Patents by Inventor Carlton A. Andrews

Carlton A. Andrews has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11509603
    Abstract: Systems and methods adjust workspaces based on available hardware resource of an IHS (Information Handling System) by which a user operates a workspace supported by a remote orchestration service. A security context and a productivity context of the IHS are determined based on reported context information. A workspace definition for providing access to a managed resource is selected based on the security context and the productivity context. A notification specifies a hardware resource of the IHS that is not used by the workspace definition, such as a microphone or camera that has not been enabled for use by workspaces. A productivity improvement that results from the updated productivity context that includes use of the first hardware resource is determined. Based on the productivity improvement, an updated workspace definition is selected that includes use of the first hardware resource in providing access to the managed resource via the IHS.
    Type: Grant
    Filed: November 30, 2020
    Date of Patent: November 22, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Patent number: 11487881
    Abstract: Systems and methods for endpoint context-driven, dynamic workspaces are described.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: November 1, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Patent number: 11475126
    Abstract: Systems and methods for modernizing workspace and hardware lifecycle management in an enterprise productivity ecosystem are described.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: October 18, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Publication number: 20220198043
    Abstract: Systems and methods for securely deploying a collective workspace across multiple local management agents are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive, at a workspace orchestration service from a first local management agent, first context information and a first split key; receive, at the workspace orchestration service from a second local management agent, second context information and a second split key; determining, by the workspace orchestration service, that the first and second context information match a collaborative workspace policy; in response to the determination, authenticate the first and second split keys; and in response to the authentication, transmit a collaborative workspace definition to the first and second local management agents.
    Type: Application
    Filed: December 18, 2020
    Publication date: June 23, 2022
    Applicant: Dell Products, L.P.
    Inventors: Joseph Kozlowski, Ricardo L. Martinez, David Konetski, Carlton A. Andrews, Nicholas D. Grobelny, Charles D. Robison, Girish S. Dhoble
  • Publication number: 20220200989
    Abstract: Systems and methods for workspace deployment using a secondary trusted device are described. In some embodiments, a first Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the first IHS to: establish a first connection with a second IHS, where the second IHS is configured to establish a second connection with a workspace orchestration service, and where the workspace orchestration service is configured to: receive device identification information of the first IHS from the second IHS; and authenticate the device identification information against a database provided by a manufacturer of the first IHS; and in response to a successful authentication, establish a third connection with the workspace orchestration service.
    Type: Application
    Filed: December 18, 2020
    Publication date: June 23, 2022
    Applicant: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Charles D. Robison, Nicholas D. Grobelny, Joseph Kozlowski, David Konetski
  • Publication number: 20220200806
    Abstract: Systems and methods for providing trusted local orchestration of workspaces are described. In some embodiments, an Information Handling System (IHS) may include a processor and a system memory coupled to the processor, the system memory having program instructions stored thereon that, upon execution, cause the IHS to: receive an orchestration code from a workspace orchestration service; record, using a trusted controller coupled to the processor, a log comprising: the orchestration code, and an indication of a sequence of operations performed during an instantiation of a workspace by the local management agent; provide a copy of the log to the workspace orchestration service; and establish a connection between the workspace and the workspace orchestration service in response to the workspace orchestration service's successful: (i) authentication of the orchestration code, and (ii) verification of the sequence of operations.
    Type: Application
    Filed: December 18, 2020
    Publication date: June 23, 2022
    Applicant: Dell Products, L.P.
    Inventors: Nicholas D. Grobelny, Ricardo L. Martinez, Carlton A. Andrews, Charles D. Robison
  • Publication number: 20220171853
    Abstract: Systems and methods for bare-metal or pre-boot user-machine authentication, binding, and entitlement provisioning are described. In some embodiments, a method may include: receiving, at a first portal managed by a manufacturer of an Information Handling System (IHS): (i) user credentials associated with a user of the IHS, and (ii) device identification associated with the IHS before the IHS is shipped to the user; selecting a customer of the manufacturer associated with the device identification; forwarding an indication of the user credentials to a second portal managed by the customer; and, in response to the second portal having successfully authenticated the user, establishing an identity session with the second portal; receiving, from the IHS, a request to initiate an entitlement sequence.
