IP Library Granted Patent US 8,001,581
Granted Patent B2
US 8,001,581 · App. 12/316,940 · Granted Aug 16, 2011

Methods and systems for embedded user authentication and/or providing computing services using an information handling system configured as a flexible computing node

Assignee: Dell Products L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,001,581
App. No.
12/316,940
Filed
Dec 17, 2008
Granted
Aug 16, 2011
Kind
B2
Art Unit
2434
USPC
726/2
Abstract

Methods and systems for providing embedded user authentication and/or providing computing services using an information handling system configured as flexible computing node, and which may be implemented to perform preboot authentication of users. The flexible computing node may also be configured to provision the appropriate work environment for a given user based on one or more user parameters (e.g. entitlements, location, network connection, and/or other parameters).

Claims (62)

1. A method of operating an information handling system, comprising:

providing an information handling system configured as a flexible computing node, said flexible computing node being coupled to a network and comprising an embedded service operating system (OS), embedded application operating system (OS), a local operating system (OS), and one or more processing devices configured to execute said embedded service operating system (OS), embedded application operating system (OS), and local operating system (OS); and

using said one or more processing devices to execute the following steps:

booting said embedded service OS on said flexible computing node without booting said local OS or said embedded application OS,

then receiving user authentication credentials or user identification information in said embedded service OS from a user,

then presenting received user authentication credentials or user authentication credentials determined based on received user identification information from said embedded service OS across said network to an authentication server,

then using said embedded service OS to determine whether to boot said embedded application OS or to boot said local OS only upon successful authentication of said presented user authentication credentials by said authentication server of said presented user authentication credentials, and

then booting either said embedded application OS or said local OS based on said determination made by said embedded service OS.

2. The method of claim 1 , further comprising using said one or more processing devices to perform the steps of: booting said embedded application OS based on said determination made by said embedded service OS; then determining at least one of device characteristics, location characteristics or network characteristics for the current user session; and then determining a list of available service/connection options based on at least one of device characteristics, location characteristics, network characteristics, or a combination thereof.

3. The method of claim 2 , further comprising using said one or more processing devices to perform the steps of: presenting said determined list of available service/connection options to said user; then receiving a selection of available service/connection options from said user; then presenting a service/connection request to a service provider across said network, said service/connection request comprising said selection of available service/connection options made by said user; and then providing said requested service/connection from said service provider for consumption by said user across said network.

4. The method of claim 3 , wherein said information handling system comprises local system storage; and wherein said method further comprising using said one or more processing devices to perform the steps of: providing said user with the capabilities of both starting a new local virtual machine from said local system storage and starting an application for remote access from a network server across said network.

5. The method of claim 3 , wherein said information handling system comprises local system storage; and wherein said method further comprises using said one or more processing devices to perform the steps of: also booting said local OS based on said determination made by said embedded service OS; and providing a user with a first computing session on said embedded application OS that provides access across said network for said user to a remote computing device in a virtual desktop session while simultaneously providing said user with a separate and second computing session on said local OS.

6. The method of claim 1 , further comprising using said one or more processing devices to perform the steps of: booting said embedded service OS on said flexible computing node in an instant-on manner upon powering on of said flexible computing node; and presenting a logon screen to receive said user authentication credentials or user identification information in said embedded service OS upon booting of said embedded service OS.

7. The method of claim 1 , wherein said information handling system comprises hardware resources; wherein said flexible computing node further comprises a virtual machine monitor configured to run on said one or more processing devices at a level between said network and each of said embedded service operating system (OS), embedded application operating system (OS) and said local operating system (OS); and wherein each of said embedded service operating system (OS), embedded application operating system (OS) and said local operating system (OS) are configured to run on said one or more processing devices at a level between said user and said virtual machine monitor.

8. The method of claim 7 , wherein said method further comprises using said one or more processing devices to perform the steps of: first validating said information handling system hardware prior to booting said embedded service OS on said flexible computing node; and only booting said embedded service OS and said virtual machine monitor on said flexible computing node if said hardware is successfully validated.

