IP Library Granted Patent US 12,483,542
Granted Patent B2
US 12,483,542 · App. 18/308,795 · Granted Nov 25, 2025

Gradual access recovery in time and authorization

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Lee Serfaty (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL)
Assignee: Dell Products L.P.
H04L63/0823H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,542
App. No.
18/308,795
Granted
Nov 25, 2025
Kind
B2
Abstract

Reinstating access to a system of an admin whose certificate is invalid or expired is disclosed. A requestor may send a request for reinstatement to tenant admins. The initiating tenant admin may initiate a voting operation to reinstate the requestor as an admin of a computing system. During the voting operation, multiple control points are implemented. At each control point, a key of the requestor is verified. The voting operation only proceeds when the key verification is successful. The voting operation is a gradual access recovery process where required keys are revealed over time and in a specific sequence.

Claims (28)

1 . A method comprising:

receiving a request, by a voting entity from a requestor, to perform a voting operation to reinstate the requestor as an admin of a computing system;

performing the voting operation;

at each control point of the voting operation, verifying a key of the requestor, wherein the voting operation continues only when the key provided by the requestor is verified by a voting engine;

when a result of the voting operation to reinstate the requestor as the admin is affirmative and all of the keys provided at the control points were successfully verified, reinstating the requestor as the admin of the computing system.

2 . The method of claim 1 , wherein the control points include at least a first control point and a second control point, wherein the first control point occurs earlier in the voting operation than the second control point.

3 . The method of claim 2 , further comprising verifying a first key at the first control point and returning a first return value to the requestor, wherein the voting operation is terminated if the first key is not successfully verified and/or if the first return value is not verified.

4 . The method of claim 3 , further comprising verifying a second key at the second control point and returning a second return value to the requestor, wherein the voting operation is terminated if the second key is not successfully verified and/or if the second return value is not verified, wherein the second key is different from the first key.

5 . The method of claim 4 , wherein the first return value and the second return value are signed by the voting engine.

6 . The method of claim 4 , wherein the first key and the second key are verified in a single session.

7 . The method of claim 6 , wherein use of the second key before use of the first key terminates the voting operation.

8 . The method of claim 3 , wherein the first key and the second key are single use keys and are invalidated after a single use, wherein use of the first key or the second key out of sequence terminates the voting operation, wherein use of the first key or the second key outside of a single session terminates the voting operation.

9 . The method of claim 1 , further comprising restarting the voting operation if any of the keys are not verified, used out of sequence, or used outside of a single session.

10 . The method of claim 1 , further comprising performing the voting operation by collecting votes from voters, wherein each of the votes are weighted based on one or more of seniority of a voter, traffic volume of the voter, authentication method of the voter, possession of an irrevocable digital asset, and rewards of the voter, wherein the rewards are based on participating in other voting operations.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving a request, by a voting entity from a requestor, to perform a voting operation to reinstate the requestor as an admin of a computing system;

performing the voting operation;

at each control point of the voting operation, verifying a key of the requestor, wherein the voting operation continues only when the key provided by the requestor is verified by a voting engine;

when a result of the voting operation to reinstate the requestor as the admin is affirmative and all of the keys provided at the control points were successfully verified, reinstating the requestor as the admin of the computing system.

12 . The non-transitory storage medium of claim 11 , wherein the control points include at least a first control point and a second control point, wherein the first control point occurs earlier in the voting operation than the second control point.

13 . The non-transitory storage medium of claim 12 , further comprising verifying a first key at the first control point and returning a first return value to the requestor, wherein the voting operation is terminated if the first key is not successfully verified and/or if the first return value is not verified.

14 . The non-transitory storage medium of claim 13 , further comprising verifying a second key at the second control point and returning a second return value to the requestor, wherein the voting operation is terminated if the second key is not successfully verified and/or if the second return value is not verified, wherein the second key is different from the first key.

15 . The non-transitory storage medium of claim 14 , wherein the first return value and the second return value are signed by the voting engine.

16 . The non-transitory storage medium of claim 14 , wherein the first key and the second key are verified in a single session.

17 . The non-transitory storage medium of claim 16 , wherein use of the second key before use of the first key terminates the voting operation.

18 . The non-transitory storage medium of claim 13 , wherein the first key and the second key are single use keys and are invalidated after a single use, wherein use of the first key or the second key out of sequence terminates the voting operation, wherein use of the first key or the second key outside of a single session terminates the voting operation.

