IP Library Granted Patent US 11,328,041
Granted Patent B2
US 11,328,041 · App. 16/775,153 · Granted May 10, 2022

Computing system virtualization continuous authentication system

Inventor: John Kelly (Mallow, IE)
Assignee: Dell Products L.P.
G06F21/316G06F9/452G06F11/3438G06F21/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,328,041
App. No.
16/775,153
Granted
May 10, 2022
Kind
B2
Abstract

A computing system virtualization continuous authentication system includes a computing system virtualization system that is configured to provide a virtual computing system on a computing client device, and a computing system virtualization management server device that is coupled to the computing system virtualization system and a management terminal. The computing system virtualization management server device monitors user activity information that is associated with a management session that corresponds with the management of the computing system virtualization system and that is associated with an authenticated user account on the computing system virtualization management server device. The computing system virtualization management server device determines that a first authentication challenge is required during the management session based on the user activity information and provides the first authentication challenge to the management terminal.

Claims (50)

1. A computing system virtualization continuous authentication system, comprising:

a computing system virtualization system that is configured to provide a virtual computing system on a client computing device;

a management terminal;

a computing system virtualization management server device that is coupled to the computing system virtualization system and the management terminal and that is configured to:

begin a management session via the management terminal with an authenticated user account that was authenticated on the computing system virtualization management server;

monitor computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system;

determine that a first authentication challenge is required during the management session based on at least one of the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system; and

provide the first authentication challenge to the management terminal.

2. The system of claim 1 , wherein the computing system virtualization management server device is configured to:

determine that the first authentication challenge has failed; and

end the management session in response to determining that the first authentication challenge has failed.

3. The system of claim 1 , wherein the computing system virtualization management server device is configured to:

continue to monitor the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system.

4. The system of claim 1 , wherein the at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a cloning technology selected for virtual computing system pool deployment.

5. The system of claim 1 , wherein the at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a virtual computing system display protocol used.

6. The system of claim 1 , wherein the computing system virtualization management server device is further configured to:

determine that the computing system virtualization management functions that have been monitored haves satisfied a condition prior to the determining that the first authentication challenge is required based on the computing system virtualization management functions.

7. The system of claim 1 , wherein the determining that the first authentication challenge is required based on the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system includes:

determining whether one or more conditions that are generated during a training process are satisfied.

8. The system of claim 1 , wherein the first authentication challenge is different than a second authentication challenge that was used to authenticate a user and to access the authenticated user account to begin the management session.

9. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a computing system virtualization management engine that is configured to:

begin a management session with an authenticated user account via a management terminal that is coupled to the processing system;

monitor computing system virtualization management functions used by the authenticated user account in the management session during the management of a computing system virtualization system that is coupled to the processing system;

determine that a first authentication challenge is required during the management session based on at least one of the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system; and

provide the first authentication challenge to a management terminal coupled to the processing system.

10. The IHS of claim 9 , wherein the computing system virtualization management engine is configured to:

determine that the first authentication challenge has failed; and

end the management session in response to determining that the first authentication challenge has failed.

11. The IHS of claim 9 , wherein the computing system virtualization management engine is configured to:

continue to monitor the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system.

12. The IHS of claim 9 , wherein the at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a cloning technology selected for virtual computing system pool deployment.

13. The IHS of claim 9 , wherein the

at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a virtual computing system display protocol used.

14. The IHS of claim 9 , wherein the determining that the first authentication challenge is required based on the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system includes:

determining whether one or more conditions that are generated during a training process are satisfied.

15. The IHS of claim 9 , wherein the first authentication challenge is different than a second authentication challenge that was used to authenticate a user and to access the authenticated user account to begin the management session.

16. A method of continuous authentication of a management session for a computing system virtualization system, comprising:

beginning, by a computing system virtualization management server device, a management session with an authenticated user account via a management terminal that is coupled to the processing system computing system virtualization management server device;

monitoring, by the computing system virtualization management server device, computing system virtualization management functions used by the authenticated user account in the management session during the management of a computing system virtualization system;

determining, by the computing system virtualization management server device, that a first authentication challenge is required during the management session based on at least one of the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system; and

providing, by the computing system virtualization management server device, first authentication challenge to the management terminal.

17. The method of claim 16 , further comprising:

determining, by the computing system virtualization management server device, that the first authentication challenge has failed; and

ending, by the computing system virtualization management server device, the management session in response to determining that the first authentication challenge has failed.

18. The method of claim 16 , further comprising:

continuing, by the computing system virtualization management server device, to monitor the computing system virtualization management functions used by the authenticated user account in the management session during the management of the computing system virtualization system.

19. The method of claim 16 , wherein the at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a cloning technology selected for virtual computing system pool deployment.

20. The method of claim 16 , wherein the at least one of the computing system virtualization management functions upon which the requirement for the first authentication challenge is based is a Virtual Desktop Infrastructure (VDI) management function that includes a virtual computing system display protocol used.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2020
From: KELLY, JOHN
To: DELL PRODUCTS L.P.
Reel/Frame 051648/0225 →