IP Library Granted Patent US 12,470,373
Granted Patent B2
US 12,470,373 · App. 18/306,024 · Granted Nov 11, 2025

Improving decentralization of last resort recovery using secrets

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Lee Serfaty (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL)
Assignee: Dell Products L.P.
H04L9/085H04L9/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,373
App. No.
18/306,024
Granted
Nov 11, 2025
Kind
B2
Abstract

Reinstating access to a system of an admin whose certificate is invalid or expired is disclosed using a secret that is remapped. When the admin's certificate is expired, the admin may send a request for reinstatement to tenant admins. The voting operation is based on shares of a secret that have been distributed to validators. When the shares are successfully reconstructed to obtain the secret, the voting operation is affirmed or allowed to proceed. The secret is remapped after a period of time. Remapping the secret includes creating a new secret and distributing new shares of the new secret to a different set of validators.

Claims (32)

1 . A method comprising:

distributing shares of a secret to a set of validators;

after a period of time, remapping the secret to a new set of validators;

distributing the shares of the secret to the new set of validators based on the remapping;

receiving a request for reinstatement from a requestor after the remapping, wherein a voting operation is performed in response to the requestor losing access to the system and the requestor is purporting to be an admin, wherein a certificate of the admin has expired and the admin cannot access the system;

reconstructing the secret from a sufficient number of the shares if the requestor passes identity tests performed by the sufficient number of the set of new validators during the voting operation, wherein the requester is reinstated as an admin if the secret is successfully reconstructed, wherein the sufficient number is at least a majority of the set of new validators.

2 . The method of claim 1 , wherein remapping the secret includes generating a new secret and dividing the new secret into new shares and distributing the new shares to the new set of validators.

3 . The method of claim 2 , further comprising detecting that the requestor is an attacker when the request is related to the secret rather than the new secret or when the request is directed to the set of validators rather than the new set of validators.

4 . The method of claim 1 , wherein the identity tests include log-based tests, identity validation tests, digital asset related tests, and/or geographical validation tests.

5 . The method of claim 1 , wherein the new set of validators includes validators that use different characteristics to perform identity tests.

6 . The method of claim 5 , further comprising organizing the validators into groups, wherein each group is associated with characteristics that are different from characteristics of other groups, wherein at least one validator in each of the groups receives one of the shares.

7 . The method of claim 1 , wherein the validators include other admins, other tenant admins, and/or applications.

8 . The method of claim 1 , further comprising terminating the voting operation when the new secret cannot be reconstructed, when an insufficient number of the new shares are received, and/or one or more of the new shares is counterfeit.

9 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

distributing shares of a secret to a set of validators;

after a period of time, remapping the secret to a new set of validators, wherein remapping the secret includes:

generating a new secret and dividing the new secret into new shares;

distributing the new shares to a new set of validators;

receiving a request for reinstatement from a requestor after the new secret has been generated, wherein a voting operation is performed in response to the requestor losing access to the system and the requestor is purporting to be the admin, wherein a certificate of the admin has expired and the admin cannot access the system;

reconstructing the new secret from a sufficient number of the new shares if the requestor passes identity tests performed by the sufficient number of the set of new validators during the voting operation, wherein the requester is reinstated as an admin if the new secret is successfully reconstructed, wherein the sufficient number is at least a majority of the new set of validators.

10 . The non-transitory storage medium of claim 9 , further comprising detecting that the requestor is an attacker when the request is related to the secret rather than the new secret or when the request is directed to the set of validators rather than the new set of validators.

11 . The non-transitory storage medium of claim 9 , wherein the identity tests include log-based tests, identity validation tests, digital asset related tests, and/or geographical validation tests.

12 . The non-transitory storage medium of claim 9 , wherein the new set of validators includes validators that use different characteristics to perform identity tests.

13 . The non-transitory storage medium of claim 12 , further comprising organizing the validators into groups, wherein each group is associated with characteristics that are different from characteristics of other groups, wherein at least one validator in each of the groups receives one of the shares.

14 . The non-transitory storage medium of claim 9 , wherein the validators include other admins, other tenant admins, and/or applications.

15 . The non-transitory storage medium of claim 9 , further comprising terminating the voting operation when the new secret cannot be reconstructed, when an insufficient number of the new shares are received, and/or one or more of the new shares is counterfeit.