    Type: Application
    Filed: December 2, 2020
    Publication date: June 2, 2022
    Applicant: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Joseph Kozlowski, Charles D. Robison, David Konetski, Nicholas D. Grobelny
  • Patent number: 11336655
    Abstract: Systems and methods provide multilevel authorization of workspaces using certificates, where all of the authorization levels may be authorized separately or may instead be authorized at once. A measurement of an IHS (Information Handling System) is calculated based on the identity of the IHS and based on firmware of the IHS. A measurement of the configuration of the IHS is calculated based on information for configuring the IHS for supporting workspaces and also based on the IHS measurement. A measurement of a workspace session is calculated based on properties of a session used to remotely support operation of the workspace by the IHS and also based on the configuration measurement. Workspace session data may by authorized at all three levels by evaluating the session measurement against a reference session measurement.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: May 17, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Patent number: 11334675
    Abstract: Systems and methods support secure transfer of data between workspaces operating on an IHS (Information Handling System). Upon a request for access to a first managed resource, such as protected data, a first workspace is deployed according to a first workspace definition. Upon a request for access to a second managed resource, a second workspace is deployed according to a second workspace definition. In response to an indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS and of a request to paste the copied portion of the protected data to the second workspace, the protections provided by the second workspace are evaluated. If the protections of the second workspace are inadequate, an updated second workspace definition is selected that specifies additional protections. The second workspace is updated according to the updated second workspace definition and the transfer is permitted.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: May 17, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Publication number: 20220141642
    Abstract: An information handling system operating an enterprise endpoint embedded subscriber identification module (eSIM) provisioning system may comprise a processor, memory, and network interface device for transceiving data with an endpoint computing device having an embedded universal integrated circuit card (eUICC) capable of programmable selection among networks including at least one network in a 5G New Radio frequency band, the processor executing code of an enterprise client management (ECM) system for management of eSIM profiles for plural endpoint computing devices, the ECM system associating a unique hardware derived device IDentification based on hardware components of the endpoint computing device with a level of wireless service for the endpoint computing device based on enterprise allocation of service for the endpoint computing device via the ECM system, and the network interface device transmitting an eSIM profile to the endpoint computing device for implementation at the eUICC for the assigned level
    Type: Application
    Filed: October 30, 2020
    Publication date: May 5, 2022
    Applicant: Dell Products, LP
    Inventors: Anantha K. Boyapalle, Venkata S. Prayaga, Joseph Kozlowski, Carlton A. Andrews, Liam B. Quinn
  • Patent number: 11316902
    Abstract: Methods and system are provided for dynamically securing a workspace based on changes in the security context in which the workspace operates. Upon receiving a request from an IHS for access to a managed resource and receiving attributes of a risk context for the request, a risk score for the request is determined. A workspace definition that provides access to the managed resource is selected based on the risk score. A workspace definition includes security requirements for operation of the workspace by the IHS, where the security requirements are commensurate with the risk score. The workspace definition is transmitted to the IHS for operation of the workspace according to the security requirements. A risk context may include, IHS software, a physical environment in which the IHS is located, a physical location of the IHS, a classification of the requested resource, IHS hardware, and a user of the IHS.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: April 26, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Publication number: 20220124486
    Abstract: An information handling system of a Radio Access Network (RAN) system operating a secure network slice orchestration system may comprise a network interface device of the RAN system transceiving data within a 5G New Radio (NR) frequency band with an endpoint computing device, the network interface device receiving an instruction from a client solutions management (CSM) platform to assign a network slice within the 5G NR frequency band, based on a security profile associating the endpoint computing device with a security tier, to a network slice as established by a software defined network (SDN) controller within a sub-portion of the 5G NR frequency band, the secure network slice orchestration system determining the endpoint computing device is associated with the network slice within a communications profile received from the CSM platform, and the SDN controller establishing a virtual access point transceiving data within the network slice with the endpoint computing device.
    Type: Application
    Filed: October 21, 2020
    Publication date: April 21, 2022
    Applicant: Dell Products, LP
    Inventors: Carlton A. Andrews, Anantha K. Boyapalle, Joseph Kozlowski, Liam B. Quinn
  • Publication number: 20220103432
    Abstract: Systems and methods for modernizing workspace and hardware lifecycle management in an enterprise productivity ecosystem are described. In some embodiments, a client Information Handling System (IHS) may include a processor and a memory, the memory having program instructions that, upon execution by the processor, cause the client IHS to: receive, from a workspace orchestration service, one or more files or policies configured to enable the client IHS to instantiate a first workspace based upon a first workspace definition; allow a user to execute a non-vetted application in the first workspace; determine that the first workspace is compromised; and receive, in response to the determination, from the workspace orchestration service, one or more other files or policies configured to enable the client IHS to instantiate a second workspace based upon a second workspace definition, where the second workspace definition allows execution of a vetted application corresponding to the non-vetted application.
    Type: Application
    Filed: December 8, 2021
    Publication date: March 31, 2022
    Applicant: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Patent number: 11265351
    Abstract: A management system manages a plurality of information handling systems by creating custom policies for each information handling system based on information gathered from or about each information handling system indicating, e.g., the user's intent, use, request for usage, security posture, productivity needs, and/or behavior. The management system creates custom policies to avoid unnecessarily impacting a user's productivity.
