IP Library Granted Patent US 11,343,244
Granted Patent B2
US 11,343,244 · App. 16/531,004 · Granted May 24, 2022

Method and apparatus for multi-factor verification of a computing device location within a preset geographic area

Inventors: Kamal J. Koshy (Austin, TX); Adolfo S. Montero (Pflugerville, TX)
Assignee: Dell Products, LP
H04L63/0876H04L41/082H04W4/021
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,343,244
App. No.
16/531,004
Granted
May 24, 2022
Kind
B2
Abstract

A location multi-factor verification method may comprise initiating a boot process of a client device via firmware of the client device, receiving, via a network interface device, an access point (AP) beacon frame identifying a nearby AP, transmitting the AP beacon frame to a location determination service via the network interface device, receiving a geographic location estimation from the location determination service, based on the AP beacon frame, transmitting the geographic location estimation to the nearby AP, and granting a user of the client device access to an operating system of the client device if a boot process authorization instruction is received at the client device via the network interface device.

Claims (59)

1. An information handling system of a wireless network access point operating a location multi-factor authentication security system comprising:

a memory storing a private key and a public key;

an access point network interface device operably connecting the wireless network access point to a network receiving a geographic location estimation from a client device requesting access to the network;

the access point network interface device transmitting a random number challenge generated using the private key to the client device if the geographic location estimation is within a preset geographical area;

the access point network interface device receiving a challenge response from the client device;

a processor generating a challenge response comparator by decrypting the random number challenge using a public key;

the processor generating a boot process authorization instruction if the challenge response matches the challenge response comparator; and

the access point network interface device transmitting the boot process authorization instruction to the client device to permit access to the client device operating system if the challenge response matches the challenge response comparator.

2. The information handling system of claim 1 , further comprising:

the access point network interface device disallowing communication between the network and the client device if the geographical location estimation is not within the preset geographical area.

3. The information handling system of claim 1 , further comprising:

the access point network interface device transmitting a boot up abort instruction to the client device if the geographical location estimation is not within the preset geographical area.

4. The information handling system of claim 1 , further comprising:

the access point network interface device transmitting a boot up abort instruction to the client device if the challenge response does not match the challenge response comparator.

5. The information handling system of claim 1 , wherein the geographic location estimation is determined based on an access point beacon frame identifying an access point known to be located within the preset geographical area, received from the client device.

6. The information handling system of claim further comprising:

the processor authenticating the client device through a Wi-Fi Protected Setup (WPS) security protocol.

7. The information handling system of claim further comprising:

the access point network interface device receiving the public key and the private key transmitted from a router within a local network that includes the AP.

8. A location multi-factor verification method comprising:

initiating a boot process of a client device via firmware of the client device;

receiving, via a network interface device, an access point (AP) beacon frame identifying a nearby AP;

transmitting the AP beacon frame to a location determination service via the network interface device;

receiving a geographic location estimation from the location determination service, based on the AP beacon frame;

transmitting the geographic location estimation to the nearby AP; and

granting a user of the client device access to an operating system of the client device if a boot process authorization instruction is received at the client device via the network interface device.

9. The method of claim further comprising:

receiving a boot up abort instruction, via the network interface device, if the geographical location estimation is not within the preset geographical area; and

aborting the boot up process such that the user cannot access the operating system of the client device.

10. The method of claim 8 , further comprising:

receiving a boot process authorization instruction from the nearby AP if the geographic location estimation is within a preset geographical area and the client device transmits a correct asymmetric cryptography challenge response to the AP.

11. The method of claim 10 , further comprising:

receiving, via the network interface device, a random number challenge generated using the private key;

generating a challenge response based on a public key stored in a memory of the client device; and

transmitting the challenge response to the AP via the network interface device.

12. The method of claim 10 , further comprising:

receiving a boot up abort instruction, via the network interface device, if the client device does not transmit the correct asymmetric cryptography challenge response to the AP; and

aborting the boot up process such that the user cannot access the operating system of the client device.

13. The method of claim 8 , wherein the geographic location estimation is determined using a network connection triangulation method.

14. The method of claim 8 , further comprising:

authenticating the client device at the AP through a Wi-Fi Protected Setup (WPS) security protocol, via the processor or network interface device.

15. An information handling system of a wireless network access point operating a location multi-factor authentication security system comprising:

a memory storing a private key and a public key;

an access point network interface device operably connecting the wireless network access point to a network receiving a geographic location estimation from a client device requesting access to the network;

a processor authenticating the client device through a Wi-Fi Protected Setup (WPS) security protocol;

the access point network interface device transmitting a random number challenge generated using the private key to the client device if the geographic location estimation is within a preset geographical area;

the access point network interface device receiving a challenge response from the client device;

a processor generating a challenge response comparator by decrypting the random number challenge using a public key;

the processor generating a boot process authorization instruction if the challenge response matches the challenge response comparator; and

the access point network interface device transmitting the boot process authorization instruction to the client device to permit access to the client device operating system if the challenge response matches the challenge response comparator.

16. The information handling system of claim 15 , further comprising:

the access point network interface device disallowing communication between the network and the client device if the geographical location estimation is not within the preset geographical area.

17. The information handling system of claim 15 , further comprising:

the access point network interface device transmitting a boot up abort instruction to the client device if the geographical location estimation is not within the preset geographical area.

18. The information handling system of claim 15 , further comprising:

the access point network interface device transmitting a boot up abort instruction to the client device if the challenge response does not match the challenge response comparator.

19. The information handling system of claim 15 , further comprising:

the access point network interface device receiving the public key and the private key transmitted from a router within a local network that includes the AP.

20. The information handling system of claim 15 , wherein the AP beacon frame identifies the nearby AP by a MAC address known to be associated with the nearby AP.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2021
From: KOSHY, KAMAL J.; MONTERO, ADOLFO S.
To: DELL PRODUCTS, LP
Reel/Frame 055810/0930 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →