IP Library Granted Patent US 11,196,733
Granted Patent B2
US 11,196,733 · App. 15/891,815 · Granted Dec 7, 2021

System and method for group of groups single sign-on demarcation based on first user login

Inventors: Yee Ja (Round Rock, TX); Marshal F. Savage (Austin, TX); Cyril Jose (Austin, TX); Srihari Srirangam (Khammam, IN); Anto Dolphinjose Jesurajan Marystella (Round Rock, TX); Farhan Mohammed Syed (Bangalore, IN)
Assignee: Dell Products L.P.
H04L63/0815G06F21/41H04L63/104H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,196,733
App. No.
15/891,815
Granted
Dec 7, 2021
Kind
B2
Abstract

Methods and systems for access in a management controller group hierarchy may involve receiving a request for a user at an information handling system, determining whether a link of trust is established, and validating the single sign-on request. The request may be to authenticate the user for access using a single sign-on token. Determination of whether the link of trust is established may be based on an initial login location stored in the single sign-on token. Validation of the single sign-on token may be based on a determination that the link of trust is established.

Claims (60)

1. A method for access in a management controller group hierarchy, comprising:

receiving a request for a user at a first management controller of a first information handling system in a management controller group hierarchy, the request to authenticate the user for access using a single sign-on token and the management controller group hierarchy formed with two or more levels, each level formed with one or more groups corresponding to one or more management controllers of one or more information handling systems;

determining whether a link of trust is established based on an initial login location stored in the single sign-on token;

validating the request to authenticate the user for access using the single sign-on token based on a determination that the link of trust is established;

determining whether the initial login location is recognized;

based on a determination that the initial login location is not recognized:

granting the user access to view information about an aggregate group in the management controller group hierarchy, the aggregate group including a first local group in the management controller group hierarchy; and

denying the user access to the first local group of the aggregate group.

2. The method of claim 1 , further comprising:

receiving a re-authenticated single sign-on token from a controlling member of a second local group in the management controller group hierarchy, the re-authenticated single sign-on token received after a request to elevate privileges is received and the second local group not including the first management controller; and

granting the user full access to the second local group of the aggregate group based on receiving the re-authenticated single sign-on token from the controlling member of the second local group.

3. The method of claim 1 , further comprising:

receiving a request to elevate privileges of the user to enable access to a second local group in the management controller group hierarchy, the second local group in the management controller group hierarchy not including the first management controller of the first information handling system;

redirecting the request to elevate privileges to a controlling member of the second local group; and

receiving a re-authenticated single sign-on token back from the controlling member of the second local group.

4. The method of claim 3 , further comprising:

determining whether a login location stored in the re-authenticated single sign-on token corresponds to a second management controller that manages the aggregate group in the management controller group hierarchy, the aggregate group including the first management controller of the first information handling system that received the request to authenticate the user for access; and

granting the user full access to the first local group and second local group based on a determination that the login location stored in the re-authenticated single sign-on token corresponds to the second management controller that manages the aggregate group in the management controller group hierarchy.

5. The method in claim 1 , wherein determining whether the link of trust is established based on the initial login location is based on a determination whether the management controller of the first information handling system and a second management controller of a second information handling system are part of the same local group in the management controller group hierarchy.

6. An information handling system, comprising:

a processor subsystem comprising a primary processor having access to a first memory;

a management controller comprising a secondary processor having access to a second memory, the second memory including an embedded storage partition and the second memory storing instructions executable by the secondary processor to:

receive a request for a user at the management controller of the information handling system in a management controller group hierarchy, the request to authenticate the user for access using a single sign-on token and the management controller group hierarchy formed with two or more levels, each level formed with one or more groups corresponding to one or more management controllers of one or more information handling systems;

determine whether a link of trust is established based on an initial login location stored in the single sign-on token;

validate request to authenticate the user for access using the single sign-on token based on a determination that the link of trust is established;

determine whether the initial login location is recognized;

based on a determination that the initial login location is not recognized:

grant the user access to view information about an aggregate group in the management controller group hierarchy, the aggregate group including a first local group in the management controller group hierarchy; and

deny the user access to the first local group of the aggregate group.

7. The information handling system of claim 6 , further comprising instructions executable by the secondary processor to:

receive a re-authenticated single sign-on token from a controlling member of a second local group in the management controller group hierarchy, the re-authenticated single sign-on token received after a request to elevate privileges is received and the second local group not including the management controller; and

grant the user full access to the second local group of the aggregate group based on receipt of the re-authenticated single sign-on token from the controlling member of the second local group.

