IP Library Granted Patent US 9,876,792
Granted Patent B2
US 9,876,792 · App. 14/528,498 · Granted Jan 23, 2018

Apparatus and method for host abstracted networked authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,876,792
App. No.
14/528,498
Granted
Jan 23, 2018
Kind
B2
Abstract

An information handling system includes a host processing system and an authentication processing system. The authentication processing system authenticates to the host processing system based upon a shared secret. An authentication module of the authentication processing system operates as a master authentication module to establish an authentication area, determine that a first device is a first trusted device of the authentication module, determine that the first device is within the authentication area, authenticate the first device on the authentication area based upon the determination that the first device is within the authentication area, determine that a second device is a second trusted device of the authentication module, determine that the second device is not within the authentication area, and prevent the second device from authenticating on the authentication area based upon the determination that the second device is not within the authentication area.

Claims (72)

1. An information handling system, comprising:

a host processing system including a processor and a shared secret, wherein the shared secret is embedded in a hardware device of the host processing system; and

an authentication processing system including a secure processor, a copy of the shared secret, and a first authenticator to execute on the secure processor stored at a storage device of the information handling system, wherein the copy of the shared secret is embedded in a hardware device of the authentication processing system;

wherein the authentication processing system authenticates to the host processing system based upon the shared secret;

wherein the first authenticator operates as a first master authenticator to:

establish a first authentication area;

determine that a first device is a first trusted slave device of the first master authenticator;

determine that the first device is within the first authentication area; and

authenticate the first device on the first authentication area based upon the determination that the first device is within the first authentication area;

determine that a second device is a second trusted slave device of the first master authenticator;

determine that the second device is not within the first authentication area;

prevent the second device from authenticating on the first authentication area based upon the determination that the second device is not within the first authentication area; and

wherein the first authenticator operates as a slave authenticator to:

determine that the information handling system is within a second authentication area of a third device; and

authenticate the information handling system on the third device based upon the determination that the information handling system is within the second authentication area.

2. The information handling system of claim 1 , wherein the first authenticator further operates as the first master authenticator to:

determine that the second device moved to within the first authentication area; and

authenticate the second device on the first authentication area based upon the determination that the second device moved to within the first authentication area.

3. The information handling system of claim 1 , wherein the first authenticator further operates as the first master authenticator to:

determine that a fourth device is not a fourth trusted device of the first authenticator;

prevent the fourth device from authenticating on the first authentication area based upon the determination that the fourth device is not a fourth trusted device of the first authenticator.

4. The information handling system of claim 1 , wherein the first authentication area is based upon a radius from the information handling system.

5. The information handling system of claim 1 , wherein the first authentication area is based upon a location relative to the information handling system.

6. The information handling system of claim 5 , wherein the location is determined based upon a location device of the information handling system.

7. The information handling system of claim 1 , wherein in authenticating the information handling system on the third device, the first authenticator further operates as the slave authenticator to authenticate the information handling system on a second master authenticator of the third device.

8. The information handling system of claim 7 , wherein the processor of the host processing system operates to:

receive secure information from the third device via an I/O device of the host processing system based upon the authentication to the second authentication area; and

send the secure information to the first device using the I/O device based upon the first device being authenticated to the first authentication area.

9. A method, comprising:

authenticating a first authentication processing system of a first information handling system to a host processing system of the first information handling system based upon a shared secret of the host processing system and a copy of the shared secret of the first authentication processing system, wherein the shared secret is embedded in a hardware device of the host processing system and the copy of the shared secret is embedded in a hardware device of the authentication processing system;

establishing, by a first master authenticator of the first authentication processing system, a first authentication area;

determining that a first device is a first trusted slave device of the first master authenticator;

determining that the first device is within the first authentication area;

authenticating, by the first master authenticator, the first device on the first authentication area based upon the determination that the first device is within the first authentication area;

determining that a second device is a second trusted slave device of the first authentication processing system;

determining that the second device is not within the first authentication area;

preventing, by the first master authenticator, the second device from authenticating on the first authentication area based upon the determination that the second device is not within the first authentication area;

determining, by a slave authenticator of the first authentication processing system, that the information handling system is within a second authentication area of a third device; and

authenticating, by the slave authenticator, the information handling system on the second authentication area based upon the determination that the information handling system is within the second authentication area.

