IP Library Granted Patent US 11,336,438
Granted Patent B2
US 11,336,438 · App. 16/835,475 · Granted May 17, 2022

Remote approval and execution of restricted operations

Inventors: Yedidia Atzmony (Zichron Yaakov, IL); Yoav Nir (Zikhron Ya'Akov, IL)
Assignee: EMC IP Holding Company LLC
H04L9/085H04L9/3234H04L9/3247H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,438
App. No.
16/835,475
Granted
May 17, 2022
Kind
B2
Abstract

Techniques are provided for approval and execution of restricted operations. One method comprises receiving a request to perform an operation from a user; providing a redirect request with a protected request to obtain approval from an approval system; receiving a protected request approval with the protected request that was generated by the approval system using a shared secret; comparing the received protected request to a regenerated request generated using information stored with the request; and initiating an execution of the operation in response to the comparing satisfying one or more approval criteria. The shared secret may be shared between an operation execution system and the approval system. The processing of the request, an approval result and/or the execution of the operation can be audited.

Claims (37)

1. A method, comprising:

receiving a request to perform an operation from a user;

providing a redirect request with a protected request to obtain approval to perform the operation from an approval system, wherein the protected request comprises a random token combined with user authentication information that is protected using one or more of an encryption and a digital signature with a shared secret;

receiving a protected request approval with the protected request, wherein the protected request approval was generated by the approval system using the shared secret;

comparing the received protected request to a regenerated request generated using the user authentication information and one or more of the encryption and the digital signature with the shared secret; and

initiating an execution of the operation in response to the comparing satisfying one or more approval criteria, wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 , wherein the receiving the request to perform the operation further comprises the user selecting the operation and providing the request to perform the selected operation.

3. The method of claim 2 , wherein the receiving the request to perform the operation further comprises one or more of initiating an authentication of the user, obtaining a secret pass phrase from the user and receiving an authentication factor from the user.

4. The method of claim 1 , wherein the providing the redirect request with the protected request further comprises auditing the approval of the request.

5. The method of claim 1 , wherein the protected request is one or more of encrypted and digitally signed using one or more of a shared key, an identifier of the user, an identifier of the operation and the user authentication information.

6. The method of claim 1 , wherein the shared secret is shared between an operation execution system and the approval system.

7. The method of claim 1 , wherein the initiating the execution of the requested operation further comprises auditing the execution of the requested operation.

8. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

receiving a request to perform an operation from a user;

providing a redirect request with a protected request to obtain approval to perform the operation from an approval system, wherein the protected request comprises a random token combined with user authentication information that is protected using one or more of an encryption and a digital signature with a shared secret;

receiving a protected request approval with the protected request, wherein the protected request approval was generated by the approval system using the shared secret;

comparing the received protected request to a regenerated request generated using the user authentication information and one or more of the encryption and the digital signature with the shared secret; and

initiating an execution of the operation in response to the comparing satisfying one or more approval criteria.

9. The apparatus of claim 8 , wherein the receiving the request to perform the operation further comprises the user selecting the operation and providing the request to perform the selected operation.

10. The apparatus of claim 9 , wherein the receiving the request to perform the operation further comprises one or more of initiating an authentication of the user, obtaining a secret pass phrase from the user and receiving an authentication factor from the user.

11. The apparatus of claim 8 , wherein the providing the redirect request with the protected request further comprises auditing the approval of the request.

12. The apparatus of claim 8 , wherein the protected request is one or more of encrypted and digitally signed using one or more of a shared key, an identifier of the user and an identifier of the operation.

13. The apparatus of claim 8 , wherein the shared secret is shared between an operation execution system and the approval system.

14. The apparatus of claim 8 , wherein the initiating the execution of the requested operation further comprises auditing the execution of the requested operation.

15. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

receiving a request to perform an operation from a user;

providing a redirect request with a protected request to obtain approval to perform the operation from an approval system, wherein the protected request comprises a random token combined with user authentication information that is protected using one or more of an encryption and a digital signature with a shared secret;

receiving a protected request approval with the protected request, wherein the protected request approval was generated by the approval system using the shared secret;

comparing the received protected request to a regenerated request generated using the user authentication information and one or more of the encryption and the digital signature with the shared secret; and

initiating an execution of the operation in response to the comparing satisfying one or more approval criteria.

16. The non-transitory processor-readable storage medium of claim 15 , wherein the receiving the request to perform the operation further comprises the user selecting the operation and providing the request to perform the selected operation.

17. The non-transitory processor-readable storage medium of claim 15 , wherein the providing the redirect request with the protected request further comprises auditing the approval of the request.

18. The non-transitory processor-readable storage medium of claim 15 , wherein the protected request is one or more of encrypted and digitally signed using one or more of a shared key, an identifier of the user, an identifier of the operation and the user authentication information.

19. The non-transitory processor-readable storage medium of claim 15 , wherein the shared secret is shared between an operation execution system and the approval system.

20. The non-transitory processor-readable storage medium of claim 15 , wherein the initiating the execution of the requested operation further comprises auditing the execution of the requested operation.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2020
From: ATZMONY, YEDIDIA; NIR, YOAV
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 052269/0927 →
Continuity (1)
Related Publication 20210306140A1 · Sep 30, 2021
Cited By (1)
US 12,462,002