8. The information handling system of claim 6 , further comprising instructions executable by the secondary processor to:

receive a request to elevate privileges of the user to enable access to a second local group in the management controller group hierarchy, the second local group in the management controller group hierarchy not including the management controller of the information handling system;

redirect the request to elevate privileges to a controlling member of the second local group; and

receive a re-authenticated single sign-on token back from the controlling member of the second local group.

9. The information handling system of claim 8 , further comprising instructions executable by the secondary processor to:

determine whether a login location stored in the re-authenticated single sign-on token corresponds to another management controller that manages the aggregate group in the management controller group hierarchy, the aggregate group including the management controller of the information handling system that received the request to authenticate the user for access; and grant the user full access to the first local group and the second local group based on a determination that the login location stored in the re-authenticated single sign-on token corresponds to the management controller that manages the aggregate group in the management controller group hierarchy.

10. The information handling system of claim 6 , wherein a determination of whether the link of trust is established based on the initial login location is based on a determination whether the management controller of the information handling system and a target management controller of another second information handling system are part of the same local group in the management controller group hierarchy.

11. The information handling system of claim 6 , wherein the initial login location stored in the single sign-on token indicates a service tag that corresponds to an initial management controller of an initial information handling system that corresponds to the initial login location.

12. A management controller for an information handling system having a primary processor and a primary memory, the management controller comprising a secondary processor having access to a secondary memory, the secondary memory including an embedded storage partition and the secondary memory storing instructions executable by the secondary processor to:

receive a request for a user at the management controller of the information handling system in a management controller group hierarchy, the request to authenticate the user for access using a single sign-on token and the management controller group hierarchy formed with two or more levels, each level formed with one or more groups corresponding to one or more management controllers of one or more information handling systems;

determine whether a link of trust is established based on an initial login location stored in the single sign-on token;

validate the request to authenticate the user for access using the single sign-on token based on a determination that the link of trust is established;

determine whether the initial login location is recognized;

based on a determination that the initial login location is not recognized:

grant the user access to view information about an aggregate group in the management controller group hierarchy, the aggregate group including a first local group in the management controller group hierarchy; and

deny the user access to the first local group included in the aggregate group.

13. The management controller of claim 12 , further comprising instructions executable by the secondary processor to:

receive a re-authenticated single sign-on token from a controlling member of a second local group in the management controller group hierarchy, the re-authenticated single sign-on token received after a request to elevate privileges is received and the second local group not including the management controller; and

grant the user full access to the second local group of the aggregate group based on receipt of the re-authenticated single sign-on token from the controlling member of the second local group.

14. The management controller of claim 12 , further comprising instructions executable by the secondary processor to:

receive a request to elevate privileges of the user to enable access to a second local group in the management controller group hierarchy, the second local group in the management controller group hierarchy not including the management controller of the information handling system;

redirect the request to elevate privileges to a controlling member of the second local group; and

receive a re-authenticated single sign-on token back from the controlling member of the second local group.

15. The management controller of claim 14 , further comprising instructions executable by the secondary processor to:

determine whether a login location stored in the re-authenticated single sign-on token corresponds to another management controller that manages the aggregate group in the management controller group hierarchy, the aggregate group including the management controller of the information handling system that received the request to authenticate the user for access; and

grant the user full access to the first local group and the second local group based on a determination that the login location stored in the re-authenticated single sign-on token corresponds to the management controller that manages the aggregate group in the management controller group hierarchy.

16. The management controller of claim 12 , wherein a determination of whether the link of trust is established based on the initial login location is based on a determination whether the management controller of the information handling system and a target management controller of another information handling system are part of the same local group in the management controller group hierarchy.

17. The management controller of claim 12 , wherein the initial login location stored in the single sign-on token indicates a service tag that corresponds to an initial management controller of an initial information handling system that corresponds to the initial login location.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2018
From: JA, YEE; SAVAGE, MARSHAL F.; JOSE, CYRIL; SRIRANGAM, SRIHARI; JESURAJAN MARYSTELLA, ANTO DOLPHINJOSE; SYED, FARHAN MOHAMMED
To: DELL PRODUCTS L.P.
Reel/Frame 045290/0313 →