condition to performing or allowing a protected operation. Authentication information is written to a library using one mechanism, and then read from the library using another mechanism. One of the mechanisms is an untrusted mechanism employing the untrusted second machine, while the other is a trusted mechanism performed by the first machine either alone or in combination with a trusted management component that has privileged access to the library. If a written and read value match, it can be inferred that the second machine is authentic, because the trusted management component has accessed an existing library that is also separately accessed by the second machine.

Claims (49)

1. A method by which a first machine authenticates an untrusted second machine as a condition to performing or allowing a protected operation for the second machine, comprising:

by the first machine, performing a write operation relating to a library of one of the first machine and the second machine and including an authentication identifier to be stored by the library;

subsequently by the first machine, performing a read operation relating to the library and returning a read value, wherein the read operation using either an untrusted mechanism employing the second machine or a trusted mechanism employing the first machine alone or in combination with a trusted management component having privileged system-level access to the library, wherein the write operation using the trusted mechanism if and only if the read operation uses the untrusted mechanism, or the write operation using the untrusted mechanism if and only if the read operation uses the trusted mechanism; and

by the first machine, performing or allowing the protected operation for the second machine only upon the read value returned by the read operation matching the authentication identifier, wherein the first and second machines are virtual machines executing on one or more physical host machines, and wherein the management component is included in a set of virtual machine management components having a pre-established trust relationship with one of the virtual machines.

2. A method according to claim 1 , wherein:

the second machine has access to the library;

the trusted mechanism includes a first communication path by which the first machine requests that the management component exercise privileged system-level access to the library; and

the untrusted mechanism includes a second communication path by which the first machine requests that the second machine exercise access to the library.

3. A method according to 2 , wherein:

the trusted mechanism is the write mechanism; and

the untrusted mechanism is the read mechanism.

4. A method according to 2 , wherein:

the trusted mechanism is the read mechanism; and

the untrusted mechanism is the write mechanism.

5. A method according to claim 2 , wherein the first machine is a service providing machine having an account by which the first machine is known to the management component.

6. A method according to claim 1 , wherein:

the first machine has access to the library;

the trusted mechanism includes a local library operation on the library by the first machine; and

the untrusted mechanism includes first and second communication paths, the first communication path used by the first machine to send a library operation request to the second machine, the second communication path used by the second machine to send a request to the management component to exercise the privileged system-level access to the library.

7. A method according to 6 , wherein:

the trusted mechanism is the write mechanism; and

the untrusted mechanism is the read mechanism.

8. A method according to 6 , wherein:

the trusted mechanism is the read mechanism; and

the untrusted mechanism is the write mechanism.

9. A method according to claim 1 , wherein one of the first and second machines is a client machine, and the other of the first and second machines is a server machine.

10. A method according to claim 1 , wherein the first and second machines are virtual machines executing on one or more physical host machines, and wherein the management component is included in a set of virtual machine management components having a pre-established trust relationship with one of the virtual machines.

11. A method according to claim 10 , wherein the first machine is server virtual machine, and the second machine is a client virtual machine.

12. A method according to claim 10 , wherein an unsuccessful response in the second operation includes an indication that a virtual machine identified in the second operation does not exist.

13. A computer, comprising:

instruction processing circuitry;

memory;

input/output circuitry; and

one or more data buses interconnecting the instruction processing circuitry, memory and input/output circuitry together for data transfer therebetween;

wherein the memory includes instructions executable by the instruction processing circuitry to cause the computer to function as a first machine performing a method of authenticating an untrusted second machine as a condition to performing or allowing a protected operation for the second machine, the method including:

performing a write operation relating to a library of one of the first machine and the second machine and including an authentication identifier to be stored by the library;

performing a read operation relating to the library and returning a read value, wherein the read operation using either an untrusted mechanism employing the second machine or a trusted mechanism employing the first machine alone or in combination with a trusted management component having privileged system-level access to the library, wherein the write operation using the trusted mechanism if and only if the read operation uses the untrusted mechanism, or the write operation using the untrusted mechanism if and only if the read operation uses the trusted mechanism; and

performing or allowing the protected operation for the second machine only upon the read value returned by the read operation matching the authentication identifier, wherein the computer being one of one or more physical host machines hosting the first and second machines as virtual machines, and wherein the management component is included in a set of virtual machine management components having a pre-established trust relationship with one of the virtual machines.

14. A computer according to claim 13 , wherein:

the second machine has access to the library;

the trusted mechanism includes a first communication path by which the first machine requests that the management component exercise privileged system-level access to the library; and

the untrusted mechanism includes a second communication path by which the first machine requests that the second machine exercise access to the library.

15. A computer according to claim 14 , wherein the first machine is a service providing machine having an account by which the first machine is known to the management component.

16. A computer according to claim 13 , wherein:

the first machine has access to the library;

the trusted mechanism includes a local library operation on the library by the first machine; and

the untrusted mechanism includes first and second communication paths, the first communication path used by the first machine to send a library operation request to the second machine, the second communication path used by the second machine to send a request to the management component to exercise the privileged system-level access to the library.

17. A computer according to claim 13 , being one of one or more physical host machines hosting the first and second machines as virtual machines, wherein the management component is included in a set of virtual machine management components having a pre-established trust relationship with one of the virtual machines.

18. A computer according to claim 17 , wherein the first machine is server virtual machine, and the second machine is a client virtual machine.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2013
From: ROBINSON, PETER A.
To: EMC CORPORATION
Reel/Frame 031295/0766 →