IP Library Granted Patent US 12695615
Granted Patent B2
US 12695615 · App. 18/643,268 · Granted Jul 28, 2026

Device onboarding in distributed systems using meta payloads

Inventors: Bradley K. Goodman (Nashua, NH); Joseph Caisse (Burlington, MA); James Daniel Harms (Worthington, OH); John Jian Li (Westford, MA)
Assignee: Dell Products L.P.
H04L9/32H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695615
App. No.
18/643,268
Granted
Jul 28, 2026
Kind
B2
Abstract

Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboard the endpoint devices, ownership vouchers may include information that directs the endpoint device to a meta payload that contains a link to a bootable installer and/or disk image and authentication data that is used to verify an integrity of the bootable installer and/or disk image. The meta payload may be stored at a location different from where the bootable installer and/or disk image are stored. Changes to the bootable installer and/or disk image would not require regeneration of every ownership voucher that referenced the previous version of the bootable installer and/or disk image before the changes.

Claims (60)

1 . A method for managing an endpoint device of endpoint devices in a deployment, the method comprising:

during an onboarding of the endpoint device that occurs after the endpoint device has been delivered to a final owner facility from a manufacturer facility or from an intermediate owner facility, and by the endpoint device:

obtaining, through a network connection and from an intermediary payload system remote to the endpoint device, an intermediary payload comprising a provisioning data locator and provisioning data authentication data, the intermediary payload being a first digital certificate and the provisioning data locator being first digital data stored in the first digital certificate, and obtaining the intermediary payload comprises:

obtaining, from a bare metal orchestration (BMO) payload included in an ownership voucher of the endpoint device, an intermediary payload locator, wherein the ownership voucher is a second digital certificate that comprises ownership information of the endpoint device, and the BMO payload is second digital data that is further stored in the second digital certificate along with the ownership information; and

using the intermediary payload locator to locate the intermediary payload system and the intermediary payload within the intermediary payload system;

using the provisioning data locator to obtain provisioning data from a provisioning data management system remote from the endpoint device, the provisioning data comprising bootable installers for installing an operating system (OS) onto the endpoint device, and the ownership voucher and the intermediary payload do not include a copy of the provisioning data such that the endpoint device must obtain the provisioning data from the provisioning data management system using the intermediary payload locater stored in the BMO included in the ownership voucher; and

executing the provisioning data to complete the onboarding of the endpoint device, wherein prior to completing the onboarding the endpoint device, the endpoint device is incapable of providing any computer implemented services.

2 . The method of claim 1 , wherein

the intermediary payload is signed using a secret key, and

prior to using the provisioning data locator to obtain the provisioning data:

obtaining a trusted public key associated with the intermediary payload from the BMO payload; and

determining that the trusted public key is referenced by the intermediary payload signed using the secret key to validate an integrity of the intermediary payload.

3 . The method of claim 2 , wherein

obtaining the provisioning data comprises using the provisioning data locator to locate the provisioning data management system and the provisioning data within the provisioning data management system; and

after obtaining the provisioning data from the provisioning data management system, using the provisioning data authentication data to validate the provisioning data obtained from the provisioning data management system.

4 . The method of claim 3 , wherein the provisioning data is only executed by the endpoint device after the provisioning data is successfully validated using the provisioning data authentication data.

5 . The method of claim 3 , wherein the provisioning data authentication data is at least one of a hash, a digest, or a checksum of the provisioning data.

6 . The method of claim 3 , wherein the provisioning data locator comprises a uniform resource locator (URL) that that the endpoint device uses to reach a location of the provisioning data and the intermediary payload locator comprises a URL that that the endpoint device uses to reach a location of the intermediary payload.

7 . The method of claim 1 , wherein the ownership voucher is provided to the endpoint device by an orchestrator controlled by an owner of the endpoint device, and the ownership voucher is provided without the provisioning data locator, and the provisioning data authentication data within other content of the ownership voucher beside the BMO payload.

8 . The method of claim 7 , further comprising:

prior to obtaining the intermediary payload and by the endpoint device:

obtaining, from the orchestrator, a work order comprising instructions for onboarding the endpoint device using the provisioning data; and

using the BMO payload in the ownership voucher instead of data included in the work order to obtain the intermediary payload.

9 . The method of claim 8 , wherein the work order is also provided without the provisioning data, the provisioning data locator, and the provisioning data authentication data in the work order.

10 . The method of claim 7 , wherein both of the provisioning data management system and the intermediary payload system are separate and distinct from the orchestrator.

11 . The method of claim 10 , wherein the provisioning data management system is remote to the intermediary payload system and the endpoint device.

