IP Library Patent Application 17032780
Patent Application
App. No. 17/032,780

SECURE AUTHENTICATION METHOD FOR PERFORMING A HOST OPERATION USING A DELEGATED AUTHORIZATION MECHANISM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/032,780
Abstract

A method includes receiving a host operation request sent without a first credential that is associated with a first user, wherein the host operation request by a second user includes a second user credential, the second user is an administrator of a systems management application, and the first user has a privilege to perform the host operation request. The method also sends the host operation request to a host operating system agent to generate an authentication token, the host operation request includes a digital certificate associated with the management controller, and the authentication token based on the first user credential of the first user. The method may also receive the authentication token generated by the host operating system agent, and send a response to the host operation request of the second user, wherein the response includes the authentication token.

Claims (36)

1 . A method comprising:

receiving, by a management controller, a host operation request at an information handling system, wherein the host operation request is sent without a first user credential that is associated with a first user, wherein the host operation request by a second user includes a second user credential, wherein the second user is an administrator of a systems management application that manages the information handling system, and wherein the first user has a privilege to perform the host operation request at the information handling system;

sending the host operation request to a host operating system agent of the information handling system to generate an authentication token, wherein the host operation request includes a digital certificate associated with the management controller, and wherein the authentication token is based on the first user credential of the first user;

receiving the authentication token generated by the host operating system agent subsequent to an authentication of the digital certificate by the host operating system agent; and

sending a response to the host operation request of the second user, wherein the response includes the authentication token.

2 . The method of claim 1 , wherein the host operation request is sent from a host operating system console interface of the systems management application through a remote client device.

3 . The method of claim 1 , further comprising determining whether the first user is configured on the information handling system.

4 . The method of claim 1 , further comprising determining whether the host operating system agent is allowed to generate the authentication token.

5 . The method of claim 1 , wherein the authentication token is generated subsequent to authentication of the second user credential.

6 . The method of claim 1 , wherein the host operation request is to perform a device inventory of the information handling system.

7 . The method of claim 1 , wherein the host operation request is to perform an update of a component of the information handling system.

8 . The method of claim 1 , wherein the authentication token may be used to authenticate the host operation request by the information handling system.

9 . The method of claim 1 , wherein the first user is configured prior to the receiving the host operation request.

10 . The method of claim 1 , wherein the first user is allowed to perform the host operation request in the information handling system.

11 . The method of claim 1 , wherein the host operating system agent is configured to generate the authentication token for the first user.

12 . The method of claim 1 , wherein the first user is configured during an installation or an update of the host operating system agent.

13 . An information handling system, comprising:

a host operating system agent configured to:

generate an authentication token for a first user subsequent to an authentication of a digital certificate associated with a service processor; and

send the authentication token to the service processor;

the service processor configured to:

receive a host operation request for the information handling system from a second user, wherein the host operation request is sent without a first user credential that is associated with the first user;

send the host operation request to the host operating system agent for the authentication of the digital certificate that is included with the host operation request, wherein the digital certificate is associated with the service processor, and wherein the authentication token is associated with the first user credential;

receive the authentication token from the host operating system agent subsequent to the authentication of the digital certificate associated with the service processor; and

send a response to the host operation request with the authentication token to the second user.

14 . The information handling system of claim 13 , wherein the host operation request is sent from a service processor console interface of a systems management application through a remote client device.

15 . The information handling system of claim 13 , wherein the host operation request is associated with a second user credential that is associated with the service processor.

16 . The information handling system of claim 15 , wherein the service processor is further configured to validate whether the second user is an administrator of the service processor.

17 . The information handling system of claim 15 , wherein the service processor is further configured with a network address translation rule that is used to send the host operation request to the host operating system agent.

18 . The information handling system of claim 17 , wherein the network address translation rule is disabled after an update package associated with the host operation request is received.

19 . A non-transitory computer-readable medium including code that when executed performs a method, the method comprising:

receiving a host operation request for an information handling system, wherein the host operation request is sent without a host operating system user credential, wherein the host operation request is sent from a user from a system management application monitoring the information handling system, and the host operation request includes user credentials associated with the system management application;

sending the host operation request to a host operating system agent for authentication, wherein the host operation request includes a digital certificate associated with a service processor, and wherein the authentication is based on the host operating system user credential preconfigured for performing the host operation request;

receiving an authentication token from the host operating system agent subsequent to the authentication of the digital certificate; and

sending the authentication token to the user.

20 . The method of claim 19 , wherein the sending the host operation request to the host operating system agent is performed over a host operating system and service processor pass-through.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2020
From: SAHA, RAJIB; GORE, SANTOSH; SURYANARAYANA, BHARATH KOUSHIK; MUKHERJEE, RISHI
To: DELL PRODUCTS, LP
Reel/Frame 053889/0220 →