IP Library › Granted Patent US 12,519,798
Granted Patent B2
US 12,519,798 · App. 18/363,191 · Granted Jan 6, 2026

Resource access using a trust scoring framework in a zero-trust computing environment

Inventors: Deepak Gaikwad (Natick, MA); Judith A. Furlong (Natick, MA); Raj Suryavanshi (Leander, TX); Biraj Silwal (Pflugerville, TX); Berke Belge (Westford, MA); Chenhao Huang (Acton, MA); Sarthak Madrecha (Milpitas, CA)
Assignee: Dell Products, L.P.
H04L63/102G06F9/45558H04L63/20G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,798
App. No.
18/363,191
Granted
Jan 6, 2026
Kind
B2
Abstract

Systems and methods are provided for controlling access to resources in a zero-trust computing environment. Requests for access to resources of the zero-trust environment are tracked, including tracking determinations to grant or deny access to resources of the environment. A trust score is calculated for a resource based on users requesting access to the resource, hardware components requesting access to the resource, software applications requesting access to the resource, networks used to request access to the resource and data exposed by providing the requested access to the resource. The trust score of the resource is adjusted upwards based on determinations to grant access to the resource and downwards based on determinations to deny access to the resource. Request for access to the resource are evaluated based on policies of the zero-trust environment that govern access to the resource, based in part on the adjusted trust score of the resource.

Claims (37)

1 . A method for controlling access to resources in a zero-trust computing environment, the method comprising:

tracking requests for access to a plurality of resources of the zero-trust computing environment, wherein the tracking comprises monitoring determinations to grant access to a first of the plurality of resources and monitoring determinations to deny access to the first resource;

calculating a trust score for the first resource, where the trust score is calculated based on users requesting access to the first resource, hardware components requesting access to the first resource, software applications requesting access to the first resource, and networks that have issued requests for access to the first resource;

adjusting the trust score of the first resource upwards based on the determinations to grant access to the first resource and adjusting the trust score of the first resource downwards based on the determinations to deny access to the first resource;

receiving a request from a first user for access to the first resource; and

evaluating the request from the first user based on one or more policies of the zero-trust computing environment that govern access to the first resource, where a first policy grants access to the first resource based in part on the adjusted trust score of the first resource.

2 . The method of claim 1 , wherein the trust score for the first resource is adjusted upwards according to a first weight assigned to the first resource.

3 . The method of claim 2 , wherein the first weight is assigned to the first resource based on a classification of the trust score of the first resource.

4 . The method of claim 1 , wherein the first resource comprises data, and wherein the granted access comprises granted access to read the data, and wherein the trust score for the first resource is adjusted upwards by a first amount.

5 . The method of claim 4 , wherein the granted access comprises granted access to update the data, and wherein the trust score for the first resource is adjusted upwards by a second amount that is smaller than the first amount.

6 . The method of claim 5 , wherein the granted access comprises granting access to delete the data, and wherein the trust score for the first resource is adjusted upwards by a third amount that is smaller than the second amount.

7 . The method of claim 1 , wherein the first resource comprises data, and wherein the denied access comprises denied access to read the data, and wherein the trust score for the first resource is adjusted downwards by a first amount.

8 . The method of claim 7 , wherein the denied access comprises denied access to update the data, and wherein the trust score for the first resource is adjusted downwards by a second amount that is greater than the first amount.

9 . The method of claim 8 , wherein the denied access comprises denied access to delete the data, and wherein the trust score for the first resource is adjusted downwards by a third amount that is greater than the second amount.

10 . The method of claim 1 , wherein the first resource of the zero-trust environment is a member of a first group of zero-trust resources and wherein the method further comprises: calculating a trust score for the first group of zero-trust resources and adjusting the trust score for the first group of zero-trust resources upwards based on a determination to grant access to the first resource.

11 . The method of claim 1 , wherein the first resource comprises a hardware component, and wherein the granted access comprises granted access to modify data used by the hardware component, and wherein the trust score for the hardware component is adjusted upwards by a first amount.

