IP Library Granted Patent US 9,779,230
Granted Patent B2
US 9,779,230 · App. 14/852,198 · Granted Oct 3, 2017

System and method for off-host abstraction of multifactor authentication

Inventors: Daniel L. Hamlin (Round Rock, TX); Charles D. Robison, Jr. (Buford, GA); Nicholas D. Grobelny (Austin, TX)
Assignee: DELL PRODUCTS, LP
G06F21/445G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,779,230
App. No.
14/852,198
Filed
Sep 11, 2015
Granted
Oct 3, 2017
Kind
B2
Art Unit
2435
USPC
726/19
Abstract

An information handling system includes a first processor, a second processor, and a third processor. The first processor requests a single-factor authentication from the second processor. The second processor receives a first authentication factor in response to the single-factor authentication request and requests a multi-factor authentication from the third processor. The third processor receives a second authentication factor in response to the multi-factor authentication request and provides the second authentication factor to the second processor. The second processor further verifies the first authentication factor and the second authentication factor and provides a single-factor authentication reply to the first processor in response to verifying the first authentication factor and the second authentication factor.

Claims (48)

1. A method, comprising:

requesting, from a first processor of an information handling system, a single-factor authentication from a second processor of the information handling system;

receiving a first authentication factor in response to the single-factor authentication request;

requesting, from the second processor, a multi-factor authentication from a third processor of the information handling system via a Baseboard Management Controller (BMC) of the information handling system;

receiving a second authentication factor in response to the multi-factor authentication request via the BMC;

providing, from the third processor, the second authentication factor to the second processor;

verifying the first authentication factor and the second authentication factor; and

providing, from the second processor, a single-factor authentication reply to the first processor in response to verifying the first authentication factor and the second authentication factor.

2. The method of claim 1 , further comprising:

instantiating an operating system on the first processor, wherein the single-factor authentication request is from the operating system.

3. The method of claim 2 , wherein the second processor, the third processor, and the BMC are isolated from the operating system.

4. The method of claim 1 , further comprising:

receiving a third authentication factor in response to the multi-factor authentication request;

providing, from the third processor, the third authentication factor to the second processor;

verifying the third authentication factor; and

providing, from the second processor, the single-factor authentication reply to the first processor in further response to verifying the third authentication factor.

5. The method of claim 4 , wherein the third authentication factor includes an authentication credential from a location service.

6. The method of claim 4 , wherein the third authentication factor includes an authentication credential from a direct access service.

7. The method of claim 1 , wherein the first authentication factor includes a template based upon a fingerprint scan.

8. The method of claim 1 , wherein the second authentication factor includes an authentication credential from a Bluetooth radio.

9. An information handling system, comprising:

a first processor;

a second processor;

a third processor; and

a baseboard management controller (BMC);

wherein the first processor requests a single-factor authentication from the second processor, the second processor receives a first authentication factor in response to the single-factor authentication request and requests a multi-factor authentication from the third processor, the third processor receives a second authentication factor in response to the multi-factor authentication request and provides the second authentication factor to the second processor, the second processor verifies the first authentication factor and the second authentication factor and provides a single-factor authentication reply to the first processor in response to verifying the first authentication factor and the second authentication factor, and the second processor requests the multi-factor authentication from the third processor and receives the second authentication factor from the third processor via the BMC.

10. The information handling system of claim 9 , wherein the first processor instantiates an operating system, and the single-factor authentication request is from the operating system.

11. The information handling system of claim 10 , wherein the second processor, the third processor, and the BMC are isolated from the operating system.

12. The information handling system of claim 9 , wherein the third processor receives a third authentication factor in further response to the multi-factor authentication request and provides the third authentication factor to the second processor, and the second processor verifies third authentication factor, and wherein the single-factor authentication reply is in further response to verifying the third authentication factor.

13. The information handling system of claim 12 , wherein the third authentication factor includes an authentication credential from a location service.

14. The information handling system of claim 12 , wherein the third authentication factor includes an authentication credential from a direct access service.

15. The information handling system of claim 9 , wherein the first authentication factor includes a template based upon a fingerprint scan.

16. The information handling system of claim 9 , wherein the second authentication factor includes an authentication credential from a Bluetooth radio.

17. A non-transitory computer-readable medium including code for performing a method, the method comprising:

requesting, from a first processor of an information handling system, a single-factor authentication from a second processor of the information handling system;

receiving a first authentication factor in response to the single-factor authentication request;

requesting, from the second processor, a multi-factor authentication from a third processor of the information handling system via a Baseboard Management Controller (BMC) of the information handling system;

receiving a second authentication factor in response to the multi-factor authentication request via the BMC;

providing, from the third processor, the second authentication factor to the second processor;

verifying the first authentication factor and the second authentication factor; and

providing, from the second processor, a single-factor authentication reply to the first processor in response to verifying the first authentication factor and the second authentication factor.

18. The computer-readable medium of claim 17 , wherein the first authentication factor includes a template based upon a fingerprint scan.

19. The computer-readable medium of claim 17 , wherein the second authentication factor includes an authentication credential from a Bluetooth radio.

20. The computer-readable medium of claim 17 , the method further comprising:

receiving a third authentication factor in response to the multi-factor authentication request;

providing, from the third processor, the third authentication factor to the second processor; and

verifying the third authentication factor;

wherein providing the single-factor authentication reply is in further response to verifying the third authentication factor.

Assignments (16)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE SECOND ASSIGNOR'S NAME PREVIOUSLY RECORDED ON REEL 037092 FRAME 0554. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 7, 2017
From: HAMLIN, DANIEL L.; ROBISON, CHARLES D.; GROBELNY, NICHOLAS D.
To: DELL PRODUCTS, LP
Reel/Frame 041905/0850 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 037160 FRAME 0239 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0115 →
RELEASE OF REEL 037160 FRAME 0142 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0812 →
RELEASE OF REEL 037160 FRAME 0171 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0253 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - TERM LOAN Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037160/0239 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - ABL Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037160/0171 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - NOTES Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 037160/0142 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2015
From: HAMLIN, DANIEL L.; ROBINSON, CHARLES D., JR.; GROBELNY, NICHOLAS D.
To: DELL PRODUCTS, LP
Reel/Frame 037092/0554 →
Continuity (1)
Related Publication 20170076087A1 · Mar 16, 2017