IP Library Granted Patent US 12,563,046
Granted Patent B2
US 12,563,046 · App. 18/057,287 · Granted Feb 24, 2026

Voting as last resort access recovery for common identity and access management

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Lee Serfaty (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL)
Assignee: Dell Products L.P.
H04L63/108H04L63/0823H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,046
App. No.
18/057,287
Granted
Feb 24, 2026
Kind
B2
Abstract

Reinstating access to a system of an admin whose certificate is invalid or expired is disclosed. When the admin's certificate is expired, the admin may send a request for reinstatement to tenant admins. One of the tenant admins, if satisfied as to the admin's identity, can invoke a voting operation that allows the tenant admins to vote on whether to reinstate the admin. If the vote is successful, one of the tenant admins is given temporary privileges or permissions to install the admin's new certificate, after which the admin is reinstated and has access to the system.

Claims (29)

1 . A method comprising:

evaluating a request for reinstatement to a system received by a tenant admin from an admin, wherein the admin has lost access to the system, wherein evaluating the request for reinstatement comprises verifying an identify of the admin, wherein the request is received from the admin via a separate communication channel and includes a new certificate of the admin to be installed if the reinstatement is authorized, and wherein receipt of the request by the tenant admin is sufficient for the tenant admin to verify the identity of the admin to the tenant admin;

in response to evaluating the request for reinstatement, receiving a request to perform a voting operation at a voting engine from the tenant admin, wherein the voting operation includes a vote to reinstate access of the admin to a system and is performed in response to the admin response to the admin losing the access to the system, wherein the voting operation is initiated only after confirming that no administrator has valid certificate-based or basic authentication access to the system, and wherein the request to perform the voting operation includes information documenting how the tenant admin verified the identity of the admin;

performing the voting operation by notifying other tenant admins of the request and providing the tenant admins with a voting mechanism;

authorizing to reinstate the admin if votes are above a threshold vote level; and

installing the new certificate of the admin by the tenant admin to reinstate the admin, wherein the tenant admin is granted temporary permissions and privileges solely to install the new certificate, and wherein the temporary privileges are executable a single time and revoked automatically after the certificate installation reinstating the admin.

2 . The method of claim 1 , wherein the system comprises access services for tenants.

3 . The method of claim 1 , wherein the request for reinstatement is received via email, text, telephone, or via an electronic mechanism.

4 . The method of claim 1 , wherein a certificate of the admin has expired and the admin cannot access the system.

5 . The method of claim 1 , wherein the voting operation is performed over a REST API.

6 . The method of claim 1 , wherein the system uses a zero-trust strategy.

7 . The method of claim 1 , wherein the request to perform the voting operation is performed via a device of the tenant admin.

8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

evaluating a request for reinstatement to a system received by a tenant admin from an admin, wherein the admin has lost access to the system, wherein evaluating the request for reinstatement comprises verifying an identify of the admin, wherein the request is received from the admin via a separate communication channel and includes a new certificate of the admin to be installed if reinstatement is authorized, and wherein receipt of the request by the tenant admin user is sufficient for the tenant admin to verify the identity of the admin to the tenant admin;

in response to evaluating the request for reinstatement, receiving a request to perform a voting operation at a voting engine from the tenant admin, wherein the voting operation includes a vote to reinstate access of the admin to a system and is performed in response to the admin response to the admin losing the access to the system, wherein the voting operation is initiated only after confirming that no administrator has valid certificate-based or basic authentication access to the system, and wherein the request to perform the voting operation includes information documenting how the tenant admin verified the identity of the admin;

performing the voting operation by notifying other tenant admins of the request and providing the tenant admins with a voting mechanism; authorizing to reinstate the admin if votes are above a threshold vote level; and

installing the new certificate of the admin by the tenant admin to reinstate the admin, wherein the tenant admin is granted temporary permissions and privileges solely to install the new certificate, and wherein the temporary privileges are executable a single time and revoked automatically after the certificate installation reinstating the admin.

9 . The non-transitory storage medium of claim 8 , wherein the system comprises access services for tenants.

10 . The non-transitory storage medium of claim 8 , wherein the request for reinstatement is received via email, text, telephone, or via an electronic mechanism.

11 . The non-transitory storage medium of claim 8 , wherein a certificate of the admin has expired and the admin cannot access the system.

12 . The non-transitory storage medium of claim 8 , wherein the voting operation is performed over a REST API.

13 . The non-transitory storage medium of claim 8 , wherein the system uses a zero-trust strategy.

14 . The non-transitory storage medium of claim 8 , wherein the request to perform the voting operation is performed via a device of the tenant admin.

