IP Library › Granted Patent US 12,519,796
Granted Patent B2
US 12,519,796 · App. 18/181,086 · Granted Jan 6, 2026

Voting as last resort access recovery for access management

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Lee Serfaty (Be'er Sheba, IL); Yeh'iel Zohar (Sderot, IL)
Assignee: Dell Products L.P.
H04L63/102H04L63/101H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,796
App. No.
18/181,086
Granted
Jan 6, 2026
Kind
B2
Abstract

When expiration of an admin's certificate is determined, an access engine may initiate an operation to restore the admin's access. This may include a voting operation where at least applications in the system vote on whether the entity claiming to be the admin is the admin. In one example, each application vote may be based on whether information provided by the alleged admin can be verified by the application or from the application. If the applications s can verify the identity of the admin may matching information provided by the admin with information in the applications, such as logged information, the admin may be verified and the certificate may be installed. If the vote is successful, one of the tenant admins may be given temporary privileges or permissions to install the admin's new certificate, after which the admin is reinstated and has access to the system.

Claims (26)

1 . A method, comprising:

determining that an entity purporting to be an admin is locked-out of a computing system;

collecting data from the entity that relates to known information about an admin of the computing system known to the computing system, wherein the known information is available from at least applications in the computing system and wherein the known information relates to actions performed by the admin or contextual information associated with the admin in the computing system;

acquiring votes from other admins, wherein the votes from the admins are based on the data collected from the entity;

querying the applications to retrieve information corresponding to the collected data;

determining affirmative votes from the applications and the other admins, wherein each of the applications is counted as an affirmative vote when corresponding information from the application matches a corresponding portion of the collected data; and

authorizing reinstatement of the entity as the admin when the collected data matches the information retrieved from the applications and a number of affirmative votes is above a threshold vote level.

2 . The method of claim 1 , wherein the applications include a logging application and the collected data includes an action most recently performed by the admin or an action performed by the admin within a specified time period, and/or an Internet Protocol address previously used by the admin.

3 . The method of claim 1 , further comprising presenting a user interface to the entity to collect the data.

4 . The method of claim 1 , wherein the data collected from the entity is verifiable by the other admins.

5 . The method of claim 1 , wherein a certificate of the admin has expired and access services, which controls access to the computing system, denies access to the admin.

6 . The method of claim 1 , wherein the system uses a zero-trust strategy.

7 . The method of claim 1 , further comprising installing a new certificate for the admin reinstatement is authorized.

8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

determining that an entity purporting to be an admin is locked-out of a computing system;

collecting data from the entity that relates to known information about an admin of the computing system known to the computing system, wherein the known information is available from at least applications in the computing system and wherein the known information relates to actions performed by the admin or contextual information associated with the admin in the computing system;

acquiring votes from other admins, wherein the votes from the admins are based on the data collected from the entity;

querying the applications to retrieve information corresponding to the collected data;

determining affirmative votes from the applications and the other admins, wherein each of the applications is counted as an affirmative vote when corresponding information from the application matches a corresponding portion of the collected data; and

authorizing reinstatement of the entity as the admin when the collected data matches the information retrieved from the applications and a number of affirmative votes is above a threshold vote level.

9 . The non-transitory storage medium of claim 8 , wherein the applications include a logging application and the collected data includes an action most recently performed by the admin or an action performed by the admin within a specified time period, and/or an Internet Protocol address previously used by the admin.

10 . The non-transitory storage medium of claim 8 , further comprising presenting a user interface to the entity to collect the data.

11 . The non-transitory storage medium of claim 8 , wherein the data collected from the entity is verifiable by the other admins.

12 . The non-transitory storage medium of claim 8 , wherein a certificate of the admin has expired and access services, which controls access to the computing system, denies access to the admin.

13 . The non-transitory storage medium of claim 8 , wherein the system uses a zero-trust strategy.

