IP Library › Granted Patent US 12,659,318
Granted Patent B2
US 12,659,318 · App. 18/635,673 · Granted Jun 16, 2026

Location-aware multi-factor authentication for virtual machine users

Inventors: Ankit Singh (Bangalore, IN); Shrikant U. Hallur (Bangalore, IN); Naveen Awasthy (Bangalore, IN)
Assignee: Dell Products L.P.
H04L63/107G06F9/45558H04L63/08G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,318
App. No.
18/635,673
Granted
Jun 16, 2026
Kind
B2
Abstract

Disclosed systems and methods provide location-aware multi-factor authentication for VM users in combination with the prohibited users lists and disconnecting VMs based on user behavior or activity. Implementations may employ a hypervisor enabled by a lightweight, secure operating system (LSOS) as a foundational, enabling, and OS-agnostic technology for multiple uses cases. An LSOS authenticator module may generate IP location based authentication number for user authentication. An OEM Secure VM manager in Domain0 (Dom0) of a Xen cloud computing model may monitor user activity while Secure OEM Hypercall communication is employed for all communication from VM to LSOS. Embodiments may employ a LSOS VM prohibited users module and hypervisor action module to remove users and destroy VMs based on data received from Dom0, VM Manager and the user module in the VM.

Claims (50)

1 . A method comprising:

responsive to a new user request to add a user as an authorized user of a virtual machine (VM) associated with a hypervisor running on an information handling system:

issuing, by the VM, a secure hypercall to establish a secure connection between the VM and an authenticator;

generating, by the authenticator, an authorization mapping for the user, wherein the authorization mapping is a 2-tuple data structure including:

an authorization number determined by the authenticator and;

location information indicative of an originating location of the new user request; and

storing the authorization mapping to a replay protected memory block (RPMB) within a secure boot partition of a nonvolatile memory (NVM) device of the information handling system; and

performing VM security operations including:

authenticating a VM login associated with the user against the authorization number and the location information corresponding to the user and responsive to detecting a mismatch, adding the user to a prohibited user list for the VM;

monitoring VM activity of the user and responsive to detecting the VM activity satisfying an activity trigger, adding the user to a prohibited user list corresponding to the VM; and

blocking VM access to users included in the prohibited users list.

2 . The method of claim 1 , wherein the location information comprises an IP address corresponding to the new user request.

3 . The method of claim 1 , further comprising storing the authorization mapping to a user database within the a user module of the VM.

4 . The method of claim 1 , wherein monitoring VM activity comprises monitoring VM activity with a VM manager in secure communication with the hypervisor and configured to monitor activity of all users of the VM.

5 . The method of claim 1 , wherein the hypervisor comprise a Xen hypervisor.

6 . The method of claim 5 , wherein the VM manager executes in a domain 0(Dom0) of the Xen hypervisor.

7 . The method of claim 5 , wherein the hypervisor is enabled by a secure, lightweight operating system (OS) including:

a kernel and base rootfs retrieved from the NVM device; and

an external rootfs retrieved from a cloud software development platform.

8 . The method of claim 7 , wherein the authenticator runs in the lightweight OS.

9 . The method of claim 1 , wherein satisfying the activity trigger includes any one or more of:

multiple requests from a single VM; and

network traffic exceeding a maximum permitted traffic volume.

10 . The method of claim 1 , wherein the VM security operations include terminating the VM upon detecting activity satisfying the activity trigger for multiple users of the VM.

11 . An information handling system, comprising:

a central processing unit (CPU);

a memory, including processor executable instructions that, when executed by the CPU, cause the system to perform operations including:

responsive to a new user request to add a user as an authorized user of a virtual machine (VM) associated with a hypervisor running on an information handling system:

issuing, by the VM, a secure hypercall to establish a secure connection between the VM and an authenticator;

generating, by the authenticator, an authorization mapping for the user, wherein the authorization mapping is a 2-tuple data structure including:

an authorization number determined by the authenticator and;

location information indicative of an originating location of the new user request; and

storing the authorization mapping to a replay protected memory block (RPMB) within a secure boot partition of a nonvolatile memory (NVM) device of the information handling system; and

performing VM security operations including:

authenticating a VM login associated with the user against the authorization number and the location information corresponding to the user and responsive to detecting a mismatch, adding the user to a prohibited user list for the VM;

monitoring VM activity of the user and responsive to detecting the VM activity satisfying an activity trigger, adding the user to a prohibited user list corresponding to the VM; and

blocking VM access to users included in the prohibited users list.

12 . The information handling system of claim 11 , wherein the location information comprises an IP address corresponding to the new user request.

13 . The information handling system of claim 11 , further comprising storing the authorization mapping to a user database within the a user module of the VM.

14 . The information handling system of claim 11 , wherein monitoring VM activity comprises monitoring VM activity with a VM manager in secure communication with the hypervisor and configured to monitor activity of all users of the VM.

15 . The information handling system of claim 11 , wherein the hypervisor comprise a Xen hypervisor.

16 . The information handling system of claim 15 , wherein the VM manager executes in a domain 0(Dom0) of the Xen hypervisor.

17 . The information handling system of claim 15 , wherein the hypervisor is enabled by a secure, lightweight operating system (OS) including:

a kernel and base rootfs retrieved from the NVM device; and

an external rootfs retrieved from a cloud software development platform.

18 . The information handling system of claim 17 , wherein the authenticator runs in the lightweight OS.

19 . The information handling system of claim 11 , wherein satisfying the activity trigger includes any one or more of:

multiple requests from a single VM; and

network traffic exceeding a maximum permitted traffic volume.

20 . The information handling system of claim 11 , wherein the VM security operations include terminating the VM upon detecting activity satisfying the activity trigger for multiple users of the VM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2024
From: SINGH, ANKIT; HALLUR, SHRIKANT U.; AWASTHY, NAVEEN
To: DELL PRODUCTS L.P.
Reel/Frame 067109/0759 →
Continuity (1)
Related Publication 20250323920A1 · Oct 16, 2025
References Cited (16)
US 9734325B1 · Neumann · 2017 [cited by examiner]
US 10509663B1 · Unnikrishnan · 2019 [cited by examiner]
US 20110004680A1 · Ryman · 2011 [cited by examiner]
US 20110239213A1 · Aswani · 2011 [cited by examiner]
US 20130086550A1 · Epstein · 2013 [cited by examiner]
US 20130185717A1 · Lakshminarayanan · 2013 [cited by examiner]
US 20130297802A1 · Laribi · 2013 [cited by examiner]
US 20140325515A1 · Salmela · 2014 [cited by examiner]
US 20150128221A1 · Cao · 2015 [cited by examiner]
US 20170147819A1 · Vasilenko · 2017 [cited by examiner]
US 20190370049A1 · Gopalan · 2019 [cited by examiner]
US 20200404002A1 · Patel · 2020 [cited by examiner]
US 20210058306A1 · Szigeti · 2021 [cited by examiner]
US 20210105275A1 · Bansal · 2021 [cited by examiner]
US 20210117249A1 · Doshi · 2021 [cited by examiner]
US 20220171648A1 · Rodriguez · 2022 [cited by examiner]