IP Library › Granted Patent US 12,225,134
Granted Patent B2
US 12,225,134 · App. 18/047,363 · Granted Feb 11, 2025

Systems and methods for dual hash rolling patch secure authentication

Inventor: Christopher Abella Poblete (Austin, TX)
Assignee: Dell Products, L.P.
H04L9/3226H04L9/3236H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,134
App. No.
18/047,363
Granted
Feb 11, 2025
Kind
B2
Abstract

Embodiments of systems and methods to provide a firmware update to devices configured in a redundant configuration in an Information Handling System (IHS) are disclosed. In an illustrative, non-limiting embodiment, an IHS may include computer-executable instructions to receive a password comprising a first plurality of characters, concatenate a second plurality of characters to the hashed password to form a patched password, encrypt the patched password, and send the hashed patched password to a server IHS for authentication. The second characters are configured to continually change value over time.

Claims (58)

1. A client Information Handling System (IHS) comprising:

at least one processor; and

a memory coupled to the at least one processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the client IHS to:

receive a password comprising a first plurality of characters;

generate a hashed password from the password;

concatenate a second plurality of characters to the hashed password to form a patched password, wherein the second characters are configured to continually change value over time;

encrypt the patched password; and

send the patched password to a server IHS for authentication;

wherein the server IHS comprises:

at least one other processor, and

another memory coupled to the at least one other processor, the other memory having other program instructions stored thereon that, upon execution by the other processor, cause the server IHS to:

obtain a stored version of the first plurality of characters from a data store configured in the server IHS;

concatenate a third plurality of characters to the stored version to form another patched password, wherein the third characters are similar to the second characters;

encrypt the another patched password; and

compare the patched password against the another patched password to determine whether to authenticate the client IHS.

2. The client IHS of claim 1 , wherein the instructions, upon execution, cause the IHS to encrypt the password prior to concatenating the second plurality of characters to the password.

3. The client IHS of claim 1 , wherein the other instructions, upon execution, cause the server IHS to:

when the hashed patched password and the other hashed patched password do not match, reject authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does not exist in a known sources (KS) file stored in the server IHS.

4. The client IHS of claim 1 , wherein the other instructions, upon execution, cause the server IHS to:

when the hashed patched password against the other hashed patched password match, accept authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does exist in a known sources (KS) file stored in the server IHS.

5. The client IHS of claim 1 , wherein the instructions, upon execution, cause the client IHS to encrypt the patched password by generating a hash of the password using a cryptographic hash function, wherein the cryptographic hash function comprises a one-way function.

6. The client IHS of claim 1 , wherein the second characters comprises at least one of letters, numerals, and symbols.

7. The client IHS of claim 1 , wherein the second characters comprise a timestamp generated by a real-time clock of the client IHS.

8. The client IHS of claim 1 , wherein the second characters comprise a token generated by a remotely configured certificate authority (CA).

9. A method comprising:

receiving, by a client Information Handling System (IHS), a password comprising a first plurality of characters;

generating a hashed password from the password;

concatenating, by the client IHS, a second plurality of characters to the hashed password to form a patched password, wherein the second characters are configured to continually change value over time;

encrypting, by the client IHS, the patched password;

sending, by the client IHS, the patched password to a server Information Handling System (IHS) for authentication;

obtaining, by a server IHS, a stored version of the first plurality of characters from a data store configured in the server IHS;

concatenating, by the server IHS, a third plurality of characters to the stored version to form another patched password, wherein the third characters are similar to the second characters;

encrypting, by the server IHS, the another patched password; and

comparing, by the server IHS, the patched password against the another patched password to determine whether to authenticate the client IHS.

10. The method of claim 9 , further comprising encrypting the password prior to concatenating the second plurality of characters to the password.

11. The method of claim 9 , further comprising, when the hashed patched password and the other hashed patched password do not match, rejecting authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does not exist in a known sources (KS) file stored in the server IHS.

12. The method of claim 9 , further comprising, when the hashed patched password against the other hashed patched password match, accepting authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does exist in a known sources (KS) file stored in the server IHS.

13. The method of claim 9 , further comprising encrypting the patched password by generating a hash of the password using a cryptographic hash function, wherein the cryptographic hash function comprises a one-way function.

