US2016080359A1PendingUtilityA1

Authentication using lights-out management credentials

Assignee: HEWLETT PACKARD ENTPR DEV LPPriority: Apr 25, 2012Filed: Nov 19, 2015Published: Mar 17, 2016
Est. expiryApr 25, 2032(~5.7 yrs left)· nominal 20-yr term from priority
G06F 21/00H04L 63/083G06F 21/31
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes upon receiving a request from a user to perform an operation on a device that is running under an operating system, authenticating the user on the basis of credential data that is retrieved from a data storage unit that is associated with a lights-out management (LOM) capability of the device. If authentication of the user is successful, the user is enabled to perform the operation.

Claims

exact text as granted — not AI-modified
1 - 19 . (canceled) 
     
     
         20 . A method comprising:
 retrieving, by a lights-out management (LOM) enabling unit, a LOM credential from a LOM data storage unit of the LOM enabling unit while a system device including the LOM enabling unit is in a powered-down state, wherein the LOM credential indicates which permissions are granted a user from a group of users;   authenticating, by the LOM enabling unit, the user based on the LOM credential retrieved from the LOM data storage unit; and   updating a current table of authorized users based on the authenticating by the LOM enabling unit, wherein the current table of authorized users is stored on the LOM data storage unit, and the updating is performed upon booting an operating system of the system device.   
     
     
         21 . The method of  claim 20 , comprising:
 receiving, by an application executing on the system device using a processor that is separate from the LOM enabling unit, a request from the user to perform an operation on the system device;   in response to receiving the request, retrieving, by the application, the LOM credential from the LOM data storage unit;   authenticating, by the application, the user based on the LOM credential that is retrieved from the LOM data storage unit; and   fulfilling or enabling the user to fulfill the request based on the authenticating by the application.   
     
     
         22 . The method of  claim 20 , wherein the credential data comprises data of a type selected from a group of credential data types consisting of: user identification, password, permission, and a public key. 
     
     
         23 . The method of  claim 20 , wherein updating the current table based on the authenticating by the LOM enabling unit comprises adding the user to the current table when the user is not included in the current table and the authenticating by the LOM enabling unit is successful. 
     
     
         24 . The method of  claim 20 , wherein updating the current table based on the authenticating by the LOM enabling unit comprises removing the user from the current table when the user is included in the current table and the authenticating by the LOM enabling unit is not successful. 
     
     
         25 . The method of  claim 20 , comprising issuing a notification if the authentication of the user is not successful. 
     
     
         26 . A non-transitory computer-readable storage medium having stored thereon instructions that when executed by hardware will cause the hardware to perform a method comprising:
 retrieving, by a lights-out management (LOM) enabling unit, a LOM credential from a LOM data storage unit of the LOM enabling unit while a system device including the LOM enabling unit is in a powered-down state, wherein the LOM credential indicates which permissions are granted a user from a group of users;   authenticating, by the LOM enabling unit, the user based on the LOM credential retrieved from the LOM data storage unit; and   updating a current table of authorized users based on the authenticating by the LOM enabling unit, wherein the current table of authorized users is stored on the LOM data storage unit, and the updating is performed upon booting an operating system of the system device.   
     
     
         27 . The non-transitory computer-readable storage medium of  claim 26 , the method comprising:
 receiving, by an application executing on the system device and not executing on the LOM enabling unit, a request from the user to perform an operation on the system device;   in response to receiving the request, retrieving, by the application, the LOM credential from the LOM data storage unit;   authenticating, by the application, the user based on the LOM credential that is retrieved from the LOM data storage unit; and   enabling the request to be fulfilled based on the authenticating by the application.   
     
     
         28 . The non-transitory computer-readable storage medium of  claim 26 , wherein the credential data comprises data of a type selected from a group of credential data types consisting of: user identification, password, permission, and a public key. 
     
     
         29 . The non-transitory computer-readable storage medium of  claim 26 , wherein updating the current table based on the authenticating by the LOM enabling unit comprises adding a given user to the current table when the given user is not included in the current table and the authenticating by the LOM enabling unit is successful. 
     
     
         30 . The non-transitory computer-readable storage medium of  claim 26 , wherein updating the current table based on the authenticating by the LOM enabling unit comprises removing the user from the current table when the user is included in the current table and the authenticating by the LOM enabling unit is not successful. 
     
     
         31 . The non-transitory computer-readable storage medium of  claim 26 , the method comprising issuing a notification if the authentication of the user is not successful. 
     
     
         32 . A system comprising:
 a light-out management (LOM) enabling unit including a data storage unit, wherein the LOM enabling unit is to:
 retrieve a LOM credential from the data storage unit while system is in a powered-down state, wherein the LOM credential indicates which permissions are granted a user from a group of users; and 
 authenticate the user based on the LOM credential retrieved from the data storage unit by the LOM enabling unit; and 
   a processing unit in communication with a computer-readable medium, the processing unit running under an operating system, wherein the computer-readable medium contains a set of instructions that, when executed by the processing unit, cause the processing unit to:
 receive a request from the user to perform an operation on the system; 
 retrieve the LOM credential from the data storage unit; 
 authenticate the user based on the LOM credential that is retrieved from the LOM data storage unit by the processing unit; and 
 enable the request to be fulfilled based on the authenticating by the processing unit. 
   
     
     
         33 . The system of  claim 32 , wherein the processing unit is configured to communicate with a remote device via a network. 
     
     
         34 . The system of  claim 33 , wherein the processing unit is configured to communicate via the network using a Secure Shell (SSH) protocol. 
     
     
         35 . The system of  claim 34 , wherein to enable communication via the SSH protocol, the processing unit is configured to obtain a public key from the LOM credential retrieved by the processing unit.

Join the waitlist — get patent alerts

Track US2016080359A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.