IP Library Granted Patent US 12,556,412
Granted Patent B2
US 12,556,412 · App. 18/308,819 · Granted Feb 17, 2026

Decentralization of last resort recovery using secrets

Inventors: Ofir Ezrielev (Be'er Sheba, IL); Lee Serfaty (Be'er Sheba, IL); Yehiel Zohar (Sderot, IL)
Assignee: Dell Products L.P.
H04L9/3268H04L9/3213H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,412
App. No.
18/308,819
Granted
Feb 17, 2026
Kind
B2
Abstract

Reinstating access to a system of an admin whose certificate is invalid or expired is disclosed. A requestor may send a request for reinstatement to tenant admins. Only some of the tenant admins are authorized. If the request is received by an authorized tenant admin, the voting operation may be performed. If the request is received by an unauthorized tenant admin, the requestor is blocked and the identity of the requestor is stored such that the requestor does not repeat the attack with a different tenant admin. The tenant admins authorized to initiate the voting operation are changed periodically or in another manner.

Claims (28)

1 . A method comprising:

receiving a request, from a requestor, to perform a voting operation to reinstate the requestor as an admin of a computing system;

determining whether a recipient of the request is authorized to initiate the voting operation;

performing the voting operation when the recipient is authorized to initiate the voting operation, wherein the requestor is reinstated as the admin if the voting operation is affirmative and the requestor is not reinstated if the voting operation is not affirmative; and

blocking the requestor when the recipient is not authorized to initiate the voting operation.

2 . The method of claim 1 , wherein the recipient is a tenant admin, and wherein and wherein authorized recipients are known to admins of the computing system, wherein a number of authorized recipients is less than a number of total recipients.

3 . The method of claim 1 , further comprising storing an identity of the requestor in a repository when the recipient is unauthorized.

4 . The method of claim 1 , wherein the recipient is included in first set of authorized recipients, further comprising establishing a second set of authorized recipients, wherein at least some of the recipients in the second set of authorized recipients are different from the recipients in the first set of authorized recipients.

5 . The method of claim 4 , wherein the first set of recipients are not authorized after the second set of authorized recipients are determined.

6 . The method of claim 1 , further comprising periodically changing which recipients are authorized to initiate the voting operation, wherein identities of the authorized recipients are known only to admins of the computing system, wherein the authorized recipients are tenant admins.

7 . The method of claim 1 , further comprising performing the voting operation, wherein the voting operation includes collecting votes from other voters, wherein the voters include tenant admins and/or applications associated with the computing system.

8 . The method of claim 7 , further comprising reinstating the requestor as the admin when the voting operation is affirmative.

9 . The method of claim 1 , further comprising distributing a token to each of the authorized recipients, wherein each of the recipients is unaware of which of the recipients are authorized.

10 . The method of claim 9 , further comprising invalidating the token when selecting a new authorized recipient and distributing a new token to the new authorized recipient.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving a request, from a requestor, to perform a voting operation to reinstate the requestor as an admin of a computing system;

determining whether a recipient of the request is authorized to initiate the voting operation;

performing the voting operation when the recipient is authorized to initiate the voting operation, wherein the requestor is reinstated as the admin if the voting operation is affirmative and the requestor is not reinstated if the voting operation is not affirmative; and

blocking the requestor when the recipient is not authorized to initiate the voting operation.

12 . The non-transitory storage medium of claim 11 , wherein the recipient is a tenant admin, and wherein and wherein authorized recipients are known to admins of the computing system, wherein a number of authorized recipients is less than a number of total recipients.

13 . The non-transitory storage medium of claim 11 , further comprising storing an identity of the requestor in a repository when the recipient is unauthorized.

14 . The non-transitory storage medium of claim 11 , wherein the recipient is included in first set of authorized recipients, further comprising establishing a second set of authorized recipients, wherein at least some of the recipients in the second set of authorized recipients are different from the recipients in the first set of authorized recipients.

15 . The non-transitory storage medium of claim 14 , wherein the first set of recipients are not authorized after the second set of authorized recipients are determined.

16 . The non-transitory storage medium of claim 11 , further comprising periodically changing which recipients are authorized to initiate the voting operation, wherein identities of the authorized recipients are known only to admins of the computing system, wherein the authorized recipients are tenant admins.

17 . The non-transitory storage medium of claim 11 , further comprising performing the voting operation, wherein the voting operation includes collecting votes from other voters, wherein the voters include tenant admins and/or applications associated with the computing system.

