IP Library Granted Patent US 11,301,557
Granted Patent B2
US 11,301,557 · App. 16/516,371 · Granted Apr 12, 2022

System and method for data processing device management

Inventors: Ravikanth Chaganti (Bangalore, IN); Rizwan Ali (Cedar Park, TX); Dharmesh M. Patel (Round Rock, TX)
Assignee: DELL PRODUCTS L.P.
G06F21/45H04L63/0884G06F21/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,301,557
App. No.
16/516,371
Granted
Apr 12, 2022
Kind
B2
Abstract

A data processing device includes primary resources, an out-of-band manager operably connected to the primary resources via an always-on in-band connection, and an authentication engine. The authentication engine obtains, via the always-on in-band connection, an operation request and an authentication token corresponding to the operation request; in response to obtaining the authentication token: obtains a list of authorized operations using the authentication token; makes a determination that an operation indicated by the operation request is allowable based on the list of authorized operations; and performs the operation based on the determination.

Claims (57)

1. A method for managing a data processing device, comprising:

obtaining, by an out-of-band manager, a remote operation request for an operation from an entity;

obtaining, by the out-of-band manager, an authentication token for the entity, wherein the authentication token is generated by an authenticator, and a list of authorized operations is obtained from the authenticator;

generating, by the out-of-band manager, an operation request based on the operation;

providing, by the out-of-band manager and via an always-on in-band connection, the operation request and the authentication token to an authentication engine;

obtaining, from the out-of-band manager and via the always-on in-band connection, the operation request and the authentication token corresponding to the operation request;

in response to obtaining the authentication token:

obtaining, by the authentication engine, the list of authorized operations using the authentication token;

making a determination that the operation indicated by the operation request is allowable based on the list of authorized operations; and

performing the operation based on the determination.

2. The method of claim 1 , wherein the method further comprises:

obtaining, via the always-on in-band connection, a second operation request and a second authentication token corresponding to the second operation request;

in response to obtaining the second authentication token:

obtaining a second list of authorized operations using the second authentication token;

making a second determination that the operation indicated by the second operation request is not allowable based on the second list of authorized operations; and

rejecting the operation based on the second determination.

3. The method of claim 1 , wherein the authentication engine is operably connected to the authenticator by an in-band connection and the out-of-band manager is operably connected to the authenticator by an out-of-band connection.

4. The method of claim 1 , wherein the operation impacts primary resources of the data processing device and the out-of-band manager is hosted by the data processing device.

5. A data processing device, comprising:

primary resources;

an out-of-band manager operably connected to the primary resources via an always-on in-band connection, wherein the out-of-band manager is programmed to:

obtain a remote operation request for an operation from an entity;

obtain an authentication token for the entity, wherein the authentication token is generated by an authenticator, and a list of authorized operations is obtained from the authenticator;

generate an operation request based on the operation; and

provide, via the always-on in-band connection, the operation request and the authentication token to an authentication engine; and

the authentication engine programmed to:

obtain, via the always-on in-band connection, the operation request and the authentication token corresponding to the operation request;

in response to obtaining the authentication token:

obtain the list of authorized operations using the authentication token;

make a determination that the operation indicated by the operation request is allowable based on the list of authorized operations; and

perform the operation based on the determination.

6. The data processing device of claim 5 , wherein the authentication engine is further programmed to:

obtain, via the always-on in-band connection, a second operation request and a second authentication token corresponding to the second operation request;

in response to obtaining the second authentication token:

obtain a second list of authorized operations using the second authentication token;

make a second determination that the operation indicated by the second operation request is not allowable based on the second list of authorized operations; and

reject the operation based on the second determination.

7. The data processing device of claim 5 , wherein the authentication engine is operably connected to the authenticator by an in-band connection and the out-of-band manager is operably connected to the authenticator by an out-of-band connection.

8. The data processing device of claim 5 , wherein the operation impacts the primary resources.

9. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for managing a data processing device, the method comprising:

obtaining, by an out-of-band manager, a remote operation request for an operation from an entity;

obtaining, by the out-of-band manager, an authentication token for the entity, wherein the authentication token is generated by an authenticator, and a list of authorized operations is obtained from the authenticator;

generating, by the out-of-band manager, an operation request based on the operation;

providing, by the out-of-band manager and via an always-on in-band connection, the operation request and the authentication token to an authentication engine;

obtaining, from the out-of-band manager and via the always-on in-band connection, the operation request and the authentication token corresponding to the operation request;

in response to obtaining the authentication token:

obtaining, by the authentication engine, the list of authorized operations using the authentication token;

making a determination that the operation indicated by the operation request is allowable based on the list of authorized operations; and

performing the operation based on the determination.

10. The non-transitory computer readable medium of claim 9 , wherein the method further comprises:

obtaining, via the always-on in-band connection, a second operation request and a second authentication token corresponding to the second operation request;

in response to obtaining the second authentication token:

obtaining a second list of authorized operations using the second authentication token;

making a second determination that the operation indicated by the second operation request is not allowable based on the second list of authorized operations; and

rejecting the operation based on the second determination.

11. The non-transitory computer readable medium of claim 9 , wherein the authentication engine is operably connected to the authenticator by an in-band connection and the out-of-band manager is operably connected to the authenticator by an out-of-band connection.

12. The non-transitory computer readable medium of claim 9 , wherein the operation impacts primary resources of the data processing device and the out-of-band manager is hosted by the data processing device.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2019
From: CHAGANTI, RAVIKANTH; ALI, RIZWAN; PATEL, DHARMESH M.
To: DELL PRODUCTS L.P.
Reel/Frame 049867/0468 →