IP Library Granted Patent US 9,894,062
Granted Patent B2
US 9,894,062 · App. 15/071,628 · Granted Feb 13, 2018

Object management for external off-host authentication processing systems

Inventors: Charles D. Robison (Buford, GA); Daniel L. Hamlin (Round Rock, TX)
Assignee: Dell Products, L.P.
H04L63/0853H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,894,062
App. No.
15/071,628
Granted
Feb 13, 2018
Kind
B2
Abstract

Systems and methods for providing object management for external off-host authentication processing systems are described. In some embodiments, a method may include: identifying, by an Information Handling System (IHS), raw data to be stored within an object in an off-host memory of an external off-host authentication processing system coupled to the IHS, wherein the external off-host authentication processing system provides a hardware environment segregated from the IHS; collecting authentication data from a user by prompting the user; generating a system identification (ID) that uniquely characterizes the IHS without prompting the user; and storing the authentication data, the system ID, and the raw data as part of the object in the off-host memory.

Claims (50)

1. A method, comprising:

identifying, by an Information Handling System (IHS), raw data to be stored within an object in an off-host memory of an external off-host authentication processing system coupled to the IHS, wherein the external off-host authentication processing system provides a hardware environment segregated from the IHS;

collecting authentication data from a user by prompting the user;

silently generating a system identification (ID) that uniquely characterizes the IHS without prompting the user;

storing the authentication data, the system ID, and the raw data as part of the object in the off-host memory;

receiving, at the external off-host authentication processing system, a request from a calling application executed by the IHS to access the object stored in the off-host memory;

making a call, via a protected Application Programming Interface (API), to retrieve the object;

collecting, via the IHS, new authentication data from a user by prompting the user;

silently generating, via the IHS, a new system ID without prompting the user;

determining, by the external off-host authentication processing system, that the new authentication data and new system ID match the authentication data and system ID stored in the object; and

retrieving, by the external off-host authentication processing system, the object from the off-host memory.

2. The method of claim 1 , wherein the raw data includes an encryption key or fingerprint template.

3. The method of claim 1 , wherein the authentication data includes a fingerprint template, a magnetic card scan, a Radio Frequency Identification (RFID) scan, a Smart Card scan, a face recognition template, an iris template, a certificate, or a passcode.

4. The method of claim 1 , wherein generating the system ID includes retrieving or generating an identification of a hardware component of the IHS.

5. The method of claim 4 , wherein the system ID includes an identification of a Central Processing Unit (CPU) of the IHS.

6. The method of claim 1 , wherein generating the system ID includes retrieving or generating an identification or signature of a software component installed in the IHS.

7. The method of claim 1 , wherein the external off-host authentication processing system is coupled to the IHS using a protocol that cryptographically tie communications between the external off-host authentication processing system and an embedded controller (EC) of the IHS without intervention by any Operating System (OS) executed by the IHS.

8. The method of claim 1 , further comprising:

receiving, at the external off-host authentication processing system, a request from a calling application executed by the IHS to access the object stored in the off-host memory;

collecting, via another IHS, new authentication data from a user by prompting the user;

generating, via the other IHS, a new system ID without prompting the user;

determining, by the external off-host authentication processing system, that the new authentication data matches the authentication data stored in the object but that the new system ID does not match the system ID stored in the object; and

denying the request.

9. An external off-host authentication processing system, comprising:

an off-host processor; and

a non-transitory, off-host memory coupled to the off-host processor, the off-host memory having program instructions stored thereon that, upon execution by the off-host processor, cause the external off-host authentication processing system to:

receive, from an Information Handling System (IHS) coupled to the external off-host authentication processing system, raw data, authentication data, and a system ID, wherein the authentication data is collected via the IHS by prompting a user, and wherein the system ID is silently generated via the IHS without prompting the user;

store the authentication data, the system ID, and the raw data as part of an object in the off-host memory;

receive a request from a calling application executed by the IHS to access the object stored in the off-host memory, wherein the request includes new authentication data obtained by the IHS from a user by prompting the user and a new system ID silently obtained by the IHS without prompting the user;

determine that the new authentication data and new system ID match the authentication data and system ID stored in the object; and

retrieve the object from the off-host memory.

10. The external off-host authentication processing system of claim 9 , wherein the raw data includes an encryption key or fingerprint template.

11. The external off-host authentication processing system of claim 9 , wherein the system ID includes an identification of a hardware or software component of the IHS.

12. The external off-host authentication processing system of claim 9 , wherein the IHS comprises an embedded controller coupled to a processor, wherein the external off-host authentication processing system is coupled to the embedded controller, and wherein the external off-host authentication processing system provides a hardware environment segregated from the processor.

13. The external off-host authentication processing system of claim 9 , wherein the program instructions, upon execution by the off-host processor, further cause the external off-host authentication processing system to:

receive a request from a calling application executed by another IHS to access the object stored in the off-host memory, wherein the request includes new authentication data obtained by the other IHS from a user by prompting the user and a new system ID obtained by the other IHS without prompting the user;

determine that the new authentication data matches the authentication data stored in the object but that the new system ID does not match the system ID stored in the object; and

deny the request.

14. A non-transitory, off-host memory having program instructions stored thereon that, upon execution by an off-host processor of an external off-host authentication processing system, further cause the external off-host authentication processing system to:

receive, from an Information Handling System (IHS) coupled to the external off-host authentication processing system, raw data, authentication data, and a system ID, wherein the authentication data is collected via the IHS by prompting a user, and wherein the system ID is silently generated via the IHS without prompting the user;

store the authentication data, the system ID, and the raw data as part of an object in the off-host memory;

receive a request from a calling application executed by the IHS to access the object stored in the off-host memory, wherein the request includes new authentication data obtained by the IHS from a user by prompting the user and a new system ID silently obtained by the IHS without prompting the user;

determine that the new authentication data and new system ID match the authentication data and system ID stored in the object; and

retrieve the object from the off-host memory.

15. The off-host memory of claim 14 , wherein the system ID includes an identification of a hardware component or a software component installed in the IHS.

16. The external off-host authentication processing system of claim 14 , wherein the IHS comprises an embedded controller coupled to a processor, wherein the external off-host authentication processing system is coupled to the embedded controller, and wherein the external off-host authentication processing system provides a hardware environment segregated from the processor.

17. The off-host memory of claim 14 , wherein the program instructions, upon execution by the off-host processor, further cause the external off-host authentication processing system to:

receive a request from a calling application executed by another IHS to access the object stored in the off-host memory, wherein the request includes new authentication data obtained by the other IHS from a user by prompting the user and a new system ID obtained by the other IHS without prompting the user;

determine that the new authentication data matches the authentication data stored in the object but that the new system ID does not match the system ID stored in the object; and

deny the request.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2016
From: ROBISON, CHARLES D.; HAMLIN, DANIEL L.
To: DELL PRODUCTS, L.P.
Reel/Frame 038117/0672 →
Continuity (1)
Related Publication 20170272427A1 · Sep 21, 2017