IP Library Granted Patent US 9,240,887
Granted Patent B2
US 9,240,887 · App. 14/268,863 · Granted Jan 19, 2016

Off-host authentication system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,240,887
App. No.
14/268,863
Granted
Jan 19, 2016
Kind
B2
Abstract

An off-host authentication system includes an authentication information handling system (IHS) that is coupled to a network. The off-host authentication system also includes a host processing system. An off-host processing system in the off-host authentication system is coupled to the host processing system and is coupled to the authentication IHS through the network. The off-host processing system provides an encrypted primary authentication item to the authentication IHS through the network. The off-host processing system then receives an encrypted secondary authentication token from the authentication IHS through the network. The off-host processing system then decrypts the encrypted secondary authentication token to produce a decrypted secondary authentication token and uses the decrypted secondary authentication token to retrieve a tertiary authentication token. The off-host processing system then provides the tertiary authentication token to the host processing system for use in logging a user into a user IHS that includes the host processing system.

Claims (51)

1. An off-host authentication system, comprising:

an authentication information handling system (IHS) that is coupled to a network;

a host processing system;

an off-host processing system that is coupled to the host processing system and that is coupled to the authentication IHS through the network, wherein the off-host processing system is configured to:

receive an authentication credential input from a user;

encrypt the authentication credential input to produce an encrypted authentication credential input;

provide the encrypted authentication credential input to the authentication IHS through the network;

receive an encrypted secondary authentication token from the authentication IHS through the network, wherein the encrypted secondary authentication token is sent by the authentication IHS through the network in response to decrypting the encrypted authentication credential input to retrieve the authentication credential input and validating the authentication credential input;

decrypt the encrypted secondary authentication token to produce a decrypted secondary authentication token and use the decrypted secondary authentication token to retrieve a tertiary authentication token; and

provide the tertiary authentication token to the host processing system; and

wherein at least one of the authentication IHS, the host processing system, and the off-host processing system utilizes a hardware processor.

2. The system of claim 1 , wherein the encrypted authentication credential input includes the authentication credential input that is encrypted by the off-host processing system with a user IHS private key and an authentication IHS public key, and wherein the authentication IHS is configured to decrypt the encrypted authentication credential input with an authentication IHS private key and a user IHS public key.

3. The system of claim 1 , wherein the encrypted secondary authentication token includes an authentication token that is encrypted by the authentication IHS with an authentication IHS private key and a user IHS public key, and wherein the off-host processor is configured to decrypt the encrypted secondary authentication token with an user IHS private key and an authentication IHS public key.

4. The system of claim 1 , further comprising:

a network controller system that couples the off-host processing system to the network, wherein the network controller is configured to forward the encrypted authentication credential input from the off-host processing system to the authentication IHS through the network, and wherein the network controller is configured to forward the encrypted secondary authentication token from the authentication IHS to the off-host processing system.

5. The system of claim 4 , further comprising:

an embedded controller system that couples the off-host processing system to the network controller, wherein the embedded controller system is configured to forward the encrypted authentication credential input from the off-host processing system to the network controller, and wherein the embedded controller system is configured to forward the encrypted secondary authentication token from the network controller to the off-host processing system.

6. An information handling system (IHS), comprising:

an IHS host processing system;

a network controller; and

an off-host processing system that is coupled to the IHS host processing system and the network controller, wherein the off-host processing system is configured to:

receive an authentication credential input from a user;

encrypt the authentication credential input to produce an encrypted authentication credential input;

provide the encrypted authentication credential input to an authentication IHS through the network controller, wherein the encrypted authentication credential input is configured to cause the authentication IHS to decrypt the encrypted authentication credential input to retrieve the authentication credential input, validated the authentication credential input and, in response, send an encrypted secondary authentication token to the off-host processing system through the network;

receive the encrypted secondary authentication token from the authentication IHS through the network controller;

decrypt the encrypted secondary authentication token to produce a decrypted secondary authentication token and use the decrypted secondary authentication token to retrieve a tertiary authentication token; and

provide the tertiary authentication token to the IHS host processing system; and

wherein at least one of the IHS host processing system and the off-host processing system utilizes a hardware processor.

7. The IHS of claim 6 , wherein the encrypted authentication credential input includes the authentication credential input that is encrypted by the off-host processing system with a user IHS private key and an authentication IHS public key, and wherein the authentication IHS is configured to decrypt the encrypted authentication credential input with an authentication IHS private key and a user IHS public key.

8. The IHS of claim 6 , wherein the encrypted secondary authentication token includes an authentication token that is encrypted by the authentication IHS with an authentication IHS private key and a user IHS public key, and wherein the off-host processor is configured to decrypt the encrypted secondary authentication token with an user IHS private key and an authentication IHS public key.

9. The IHS of claim 6 , further comprising:

an embedded controller system that couples the off-host processing system to the network controller, wherein the embedded controller system is configured to forward the encrypted authentication credential input from the off-host processing system to the network controller, and wherein the embedded controller system is configured to forward the encrypted secondary authentication token from the network controller to the off-host processing system.

10. The IHS of claim 6 , further comprising:

an IHS chassis, wherein the IHS host processing system and the off-host processing system are each located in the IHS chassis.

11. A method for providing off-host authentication, comprising:

receiving, by an off-host processing system, an authentication credential input from a user;

encrypting, by the off-host processing system, the authentication credential input to produce an encrypted authentication credential input;

providing, by the off-host processing system, the encrypted authentication credential input to an authentication IHS through a network;

decrypting, by the authentication IHS, the encrypted authentication credential input;

validating, by the authentication IHS, the authentication credential input and, in response, sending an encrypted secondary authentication token to the off-host processing system through the network;

receiving, by the off-host processing system, the encrypted secondary authentication token from the authentication IHS through the network;

decrypting, by the off-host processing system, the encrypted secondary authentication token to produce a decrypted secondary authentication token and using the decrypted secondary authentication token to retrieve a tertiary authentication token; and

providing, by the off-host processing system, the tertiary authentication token to a host processing system; and

wherein at least one of the off-host processing system and the authentication IHS utilizes a hardware processor.

12. The method of claim 11 , wherein the encrypted authentication credential input includes the authentication credential input that is encrypted by the off-host processing system with a user IHS private key and an authentication IHS public key, and wherein the authentication IHS decrypts the encrypted authentication credential input with an authentication IHS private key and a user IHS public key.

13. The method of claim 11 , wherein the encrypted secondary authentication token includes an authentication token that is encrypted by the authentication IHS with an authentication IHS private key and a user IHS public key, and wherein the off-host processor decrypts the encrypted secondary authentication token with an user IHS private key and an authentication IHS public key.

14. The method of claim 11 , further comprising:

forwarding, by an embedded controller system, the encrypted authentication credential input from the off-host processing system to a network controller;

forwarding, by the network controller, the encrypted authentication credential input from the embedded controller system to the authentication IHS through the network,

forwarding, by the network controller, the encrypted secondary authentication token from the authentication IHS to the embedded controller system; and

forwarding, by the embedded controller system, the encrypted secondary authentication token from the network controller to the off-host processing system.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2014
From: ROBISON, CHARLES; HAMLIN, DANIEL
To: DELL PRODUCTS LP
Reel/Frame 033158/0533 →