18 . The non-transitory storage medium of claim 17 , further comprising reinstating the requestor as the admin when the voting operation is affirmative.

19 . The non-transitory storage medium of claim 11 , further comprising distributing a token to each of the authorized recipients, wherein each of the recipients is unaware of which of the recipients are authorized.

20 . The non-transitory storage medium of claim 19 , further comprising invalidating the token when selecting a new authorized recipient and distributing a new token to the new authorized recipient.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: EZRIELEV, OFIR; SERFATY, LEE; ZOHAR, YEHIEL
To: DELL PRODUCTS L.P.
Reel/Frame 063476/0255 →
Continuity (1)
Related Publication 20240364541A1 · Oct 31, 2024
References Cited (54)
US 6748084B1 · Gau et al. · 2004 [cited by applicant]
US 8181016B1 · Borgia · 2012 [cited by examiner]
US 9652617B1 · Evans · 2017 [cited by examiner]
US 10412097B1 · Banshats et al. · 2019 [cited by applicant]
US 10601816B1 · Stickle · 2020 [cited by examiner]
US 10903991B1 · Craige · 2021 [cited by examiner]
US 11057210B1 · Sierra et al. · 2021 [cited by applicant]
US 11722491B1 · Al-Rashid · 2023 [cited by examiner]
US 11914696B1 · Saxe · 2024 [cited by examiner]
US 12154047B1 · Govindan · 2024 [cited by examiner]
US 12299173B2 · O'Neil et al. · 2025 [cited by applicant]
US 20020184493A1 · Rees · 2002 [cited by applicant]
US 20030159032A1 · Gerck · 2003 [cited by examiner]
US 20070223702A1 · Tengler · 2007 [cited by examiner]
US 20090283597A1 · Charles · 2009 [cited by examiner]
US 20110022883A1 · Hansen · 2011 [cited by examiner]
US 20120016723A1 · Vall A Fontanals · 2012 [cited by examiner]
US 20140195546A1 · Ren · 2014 [cited by applicant]
US 20160140335A1 · Proulx et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20160350874A1 · Santos · 2016 [cited by examiner]
US 20180032750A1 · Hammel · 2018 [cited by applicant]
US 20180241747A1 · Tanaka et al. · 2018 [cited by applicant]
US 20190305938A1 · Sandberg-Maitland · 2019 [cited by examiner]
US 20200036707A1 · Callahan · 2020 [cited by examiner]
US 20200242232A1 · Machani · 2020 [cited by applicant]
US 20200351083A1 · Bartolucci · 2020 [cited by examiner]
US 20200382327A1 · Mokhasi et al. · 2020 [cited by applicant]
US 20200412542A1 · Bartolucci · 2020 [cited by examiner]
US 20210006418A1 · Wei · 2021 [cited by applicant]
US 20210064759A1 · Lomonaco et al. · 2021 [cited by applicant]
US 20210081520A1 · Howarth et al. · 2021 [cited by applicant]
US 20210133359A1 · Liu · 2021 [cited by examiner]
US 20210182423A1 · Padmanabhan · 2021 [cited by examiner]
US 20210258298A1 · Pattar et al. · 2021 [cited by applicant]
US 20210289033A1 · Ahuja · 2021 [cited by examiner]
US 20220076253A1 · Chaum · 2022 [cited by examiner]
US 20220076518A1 · Byun · 2022 [cited by examiner]
US 20220182239A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220271933A1 · Chen et al. · 2022 [cited by applicant]
US 20220342980A1 · Myers · 2022 [cited by applicant]
US 20230401307A1 · Pop · 2023 [cited by examiner]
US 20240086550A1 · Tamir et al. · 2024 [cited by applicant]
US 20240154988A1 · Yates · 2024 [cited by applicant]
US 20240163305A1 · Fridman · 2024 [cited by examiner]
US 20240171589A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240171602A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240305643A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240356740A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240356921A1 · Ezrielev et al. · 2024 [cited by applicant]
US 20240380585A1 · Arora et al. · 2024 [cited by applicant]
WO 2016205886A1 · 2016 [cited by applicant]
Gunther Schiefer et al., “Security in a Distributed Key Management Approach,” 2017, pp. 816-821. (Year: 2017). [cited by applicant]
Mohammad Faraji et al., “Identity Access Management for Multi-tier Cloud Infrastructures,” 2014, pp. 1-9 (Year: 2014). [cited by applicant]