12 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor of an endpoint device of endpoint devices in a deployment, cause the processor to perform operations for managing the endpoint device, the operations comprising:

during an onboarding of the endpoint device that occurs after the endpoint device has been delivered to a final owner facility from a manufacturer facility or from an intermediate owner facility, and by the endpoint device:

obtaining, through a network connection and from an intermediary payload system remote to the endpoint device, an intermediary payload comprising a provisioning data locator and provisioning data authentication data, the intermediary payload being a first digital certificate and the provisioning data locator being first digital data stored in the first digital certificate, and obtaining the intermediary payload comprises:

obtaining, from a bare metal orchestration (BMO) payload included in an ownership voucher of the endpoint device, an intermediary payload locator, wherein the ownership voucher is a second digital certificate that comprises ownership information of the endpoint device, and the BMO payload is second digital data that is further stored in the second digital certificate along with the ownership information; and

using the intermediary payload locator to locate the intermediary payload system and the intermediary payload within the intermediary payload system;

using the provisioning data locator to obtain provisioning data from a provisioning data management system remote from the endpoint device, the provisioning data comprising bootable installers for installing an operating system (OS) onto the endpoint device, and the ownership voucher and the intermediary payload do not include a copy of the provisioning data such that the endpoint device must obtain the provisioning data from the provisioning data management system using the intermediary payload locater stored in the BMO included in the ownership voucher; and

executing the provisioning data to complete the onboarding of the endpoint device, wherein prior to completing the onboarding the endpoint device, the endpoint device is incapable of providing any computer implemented services.

13 . The non-transitory machine-readable medium of claim 12 , wherein the intermediary payload is signed using a secret key, and

prior to using the provisioning data locator to obtain the provisioning data:

obtaining a trusted public key associated with the intermediary payload from the BMO payload; and

determining that the trusted public key is referenced by the intermediary payload signed using the secret key to validate an integrity of the intermediary payload.

14 . The non-transitory machine-readable medium of claim 13 , wherein

obtaining the provisioning data comprises using the provisioning data locator to locate the provisioning data management system and the provisioning data within the provisioning data management system; and

after obtaining the provisioning data from the provisioning data management system, using the provisioning data authentication data to validate the provisioning data obtained from the provisioning data management system.

15 . An endpoint device, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the endpoint device to perform operations for onboarding, the operations comprising:

during an onboarding of the endpoint device that occurs after the endpoint device has been delivered to a final owner facility from a manufacturer facility or from an intermediate owner facility, and by the endpoint device:

obtaining, through a network connection and from an intermediary payload system remote to the endpoint device, an intermediary payload comprising a provisioning data locator and provisioning data authentication data, the intermediary payload being a first digital certificate and the provisioning data locator being first digital data stored in the first digital certificate, and obtaining the intermediary payload comprises:

obtaining, from a bare metal orchestration (BMO) payload included in an ownership voucher of the endpoint device, an intermediary payload locator, wherein the ownership voucher is a second digital certificate that comprises ownership information of the endpoint device, and the BMO payload is second digital data that is further stored in the second digital certificate along with the ownership information; and

using the intermediary payload locator to locate the intermediary payload system and the intermediary payload within the intermediary payload system;

using the provisioning data locator to obtain provisioning data from a provisioning data management system remote from the endpoint device, the provisioning data comprising bootable installers for installing an operating system (OS) onto the endpoint device, and the ownership voucher and the intermediary payload do not include a copy of the provisioning data such that the endpoint device must obtain the provisioning data from the provisioning data management system using the intermediary payload locater stored in the BMO included in the ownership voucher; and

executing the provisioning data to complete the onboarding of the endpoint device, wherein prior to completing the onboarding the endpoint device, the endpoint device is incapable of providing any computer implemented services.

16 . The endpoint device of claim 15 , wherein

the intermediary payload is signed using a secret key, and

prior to using the provisioning data locator to obtain the provisioning data:

obtaining a trusted public key associated with the intermediary payload from the BMO payload; and

determining that the trusted public key is referenced by the intermediary payload signed using the secret key to validate an integrity of the intermediary payload.

17 . The endpoint device of claim 16 , wherein

obtaining the provisioning data comprises using the provisioning data locator to locate the provisioning data management system and the provisioning data within the provisioning data management system; and

after obtaining the provisioning data from the provisioning data management system, using the provisioning data authentication data to validate the provisioning data obtained from the provisioning data management system.

18 . The endpoint device of claim 17 , wherein the provisioning data is only executed by the endpoint device after the provisioning data is successfully validated using the provisioning data authentication data.

19 . The endpoint device of claim 17 , wherein the provisioning data authentication data is at least one of a hash, a digest, or a checksum of the provisioning data.

20 . The endpoint device of claim 17 , wherein the provisioning data locator comprises a uniform resource locator (URL) that specifies a location of the provisioning data and the intermediary payload locator comprises a URL that specifies a location of the intermediary payload.