IP Library Granted Patent US 10,552,590
Granted Patent B2
US 10,552,590 · App. 14/994,735 · Granted Feb 4, 2020

System and method for providing an authentication agent in a persistent authentication framework

Inventors: Daniel Hamlin (Round Rock, TX); Charles D. Robison, Jr. (Buford, GA); Carrie Elaine Gates (Livermore, CA)
Assignee: Dell Products, LP
G06F21/31G06F21/316G06F21/34H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,552,590
App. No.
14/994,735
Granted
Feb 4, 2020
Kind
B2
Abstract

An authentication agent for an information handling system includes a request module, a threshold table, and a comparison module. The request module receives a first request to access a secure resource of the information handling system, determines a first access level associated with the first request, and requests first confidence level information from the information handling system. The threshold table includes a first confidence threshold associated with the first access level. The comparison module compares the first confidence level information with the first confidence threshold. The authentication agent grants access to the secure resource at the first access level when the first confidence level information is greater than the first confidence threshold.

Claims (63)

1. A computing device of an authentication agent for an information handling system, the computing device comprising:

a hardware processor;

a request module that receives a first request by a user to access a secure resource of the information handling system, determines a first access level of the user associated with the first request, and requests first confidence level information from the information handling system, the first confidence level information including a confidence score for the information handling system, a confidence level associated with the confidence score, and confidence score meta-data that includes a time stamp associated with a time that a first input device received a first authentication information and includes information as to a source of the first request, wherein the confidence score is decreased exponentially over a period of inactivity during which no additional input is provided by the user to the information handling system, the period of inactivity occurring after successfully providing the first authentication information to increase the confidence score;

a threshold table that includes a first confidence threshold associated with the first access level;

a comparison module that compares the first confidence level information with the first confidence threshold; and

a time base that determines that an assurance event has occurred within a time limit, based upon the confidence score meta-data;

the authentication agent grants access to the secure resource at the first access level when the first confidence level information is greater than the first confidence threshold, and when the assurance event has occurred within the time limit.

2. The computing device of claim 1 , the authentication agent further denies access to the secure resource at the first access level when the first confidence level information is less than the first confidence threshold.

3. The computing device of claim 2 , the authentication agent further provides a reauthentication request when the first confidence level information is less than the first confidence threshold.

4. The computing device of claim 3 ,

the request module further receives second confidence level information from the information handling system in response to the reauthentication request;

the comparison module further compares the third confidence level with the first confidence threshold; and

the authentication agent further grants access to the secure resource at the first access level when the second confidence level information is greater than the first confidence threshold and denies access to the secure resource at the first access level when the second confidence level information is less than the first confidence threshold.

5. The computing device of claim 1 ,

the request module further receives a second request to access the secure resource, determines a second access level associated with the second request, and requests second confidence level information from the information handling system;

the threshold table includes a second confidence threshold associated with the second access level;

the comparison module further compares the second confidence level information with the second confidence threshold; and

the authentication further agent grants access to the secure resource at the second access level when the second confidence level information is greater than the second confidence threshold.

6. The computing device of claim 1 , wherein:

the time base provides the time stamp;

the confidence score metadata includes a confidence parameter time stamp;

the first confidence threshold includes a parameter time stamp threshold that is based upon the time stamp;

the comparison module compares the confidence parameter time stamp with the parameter time stamp threshold; and

the authentication agent grants access to the secure resource at the first access level when the confidence parameter time stamp is less than the parameter time stamp threshold.

7. A method, comprising:

receiving, at a request module of an authentication agent of an information handling system, a first request by a user to access a secure resource of the information handling system;

determining a first access level of the user associated with the first request;

requesting first confidence level information from the information handling system, the first confidence level information including a confidence score for the information handling system, a confidence level associated with the confidence score, and confidence score meta-data that includes a time stamp associated with a time that a first input device received a first authentication information and includes information as to a source of the first request, wherein the confidence score is decreased exponentially over a period of inactivity during which no additional input is provided by the user to the information handling system, the period of inactivity occurring after successfully providing the first authentication information to increase the confidence score;

comparing, at a comparison module of the authentication agent, the first confidence level information with a first confidence threshold associated with the first access level;

determining, by a time base, that an assurance event has occurred within a time limit, based upon the confidence score meta-data; and

granting access to the secure resource at the first access level when the first confidence level information is greater than the first confidence threshold, and when the assurance event has occurred within the time limit.

8. The method of claim 7 , further comprising:

denying access to the secure resource at the first access level when the first confidence level information is less than the first confidence threshold.

9. The method of claim 8 , further comprising:

providing a reauthentication request when the first confidence level information is less than the first confidence threshold.

10. The method of claim 9 , further comprising:

receiving, at the request module, second confidence level information from the information handling system in response to the reauthentication request;

comparing, at the comparison module, the second confidence level information with the first confidence threshold;

granting access to the secure resource at the first access level when the second confidence level information is greater than the first confidence threshold; and

denying access to the secure resource at the first access level when the second confidence level information is less than the first confidence threshold.

11. The method of claim 7 , wherein:

receiving, at the request module, a second request to access the secure resource;

determining a second access level associated with the second request;

requesting second confidence level information from the information handling system;

comparing, at the comparison module, the second confidence level information with a second confidence threshold associated with the second access level; and

granting access to the secure resource at the second access level when the second confidence level information is greater than the second confidence threshold.

12. The method of claim 7 , further comprising:

providing, by the time base of the authentication agent, the time stamp, wherein first confidence threshold includes a parameter time stamp threshold that is based upon the time stamp;

comparing, by the comparison module, the confidence parameter time stamp with the parameter time stamp threshold; and

granting access to the secure resource at the first access level when the confidence parameter time stamp is less than the parameter time stamp threshold.

13. A non-transitory computer readable medium including code for performing a method, the method comprising:

receiving, at an information handling system, a first request by a user to access a secure resource of the information handling system;

determining a first access level of the first user associated with the first request;

requesting first confidence level information from the information handling system, the first confidence level information including a confidence score for the information handling system, a confidence level associated with the confidence score, and confidence score meta-data associated that includes a time stamp associated with a time that a first input device received a first authentication information and includes information as to a source of the first request, wherein the confidence score is decreased exponentially over a period of inactivity during which no additional input is provided by the user to the information handling system, the period of inactivity occurring after successfully providing the first authentication information to increase the confidence score;

comparing, at a comparison module of an authentication agent, the first confidence level information with a first confidence threshold that includes a time stamp associated with a time that the first input device received the first authentication information;

determining, by a time base, that an assurance event has occurred within a time limit, based upon the confidence score meta-data; and

granting access to the secure resource at the first access level when the first confidence level information is greater than the first confidence threshold, and when the assurance event has occurred within the time limit.

14. The computer-readable medium of claim 13 , wherein:

the first confidence level information comprises confidence score metadata associated with a confidence score for the information handling system; and

the method further comprises:

providing, by a time base of the authentication agent, a time stamp, wherein the confidence score metadata includes a confidence parameter time stamp, the first confidence threshold includes a parameter time stamp threshold that is based upon the time stamp;

comparing, by the comparison module, the confidence parameter time stamp with the parameter time stamp threshold; and

granting access to the secure resource at the first access level when the confidence parameter time stamp is less than the parameter time stamp threshold.

Assignments (21)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2016
From: HAMLIN, DANIEL; ROBISON, CHARLES D., JR.; GATES, CARRIE ELAINE
To: DELL PRODUCTS, LP
Reel/Frame 038489/0011 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
Cited By (2)
US 12,284,225 US 12,388,808