IP Library Granted Patent US 9,256,725
Granted Patent B2
US 9,256,725 · App. 14/190,195 · Granted Feb 9, 2016

Credential recovery with the assistance of trusted entities

Inventors: Alina Oprea (Arlington, MA); Kevin D. Bowers (Melrose, MA); Nikolaos Triandopoulos (Arlington, MA); Ting-Fang Yen (Cambridge, MA); Ari Juels (Brookline, MA)
Assignee: EMC Corporation
G06F21/445G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,256,725
App. No.
14/190,195
Filed
Feb 26, 2014
Granted
Feb 9, 2016
Kind
B2
Art Unit
2436
USPC
726/1
Abstract

There is disclosed a method for use in credential recovery. In one exemplary embodiment, the method comprises determining a policy that requires at least one trusted entity to verify the identity of a first entity in order to facilitate credential recovery. The method also comprises receiving at least one communication that confirms verification of the identity of the first entity by at least one trusted entity. The method further comprises permitting credential recovery based on the received verification.

Claims (42)

1. A computer-implemented method, comprising:

determining a policy that requires at least one trusted entity to verify the identity of a first entity in order to facilitate credential recovery, wherein the determined policy describes the number of trusted entities that are required to verify the identity of the first entity;

receiving at least one communication that confirms verification of the identity of the first entity by at least one trusted entity; and

based on the received verification, permitting credential recovery.

2. The method as claimed in claim 1 , wherein permitting credential recovery comprises providing a credential to the first entity.

3. The method as claimed in claim 2 , wherein the provided credential is one of similar, different, or a derivative of an original credential that is currently unavailable to the first entity.

4. The method as claimed in claim 2 , wherein the provided credential is one of a password, a PIN, or a cryptographic key.

5. The method as claimed in claim 1 , wherein permitting credential recovery comprises providing an opportunity to the first entity for facilitating generation of a credential.

6. The method as claimed in claim 1 , wherein receiving at least one communication comprises receiving at least one communication from at least one trusted entity confirming verification of the identity of the first entity by the at least one trusted entity.

7. The method as claimed in claim 1 , wherein receiving at least one communication comprises receiving a communication from the first entity confirming verification of the identity of the first entity by at least one trusted entity.

8. The method as claimed in claim 1 , wherein receiving at least one communication comprises receiving at least one communication that confirms verification of a biometric characteristic of the first entity by at least one trusted entity.

9. The method as claimed in claim 1 , further comprising:

obtaining information in connection with at least one trusted entity that is suitable for use in confirming that at least one trusted entity verified the identity of the first entity.

10. The method as claimed in claim 9 , wherein the information is obtained from one of the first entity, an employee chart, or a social network.

11. The method as claimed in claim 1 , wherein determining a policy comprises dynamically determining a policy from a set of policies that requires at least one trusted entity to verify the identity of the first entity in order to facilitate credential recovery.

12. The method as claimed in claim 11 , wherein the policy is determined from the set of policies based on at least one factor associated with the first entity.

13. The method as claimed in claim 11 , wherein the policy is determined from the set of policies based on the current location associated with the first entity.

14. The method as claimed in claim 1 , further comprising:

in response to receiving at least one communication that confirms verification of the identity of the first entity by at least one trusted entity, determining whether the requirements of the determined policy have been satisfied; and

in response to determining that the requirements of the determined policy have been satisfied, permitting credential recovery.

15. The method as claimed in claim 1 , further comprising:

based on at least one factor associated with the first entity, determining access rights; and

based on permitting credential recovery, granting the access rights to first entity.

16. The method as claimed in claim 15 , wherein the access rights are one of full access rights or restricted access rights.

17. A non-transitory processor-readable storage medium having embodied therein one or more software programs, wherein the one or more software programs when executed by a processor cause the processor to implement the steps of the method of:

determining a policy that requires at least one trusted entity to verify the identity of a first entity in order to facilitate credential recovery, wherein the determined policy describes the number of trusted entities that are required to verify the identity of the first entity;

receiving at least one communication that confirms verification of the identity of the first entity by at least one trusted entity; and

based on the received verification, permitting credential recovery.

18. An apparatus, comprising:

at least one processing device, said at least one processing device comprising a processor coupled to a memory;

wherein the apparatus is configured to:

determine a policy that requires at least one trusted entity to verify the identity of a first entity in order to facilitate credential recovery, wherein the determined policy describes the number of trusted entities that are required to verify the identity of the first entity;

receive at least one communication that confirms verification of the identity of the first entity by at least one trusted entity; and

based on the received verification, permit credential recovery.

19. A system, comprising:

a first processing device associated with a first entity;

a second processing device associated with a trusted entity; and

a server configured for communication with at least one of the first and second processing devices over a network;

wherein the server is configured to:

determine a policy that requires at least one trusted entity to verify the identity of the first entity in order to facilitate credential recovery, wherein the determined policy describes the number of trusted entities that are required to verify the identity of the first entity;

receive at least one communication that confirms verification of the identity of the first entity by at least one trusted entity; and

based on the received verification, permit credential recovery.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2014
From: OPREA, ALINA; BOWERS, KEVIN D.; TRIANDOPOULOS, NIKOLAOS; YEN, TING-FANG
To: EMC CORPORATION
Reel/Frame 032298/0858 →
Continuity (1)
Related Publication 20150242616A1 · Aug 27, 2015