19 . The non-transitory storage medium of claim 11 , further comprising restarting the voting operation if any of the keys are not verified, used out of sequence, or used outside of a single session.

20 . The non-transitory storage medium of claim 11 , further comprising performing the voting operation by collecting votes from voters, wherein each of the votes are weighted based on one or more of seniority of a voter, traffic volume of the voter, authentication method of the voter, possession of an irrevocable digital asset, and rewards of the voter, wherein the rewards are based on participating in other voting operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: EZRIELEV, OFIR; SERFATY, LEE; ZOHAR, YEHIEL
To: DELL PRODUCTS L.P.
Reel/Frame 063476/0117 →
Continuity (1)
Related Publication 20240364677A1 · Oct 31, 2024
References Cited (55)
US 6748084B1 · Gau et al. · 2004 [cited by applicant]
US 8181016B1 · Borgia et al. · 2012 [cited by applicant]
US 9652617B1 · Evans et al. · 2017 [cited by applicant]
US 10412097B1 · Banshats et al. · 2019 [cited by applicant]
US 10601816B1 · Stickle · 2020 [cited by examiner]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 11722491B1 · Al-Rashid et al. · 2023 [cited by applicant]
US 11914696B1 · Saxe et al. · 2024 [cited by applicant]
US 12154047B1 · Govindan et al. · 2024 [cited by applicant]
US 12299173B2 · O'Neil · 2025 [cited by examiner]
US 20020184493A1 · Rees · 2002 [cited by applicant]
US 20030159032A1 · Gerck · 2003 [cited by applicant]
US 20070223702A1 · Tengler et al. · 2007 [cited by applicant]
US 20090283597A1 · Charles et al. · 2009 [cited by applicant]
US 20110022883A1 · Hansen · 2011 [cited by examiner]
US 20120016723A1 · Valles et al. · 2012 [cited by applicant]
US 20140195546A1 · Ren · 2014 [cited by applicant]
US 20160140335A1 · Proulx et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20160350874A1 · Santos · 2016 [cited by examiner]
US 20180032750A1 · Hammel · 2018 [cited by applicant]
US 20180241747A1 · Tanaka et al. · 2018 [cited by applicant]
US 20190305938A1 · Sandberg-Maitland et al. · 2019 [cited by applicant]
US 20200036707A1 · Callahan · 2020 [cited by examiner]
US 20200242232A1 · Machani · 2020 [cited by examiner]
US 20200351083A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20200382327A1 · Mokhasi et al. · 2020 [cited by applicant]
US 20200412542A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20210006418A1 · Wei · 2021 [cited by applicant]
US 20210064759A1 · Lomonaco et al. · 2021 [cited by applicant]
US 20210081520A1 · Howarth et al. · 2021 [cited by applicant]
US 20210133359A1 · Liu · 2021 [cited by examiner]
US 20210182423A1 · Padmanabhan · 2021 [cited by examiner]
US 20210258298A1 · Pattar et al. · 2021 [cited by applicant]
US 20210289033A1 · Ahuja · 2021 [cited by applicant]
US 20220076253A1 · Chaum · 2022 [cited by applicant]
US 20220076518A1 · Byun · 2022 [cited by applicant]
US 20220182239A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220271933A1 · Chen et al. · 2022 [cited by applicant]
US 20220342980A1 · Myers · 2022 [cited by applicant]
US 20230401307A1 · Pop · 2023 [cited by examiner]
US 20240086550A1 · Tamir et al. · 2024 [cited by applicant]
US 20240154988A1 · Yates · 2024 [cited by applicant]
US 20240163305A1 · Fridman · 2024 [cited by examiner]
US 20240171589A1 · Ezrielev · 2024 [cited by examiner]
US 20240171602A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240305643A1 · Ezrielev · 2024 [cited by examiner]
US 20240356740A1 · Ezrielev · 2024 [cited by examiner]
US 20240356921A1 · Ezrielev · 2024 [cited by examiner]
US 20240364541A1 · Ezrielev · 2024 [cited by examiner]
US 20240380585A1 · Arora et al. · 2024 [cited by applicant]
WO 2016205886A1 · 2016 [cited by applicant]
Gunther Schiefer et al., “Security in a Distributed Key Management Approach,” 2017, pp. 816-821. (Year: 2017). [cited by applicant]
Mohammad Faraji et al., “Identity Access Management for Multi-tier Cloud Infrastructures,” 2014, pp. 1-9 (Year: 2014). [cited by applicant]