Authorization method and apparatus
US-2024388909-A1 · Nov 21, 2024 · US
US2018262479A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2018262479-A1 |
| Application number | US-201815976207-A |
| Country | US |
| Kind code | A1 |
| Filing date | May 10, 2018 |
| Priority date | Dec 12, 2014 |
| Publication date | Sep 13, 2018 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Technologies for verifying authorized operation includes an administration server to query a dual-headed identification device of a server for identification data indicative of an identity of the server. The dual-headed identification device includes a wired communication circuit, a wireless communication circuit, and a memory having the identification data stored therein. The administration server further obtains the identification data from the dual-headed identification device of the server, determines a context of the server, and determines whether boot of the server is authorized based on the context of the server, the identification data of the server, and a security policy of the server.
Opening claim text (preview).
1 . A server for confirming authorized operation, the server comprising: a dual-headed identification device that includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; and a platform management module to (i) receive a query from an administration server, (ii) determine a context of the server, (iii) generate a response to the received query based on the determined context, and (iv) store the generated response to the memory of the dual-headed identification device for access by the administration server. 2 . The server of claim 1 , wherein to receive the query comprises to receive the query over the wireless communication circuit of the dual-headed identification device. 3 . The server of claim 2 , wherein the wireless communication circuit comprises a radio frequency identification circuit; and wherein to receive the query comprises to receive the query over the radio frequency identification circuit of the dual-headed identification device. 4 . The server of claim 2 , wherein to receive the query comprises to receive the query over an out-of-band communication channel between the administration server and the dual-headed identification device. 5 . The server of claim 1 , wherein to determine the context of the server comprises to determine a geographical location of the server. 6 . The server of claim 1 , wherein to generate the response to the received query comprises to attest to the integrity of at least one of the identification data or the context of the server. 7 . The server of claim 1 , further comprising a manageability engine to: read the memory of the dual-headed identification device to access the received query; and store the generated response to the memory of the dual-headed identification device, wherein to generate the response comprises generate the response by the manageability engine. 8 . The server of claim 7 , wherein the manageability engine comprises an out-of-band processor of the server. 9 . The server of claim 7 , wherein to read the memory comprises to read the memory via the wired communication circuit; and wherein to store the generated response comprises to store the generated response to the memory via the wired communication circuit. 10 . The server of claim 9 , wherein to read the memory comprises to read the memory over a dedicated communication bus between the dual-headed identification device and the manageability engine; and wherein the wired communication circuit is electrically coupled to the dedicated communication bus. 11 . The server of claim 7 , wherein the manageability engine is to perform at least one of an unlock, read, write, or lock operation on the memory of the dual-headed identification device based on credentials established at the time of provisioning of the dual-headed identification device. 12 . The server of claim 1 , wherein the platform management module is further to receive instructions based on a determination of the administration server regarding whether the server is authorized to operate based on the context and a security policy of the server. 13 . The server of claim 1 , wherein the platform management module is further to perform a security action in response to receipt of instructions that indicate the server is not authorized to operate based on the security policy. 14 . A method for confirming authorized operation of a server, the method comprising: receiving, by a dual-headed identification device of the server, a query from an administration server, wherein the dual-headed identification device includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; determining, by the server, a context of the server; generating, by the server, a response to the received query based on the determined context; and storing, by the server, the generated response to the memory of the dual-headed identification device for access by the administration server. 15 . The method of claim 14 , wherein receiving the query comprises receiving the query over the wireless communication circuit of the dual-headed identification device. 16 . The method of claim 14 , further comprising: reading, by a manageability engine of the server, the memory of the dual-headed identification device to access the received query; and storing, by the manageability engine, the generated response to the memory of the dual-headed identification device, wherein generating the response comprises generating the response by the manageability engine. 17 . The method of claim 16 , wherein reading the memory comprises reading the memory via the wired communication circuit; and wherein storing the generated response comprises storing the generated response to the memory via the wired communication circuit. 18 . The method of claim 17 , wherein reading the memory comprises reading the memory over a dedicated communication bus between the dual-headed identification device and the manageability engine; and wherein the wired communication circuit is electrically coupled to the dedicated communication bus. 19 . The method of claim 16 , further comprising performing, by the manageability engine of the server, at least one of an unlock, read, write, or lock operation on the memory of the dual-headed identification device based on credentials established at the time of provisioning of the dual-headed identification device. 20 . One or more computer-readable storage media comprising a plurality of instructions that in response to being executed cause a server to: receive, by a dual-headed identification device of the server, a query from an administration server, wherein the dual-headed identification device includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; determine a context of the server; generate a response to the received query based on the determined context; and store the generated response to the memory of the dual-headed identification device for access by the administration server. 21 . The one or more computer-readable storage media of claim 20 , wherein to receive the query comprises to receive the query over the wireless communication circuit of the dual-headed identification device. 22 . The one or more computer-readable storage media of claim 20 , further comprising a plurality of instructions that in response to being executed cause the server to: read, by a manageability engine of the server, the memory of the dual-headed identification device to access the received query; and store, by the manageability engine, the generated response to the memory of the dual-headed identification device, wherein to generate the response comprises to generate the response by the manageability engine. 23 . The one or more computer-readable storage media of claim 22 , wherein to read the memory comprises to read the memory via the wired communication circuit; and wherein to store the generated response comprises to store the generated response to the memory via the wired communication circuit. 24 . The one or more computer-readable storage media of claim 23 , wherein to read th
when the policy decisions are valid for a limited amount of time · CPC title
Secure boot · CPC title
wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title
Location-sensitive, e.g. geographical location, GPS · CPC title
involving the use of external additional devices, e.g. dongles or smart cards · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.