15 . A method comprising: evaluating a request for reinstatement from an admin by a tenant admin, wherein a certificate of the admin needed to manage access services has expired, wherein the request is received by the tenant admin via a separate communication channel from the access services and includes a new certificate of the admin to be installed if reinstatement is authorized, wherein receipt of the request by the tenant admin is sufficient for the tenant admin to verify the identity of the admin;

verifying, by the tenant admin, an identity of the admin;

receiving a request to perform a voting operation at a voting engine from the tenant admin, wherein the voting operation includes a vote to reinstate access of the admin to the access services, wherein the voting operation is initiated only after confirming that no administrator has valid certificate-based or basic authentication access to the access services, and wherein the request to perform the voting operation includes information documenting how the tenant admin verified the identity of the admin;

performing the voting operation by notifying other tenant admins of the request for reinstatement and providing the tenant admin and the other tenant admins with a voting mechanism;

authorizing to reinstate the admin if votes are above a threshold vote level; and installing a new certificate for the admin, by the tenant admin to reinstate the admin to the access services, wherein the tenant admin is granted temporary permissions and privileges solely to install the new certificate, and wherein the temporary privileges are executable a single time and revoked automatically after the certificate installation.

16 . The method of claim 15 , wherein privileges and permissions granted to the tenant admin to install the new certificate in the access services is revoked after the new certificate is installed in the access services.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2022
From: EZRIELEV, OFIR; SERFATY, LEE; ZOHAR, YEHIEL
To: DELL PRODUCTS L.P.
Reel/Frame 061837/0849 →
Continuity (1)
Related Publication 20240171589A1 · May 23, 2024
References Cited (50)
US 6748084B1 · Gau et al. · 2004 [cited by applicant]
US 8181016B1 · Borgia et al. · 2012 [cited by applicant]
US 9652617B1 · Evans et al. · 2017 [cited by applicant]
US 10412097B1 · Banshats · 2019 [cited by examiner]
US 10601816B1 · Stickle · 2020 [cited by examiner]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 11722491B1 · Al-Rashid et al. · 2023 [cited by applicant]
US 11914696B1 · Saxe et al. · 2024 [cited by applicant]
US 12154047B1 · Govindan et al. · 2024 [cited by applicant]
US 12299173B2 · O'Neil et al. · 2025 [cited by applicant]
US 20020184493A1 · Rees · 2002 [cited by applicant]
US 20030159032A1 · Gerck · 2003 [cited by applicant]
US 20070223702A1 · Tengler et al. · 2007 [cited by applicant]
US 20090283597A1 · Charles et al. · 2009 [cited by applicant]
US 20110022883A1 · Hansen · 2011 [cited by applicant]
US 20120016723A1 · Valles et al. · 2012 [cited by applicant]
US 20140195546A1 · Ren · 2014 [cited by applicant]
US 20160140335A1 · Proulx et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20160350874A1 · Santos · 2016 [cited by examiner]
US 20180032750A1 · Hammel · 2018 [cited by applicant]
US 20180241747A1 · Tanaka et al. · 2018 [cited by applicant]
US 20190305938A1 · Sandberg-Maitland et al. · 2019 [cited by applicant]
US 20200036707A1 · Callahan et al. · 2020 [cited by applicant]
US 20200242232A1 · Machani · 2020 [cited by applicant]
US 20200351083A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20200382327A1 · Mokhasi et al. · 2020 [cited by applicant]
US 20200412542A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20210006418A1 · Wei · 2021 [cited by applicant]
US 20210064759A1 · Lomonaco et al. · 2021 [cited by applicant]
US 20210081520A1 · Howarth et al. · 2021 [cited by applicant]
US 20210133359A1 · Liu · 2021 [cited by examiner]
US 20210182423A1 · Padmanabhan · 2021 [cited by examiner]
US 20210258298A1 · Pattar et al. · 2021 [cited by applicant]
US 20210289033A1 · Ahuja · 2021 [cited by applicant]
US 20220076253A1 · Chaum · 2022 [cited by applicant]
US 20220076518A1 · Byun · 2022 [cited by applicant]
US 20220182239A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220271933A1 · Chen et al. · 2022 [cited by applicant]
US 20220342980A1 · Myers · 2022 [cited by examiner]
US 20230401307A1 · Pop · 2023 [cited by examiner]
US 20240086550A1 · Tamir et al. · 2024 [cited by applicant]
US 20240154988A1 · Yates · 2024 [cited by applicant]
US 20240163305A1 · Fridman · 2024 [cited by examiner]
US 20240171602A1 · Ezrielev · 2024 [cited by examiner]
US 20240380585A1 · Arora et al. · 2024 [cited by applicant]
WO 2016205886A1 · 2016 [cited by applicant]
Gunther Schiefer et al., “Security in a Distributed Key Management Approach,” 2017, pp. 816-821. (Year: 2017). [cited by applicant]
Mohammad Faraji et al., “Identity Access Management for Multi-tier Cloud Infrastructures,” 2014, pp. 1-9 (Year: 2014). [cited by applicant]