IP Library Granted Patent US 12677154
Granted Patent B2
US 12677154 · App. 18/215,799 · Granted Jul 7, 2026

Zero-touch secure DNS device provisioning

Inventors: Matthew Vlasach (Larkspur, CA); Dan Cuddeford (Mill Valley, CA); Jakub Talas (Brno, CZ)
Assignee: JAMF Software, LLC
H04W12/35H04L63/0823H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12677154
App. No.
18/215,799
Granted
Jul 7, 2026
Kind
B2
Abstract

In certain aspects of the present disclosure, a computer-implemented method includes receiving a configuration profile from a risk assessment service, wherein the risk assessment service generated the configuration profile to comprise service policies associated with DNS traffic and an HTTPS URL. The method includes modifying the HTTPS URL of the configuration profile to include an UDID associated with a target device. The method includes transmitting, to the target device, the configuration profile comprising the HTTPS URL with the UDID associated with the target device, wherein the risk assessment service, responsive to the target device receiving the configuration profile, generates a device object based on the configuration profile comprising the HTTPS URL with the UDID. The method includes identifying, based on the UDID, meta data associated with the target device for returning a DNS response to a DNS request from the target device. Systems and machine-readable media are also provided.

Claims (40)

1 . A computer-implemented method comprising:

receiving, at a mobile device management service, a configuration profile from a risk assessment service, wherein the risk assessment service generated the configuration profile to comprise service policies associated with domain name system (DNS) traffic and an HTTPS URL;

modifying, by the mobile device management service, the HTTPS URL of the configuration profile to include a Unique Device Identifier (UDID) associated with a target device;

transmitting, by the mobile device management service to the target device, the configuration profile comprising the HTTPS URL with the UDID associated with the target device, wherein the risk assessment service, responsive to the target device receiving the configuration profile from the mobile device management service, generates a device object based on the configuration profile comprising the HTTPS URL with the UDID;

identifying agentlessly, by the mobile device management service, based on the UDID, meta data associated with the target device for returning a DNS response to a DNS request from the target device; and

maintaining service for the target device when the target device is identified as being administratively decommissioned, wherein the service policies comprise a capability to limit access to Domain Name System over HTTPS (DoH) URLs based on a client certificate associated with the target device.

2 . The computer-implemented method of claim 1 , further comprising:

transmitting, responsive to receiving the DNS request from the target device, the DNS response to the target device based on the service policies of the configuration profile associated with the target device.

3 . The computer-implemented method of claim 1 , further comprising:

encoding an error report into the DNS response.

4 . The computer-implemented method claim 1 , further comprising:

generating a log associated with receiving the DNS request from the target device.

5 . The computer-implemented method of claim 1 , wherein the client certificate is one of Automated Certificate Management Environment (ACME) and Simple Certificate Enrollment Protocol (SCEP).

6 . A system comprising:

a memory comprising instructions; and

a processor configured to execute the instructions which, when executed, cause the processor to:

receive, at a mobile device management service, a configuration profile from a risk assessment service, wherein the risk assessment service generated the configuration profile to comprise service policies associated with domain name system (DNS) traffic and an HTTPS URL;

modify, by the mobile device management service, the HTTPS URL of the configuration profile to include a Unique Device Identifier (UDID) associated with a target device;

transmit, by the mobile device management service to the target device, the configuration profile comprising the HTTPS URL with the UDID associated with the target device, wherein the risk assessment service, responsive to the target device receiving the configuration profile from the mobile device management service, generates a device object based on the configuration profile comprising the HTTPS URL with the UDID;

identify agentlessly, by the mobile device management service, based on the UDID, meta data associated with the target device for returning a DNS response to a DNS request from the target device; and

maintain service for the target device when the target device is identified as being administratively decommissioned, wherein the service policies comprise a capability to limit access to Domain Name System over HTTPS (DoH) URLs based on a client certificate associated with the target device.

7 . The system of claim 6 , further comprising instructions to cause the processor to:

transmit, responsive to receiving the DNS request from the target device, the DNS response to the target device based on the service policies of the configuration profile associated the target device.

8 . The system of claim 6 , further comprising instructions to cause the processor to:

encode an error report into the DNS response.

9 . The system of claim 6 , further comprising instructions to cause the processor to:

generate a log associated with receiving the DNS request from the target device.

10 . The system of claim 6 , wherein the client certificate is one of Automated Certificate Management Environment (ACME) and Simple Certificate Enrollment Protocol (SCEP).

11 . A non-transitory machine-readable storage medium comprising machine-readable instructions for causing a processor to execute a method, the method comprising:

receiving, at a mobile device management service, a configuration profile from a risk assessment service, wherein the risk assessment service generated the configuration profile to comprise service policies associated with domain name system (DNS) traffic and an HTTPS URL;

modifying, by the mobile device management service, the HTTPS URL of the configuration profile to include a Unique Device Identifier (UDID) associated with a target device;

transmitting, by the mobile device management service to the target device, the configuration profile comprising the HTTPS URL with the UDID associated with the target device, wherein the risk assessment service, responsive to the target device receiving the configuration profile from the mobile device management service, generates a device object based on the configuration profile comprising the HTTPS URL with the UDID;

identifying agentlessly, by the mobile device management service, based on the UDID, meta data associated with the target device for returning a DNS response to a DNS request from the target device; and

maintaining service for the target device when the target device is identified as being administratively decommissioned, wherein the service policies comprise a capability to limit access to Domain Name System over HTTPS (DoH) URLs based on a client certificate associated with the target device.

12 . The non-transitory machine-readable storage medium of claim 11 , further including instructions for causing the processor to execute the method comprising:

transmitting, responsive to receiving the DNS request from the target device, the DNS response to the target device based on the service policies of the configuration profile associated the target device.

13 . The non-transitory machine-readable storage medium of claim 11 , further including instructions for causing the processor to execute the method comprising:

encoding an error report into the DNS response.

14 . The non-transitory machine-readable storage medium of claim 11 , further including instructions for causing the processor to execute the method comprising:

generating a log associated with receiving the DNS request from the target device.