IP Library Granted Patent US 11,757,859
Granted Patent B2
US 11,757,859 · App. 17/324,381 · Granted Sep 12, 2023

Run-time attestation of a user workspace

Inventors: Jason A. Kolodziej (Falls City, TX); Anantha K. Boyapalle (Cedar Park, TX)
Assignee: Dell Products L.P.
H04L63/08G06F8/60H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,859
App. No.
17/324,381
Granted
Sep 12, 2023
Kind
B2
Abstract

Run-time attestation of a workspace including deploying, at a client information handling system, an application broker, the application broker including a model that defines characteristics of a computer-implemented application accessible through a server information handling system; establishing a trust relationship between a control vault system of the client information handling system and the server information handling system; provisioning entitlements, by the application broker, that are associated with the computer-implemented application at the client information handling system; identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the model; determining, based on the comparing, a violation of the model, and in response, procuring a trust challenge from the server information handling system; generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.

Claims (47)

1. A computer-implemented method of run-time attestation of a workspace, the method including:

deploying, at a client information handling system, an application broker, the application broker including a dynamically attestable runtime properties model that defines characteristics of a computer-implemented application, the computer-implemented application accessible through a server information handling system;

establishing a trust relationship between a control vault system of the client information handling system and the server information handling system;

provisioning entitlements, by the application broker, that are associated with the computer-implemented application at the client information handling system;

identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the dynamically attestable runtime properties model;

determining, based on the comparing, a violation of the dynamically attestable runtime properties model, and in response, procuring a trust challenge from the server information handling system; and

generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.

2. The computer-implemented method of claim 1 , further comprising:

receiving, from the server information handling system and at the application broker, an action response to the attestation.

3. The computer-implemented method of claim 2 , further comprising:

invoking, by the application broker, the action response at the client information handling system.

4. The computer-implemented method of claim 3 , wherein the action response includes denying execution of the entitlements at the client computing device.

5. The computer-implemented method of claim 3 , wherein the action response includes allowing execution of the entitlements at the client computing device.

6. The computer-implemented method of claim 1 , further comprising:

authenticating the client information handling system at the server information handling system.

7. The computer-implemented method of claim 6 , wherein deploying the application broker at the client information handling system is in response to authenticating the client information handling system at the server information handling system.

8. The computer-implemented method of claim 1 , wherein the characteristics of the computer-implemented application include file management kernel-service characteristics, structural-constraint characteristics, and equality-based data invariant characteristics.

9. The computer-implemented method of claim 1 , further comprising:

verifying a signature and nonce of the control vault system.

10. An information handling system comprising a processor having access to memory media storing instructions executable by the processor to perform operations, comprising:

deploying, at a client information handling system, an application broker, the application broker including a dynamically attestable runtime properties model that defines characteristics of a computer-implemented application, the computer-implemented application accessible through a server information handling system;

establishing a trust relationship between a control vault system of the client information handling system and the server information handling system;

provisioning entitlements, by the application broker, that are associated with a workspace at the client information handling system;

identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the dynamically attestable runtime properties model;

determining, based on the comparing, a violation of the dynamically attestable runtime properties model, and in response, procuring a trust challenge from the server information handling system; and

generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.

11. The information handling system of claim 10 , further comprising:

receiving, from the server information handling system and at the application broker, an action response to the attestation.

12. The information handling system of claim 11 , further comprising:

invoking, by the application broker, the action response at the client information handling system.

13. The information handling system of claim 12 , wherein the action response includes denying execution of the entitlements at the client computing device.

14. The information handling system of claim 12 , wherein the action response includes allowing execution of the entitlements at the client computing device.

15. The information handling system of claim 10 , further comprising:

authenticating the client information handling system at the server information handling system.

16. The information handling system of claim 15 , wherein deploying the application broker at the client information handling system is in response to authenticating the client information handling system at the server information handling system.

17. The information handling system of claim 10 , wherein the characteristics of the computer-implemented application include file management kernel-service characteristics, structural-constraint characteristics, and equality-based data invariant characteristics.

18. The information handling system of claim 10 , further comprising:

verifying a signature and nonce of the control vault system.

19. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

deploying, at a client information handling system, an application broker, the application broker including a dynamically attestable runtime properties model that defines characteristics of a computer-implemented application, the computer-implemented application accessible through a server information handling system;

establishing a trust relationship between a control vault system of the client information handling system and the server information handling system;

provisioning entitlements, by the application broker, that are associated with the computer-implemented application at the client information handling system;

identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the dynamically attestable runtime properties model;

determining, based on the comparing, a violation of the dynamically attestable runtime properties model, and in response, procuring a trust challenge from the server information handling system; and

generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.

20. The transitory computer-readable medium of claim 19 , further comprising:

receiving, from the server information handling system and at the application broker, an action response to the attestation.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: KOLODZIEJ, JASON A.; BOYAPALLE, ANANTHA K.
To: DELL PRODUCTS L.P.
Reel/Frame 056286/0536 →
Continuity (1)
Related Publication 20220377062A1 · Nov 24, 2022