IP Library Granted Patent US 9,467,441
Granted Patent B2
US 9,467,441 · App. 14/189,991 · Granted Oct 11, 2016

Secure service delegator

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,441
App. No.
14/189,991
Granted
Oct 11, 2016
Kind
B2
Abstract

Systems and methods for a secure service delegator. In some embodiments, an Information Handling System (IHS) operated by a manufacturer of a client device provided to a customer enterprise may include a processor and a memory coupled to the processor. The memory may include program instructions stored thereon that, upon execution by the processor, cause the IHS to: receive, from the client device via a secure connection, a request to obtain a provisioning credential; identify a delegate provisioning server associated with the customer enterprise; and enable the client device to access the delegate provisioning server and to retrieve the provisioning credential from the delegate provisioning server.

Claims (26)

1. A delegator server, comprising:

a processor; and

a memory coupled to the processor, the memory including program instructions stored thereon that, upon execution by the processor, cause the delegator server to:

receive, from a given client device via a secure connection, a request to obtain a provisioning credential, wherein the secure connection is established based upon a certificate stored in the given client device during manufacturing, wherein the given client device is one of a plurality of client devices provided by a vendor to a plurality of customer enterprises, wherein the delegator server is controlled by the vendor, wherein the delegator server is in communication with a plurality of delegate provisioning servers, and wherein each of the delegate provisioning servers is controlled by one of the plurality of customer enterprises;

identify a given one of the plurality of delegate provisioning servers that is associated with a given one of the plurality of customer enterprises to which the given client device has been provided;

retrieve the provisioning credential from the given delegate provisioning server; and

provide the provisioning credential to the given client device, wherein the provisioning credential includes a username and password that enables the given client device to retrieve provisioning data from the given delegate provisioning server, and wherein the provisioning data prepares the given client device to be set up by the given customer enterprise.

2. The delegator server of claim 1 , wherein the given client device is a smart phone, tablet, laptop, desktop, or server.

3. The delegator server of claim 1 , wherein the certificate is inaccessible to the given customer enterprise.

4. The delegator server of claim 3 , wherein the same certificate is stored in each of the plurality of client devices provided to the plurality of customer enterprises.

5. The delegator server of claim 4 , wherein the given delegate provisioning server is identified based, at least in part, upon an identity of the given client device provided to the delegator service as part of the request.

6. The delegator server of claim 5 , wherein the identity is represented by a service tag stored in the given client device during manufacturing.

7. The delegator server of claim 1 , wherein the program instructions further cause the delegator server to, prior to receiving the request, receive a registration of the given client device from the given customer enterprise via a registration portal.

8. The delegator server of claim 1 , wherein to identify the given delegate provisioning server associated with the given customer enterprise, the program instructions further cause the delegator server to identify a domain of the given customer enterprise based, at least in part, upon the request.

9. A method, comprising:

transmitting, by a given client device to a delegator server, a request to obtain a provisioning credential, wherein the given client device is one of a plurality of client devices provided by a vendor to a plurality of customer enterprises, wherein the delegator server is controlled by the vendor, wherein the delegator server is in communication with a plurality of delegate provisioning servers, wherein each of the delegate provisioning servers is controlled by a respective one of the plurality of customer enterprises, wherein the request is part of an activation procedure of the given client device within a given one of the plurality of customer enterprises after the given client device has been provided to the given customer enterprise, wherein transmitting includes establishing a secure connection with the delegator server based upon a certificate stored within the given client device during manufacturing, and wherein the same certificate is stored in each of the plurality of client devices provided to the plurality of customer enterprises;

receiving, at the client device from the delegator server, the provisioning credential, wherein the delegator server is configured to identify a given one of the plurality of delegate provisioning servers that is associated with the given customer enterprise and to retrieve the provisioning credential from the given delegate provisioning server; and

using the provisioning credential, by the client device, to retrieve provisioning data from the given delegate provisioning server, wherein the provisioning data enables the given client device to be activated within the given customer enterprise.

10. The method of claim 9 , wherein the provisioning credential includes a password.

11. The method of claim 9 , wherein the delegator server if configured to identify the given customer enterprise based, at least in part, upon an identity of the given device submitted to the delegator server as part of the request.

12. A non-transitory computer-readable medium having program instructions stored thereon that, upon execution by a given delegate provisioning server, cause the given delegate provisioning server to:

receive an indication from a delegator server that a given client device has requested the delegator server for an activation service, wherein the given client device is one of a plurality of client devices provided by a vendor to a plurality of customer enterprises, wherein the delegator server is controlled by the vendor, wherein the delegator server is in communication with a plurality of delegate provisioning servers, wherein each of the delegate provisioning servers is controlled by a respective one of the plurality of customer enterprises, and wherein the delegator server is configured to identify the given delegate provisioning server among the plurality of delegate provisioning servers as being associated with a given one of the plurality of customer enterprises to which the given client device has been provided;

provide a provisioning credential to the delegator server, wherein the delegator server is configured to transmit the provisioning credential to the client device; and

in response to receiving the provisioning credential from the given client device, provide provisioning data to the given client device, wherein the provisioning data prepares the given client device to be activated within the given customer enterprise, wherein the indication is received in response to the delegator server having established a secure connection with the given client device, the secure connection created based, at least in part, upon a certificate stored in the given client device during manufacturing, wherein the same certificate is stored in the plurality of client devices.

13. The non-transitory computer-readable medium of claim 12 , wherein the delegator server is configured to identify the given delegate provisioning server based, at least in part, upon a service tag associated with the given client device, wherein the service tag is stored in the given client device upon manufacturing.

14. The non-transitory computer-readable medium of claim 13 , wherein prior to the given client device having obtained the provisioning credential, the vendor receives a registration of the given client device as belonging to the given customer enterprise through a web portal.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 032810 FRAME 0038 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040027/0686 →
RELEASE OF REEL 032809 FRAME 0987 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040026/0953 →
RELEASE OF REEL 032810 FRAME 0023 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040014/0320 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032810/0038 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032810/0023 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032809/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2014
From: BALLARD, LEE E.
To: DELL PRODUCTS, L.P.
Reel/Frame 032297/0351 →