IP Library Granted Patent US 11,443,023
Granted Patent B2
US 11,443,023 · App. 15/685,299 · Granted Sep 13, 2022

Distributed profile and key management

Inventors: Eugene Liderman (Olney, MD); Jonathon Deriso (Cumming, GA); William Thomas Hooper (Norcross, GA); Sagar Date (Alpharetta, GA); Tejas Mehrotra (Santa Clara, CA); Stephen Turner (Atlanta, GA); Amogh Datar (Atlanta, GA); Dipanshu Gupta (Atlanta, GA)
Assignee: VMware, Inc.
G06F21/34G06F21/33H04L9/3234H04L9/3268H04L63/062H04L63/0823H04W12/04H04W12/06H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,443,023
App. No.
15/685,299
Granted
Sep 13, 2022
Kind
B2
Abstract

Disclosed are various examples for distributed profile and key management. In one example, a client device can include an agent application and a PIV-D application. The agent application can receive a partially populated device profile generated by a management service to configure a setting on the client device. The PIV-D application can generate a derived credential and provide the derived credential to the agent application. The agent application can modify the partially populated device profile to include the credential to create a fully populated device profile and configure the client device in accordance with the fully populated device profile.

Claims (37)

1. A system for distributed profile and key management, comprising:

a client device; and

program instructions executable in the client device that, when executed by the client device, cause the client device to:

receive, by a first client application of the client device, a partially populated device profile, the partially populated device profile generated by a management service remotely located from the client device to configure at least one setting on the client device, the partially populated device profile as generated comprising a credential payload portion having a temporary string or an empty portion;

authenticate, by a second client application of the client device, the client device through communication with a third-party security service;

in response to the client device being authenticated, generate, by the second client application, a credential, wherein the credential is a derived credential, the derived credential being generated using at least one personal identity verification (PIV) card credential;

provide, by the second client application, the credential to the first client application;

modify, by the first client application, the partially populated device profile to include the credential to create a fully populated device profile by replacing the temporary string or inserting the credential to generate the fully populated device profile; and

cause, by the first client application, the client device to be configured in accordance with the fully populated device profile.

2. The system of claim 1 , wherein the first client application is an agent application executable on the client device.

3. The system of claim 2 , further comprising program instructions executable in the client device that, when executed by the client device, cause the client device to encrypt, by the agent application, the fully populated device profile.

4. The system of claim 3 , further comprising program instructions executable in the client device that, when executed by the client device, cause the client device to send, by the agent application, the fully populated device profile to the management service.

5. The system of claim 1 , wherein the client device is configured in accordance with the fully populated device profile using at least one device management feature of an Android® operating system.

6. The system of claim 1 , wherein the derived credential is an X.509 public key certificate.

7. A non-transitory computer-readable medium for distributed profile and key management embodying program code executable in a client device that, when executed by the client device, causes the client device to:

receive, by a first client application of the client device, a partially populated device profile, the partially populated device profile generated by a management service remotely located from the client device to configure atleast one setting on the client device, the partially populated device profile as generated comprising a credential payload portion having a temporary string or an empty portion;

authenticate, by a second client application, the client device through communication with a third-party security service;

in response to the client device being authenticated, generate, by the second client application, a credential, wherein the credential is a derived credential, the derived credential being generated using at least one personal identity verification (PIV) card credential;

provide, by the second client application, the credential to the first client application;

modify, by the first client application, the partially populated device profile to include the credential to create a fully populated device profile by replacing the temporary string or inserting the credential to generate the fully populated device profile; and

cause, by the first client application, the client device to be configured in accordance with the fully populated device profile.

8. The non-transitory computer-readable medium of claim 7 , wherein the first client application is an agent application executable on the client device.

9. The non-transitory computer-readable medium of claim 8 , further comprising program code executable in the client device that, when executed by the client device, causes the client device to encrypt, by the agent application, the fully populated device profile.

10. The non-transitory computer-readable medium of claim 9 , further comprising program code executable in the client device that, when executed by the client device, causes the client device to send, by the agent application, the fully populated device profile to the management service.

11. The non-transitory computer-readable medium of claim 7 , wherein the client device is configured in accordance with the fully populated device profile using at least one device management feature of an Android® operating system.

12. The non-transitory computer-readable medium of claim 7 , wherein the derived credential is an X.509 public key certificate.

13. A computer-implemented method for distributed profile and key management, comprising:

receiving, by a first client application of the client device, a partially populated device profile, the partially populated device profile generated by a management service remotely located from the client device to configure at least one setting on the client device, the partially populated device profile as generated comprising a credential payload portion having a temporary string or an empty portion;

authenticating, by a second client application, the client device through communication with a third-party security service;

in response to the client device being authenticated, generating, by the second client application, a credential, wherein the credential is a derived credential, the derived credential being generated using at least one personal identity verification (PIV) card credential;

providing, by the second client application, the credential to the first client application;

modifying, by the first client application, the partially populated device profile to include the credential to create a fully populated device profile by replacing the temporary string or inserting the credential to generate the fully populated device profile; and

configuring, by the first client application, the client device in accordance with the fully populated device profile.

14. The computer-implemented method of claim 13 , wherein the first client application is an agent application executable on the client device.

15. The computer-implemented method of claim 14 , further comprising encrypting, by the agent application, the fully populated device profile.

16. The computer-implemented method of claim 15 , further comprising sending, by the agent application, the fully populated device profile to the management service.

17. The computer-implemented method of claim 13 , wherein the client device is configured in accordance with the fully populated device profile using at least one device management feature of an Android® operating system.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: LIDERMAN, EUGENE; DERISO, JONATHON; HOOPER, WILLIAM THOMAS; DATE, SAGAR; MEHROTRA, TEJAS; TURNER, STEPHEN; DATAR, AMOGH; GUPTA, DIPANSHU
To: VMWARE, INC.
Reel/Frame 043462/0116 →
Continuity (1)
Related Publication 20190065725A1 · Feb 28, 2019