12 . The method of claim 11 , wherein the first resource of the zero-trust environment comprises a virtualized resource and wherein the granted access comprises granted access to modify data used by the virtualized resource, and wherein the trust score for the virtualized resource is adjusted upwards by a second amount that is less than the first amount.

13 . The method of claim 12 , wherein the virtualized resource comprises a virtual machine and wherein the trust score for the virtual machine is adjusted upwards based on granted requests to operate a virtual machine.

14 . The method of claim 13 , wherein the trust score for the virtual machine is adjusted downwards based on a denied request to upload instructions for use by the virtual machine.

15 . An IHS (Information Handling System) operating in support of a zero-trust computing environment, the IHS comprising:

one or more CPUs (Central Processing Units); and

one or more memory devices having instructions stored thereon that, upon execution by a CPU, cause the IHS to:

track requests for access to a plurality of resources of the zero-trust computing environment, wherein the tracking comprises monitoring determinations to grant access to a first of the plurality of resources and monitoring determinations to deny access to the first resource;

calculate a trust score for the first resource, where the trust score is calculated based on users requesting access to the first resource, hardware components requesting access to the first resource, software applications requesting access to the first resource, and networks that have issued requests for access to the first resource;

adjust the trust score of the first resource upwards based on the determinations to grant access to the first resource and adjusting the trust score of the first resource downwards based on the determinations to deny access to the first resource;

receive a request from a first user for access to the first resource; and

evaluate the request from the first user based on one or more policies of the zero-trust computing environment that govern access to the first resource, where a first policy grants access to the first resource based in part on the adjusted trust score of the first resource.

16 . The IHS of claim 15 , wherein the first resource of the zero-trust environment comprises at least one of a hardware component, a software application and a data element.

17 . The IHS of claim 15 , wherein the first resource comprises a hardware component of the IHS, and wherein the granted access comprises granted access to modify data used by the hardware component, and wherein the trust score for the hardware component is adjusted upwards by a first amount.

18 . The IHS of claim 17 , wherein the first resource of the zero-trust environment comprises a virtualized resource and wherein the granted access comprises granted access to modify data used by the virtualized resource, and wherein the trust score for the virtualized resource is adjusted upwards by a second amount that is less than the first amount.

19 . The IHS of claim 18 , wherein the virtualized resource comprises a virtual machine and wherein the trust score for the virtual machine is adjusted based on users other than the first user accessing the virtual machine.

20 . A computer-readable storage device operating within a zero-trust computing environment and having program instructions stored thereon that, upon execution by one or more processors, cause the one or more processors to:

track requests for access to a plurality of resources of the zero-trust computing environment, wherein the tracking comprises monitoring determinations to grant access to a first of the plurality of resources and monitoring determinations to deny access to the first resource;

calculate a trust score for the first resource, where the trust score is calculated based on users requesting access to the first resource, hardware components requesting access to the first resource, software applications requesting access to the first resource, and networks that have issued requests for access to the first resource;

adjust the trust score of the first resource upwards based on the determinations to grant access to the first resource and adjusting the trust score of the first resource downwards based on the determinations to deny access to the first resource;

receive a request from a first user for access to the first resource; and

evaluate the request from the first user based on one or more policies of the zero-trust computing environment that govern access to the first resource, where a first policy grants access to the first resource based in part on the adjusted trust score of the first resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: GAIKWAD, DEEPAK; FURLONG, JUDITH A.; SURYAVANSHI, RAJ; SILWAL, BIRAJ; BELGE, BERKE; HUANG, CHENHAO; MADRECHA, SARTHAK
To: DELL PRODUCTS, L.P.
Reel/Frame 064450/0391 →
Continuity (1)
Related Publication 20250047679A1 · Feb 6, 2025
References Cited (4)
US 20230188527A1 · O'Neill · 2023 [cited by examiner]
US 20230300150A1 · O'Neill · 2023 [cited by examiner]
US 20240223589A1 · Grammel · 2024 [cited by examiner]
US 20240388901A1 · Gandhi · 2024 [cited by examiner]