    Type: Grant
    Filed: January 24, 2019
    Date of Patent: March 1, 2022
    Assignee: Dell Products L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Joseph Kozlowski
  • Patent number: 11240109
    Abstract: Systems and methods for modernizing workspace and hardware lifecycle management in an enterprise productivity ecosystem are described. In some embodiments, a client Information Handling System (IHS) may include a processor and a memory, the memory having program instructions that, upon execution by the processor, cause the client IHS to: receive, from a workspace orchestration service, one or more files or policies configured to enable the client IHS to instantiate a first workspace based upon a first workspace definition; allow a user to execute a non-vetted application in the first workspace; determine that the first workspace is compromised; and receive, in response to the determination, from the workspace orchestration service, one or more other files or policies configured to enable the client IHS to instantiate a second workspace based upon a second workspace definition, where the second workspace definition allows execution of a vetted application corresponding to the non-vetted application.
    Type: Grant
    Filed: October 31, 2019
    Date of Patent: February 1, 2022
    Assignee: Dell Products, L.P.
    Inventors: Carlton A. Andrews, Girish S. Dhoble, Nicholas D. Grobelny, David Konetski, Joseph Kozlowski, Ricardo L. Martinez, Charles D. Robison
  • Patent number: 11096229
    Abstract: An endpoint computing device dynamic network slice utilization system includes a core network system that is coupled to a RAN system and that is configured to allocate network slices and make them available for use in wireless communications via the RAN system. An endpoint computing device that includes an application operates to determine changing networking connectivity requirement for the application and/or the changing network characteristics of network slices during an application session, identify different network slices with networking characteristics that satisfy the changing networking connectivity requirements for the application, establish connection(s) for the application with those network slices, and exchange communications via the RAN system and the core network system for the application during the application session using the respective connection(s) established for the application with the respective network slices as the networking connectivity requirement for the application changes.
    Type: Grant
    Filed: January 29, 2020
    Date of Patent: August 17, 2021
    Assignee: Dell Products L.P.
    Inventors: Joseph Kozlowski, Anantha Boyapalle, Carlton Andrews
  • Patent number: 11086998
    Abstract: A secure boot violation system includes a BIOS with an authenticated variables storage storing at least one authorization key and at least one signatures database. The BIOS receives a first policy action entry for association with a first signature in the at least one signatures database, determines that the first policy action entry is signed with the at least one authorization key and, in response, associates the first policy action entry with the first signature in the at least one signatures database. The BIOS then determines, during a boot process and subsequent to the associating the first policy action entry with the first signature, that a first secure boot violation has occurred based on the first signature in the at least one signatures database. In response to determining that the first secure boot violation has occurred, the BIOS performs a first policy action defined by the first policy action entry.
    Type: Grant
    Filed: January 30, 2018
    Date of Patent: August 10, 2021
    Assignee: Dell Products L.P.
    Inventors: Ricardo L. Martinez, David Konetski, Joseph Kozlowski, Carlton Andrews
  • Publication number: 20210235526
    Abstract: An endpoint computing device dynamic network slice utilization system includes a core network system that is coupled to a RAN system and that is configured to allocate network slices and make them available for use in wireless communications via the RAN system. An endpoint computing device that includes an application operates to determine changing networking connectivity requirement for the application and/or the changing network characteristics of network slices during an application session, identify different network slices with networking characteristics that satisfy the changing networking connectivity requirements for the application, establish connection(s) for the application with those network slices, and exchange communications via the RAN system and the core network system for the application during the application session using the respective connection(s) established for the application with the respective network slices as the networking connectivity requirement for the application changes.
    Type: Application
    Filed: January 29, 2020
    Publication date: July 29, 2021
    Inventors: Joseph Kozlowski, Anantha Boyapalle, Carlton Andrews
  • Patent number: 11070551
    Abstract: Systems and methods for a network environment for client-side remote access of a server device from a client device may utilize a biometric sensor device of the client device and a pluggable authentication and authorization framework. The biometric sensor device may capture a gesture of a target user. The server device may authenticate the target user based on previously registered encrypted biometric information of the target user utilizing the pluggable authentication and authorization framework and a remote desktop protocol. When the target user has been authenticated, the client device may be authorized to access a service of the server device.
    Type: Grant
    Filed: January 18, 2018
    Date of Patent: July 20, 2021
    Assignee: Dell Products L.P.
    Inventors: Andrew T. Fausak, Oleg Rombakh, Charles D. Robison, Jr., Carlton A. Andrews
  • Publication number: 20210185615
    Abstract: An information handling system operating a low power communications engine comprising a wireless adapter for communicating on a low power communication technology network for receiving low power communication technology data traffic for at least one always-on remote management service for the information handling system, a controller receiving a location status of the information handling system via the low power communication technology network indicating a location or network, where the controller executes code instructions for a low power communications engine to assess a location trust level from an environment characteristics analysis engine to determine whether the location status is a trusted zone location or an untrusted zone location utilizing binary classification machine learning based on input variables including data relating to history of activity at the location or on the network learned by the environment characteristics analysis engine from reported operational or network activity, and the co
    Type: Application
    Filed: March 1, 2021
    Publication date: June 17, 2021
    Applicant: Dell Products, LP
    Inventors: Sinem Gulbay, Carlton A. Andrews