IP Library Granted Patent US 10,938,831
Granted Patent B2
US 10,938,831 · App. 16/007,414 · Granted Mar 2, 2021

Methods and apparatus to enable services to run in multiple security contexts

Inventors: Abu Shaher Sanaullah (Austin, TX); Danilo O. Tan (Austin, TX); Srikanth Kondapi (Austin, TX)
Assignee: Dell Products, L.P.
H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,938,831
App. No.
16/007,414
Granted
Mar 2, 2021
Kind
B2
Abstract

An information handling system includes a service master and a command router. The service master is configured to host one or more service threads running under different access levels. The command router is configured to receive a request for a service from an application, the request including an access control token, determine the access control token matches the service and an access level corresponding to the access control token, and route the request to a service thread matching the access level of the access control token.

Claims (34)

1. An information handling system comprising:

a hardware processor;

a service master configured to host one or more service threads running on the hardware processor under different access levels, the service threads performing local service tasks; and

a command router configured to:

receive a request for a service from a local application running on the processor, the request including an access control token;

determine, using the processor, the access control token matches the service and an access level corresponding to the access control token; and

route the request to a service thread matching the access level, wherein the service is provided at a minimal access level based on the information indicating the local application access is reduced, wherein the local application access is reduced due to a new version of the application being available.

2. The information handling system of claim 1 , further comprising obtaining information relating applications, services, and access levels from a server.

3. The information handling system of claim 2 , further comprising receiving a registration request from the local application and providing the access control token to the local application based on the information from the server.

4. The information handling system of claim 2 , wherein determining includes comparing the access control token to the information from the server.

5. The information handling system of claim 2 , further comprising rejecting the request based on the information from the server indicating the local application access is revoked due to a discovered vulnerability.

6. The information handling system of claim 1 , wherein the service master or the command router is further configured to provide the access control token to the application upon registration of the application.

7. The information handling system of claim 1 , wherein the service threads include a first service thread for a first user and a second service thread for a second user, wherein routing the request is further based on matching the user.

8. A method comprising:

receiving a request for a local service from a local application running on a processor, the request utilizing an access control token;

determining, by the processor, if the access control token matches the requested local service and an access level; and

providing the local service by a service thread matching the access level, the service thread executing on the processor,

wherein the service is provided at a minimal access level based on the information indicating the local application access is reduced, wherein the local application access is reduced due to a new version of the application being available.

9. The method of claim 8 , further comprising obtaining information relating applications, services, and access levels from a server.

10. The method of claim 9 , further comprising receiving a registration request from the local application and providing the access control token to the local application based on the information from the server.

11. The method of claim 9 , wherein determining includes comparing the access control token to the information from the server.

12. The method of claim 9 , further comprising rejecting the request based on the information from the server indicating the local application access is revoked due to a discovered vulnerability in the local application.

13. An authentication service comprising:

an authentication server configured to:

store information relating to applications, services, and access levels; and

provide information to a command router; and

the command router configured to:

receive a request for a local service from one of the local applications running on a processor, the request utilizing an access control token;

determine the access control token matches the local service and determining an access level corresponding to the access control token; and

route the request to a local service thread matching providing the local service at the corresponding access level, the local service thread hosted by a service master configured to host one or more service threads executing on a processor under different access levels, wherein the service is provided at a minimal access level based on the information indicating the local application access is reduced, wherein the local application access is reduced due to a new version of the application being available.

14. The authentication service of claim 13 , wherein the command router is further configured to receive a registration request from the local application and providing the access control token to the local application based on the information.

15. The authentication service of claim 13 , wherein determining includes comparing the access control token to the information.

16. The authentication service of claim 13 , further comprising rejecting the request based on the information indicating an application access is revoked due to a discovered vulnerability.

17. The authentication service of claim 13 , wherein the authentication service is further configured to provide the access control token to the local application.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2019
From: SANAULLAH, ABU SHAHER; TAN, DANILO O.; KONDAPI, SRIKANTH
To: DELL PRODUCTS, LP
Reel/Frame 049045/0479 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
Continuity (1)
Related Publication 20190387001A1 · Dec 19, 2019