IP Library Granted Patent US 11,258,781
Granted Patent B2
US 11,258,781 · App. 16/804,436 · Granted Feb 22, 2022

Context and device state driven authorization for devices

Inventors: Charles D. Robison (Buford, GA); Daniel L. Hamlin (Round Rock, TX)
Assignee: Dell Products L.P.
H04L63/0823H04L63/105H04L63/1408H04L63/1475H04W4/70H04W4/80H04W12/06H04W12/08H04W12/122H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,258,781
App. No.
16/804,436
Granted
Feb 22, 2022
Kind
B2
Abstract

In some examples, a target device determines that each device of a plurality of devices (i) includes a certificate that is provided to each device during provisioning, (ii) is within a predetermined distance from the target device, (iii) includes a beacon secret that is broadcast to each device at a predetermined time interval, and (iv) that either: (a) a privilege level associated with at least one device of the plurality of devices satisfies a particular privilege level specified by an access policy or (b) a number of the plurality devices with the determined distance from the target device satisfies a predetermined number specified by the access policy. The target device grants at least one device of the plurality of devices access to the target device, and receives a message from the at least one device. The target device initiates an action based at least in part on the message.

Claims (82)

1. A method comprising:

determining, by one or more processors of a target device, that each device of a plurality of devices includes a certificate that is provided to each device during provisioning;

determining, by the one or more processors, that each device of the plurality of devices is within a predetermined distance from the target device;

determining, by the one or more processors, that each device of the plurality of devices includes a beacon secret that is broadcast to each device at a predetermined time interval; and

determining, by the one or more processors, that either:

a privilege level associated with at least one device of the plurality of devices satisfies a particular privilege level specified by an access policy; or

a number of the plurality of devices within the predetermined distance from the target device satisfies a predetermined number specified by the access policy;

granting, by the one or more processors, at least one device of the plurality of devices access to the target device;

receiving, by the one or more processors, a message from the at least one device of the plurality of devices; and

initiating, by the target device, an action based at least in part on the message.

2. The method of claim 1 , wherein determining that each device of the plurality of devices includes the certificate comprises:

performing a certificate-based handshake between the target device and each device of the plurality of devices.

3. The method of claim 1 , further comprising:

receiving a new beacon secret; and

based at least in part on determining that at least one device did not receive the new beacon secret:

denying the at least one device of the plurality of devices access to the target device; or

reducing a level of access of the at least one device to the target device.

4. The method of claim 1 , wherein the predetermined distance comprises at least one of:

a minimum distance between each device and the target device; or

a maximum distance between each device and the target device.

5. The method of claim 1 , wherein each device of the plurality of devices performs a certificate-based handshake with other devices of the plurality of devices.

6. The method of claim 1 , further comprising:

determining that an unauthorized device does not satisfy at least a particular condition specified by the access policy; and

creating a security notification associated with the unauthorized device.

7. The method of claim 1 , wherein the target device comprises one of:

a streaming media player; or

a remote-controlled robotic device.

8. A target device comprising:

one or more processors; and

one or more non-transitory computer-readable storage media to store instructions executable by the one or more processors to perform operations comprising:

determining that each device of a plurality of devices includes a certificate that is provided to each device during provisioning;

determining that each device of the plurality of devices is within a predetermined distance from the target device;

determining that each device of the plurality of devices includes a beacon secret that is broadcast to each device at a predetermined time interval; and

determining that either:

a privilege level associated with at least one device of the plurality of devices satisfies a particular privilege level specified by an access policy; or

a number of the plurality of devices within the predetermined distance from the target device satisfies a predetermined number specified by the access policy;

granting, by the one or more processors, at least one device of the plurality of devices access to the target device;

receiving, by the one or more processors, a message from the at least one device of the plurality of devices; and

initiating, by the target device, an action based at least in part on the message.

9. The target device of claim 8 , wherein determining that each device of the plurality of devices include the certificate comprises:

performing a certificate-based handshake between each device of the plurality of devices and the target device.

10. The target device of claim 8 , the operations further comprising:

receiving a new beacon secret; and

based at least in part on determining that at least one device did not receive the new beacon secret:

denying the at least one device of the plurality of devices access to the target device; or

reducing a level of access of the at least one device to the target device.

11. The target device of claim 8 , wherein the predetermined distance comprises at least one of:

a minimum distance between each device and the target device; or

a maximum distance between each device and the target device.

12. The target device of claim 8 , wherein each device of the plurality of devices performs a certificate-based handshake with other devices of the plurality of devices before being granted access to the target device.

13. The target device of claim 8 , the operations further comprising:

determining that an unauthorized device does not satisfy at least a particular condition of the access policy; and

creating a security notification associated with the unauthorized device.

14. The target device of claim 8 , wherein the target device comprises one of:

a streaming media player; or

a remote-controlled robotic device.

15. One or more non-transitory computer-readable storage media to store instructions executable by one or more processors of a target device to perform operations comprising:

determining that each device of a plurality of devices includes a certificate that is provided to each device during provisioning;

determining that each device of the plurality of devices is within a predetermined distance from the target device;

determining that each device of the plurality of devices includes a beacon secret that is broadcast to each device at a predetermined time interval; and

determining that either:

a privilege level associated with at least one device of the plurality of devices satisfies a particular privilege level specified by an access policy; or

a number of the plurality of devices within the predetermined distance from the target device satisfies a predetermined number specified by the access policy;

granting, by the one or more processors, at least one device of the plurality of devices access to the target device;

receiving, by the one or more processors, a message from the at least one device of the plurality of devices; and

initiating, by the target device, an action based at least in part on the message.

16. The one or more non-transitory computer-readable storage media of claim 15 , further comprising:

receiving a new beacon secret broadcast by a beacon at a predetermined time interval; and

replacing a beacon secret stored in the one or more non-transitory computer-readable storage media with the new beacon secret.

17. The one or more non-transitory computer-readable storage media of claim 15 , the operations further comprising:

receiving a new beacon secret; and

based at least in part on determining that at least one device did not receive the new beacon secret:

denying the at least one device of the plurality of devices access to the target device; or

reducing a level of access of the at least one device to the target device.

18. The one or more non-transitory computer-readable storage media of claim 15 , wherein the predetermined distance comprises at least one of:

a minimum distance between each device and the target device; or

a maximum distance between each device and the target device.

19. The one or more non-transitory computer-readable storage media of claim 15 , wherein determining that each device of the plurality of devices includes the certificate comprises:

performing a certificate-based handshake between the target device and each device of the plurality of devices.

20. The one or more non-transitory computer-readable storage media of claim 15 , further comprising:

determining that an unauthorized device does not satisfy at least a particular condition of the access policy; and

sending a security notification indicating a presence of the unauthorized device.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2020
From: ROBISON, CHARLES D.; HAMLIN, DANIEL L.
To: DELL PRODUCTS L. P.
Reel/Frame 053200/0372 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →