IP Library Granted Patent US 12,682,027
Granted Patent B2
US 12,682,027 · App. 17/332,115 · Granted Jul 14, 2026

Access control using user behavior profile and storage system-based multi-factor authentication

Inventors: Tomer Shachar (Omer, IL); Yevgeni Gehtman (Modi'in, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: EMC IP Holding Company LLC
G06F21/316G06N20/00H04L63/18H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,682,027
App. No.
17/332,115
Granted
Jul 14, 2026
Kind
B2
Abstract

Techniques are provided for access control using user behavior profiles and storage system-based multi-factor authentication. One method comprises obtaining a behavior profile for a user; obtaining an input/output request from the user; determining whether the input/output request exhibits anomalous user behavior relative to the behavior profile; initiating a multi-factor authentication of the user in response to the input/output request exhibiting anomalous user behavior to obtain a verification result; and processing the input/output request based at least in part on the verification result. The behavior profile for the user may be obtained by obtaining behavioral information from the user and/or monitoring a plurality of input/output requests of the user to learn at least a portion of the behavior profile for the user. The multi-factor authentication may comprise an out-of-band authorization request (e.g., to approve the input/output request) sent to a user associated with the input/output request.

Claims (37)

1 . A method, comprising:

obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;

performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:

determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;

initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and

processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.

2 . The method of claim 1 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.

3 . The method of claim 1 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.

4 . The method of claim 1 , further comprising updating the behavior profile for the user based at least in part on the verification result.

5 . The method of claim 1 , wherein the obtained at least one read or write request is only completed if the verification result is successful.

6 . The method of claim 1 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.

7 . The method of claim 1 , further comprising performing one or more automated remedial actions in response to the verification result.

8 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;

performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:

determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;

initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and

processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.

9 . The apparatus of claim 8 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.

10 . The apparatus of claim 9 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.

11 . The apparatus of claim 8 , further comprising updating the behavior profile for the user based at least in part on the verification result.

12 . The apparatus of claim 8 , wherein the obtained at least one read or write request is only completed if the verification result is successful.

13 . The apparatus of claim 8 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.

14 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining, by a storage controller of a storage system, a behavior profile for a user, wherein the storage system (i) comprises the storage controller, a plurality of storage devices and at least one processing device and (ii) processes one or more of a plurality of read requests and a plurality of write requests directed to one or more of the storage devices, the at least one processing device comprising a processor coupled to a memory, wherein the storage controller learns at least a portion of the behavior profile during a learning period by monitoring one or more of a plurality of the read requests and a plurality of the write requests of the user;

performing the following steps, in response to obtaining, by the storage controller of the storage system, at least one read or write request from the user directed to one or more of the storage devices, of the storage system, that store data associated with the obtained at least one read or write request:

determining, by the storage controller of the storage system, prior to a completion of a processing of the obtained at least one read or write request, whether the obtained at least one read or write request exhibits anomalous user behavior relative to the behavior profile;

initiating, by the storage controller of the storage system, a multi-factor authentication of the user, in response to the determining that the obtained at least one read or write request exhibits anomalous user behavior, to obtain a verification result; and

processing, by the storage controller of the storage system, the obtained at least one read or write request based at least in part on the verification result.

15 . The non-transitory processor-readable storage medium of claim 14 , wherein the obtaining the behavior profile for the user comprises obtaining behavioral information from the user.

16 . The non-transitory processor-readable storage medium of claim 14 , wherein the multi-factor authentication comprises an out-of-band authorization request sent to at least one user associated with the at least one read or write request.

17 . The non-transitory processor-readable storage medium of claim 4 , further comprising updating the behavior profile for the user based at least in part on the verification result.

18 . The non-transitory processor-readable storage medium of claim 14 , wherein the obtained at least one read or write request is only completed if the verification result is successful.

19 . The non-transitory processor-readable storage medium of claim 14 , wherein the determining whether the obtained at least one read or write request exhibits anomalous user behavior employs machine learning techniques.

20 . The apparatus of claim 8 , further comprising performing one or more automated remedial actions in response to the verification result.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2021
From: SHACHAR, TOMER; GEHTMAN, YEVGENI; BALIN, MAXIM
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 056372/0304 →
Continuity (1)
Related Publication 20220382837A1 · Dec 1, 2022
References Cited (30)
US 10108791B1 · Masterman · 2018 [cited by examiner]
US 10587596B1 · Sahar · 2020 [cited by examiner]
US 10592978B1 · Vaystikh · 2020 [cited by examiner]
US 10860382B1 · Sharifi Mehr · 2020 [cited by examiner]
US 11113370B2 · Toth · 2021 [cited by examiner]
US 11170104B1 · Stickle · 2021 [cited by examiner]
US 11176230B2 · Toth · 2021 [cited by examiner]
US 11455641B1 · Shahidzadeh · 2022 [cited by examiner]
US 11552953B1 · Avadhanam · 2023 [cited by examiner]
US 11775623B2 · Toth · 2023 [cited by examiner]
US 11853415B1 · Wainer · 2023 [cited by examiner]
US 12399965B2 · Gelardi · 2025 [cited by examiner]
US 20150106870A1 · Li · 2015 [cited by examiner]
US 20180332071A1 · Ford · 2018 [cited by examiner]
US 20190377853A1 · Obaidi · 2019 [cited by examiner]
US 20200242222A1 · Machani · 2020 [cited by examiner]
US 20200280575A1 · Dean · 2020 [cited by examiner]
US 20200334122A1 · Shepard · 2020 [cited by examiner]
US 20210173930A1 · Dahal · 2021 [cited by examiner]
US 20210200450A1 · Lim · 2021 [cited by examiner]
US 20210209024A1 · Liang · 2021 [cited by examiner]
US 20220138292A1 · Wojnowicz · 2022 [cited by examiner]
US 20220164422A1 · Gelardi · 2022 [cited by examiner]
US 20220182397A1 · Romero Zambrano · 2022 [cited by examiner]
US 20220358235A1 · Gehtman · 2022 [cited by examiner]
US 20220382837A1 · Shachar · 2022 [cited by examiner]
https://www.cisco.com/c/en/us/products/security/what-is-multi-factor-authentication.html#~methods, downloaded Apr. 21, 2021. [cited by applicant]
https://support.huawei.com/enterprise/en/doc/EDOC1100140613/e53e49d7/how-do-i-log-in-to-the-storage-system-through-multi-factor-authentication, downloaded Apr. 21, 2021. [cited by applicant]
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks, downloaded Apr. 21, 2021. [cited by applicant]
https://cloudstorageinfo.org/multi-factor-authentication, downloaded Apr. 21, 2021. [cited by applicant]