14. A server Information Handling System (IHS) comprising:

at least one processor; and

a memory coupled to the at least one processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the server IHS to:

obtain a stored version of a first plurality of characters from a data store configured in the server IHS, the first characters comprising a password;

generate a hashed password from the password;

concatenate a stored version of a second plurality of characters to the hashed password to form a patched password, wherein the second characters are configured to continually change value over time;

encrypt the patched password; and

compare the patched password against another patched password obtained from a client IHS to determine whether to authenticate the client IHS;

wherein the client IHS comprises:

at least one other processor; and

another memory coupled to the at least one other processor, the other memory having other program instructions stored thereon that, upon execution by the other processor, cause the client HIS to:

receive the first plurality of characters;

concatenate a third plurality of characters to the first plurality of characters to form another patched password, wherein the third characters are similar to the second characters;

encrypt the another patched password; and

send the another patched password to a server IHS for authentication.

15. The server IHS of claim 14 , wherein the instructions, upon execution, cause the IHS to encrypt the password prior to concatenating the second plurality of characters to the password.

16. The server IHS of claim 14 , wherein the instructions, upon execution, cause the server IHS to:

when the hashed patched password and the other hashed patched password do not match, reject authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does not exist in a known sources (KS) file stored in the server IHS.

17. The server IHS of claim 14 , wherein the other instructions, upon execution, cause the server IHS to:

when the hashed patched password against the other hashed patched password match, accept authentication of the client IHS when the third plurality of characters comprises a token and when an identity of the client IHS does exist in a known sources (KS) file stored in the server IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2022
From: POBLETE, CHRISTOPHER ABELLA
To: DELL PRODUCTS, L.P.
Reel/Frame 061453/0784 →
Continuity (1)
Related Publication 20240129127A1 · Apr 18, 2024
References Cited (104)
US 5666415A · Kaufman · 1997 [cited by examiner]
US 6079021A · Abadi · 2000 [cited by examiner]
US 6230269B1 · Spies · 2001 [cited by examiner]
US 6944296B1 · Liu · 2005 [cited by examiner]
US 6981145B1 · Calvez · 2005 [cited by examiner]
US 6996714B1 · Halasz · 2006 [cited by examiner]
US 7650509B1 · Dunning · 2010 [cited by examiner]
US 8756672B1 · Allen · 2014 [cited by examiner]
US 8868923B1 · Hamlet · 2014 [cited by examiner]
US 8966597B1 · Saylor · 2015 [cited by examiner]
US 9477825B1 · Sinchak · 2016 [cited by examiner]
US 9491164B1 · Fay · 2016 [cited by examiner]
US 9640001B1 · Vazquez · 2017 [cited by examiner]
US 10211992B1 · Tarandach · 2019 [cited by examiner]
US 10878207B1 · Tran · 2020 [cited by examiner]
US 11075931B1 · Warren · 2021 [cited by examiner]
US 11321448B1 · Sanchez · 2022 [cited by examiner]
US 11373172B1 · Griffin · 2022 [cited by examiner]
US 11405189B1 · Bennison · 2022 [cited by examiner]
US 11438378B1 · Dell'Amico · 2022 [cited by examiner]
US 11861545B1 · Atkinson · 2024 [cited by examiner]
US 11936796B1 · Allen · 2024 [cited by examiner]
US 11943215B1 · Nair · 2024 [cited by examiner]
US 20030188012A1 · Ford · 2003 [cited by examiner]
US 20040019786A1 · Zorn · 2004 [cited by examiner]
US 20040146164A1 · Jonas · 2004 [cited by examiner]
US 20040158714A1 · Peyravian · 2004 [cited by examiner]
US 20050250473A1 · Brown · 2005 [cited by examiner]
US 20050259458A1 · Rustagi · 2005 [cited by examiner]
US 20060036857A1 · Hwang · 2006 [cited by examiner]