10. The method of claim 9 , further comprising:

determining that the second device moved to within the first authentication area; and

authenticating, by the first master authenticator, the second device on the first authentication area based upon the determination that the second device moved to within the first authentication area.

11. The method of claim 9 , further comprising:

determining that a fourth device is not a third trusted device of the first authentication processing system;

preventing, by the first master authenticator, the fourth device from authenticating on the first authentication area based upon the determination that the fourth device is not a third trusted device of the first authentication processing system.

12. The method of claim 9 , wherein the first authentication area is based upon a radius from the information handling system.

13. The method of claim 9 , wherein the first authentication area is based upon a location relative to the information handling system.

14. The method of claim 13 , wherein the location is determined based upon a location device of the information handling system.

15. The method of claim 9 , wherein in authenticating the information handling system on the third device, the method further comprises:

authenticating, by the slave authenticator, the information handling system on a second master authenticator of the third device.

16. The method of claim 15 , further comprising:

receiving secure information from the third device based upon the authentication to the second authentication area; and

sending the secure information to the first device based upon the first device being authenticated to the first authentication area.

17. A non-transitory computer-readable medium including code when executed by at least one processor, causes the at least one processor to perform a method comprising:

authenticating a first authentication processing system of a first information handling system to a host processing system of the first information handling system based upon a shared secret of the host processing system and a copy of the shared secret of the first authentication processing system, wherein the shared secret is embedded in a hardware device of the host processing system and the copy of the shared secret is embedded in a hardware device of the authentication processing system;

establishing, by a first master authenticator of the host processing system, a first authentication area;

determining that a first device is a first trusted slave device of the first master authenticator;

determining that the first device is within the first authentication area;

authenticating, by the first master authenticator, the first device on the first authentication area based upon the determination that the first device is within the first authentication area;

determining that a second device is a second trusted slave device of the first authentication processing system;

determining that the second device is not within the first authentication area;

preventing, by the first master authenticator, the second device from authenticating on the first authentication area based upon the determination that the second device is not within the first authentication area;

determining, by a slave authenticator of the first authentication processing system, that the information handling system is within a second authentication area of a third device; and

authenticating, by the slave authenticator, the information handling system on the second authentication area based upon the determination that the information handling system is within the second authentication area.

18. The computer-readable medium of claim 17 , the method further comprising:

determining that the second device moved to within the first authentication area; and

authenticating the second device on the first authentication area based upon the determination that the second device moved to within the first authentication area.

19. The computer-readable medium of claim 17 , the method further comprising:

determining that a fourth device is not a third trusted device of the first authentication processing system;

preventing the fourth device from authenticating on the first authentication area based upon the determination that the fourth device is not a third trusted device of the first authentication processing system.

20. The computer-readable medium of claim 17 , wherein in authenticating the information handling system on the third device, the method further comprises:

authenticating, by the slave authenticator, the information handling system on a second master authenticator of the third device.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF REEL 034590 FRAME 0731 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0070 →
RELEASE OF REEL 034591 FRAME 0391 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040027/0719 →
RELEASE OF REEL 034590 FRAME 0696 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL PRODUCTS L.P.
Reel/Frame 040016/0964 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 034591/0391 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 034590/0696 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 10, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 034590/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2014
From: ROBISON JR., CHARLES D.; AURONGZEB, DEEDER M.; SCHUCKLE, RICHARD W.; HAMLIN, DANIEL L.
To: DELL PRODUCTS, LP
Reel/Frame 034074/0729 →