9. The method of claim 8 , further comprising using said one or more processing devices to perform the steps of: validating said virtual machine monitor and said embedded service OS after successful validation of said information handling system hardware and prior to booting said embedded service OS and said virtual machine monitor on said flexible computing node; and only booting said embedded service OS and said virtual machine monitor on said flexible computing node if said embedded service OS and virtual machine monitor are each successfully validated on said flexible computing node.

10. An information handling system configured as flexible computing node, comprising:

one or more processing devices;

an embedded service operating system (OS);

an embedded application operating system (OS); and

a local operating system (OS);

wherein said flexible computing node is configured to be coupled to a network; and

wherein said flexible computing node is configured to use said one or more processing devices to:

boot said embedded service OS on said flexible computing node without booting said local OS or said embedded application OS,

then receive user authentication credentials or user identification information in said embedded service OS from a user,

then present received user authentication credentials or user authentication credentials determined based on received user identification information from said embedded service OS across said network to an authentication server,

then use said embedded service OS to determine whether to boot said embedded application OS or to boot said local OS only upon successful authentication of said presented user authentication credentials by said authentication server of said presented user authentication credentials, and

then boot either said embedded application OS or said local OS based on said determination made by said embedded service OS.

11. The information handling system of claim 10 , wherein said flexible computing node furthered configured to use said one or more processing devices to: boot said embedded application OS based on said determination made by said embedded service OS; then determine at least one of device characteristics, location characteristics or network characteristics for the current user session; and then determine a list of available service/connection options based on at least one of device characteristics, location characteristics, network characteristics, or a combination thereof.

12. The information handling system of claim 11 , wherein said flexible computing node is furthered configured to use said one or more processing devices to: present said determined list of available service/connection options to said user; then receive a selection of available service/connection options from said user; then present a service/connection request to a service provider across said network, said service/connection request comprising said selection of available service/connection options made by said user; and then provide said requested service/connection from said service provider for consumption by said user across said network.

13. The information handling system of claim 12 , wherein said information handling system comprises local system storage; and wherein said wherein said flexible computing node is furthered configured to use said one or more processing devices to: provide said user with the capabilities of both starting a new local virtual machine from said local system storage and to start an application for remote access from a network server across said network.

14. The information handling system of claim 12 , wherein said information handling system comprises local system storage; and wherein said flexible computing node is furthered configured to use said one or more processing devices to: also boot said local OS based on said determination made by said embedded service OS, and to provide a user with a first computing session on said embedded application OS that provides access across said network for said user to a remote computing device in a virtual desktop session while simultaneously providing said user with a separate and second computing session on said local OS.

15. The information handling system of claim 10 , wherein said flexible computing node is furthered configured to use said one or more processing devices to: boot said embedded service OS on said flexible computing node in an instant-on manner upon powering on of said flexible computing node; and to present a logon screen to receive said user authentication credentials or said user identification information in said embedded service OS upon booting of said embedded service OS.

16. The information handling system of claim 10 , wherein said information handling system comprises hardware resources; wherein said flexible computing node further comprises a virtual machine monitor configured to run on one or more of said processing devices at a level between said network and each of said embedded service operating system (OS), embedded application operating system (OS) and said local operating system (OS); and wherein each of said embedded service operating system (OS), embedded application operating system (OS) and said local operating system (OS) are configured to run on one or more of said processing devices at a level between said user and said virtual machine monitor.

17. The information handling system of claim 16 , wherein said information handling system comprises an embedded controller (EC); and firmware provided to execute on said EC that is configured to: validate said information handling system hardware prior to booting said embedded service OS on said flexible computing node; and to only boot said embedded service OS and said virtual machine monitor on said flexible computing node if said hardware is successfully validated.