16 . A method comprising:

distributing shares of a secret to a set of validators;

redistributing the shares to a new set of validators or redistributing new shares of a new secret to the new set of validators;

receiving a request for reinstatement from a requestor, wherein the requestor is identified as an attacker if shares of the secret are requested or if the request is directed to the set of validators rather than the new set of validators;

receiving a number of the shares from the validators at a voting engine, wherein each of the validators in the set of validators performs an identity test prior to providing their shares to the voting engine;

reconstructing the secret if a sufficient number of the shares are received from the set of validators, wherein the requester is reinstated as an admin if the new secret is successfully reconstructed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: EZRIELEV, OFIR; SERFATY, LEE; ZOHAR, YEHIEL
To: DELL PRODUCTS L.P.
Reel/Frame 063421/0296 →
Continuity (1)
Related Publication 20240356740A1 · Oct 24, 2024
References Cited (52)
US 6748084B1 · Gau · 2004 [cited by examiner]
US 8181016B1 · Borgia et al. · 2012 [cited by applicant]
US 9652617B1 · Evans et al. · 2017 [cited by applicant]
US 10412097B1 · Banshats et al. · 2019 [cited by applicant]
US 10601816B1 · Stickle et al. · 2020 [cited by applicant]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 11722491B1 · Al-Rashid et al. · 2023 [cited by applicant]
US 11914696B1 · Saxe et al. · 2024 [cited by applicant]
US 12154047B1 · Govindan et al. · 2024 [cited by applicant]
US 12299173B2 · O'Neil et al. · 2025 [cited by applicant]
US 20020184493A1 · Rees · 2002 [cited by applicant]
US 20030159032A1 · Gerck · 2003 [cited by applicant]
US 20070223702A1 · Tengler et al. · 2007 [cited by applicant]
US 20090283597A1 · Charles et al. · 2009 [cited by applicant]
US 20110022883A1 · Hansen · 2011 [cited by applicant]
US 20120016723A1 · Valles et al. · 2012 [cited by applicant]
US 20140195546A1 · Ren · 2014 [cited by applicant]
US 20160140335A1 · Proulx et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20160350874A1 · Santos et al. · 2016 [cited by applicant]
US 20180032750A1 · Hammel · 2018 [cited by applicant]
US 20180241747A1 · Tanaka et al. · 2018 [cited by applicant]
US 20190305938A1 · Sandberg-Maitland et al. · 2019 [cited by applicant]
US 20200036707A1 · Callahan et al. · 2020 [cited by applicant]
US 20200242232A1 · Machani · 2020 [cited by applicant]
US 20200351083A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20200382327A1 · Mokhasi et al. · 2020 [cited by applicant]
US 20200412542A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20210006418A1 · Wei · 2021 [cited by applicant]
US 20210064759A1 · Lomonaco et al. · 2021 [cited by applicant]
US 20210081520A1 · Howarth et al. · 2021 [cited by applicant]
US 20210133359A1 · Liu · 2021 [cited by applicant]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210258298A1 · Pattar et al. · 2021 [cited by applicant]
US 20210289033A1 · Ahuja · 2021 [cited by applicant]
US 20220076253A1 · Chaum · 2022 [cited by applicant]
US 20220076518A1 · Byun · 2022 [cited by applicant]
US 20220182239A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220271933A1 · Chen · 2022 [cited by examiner]
US 20220342980A1 · Myers · 2022 [cited by applicant]
US 20230401307A1 · Pop et al. · 2023 [cited by applicant]
US 20240086550A1 · Tamir et al. · 2024 [cited by applicant]
US 20240154988A1 · Yates · 2024 [cited by applicant]
US 20240163305A1 · Fridman · 2024 [cited by applicant]
US 20240171589A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240171602A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240305643A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240380585A1 · Arora · 2024 [cited by examiner]
WO 2016205886A1 · 2016 [cited by applicant]
Gunther Schiefer et al., “Security in a Distributed Key Management Approach,” 2017, pp. 816-821. (Year: 2017). [cited by applicant]
Mohammad Faraji et al., “Identity Access Management for Multi-tier Cloud Infrastructures,” 2014, pp. 1-9 (Year: 2014). [cited by applicant]