IP Library Granted Patent US 11,755,738
Granted Patent B2
US 11,755,738 · App. 17/355,302 · Granted Sep 12, 2023

Platform framework security state management

Inventors: Daniel L. Hamlin (Round Rock, TX); Vivek Viswanathan Iyer (Austin, TX)
Assignee: Dell Products, L.P.
G06F21/57G06F21/32G06F21/84G06F2221/034G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,738
App. No.
17/355,302
Granted
Sep 12, 2023
Kind
B2
Abstract

Embodiments of systems and methods for platform framework security state management are described. In some embodiments, an Information Handling System (IHS) collects context information that describes logical and physical environments in which the IHS is operating. This context information is used to determine a security state for the IHS. A launch of a resource of the IHS is detected. In response, updated context information is collected that further describes the logical and physical environments. Based on the security state, the launched resource and the updated context information, an updated security state of the IHS is determined. Based on the updated security state, changes are determined to security policies that are used to operate hardware devices of the IHS. Platform framework participants are identified that are registered users of the security polices affected by the updated security state, and these participants are notified of the security policy changes.

Claims (44)

1. An Information Handling System (IHS), comprising:

a plurality of hardware devices, each operated at least in part according to one or more security policies and each operated by one or more registered participants of a platform framework;

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the platform framework of the IHS to:

collect context information describing logical and physical environments in which the IHS is operating, wherein the context information is used to determine a security state for the IHS;

detect a launch of a resource of the IHS;

in response to the detected resource launch, collect updated context information further describing the logical and physical environments in which the IHS is operating;

based on the security state, the launched resource and the updated context information, determine an updated security state for the IHS;

based on the updated security state for the IHS, determine changes to one or more security policies that are used to operate the hardware devices of the IHS;

identify platform framework participants that are registered users of the security polices affected by the changes resulting from the updated security state; and

notify the identified platform framework participants of changes to the security policies that are to be used to operate the hardware devices of the IHS.

2. The IHS of claim 1 , wherein the launched resource comprises at least one of a file and a software application.

3. The IHS of claim 1 , wherein the launched resource comprises a containerized workspace.

4. The IHS of claim 1 , wherein each respective security policy comprises a plurality of communication handles for use in notifying the identified platform framework participants of the changes to the security policy.

5. The IHS of claim 1 , wherein the one or more security policies comprise a policy specifying a type of proximity determination that is utilized by user presence detection capabilities of the IHS.

6. The IHS of claim 5 , wherein the plurality of hardware devices comprises a time-of-flight sensor, and wherein the proximity determination types comprise detecting an individual within a specified distance of the IHS using the time-of-flight sensor.

7. The IHS of claim 1 , wherein the plurality of hardware devices comprises one or more displays, and wherein the one or more security policies comprise a policy specifying events that trigger a privacy capability of the one or more displays.

8. The IHS of claim 7 , wherein the privacy capability that is triggered comprises at least one of dimming the one or more displays and blurring outputs of the one or more displays.

9. The IHS of claim 1 , wherein the context information describing physical environments in which the IHS is operating comprises a location of the IHS.

10. The IHS of claim 9 , wherein the one or more security policies comprise a policy specifying a plurality of networks that are required for use when the IHS is at the location.

11. The IHS of claim 9 , wherein the one or more security policies comprise a policy specifying a requirement for user presence detection capabilities of the IHS to require biometric identification of a user when the IHS is at the location.

12. The IHS of claim 9 , wherein the one or more security policies comprise a policy disabling one or more I/O ports of the IHS when the IHS is at the location.

13. The IHS of claim 9 , wherein the one or more security policies comprise a policy enabling a camera of the IHS when the IHS is at the location of a scheduled event.

14. The IHS of claim 1 , wherein the context information describing physical environments in which the IHS is operating comprises operation of the IHS at the location of a scheduled event.

15. The IHS of claim 1 , wherein the context information describing physical environments in which the IHS is operating comprises operation of the IHS using an external monitor and further comprises detection of multiple individuals in proximity to the IHS, and wherein the one or more security policies comprise a policy that initiates a privacy capability of the IHS.

16. A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

collect context information describing logical and physical environments in which the IHS is operating, wherein the context information is used to determine a security state for the IHS;

detect a launch of a resource of the IHS;

in response to the detected resource launch, collect updated context information further describing the logical and physical environments in which the IHS is operating;

based on the security state, the launched resource and the updated context information, determine an updated security state for the IHS;

based on the updated security state for the IHS, determine changes to one or more security policies that are used to operate hardware devices of the IHS;

identify platform framework participants that are registered users of the security polices affected by the changes resulting from the updated security state; and

notify the identified platform framework participants of changes to the security policies that are to be used to operate the hardware devices of the IHS.

17. The memory storage device of claim 16 , wherein the launched resource comprises at least one of a file and a software application.

18. The memory storage device of claim 16 , wherein the launched resource comprises a containerized workspace.

19. A method, comprising:

collecting context information describing logical and physical environments in which an IHS (Information Handling System) is operating, wherein the context information is used to determine a security state for the IHS;

detecting a launch of a resource of the IHS;

in response to the detected resource launch, collecting updated context information further describing the logical and physical environments in which the IHS is operating;

based on the security state, the launched resource and the updated context information, determining an updated security state for the IHS;

based on the updated security state for the IHS, determining changes to one or more security policies that are used to operate hardware devices of the IHS;

identifying platform framework participants that are registered users of the security polices affected by the changes resulting from the updated security state; and

notifying the identified platform framework participants of changes to the security policies that are to be used to operate the hardware devices of the IHS.

20. The method of claim 19 , wherein the launched resource comprises at least one of a file and a software application.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: HAMLIN, DANIEL L.; IYER, VIVEK VISWANATHAN
To: DELL PRODUCTS, L.P.
Reel/Frame 056631/0113 →
Continuity (1)
Related Publication 20220414221A1 · Dec 29, 2022