18. The information handling system of claim 17 , wherein said information handling system further comprises firmware provided to execute on said EC that is configured to: validate said virtual machine monitor and said embedded service OS after successful validation of said information handling system hardware and prior to booting said embedded service OS and said virtual machine monitor on said flexible computing node; and to only boot said embedded service OS and said virtual machine monitor on said flexible computing node if said embedded service OS and virtual machine monitor are each successfully validated on said flexible computing node.

19. The information handling system of claim 10 , wherein said information handling system further comprises local system storage, a central processing unit (CPU), and an embedded controller (EC); wherein each of said embedded service OS and said embedded application OS are configured as firmware that execute on said EC; and wherein said local OS is configured as software on said local system storage that executes on said CPU.

20. A method of operating an information handling system, comprising:

providing an information handling system configured as a flexible computing node, said flexible computing node being coupled to a network and comprising a flexible computing client, an embedded application operating system (OS), a local operating system (OS), and further comprising one or more processing devices; and

using said one or more processing devices to execute the following steps with the flexible client without booting said local OS or said embedded application OS:

accepting user authorization credentials or user identification information in said flexible computing client from a user,

then presenting accepted user authorization credentials or accepted user authentication credentials determined based on accepted user identification information from said flexible computing client across said network to an authentication server,

then determining whether to boot said embedded application OS or to boot said local OS only upon successful authentication of said presented user authentication credentials by said authentication server of said presented user authentication credentials; and

then using said one or more processing devices to boot either said embedded application OS or said local OS based on said determination.

21. The method of claim 20 , further comprising using said one or more processing devices to perform the steps of:

compiling a list of one or more authorized computing resources for said user in said flexible computing client based at least in part on said user authorization credentials, and presenting said list of said one or more authorized computing resources for said user upon successful user authentication by said authentication server, and

using said flexible computing client to at least one of connect to said authorized computing resources for said user, present choices of two or more authorized computing resources to said user for connection to said authorized computing resources, or a combination thereof.

22. The method of claim 20 , further comprising using said one or more processing devices to perform the steps of: compiling a list of network connection options from said flexible computing client to said user based on at least one of device characteristics, location characteristics or network characteristics for the current user session; and then allowing said user to select at least one of said network connection options.

23. An information handling system configured as a flexible computing node configured for coupling to a network, said information handling system comprising:

a flexible computing client;

a local operating system (OS);

an embedded application operating system (OS); and

one or more processing devices, said one or more processing devices being configured to execute said flexible computing client to execute the following steps with the flexible client without booting said local OS or said embedded application OS:

accept user authorization credentials or user identification information from a user and present accepted user authorization credentials or user authentication credentials determined based on accepted user identification information across said network to an authentication server,

then determining whether to boot said embedded application OS or to boot said local OS only upon successful authentication of said presented user authentication credentials by said authentication server of said presented user authentication credentials; and

where the one or more processing devices are configured to then boot either said embedded application OS or said local OS based on said determination.

24. The information handling system of claim 23 , wherein said one or more processing devices are further configured to execute said flexible computing client to:

compile and present a list of one or more authorized computing resources to said user upon successful user authentication, said list of one or more authorized computing resources being based at least in part on said user authorization credentials of said user; and

at least one of connect to said authorized computing resources for said user, present choices of two or more authorized computing resources to said user for connection to said authorized computing resources, or a combination thereof.

25. The information handling system of claim 23 , wherein said one or more processing devices are further configured to execute said flexible computing client to:

compile a list of network connection options for said user based on at least one of device characteristics, location characteristics or network characteristics for the current user session;

then present said list of network connection options to said user; and then allow said user to select at least one of said network connection options.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2008
From: FORD, JEREMY; LO, YUAN-CHANG; O'CONNOR, CLINT
To: DELL PRODUCTS, L.P.
Reel/Frame 022054/0830 →
Continuity (1)
Related Publication 20100153697A1 · Jun 17, 2010