14 . The non-transitory storage medium of claim 8 , further comprising installing a new certificate for the admin reinstatement is authorized.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2023
From: EZRIELEV, OFIR; SERFATY, LEE; ZOHAR, YEH'IEL
To: DELL PRODUCTS L.P.
Reel/Frame 062933/0315 →
Continuity (1)
Related Publication 20240305643A1 · Sep 12, 2024
References Cited (51)
US 6748084B1 · Gau et al. · 2004 [cited by applicant]
US 8181016B1 · Borgia et al. · 2012 [cited by applicant]
US 9652617B1 · Evans et al. · 2017 [cited by applicant]
US 10412097B1 · Banshats et al. · 2019 [cited by applicant]
US 10601816B1 · Stickle et al. · 2020 [cited by applicant]
US 10903991B1 · Craige et al. · 2021 [cited by applicant]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 11722491B1 · Al-Rashid et al. · 2023 [cited by applicant]
US 11914696B1 · Saxe et al. · 2024 [cited by applicant]
US 12154047B1 · Govindan et al. · 2024 [cited by applicant]
US 12299173B2 · O'Neil et al. · 2025 [cited by applicant]
US 20020184493A1 · Rees · 2002 [cited by examiner]
US 20030159032A1 · Gerck · 2003 [cited by applicant]
US 20070223702A1 · Tengler et al. · 2007 [cited by applicant]
US 20090283597A1 · Charles et al. · 2009 [cited by applicant]
US 20110022883A1 · Hansen · 2011 [cited by applicant]
US 20120016723A1 · Valles et al. · 2012 [cited by applicant]
US 20140195546A1 · Ren · 2014 [cited by examiner]
US 20160140335A1 · Proulx et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani · 2016 [cited by examiner]
US 20160350874A1 · Santos et al. · 2016 [cited by applicant]
US 20180032750A1 · Hammel · 2018 [cited by examiner]
US 20180241747A1 · Tanaka · 2018 [cited by examiner]
US 20190305938A1 · Sandberg-Maitland et al. · 2019 [cited by applicant]
US 20200036707A1 · Callahan et al. · 2020 [cited by applicant]
US 20200242232A1 · Machani · 2020 [cited by applicant]
US 20200351083A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20200382327A1 · Mokhasi · 2020 [cited by examiner]
US 20200412542A1 · Bartolucci et al. · 2020 [cited by applicant]
US 20210006418A1 · Wei · 2021 [cited by examiner]
US 20210064759A1 · Lomonaco · 2021 [cited by examiner]
US 20210081520A1 · Howarth · 2021 [cited by examiner]
US 20210133359A1 · Liu · 2021 [cited by applicant]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210258298A1 · Pattar · 2021 [cited by examiner]
US 20210289033A1 · Ahuja · 2021 [cited by applicant]
US 20220076253A1 · Chaum · 2022 [cited by applicant]
US 20220076518A1 · Byun · 2022 [cited by applicant]
US 20220182239A1 · Hassanzadeh · 2022 [cited by examiner]
US 20220271933A1 · Chen et al. · 2022 [cited by applicant]
US 20220342980A1 · Myers · 2022 [cited by applicant]
US 20230401307A1 · Pop et al. · 2023 [cited by applicant]
US 20240086550A1 · Tamir · 2024 [cited by examiner]
US 20240154988A1 · Yates · 2024 [cited by applicant]
US 20240163305A1 · Fridman · 2024 [cited by examiner]
US 20240171589A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240171602A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240380585A1 · Arora et al. · 2024 [cited by applicant]
WO 2016205886A1 · 2016 [cited by applicant]
Gunther Schiefer et al., “Security in a Distributed Key Management Approach,” 2017, pp. 816-821. (Year: 2017). [cited by examiner]
Mohammad Faraji et al., “Identity Access Management for Multi-tier Cloud Infrastructures,” 2014, pp. 1-9 (Year: 2014). [cited by examiner]