IP Library › Granted Patent US 12,549,345
Granted Patent B2
US 12,549,345 · App. 18/158,648 · Granted Feb 10, 2026

Password reset

Inventors: Chandrasekhar Revuri (Bangalore, IN); Rama Rao Bisa (Bangalore, IN); Bala Balaji Gupta M (Bangalore, IN); Mini Thottunkal Thankappan (Bangalore, IN)
Assignee: Dell Products L.P.
H04L9/0863H04L9/0631H04L9/3226H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,345
App. No.
18/158,648
Granted
Feb 10, 2026
Kind
B2
Abstract

An information handling system may include at least one processor and a memory. The information handling system may be configured to: receive a password reset request associated with a machine identifier of a target information handling system; and in response to the password reset request, provide a payload, wherein the payload includes: an encrypted reset command encrypted with a first key; a wrapped version of the first key, wherein the wrapped version of the first key is encrypted with a public key associated with the target information handling system; and a cryptographic signature; wherein in response to receiving the payload, the target information handling system is configured to verify the cryptographic signature, unwrap the wrapped version of the first key with a private key associated with the public key, decrypt the encrypted reset command, and allow a password reset.

Claims (33)

1 . An information handling system comprising:

at least one processor; and

a memory;

wherein the information handling system is configured to:

receive, at a management website, a password reset request associated with a machine identifier of a target information handling system, wherein the target information handling system is a management controller configured to provide out-of-band management of a host system, and wherein the password reset request is associated with login information for the management website;

verify that the login information is associated with the machine identifier of the target information handling system; and

in response, provide a payload, wherein the payload includes:

an encrypted reset command, wherein a reset command is encrypted with a first key to generate the encrypted reset command;

a wrapped version of the first key, wherein the wrapped version of the first key is encrypted with a public key associated with the target information handling system; and

a cryptographic signature;

wherein in response to receiving the payload, the target information handling system is configured to verify the cryptographic signature, unwrap the wrapped version of the first key with a private key associated with the public key, decrypt the encrypted reset command, execute the reset command to initiate a password reset, and store a record associated with the password reset request, wherein the record is configured to prevent subsequent reuse of the password reset request, and wherein executing the reset command is configured to cause the target system to prompt a user for a new password.

2 . The information handling system of claim 1 , wherein the first key as an AES key.

3 . The information handling system of claim 1 , wherein the cryptographic signature is configured to be verifiable for a predetermined amount of time.

4 . A method comprising:

an information handling system, at a management website, a password reset request associated with a machine identifier of a target information handling system, wherein the target information handling system is a management controller configured to provide out-of-band management of a host system, and wherein the password reset request is associated with login information for the management website;

the information handling system verifying that the login information is associated with the machine identifier of the target information handling system; and

in response, the information handling system providing a payload, wherein the payload includes:

an encrypted reset command, wherein a reset command is encrypted with a first key to generate the encrypted reset command;

a wrapped version of the first key, wherein the wrapped version of the first key is encrypted with a public key associated with the target information handling system; and

a cryptographic signature;

wherein in response to receiving the payload, the target information handling system verifies the cryptographic signature, unwraps the wrapped version of the first key with a private key associated with the public key, decrypts the encrypted reset command, executes the reset command to initiate a password reset, and stores a record associated with the password reset request, wherein the record is configured to prevent subsequent resue of the password reset request, and wherein executing the reset command is configured to cause the target system to prompt a user for a new password.

5 . The method of claim 4 , wherein the first key as an AES key.

6 . The method of claim 4 , wherein the cryptographic signature is configured to be verifiable for a predetermined amount of time.

7 . An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:

receiving, at a management website, a password reset request associated with a machine identifier of a target information handling system, wherein the target information handling system is a management controller configured to provide out-of-band management of a host system, and wherein the password reset request is associated with login information for the management website;

verifying that the login information is associated with the machine identifier of the target information handling system; and

in response, providing a payload, wherein the payload includes:

an encrypted reset command, wherein a reset command is encrypted with a first key to generate the encrypted reset command;

a wrapped version of the first key, wherein the wrapped version of the first key is encrypted with a public key associated with the target information handling system; and

a cryptographic signature;

wherein in response to receiving the payload, the target information handling system is configured to verify the cryptographic signature, unwrap the wrapped version of the first key with a private key associated with the public key, decrypt the encrypted reset command, execute the reset command to initiate a password reset, and store a record associated wit the password reset request, wherein the record is configured to prevent subsequent reuse of the password reset request, and wherein executing the reset command is configured to cause the target system to prompt a user for a new password.

8 . The article of claim 7 , wherein the first key as an AES key.

9 . The article of claim 7 , wherein the cryptographic signature is configured to be verifiable for a predetermined amount of time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2023
From: REVURI, CHANDRASEKHAR; BISA, RAMA RAO; GUPTA M, BALA BALAJI; THANKAPPAN, MINI THOTTUNKAL
To: DELL PRODUCTS L.P.
Reel/Frame 062467/0274 →
Continuity (1)
Related Publication 20240250813A1 · Jul 25, 2024
References Cited (9)
US 10826875B1 · Kim · 2020 [cited by examiner]
US 20130246787A1 · Everett · 2013 [cited by examiner]
US 20140364099A1 · Pai · 2014 [cited by examiner]
US 20200092107A1 · Cole · 2020 [cited by examiner]
US 20200329062A1 · Beauchesne · 2020 [cited by examiner]
US 20210406376A1 · Sayapin · 2021 [cited by examiner]
US 20220393867A1 · Thirumalai · 2022 [cited by examiner]
US 20240054494A1 · Hirshon · 2024 [cited by examiner]
US 20240135040A1 · Vaassen · 2024 [cited by examiner]