IP Library Granted Patent US 9,489,543
Granted Patent B2
US 9,489,543 · App. 14/463,278 · Granted Nov 8, 2016

Supporting port security on power-over-Ethernet enabled ports

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,489,543
App. No.
14/463,278
Granted
Nov 8, 2016
Kind
B2
Abstract

Embodiments of the present invention include systems and methods for controlling power delivery to a port in a power sourcing equipment. The power sourcing equipment receives identity information from a device connected to the port and determines whether the device is a trusted device or a rogue device according to a security policy. If the device is a trusted device, the power sourcing equipment supplies data and electrical power to the port according to a priority policy. If the device is a rogue device, the power source equipment does not supply electrical power to the port.

Claims (39)

1. A computer-implemented method for controlling power delivery to a port in a power sourcing equipment, the method comprising:

receiving one or more indicators containing an identity from a device connected to the port via a cable for receiving data and electrical power;

determining whether the device is a rogue device or a trusted device by comparing at least one of the one or more indicators to a security policy;

responsive to a determination that the device is a rogue device, not supplying electrical power to the port to power the device via the cable but providing to the port, at least some times, a detecting electrical voltage that is insufficient to power the rogue device but is sufficient to detect that the rogue device is not connected to the port; and

responsive to a determination that the device is a trusted device, assigning a priority to the device for delivering power to the device based upon least one of the one or more indicators and a priority policy.

2. A computer-implemented method as recited in claim 1 , wherein the security policy includes one or more identities of trusted devices.

3. A computer-implemented method as recited in claim 1 , further comprising:

delivering electrical power to the port according to a priority assigned to the device.

4. A computer-implemented method as recited in claim 3 , wherein the security policy is applied on per-port level.

5. A computer-implemented method as recited in claim 1 , wherein the security policy includes one or more identities of devices to be denied by the power sourcing equipment.

6. A computer-implemented method as recited in claim 1 wherein least one of the one or more indicators comprises a priority indicator and the step of responsive to a determination that the device is a trusted device, assigning a priority to the device for delivering power to the device based upon least one of the one or more indicators and a priority policy comprises assigning a priority to the device using, at least in part, the priority indicator.

7. A computer-implemented method as recited in claim 1 further comprising:

responsive to a plurality of trusted devices being connected to the power sourcing equipment via ports for receiving data and electrical power and responsive to the power sourcing equipment not having sufficient power to power all of the plurality of trusted device connected to the power sourcing equipment, delivering power to a set of one or more trusted devices from the plurality of trusted devices according to priorities assigned to each of the trusted devices.

8. A computer-implemented method as recited in claim 7 , wherein the step of delivering power to a set of one or more trusted devices from the plurality of trusted devices according to priorities assigned to each of the trusted devices comprises:

not providing power via a port or ports associated with one or more trusted devices having the lowest priority or priorities so that sufficient power is available for the set of one or more trusted devices from the plurality of trusted devices that do receive power.

9. An information handling system of claim 8 , wherein the step of delivering power to a set of one or more trusted devices from the plurality of trusted devices according to priorities assigned to each of the trusted devices comprises:

not providing power via a port or ports associated with one or more trusted devices having the lowest priority or priorities so that sufficient power is available for the set of one or more trusted devices from the plurality of trusted devices that do receive power.

10. A computer-implemented method of claim 1 further comprising:

responsive to determining that the rogue device has disconnected from the port, causing the port to change to an authorized state in which power is available to the port.

11. An information handling system configured to control power delivery to a port in the system, the system comprising:

a controller for controlling electrical power delivery to the port; and

a security manager connected to the controller and configured to:

receive one or more indicators containing an identity from a device connected to the port via a cable for receiving data and electrical power;

determine whether the device is a rogue device or a trusted device by comparing at least one of the one or more indicators to a security policy;

responsive to a determination that the device is a rogue device, not supplying electrical power to the port to power the device via the cable but providing to the port, at least some times, a detecting electrical voltage that is insufficient to power the rogue device but is sufficient to detect that the rogue device is not connected to the port; and

responsive to a determination that the device is a trusted device, assigning a priority to the device for delivering power to the device based upon least one of the one or more indicators and a priority policy.

12. An information handling system as recited in claim 11 , wherein the security policy includes one or more identities of trusted devices.

13. An information handling system as recited in claim 11 , wherein the security manager is further configured to:

responsive to a determination that the device is a trusted device, deliver

electrical power to the port according to a priority assigned to the device.

14. An information handling system as recited in claim 13 , wherein the security policy is applied on per-port level.

15. An information handling system as recited in claim 13 , wherein the security policy is applied on per-system level.

16. An information handling system as recited in claim 11 , wherein the security policy includes one or more identities of devices to be denied by the information handling system.

17. An information handling system of claim 11 wherein least one of the one or more indicators comprises a priority indicator and the step of responsive to a determination that the device is a trusted device, assigning a priority to the device for delivering power to the device based upon least one of the one or more indicators and a priority policy comprises assigning a priority to the device using, at least in part, the priority indicator.

18. An information handling system of claim 17 , wherein the priority indicator from the device is received via one or more type-length-value (TLV) fields.

19. An information handling system of claim 11 further comprising:

responsive to a plurality of trusted devices being connected to the power sourcing equipment via ports for receiving data and electrical power and responsive to the power sourcing equipment not having sufficient power to power all of the plurality of trusted device connected to the power sourcing equipment, delivering power to a set of one or more trusted devices from the plurality of trusted devices according to priorities assigned to each of the trusted devices.

20. An information handling system of claim 11 wherein the security manager is further configured to:

responsive to determining that the rogue device has disconnected from the port, causes the controller to return the port to an authorized state in which power is available to the port.

Assignments (16)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2015
From: JINARAJ, SURESH; VENKATESAN, SHATHISH MUTHU; SHANMUGASUNDARAM, RAMAKRISHNAN; SUNDARABABU, PREMNATH
To: DELL PRODUCST L.P.
Reel/Frame 036199/0727 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2014
From: JINARAJ, SURESH; VENKATESAN, SHATHISH MATHU; SHANMUGASUNDARAM, RAMAKRISHNAN; SUNDARABABU, PREMNATH
To: DELL PRODUCTS L.P.
Reel/Frame 033566/0118 →