IP Library Granted Patent US 10,757,094
Granted Patent B2
US 10,757,094 · App. 16/146,651 · Granted Aug 25, 2020

Trusted container

Inventors: Vincent Edward Von Bokern (Rescue, CA); Purushottam Goel (Portland, OR); Sven Schrecker (San Marcos, CA); Ned McArthur Smith (Beaverton, OR)
Assignee: McAfee, LLC
H04L63/0838H04L41/046H04L41/28H04L63/061H04L63/0823H04L63/18H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,757,094
App. No.
16/146,651
Granted
Aug 25, 2020
Kind
B2
Abstract

A secure identifier is derived, using a secured microcontroller of a computing device, that is unique to a pairing of the computing device and a particular domain. Secure posture data corresponding to attributes of the computing device is identified in secured memory of the computing device. The secure identifier and security posture is sent in a secured container to a management device of the particular domain. The particular domain can utilize the information in the secured container to authenticate the computing device and determine a security task to be performed relating to interactions of the computing device with the particular domain.

Claims (33)

1. At least one storage device or storage disk comprising instructions that, when executed on at least one processor, cause the at least one processor to, at least:

establish a secure connection between a domain and a client computing device;

receive, from the client computing device, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to a pairing of the client computing device and the domain, the secure identifier derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receive, from the client computing device, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

perform a security task relating to an interaction of the client computing device with the domain.

2. The storage device or storage disk as defined in claim 1 , wherein the security task includes application of a security policy to the client computing device.

3. The storage device or storage disk as defined in claim 1 , wherein the instructions, when executed, cause the at least one processor to provide the domain identifier for authentication of the domain to the client computing device.

4. The storage device or storage disk as defined in claim 1 , wherein the instructions, when executed, cause the at least one processor to:

receive, from a second computing device, a second secure identifier for the second computing device, the second secure identifier of the second computing device derived from authentication data stored in secure memory of the second computing device;

receive, from the second computing device, second security posture data corresponding to the second computing device bound to the second secure identifier, the second security posture data to identify attributes of the second computing device; and

perform a security task relating to interaction of the second computing device with the domain.

5. A system comprising:

at least one processor;

memory in circuit with the at least one processor; and

a controller manager isolated from the at least one processor and to interact with a client computing device, the controller manager to:

negotiate a secure session with a client computing device;

provision seed data to the client computing device in response to the negotiation of the secure session, the seed data (a) separate from a domain identifier of a domain, (b) unique to a pairing of the client computing device and the domain, and (c) to be stored in a secure memory of the client computing device;

receive, from the client computing device, a secure identifier including a one-time password unique to the pairing of the client computing device and the domain, the secure identifier derived based at least in part on the seed data;

authenticate the client computing device using the one-time password; and

receive a secured container including the secure identifier and the security posture data from the client computing device.

6. The system as defined in claim 5 , further including a domain manager to apply at least one policy on the client computing device for a transaction based on the security posture data.

7. The system as defined in claim 5 , further including a policy manager to apply the at least one policy.

8. A method comprising:

establishing, by executing an instruction with at least one processor, a secure connection between a domain and a client computing device;

receiving from the client computing device, by executing an instruction with the at least one processor, a secure identifier corresponding to the client computing device, the secure identifier including a one-time password unique to a pairing of the client computing device and the domain, the secure identifier derived based at least in part on seed data received from the domain, the seed data separate from a domain identifier corresponding to the domain and unique to the pairing of the client computing device and the domain;

receiving from the client computing device, by executing an instruction with the at least one processor, a container including security posture data corresponding to the client computing device bound to the secure identifier, the security posture data to identify attributes of the client computing device; and

performing a security task relating to an interaction of the client computing device with the domain.

9. The method as defined in claim 8 , further including application of a security policy to the client computing device.

10. The method as defined in claim 8 , further including providing the domain identifier for authentication of the domain to the client computing device.

11. The method as defined in claim 8 , further including:

receiving, from a second computing device, a second secure identifier for the second computing device, the second secure identifier of the second computing device derived from authentication data stored in secure memory of the second computing device;

receiving second security posture data corresponding to the second computing device bound to the second secure identifier, the second security posture data to identify attributes corresponding to the second computing device; and

performing a security task relating to interaction of the second computing device with the domain.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2018
From: VON BOKERN, VINCENT EDWARD; GOEL, PURUSHOTTAM; SCHRECKER, SVEN; SMITH, NED MCARTHUR
To: INTEL CORPORATION
Reel/Frame 047337/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2018
From: INTEL CORPORATION
To: MCAFEE, INC.
Reel/Frame 047337/0199 →
CHANGE OF NAME Recorded Oct 29, 2018
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 047902/0911 →
Continuity (3)
Continuation 15207568 · Jul 12, 2016
Division 13726167 · Dec 23, 2012
Related Publication 20190036916A1 · Jan 31, 2019