US 20060195402A1 · Malina · 2006 [cited by examiner]
US 20070006305A1 · Florencio · 2007 [cited by examiner]
US 20070014398A1 · Eldridge · 2007 [cited by examiner]
US 20070157028A1 · Lott · 2007 [cited by examiner]
US 20070198856A1 · Lee · 2007 [cited by examiner]
US 20070204330A1 · Townsley · 2007 [cited by examiner]
US 20070220591A1 · Damodaran · 2007 [cited by examiner]
US 20070283161A1 · Yami · 2007 [cited by examiner]
US 20080244266A1 · Cai · 2008 [cited by examiner]
US 20090060187A1 · Doyle · 2009 [cited by examiner]
US 20090147958A1 · Calcaterra · 2009 [cited by examiner]
US 20090210712A1 · Fort · 2009 [cited by examiner]
US 20100042839A1 · Ho · 2010 [cited by examiner]
US 20100054475A1 · Schneider · 2010 [cited by examiner]
US 20100058060A1 · Schneider · 2010 [cited by examiner]
US 20110040946A1 · Courtney · 2011 [cited by examiner]
US 20110191586A1 · Jung · 2011 [cited by examiner]
US 20120284785A1 · Salkintzis · 2012 [cited by examiner]
US 20130042111A1 · Fiske · 2013 [cited by examiner]
US 20130262867A1 · Evancich · 2013 [cited by examiner]
US 20140032922A1 · Spilman · 2014 [cited by examiner]
US 20140181893A1 · Von Bokern · 2014 [cited by examiner]
US 20140189805A1 · Summers · 2014 [cited by examiner]
US 20160044034A1 · Spilman · 2016 [cited by examiner]
US 20160048836A1 · Sabatier · 2016 [cited by examiner]
US 20160134660A1 · Ponsini · 2016 [cited by examiner]
US 20170063812A1 · Dash · 2017 [cited by examiner]
US 20170178127A1 · Kravitz · 2017 [cited by examiner]
US 20170230372A1 · Weinstein · 2017 [cited by examiner]
US 20170244698A1 · Gale · 2017 [cited by examiner]
US 20170295195A1 · Wettstein · 2017 [cited by examiner]
US 20170317828A1 · Reinhold · 2017 [cited by examiner]
US 20180191688A1 · Chen · 2018 [cited by examiner]
US 20180191702A1 · Padmanabhan · 2018 [cited by examiner]
US 20180247071A1 · Resch · 2018 [cited by examiner]
US 20180288019A1 · Dinia · 2018 [cited by examiner]
US 20190013945A1 · Hamlin · 2019 [cited by examiner]
US 20190180046A1 · Goenka · 2019 [cited by examiner]
US 20190220618A1 · Ocher · 2019 [cited by examiner]
US 20190268317A1 · Haelion · 2019 [cited by examiner]
US 20190305938A1 · Sandberg-Maitland · 2019 [cited by examiner]
US 20190364041A1 · Durski · 2019 [cited by examiner]
US 20200127837A1 · Kaladgi · 2020 [cited by examiner]
US 20200132761A1 · Rahardjo · 2020 [cited by examiner]
US 20200145498A1 · Grayson · 2020 [cited by examiner]
US 20200242256A1 · Kaczynski · 2020 [cited by examiner]
US 20200295939A1 · Matovsky · 2020 [cited by examiner]
US 20200366669A1 · Gupta · 2020 [cited by examiner]
US 20200374277A1 · Fuka · 2020 [cited by examiner]
US 20210067322A1 · Hazan · 2021 [cited by examiner]
US 20210099302A1 · Lavery · 2021 [cited by examiner]
US 20210157939A1 · Bilger · 2021 [cited by examiner]
US 20210273800A1 · Hassani · 2021 [cited by examiner]
US 20210314176A1 · Cambou · 2021 [cited by examiner]
US 20220070000A1 · Gondza · 2022 [cited by examiner]
US 20220108314A1 · Mehta · 2022 [cited by examiner]
US 20220198059A1 · Hatcher · 2022 [cited by examiner]
US 20220263668A1 · Autiosalo · 2022 [cited by examiner]
US 20220286446A1 · Hecht · 2022 [cited by examiner]
US 20220294778A1 · Li · 2022 [cited by examiner]
US 20220300478A1 · Scott · 2022 [cited by examiner]
US 20220311597A1 · Goel · 2022 [cited by examiner]
US 20220336096A1 · Sanigepalli · 2022 [cited by examiner]
US 20220338005A1 · Tamai · 2022 [cited by examiner]
US 20220374896A1 · Ma · 2022 [cited by examiner]
US 20220413876A1 · Rajagopal · 2022 [cited by examiner]
US 20230012084A1 · Herrero · 2023 [cited by examiner]
US 20230082633A1 · Seletskiy · 2023 [cited by examiner]
US 20230103698A1 · Hayami · 2023 [cited by examiner]
US 20230222205A1 · Nambannor Kunnath · 2023 [cited by examiner]
US 20230247436A1 · Boettger · 2023 [cited by examiner]
US 20230264709A1 · Wang · 2023 [cited by examiner]
US 20230283285A1 · Paxton · 2023 [cited by examiner]
US 20240045981A1 · Santaus · 2024 [cited by examiner]