IP Library Granted Patent US 10,333,926
Granted Patent B2
US 10,333,926 · App. 15/207,568 · Granted Jun 25, 2019

Trusted container

Inventors: Vincent Edward Von Bokern (Rescue, CA); Purushottam Goel (Portland, OR); Sven Schrecker (San Marcos, CA); Ned McArthur Smith (Beaverton, OR)
Assignee: McAfee, LLC
H04L63/0838H04L41/046H04L41/28H04L63/061H04L63/0823H04L63/18H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,926
App. No.
15/207,568
Granted
Jun 25, 2019
Kind
B2
Abstract

A secure identifier is derived, using a secured microcontroller of a computing device, that is unique to a pairing of the computing device and a particular domain. Secure posture data corresponding to attributes of the computing device is identified in secured memory of the computing device. The secure identifier and security posture is sent in a secured container to a management device of the particular domain. The particular domain can utilize the information in the secured container to authenticate the computing device and determine a security task to be performed relating to interactions of the computing device with the particular domain.

Claims (67)

1. At least one storage device or storage disk comprising instructions that, when executed on at least one processor, cause the at least one processor to, at least:

establish a secure connection between a domain and a client computing device;

receive, from the client computing device, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to a pairing of the client computing device and the domain, the secure identifier derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receive, from the client computing device, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

perform a security task relating to an interaction of the client computing device with the domain, the security task including identification of a driver corresponding to the client computing device, the identification of the driver based on the security posture data.

2. At least one storage device or storage disk comprising instructions that, when executed on at least one processor, cause the at least one processor to, at least:

establish a secure connection between a domain and a client computing device;

receive, from the client computing device, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to (a) a pairing of the client computing device and (b) the domain, the one-time password derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receive, from the client computing device, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

perform a security task relating to an interaction of the client computing device with the domain, the security task including a load of an agent onto the client computing device.

3. A system comprising:

at least one processor;

memory in circuit with the at least one processor;

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password; and

receive a secured container including the secure identifier and security posture data from the client computing device; and

an agent manager to load an agent onto the client computing device via a cloud connection.

4. A system comprising:

at least one processor;

memory in circuit with the at least one processor; and

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password; and

receive a secured container including the secure identifier and security posture data from the client computing device, wherein the system is to receive the secured container over a secure communication channel, the secure communication channel including an out-of-band communication channel between the client computing device and the domain independent from an in-band communication channel between a central processing unit of the client computing device and the domain.

5. A system comprising:

at least one processor;

memory in circuit with the at least one processor; and

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password; and receive a secured container including the secure identifier and security posture data from the client computing device, wherein the system is to establish a second secure communication channel with the client computing device according to a second secure identifier including a second one-time password.

6. A system comprising:

at least one processor;

memory in circuit with the at least one processor; and

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password;

receive a secured container including the secure identifier and security posture data from the client computing device; and

validate the client computing device based at least in part on a certificate from a trusted authority.

7. A system comprising:

at least one processor;

memory in circuit with the at least one processor; and

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password;

receive a secured container including the secure identifier and security posture data from the client computing device; and

negotiate a form of the secure identifier via a combination of the seed data and the domain identifier.

8. A method comprising:

establishing, by executing an instruction with at least one processor, a secure connection between a domain and a client computing device;

receiving from the client computing device, by executing an instruction with the at least one processor, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to a pairing of the client computing device and the domain, the secure identifier derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receiving from the client computing device, by executing an instruction with the at least one processor, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

performing a security task relating to an interaction of the client computing device with the domain, wherein the security task includes identification of a driver corresponding to the client computing device based on the security posture data.

9. A method comprising:

establishing, by executing an instruction with at least one processor, a secure connection between a domain and a client computing device;

receiving from the client computing device, by executing an instruction with the at least one processor, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to a pairing of the client computing device and the domain, the secure identifier derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receiving from the client computing device, by executing an instruction with the at least one processor, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

performing a security task relating to an interaction of the client computing device with the domain, wherein the security task includes a load of an agent onto the client computing device.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2018
From: INTEL CORPORATION
To: MCAFEE, INC.
Reel/Frame 046084/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2018
From: VON BOKERN, VINCENT EDWARD; GOEL, PURUSHOTTAM; SCHRECKER, SVEN; SMITH, NED MCARTHUR
To: INTEL CORPORATION
Reel/Frame 046076/0118 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (2)
Division 13726167 · Dec 23, 2012
Related Publication 20160323268A1 · Nov 3, 2016
Cited By (1)
US 12,335,294