IP Library › Granted Patent US 11,134,386
Granted Patent B2
US 11,134,386 · App. 16/674,111 · Granted Sep 28, 2021

Device identification for management and policy in the cloud

Inventors: Ajit Singh (Fremont, CA); Vivek Ashwin Raman (San Jose, CA); Abhinav Bansal (San Jose, CA)
Assignee: Zscaler, Inc.
H04W12/08G06F21/57H04L61/1511H04L63/0272H04L63/0281H04L63/0884H04L63/20H04L67/02H04L67/10H04L67/1002H04L67/125H04L67/16H04L67/22H04L67/28H04L67/2809H04L69/162H04W12/12H04L61/6063H04L63/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,134,386
App. No.
16/674,111
Granted
Sep 28, 2021
Kind
B2
Abstract

Systems and methods for device identification for management and policy in the cloud, using a combination of several hardware parameters and user's identification to generate a unique identifier for a user device and associated user. IOCTL and Assembly can be used to get the different hardware parameters. All the hardware parameters can then run through a process to generate a fixed size hardware fingerprint. A base64 encoding can be performed to convert it into a string, for consumption of database. The resultant identifier is unique and it is never stored on machine. The application can simply generate it whenever needed. The resultant identifier can used by a service provider to uniquely identify the device even when the device is moving hands or locations. The resultant identifier is never stored, so moving data from one device to another will not result in the same identifier for two devices.

Claims (40)

1. A non-transitory computer-readable storage medium having computer readable code stored thereon for programming a processor to perform steps of:

obtaining a plurality of hardware parameters associated with a user device;

utilizing the plurality of hardware parameters to determine a hardware fingerprint of the user device; and

utilizing the hardware fingerprint for a plurality of enrollment and management of the user device in a cloud service.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of

obtaining a unique identifier of a user from the user device; and

utilizing the hardware fingerprint and the unique identifier of the user for the plurality of enrollment and management of the device in a cloud service.

3. The non-transitory computer-readable storage medium of claim 2 , wherein the unique identifier of the user is based on a user account in an operating system of the user device.

4. The non-transitory computer-readable storage medium of claim 1 , wherein the plurality of hardware parameters are obtained through any of assembly code, operating system Application Programming Interfaces (APIs).

5. The non-transitory computer-readable storage medium of claim 1 , wherein the plurality of hardware parameters relate to any of a processor identifier, a manufacturer serial number, a hard drive serial number, hard drive parameters, and battery.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the computer readable code is further configured to program the processor to perform steps of

subsequent to the enrollment of the user device in the cloud service, redetermining the hardware fingerprint locally on the user device for operation of the cloud service, such that the hardware fingerprint is recomputed and not stored on the user device.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the hardware fingerprint is determined based on a bit computation of the plurality of hardware parameters that is unique for every device.

8. A user device comprising:

a network interface, a data store, and a processor communicatively coupled to one another; and

memory storing computer executable instructions, and in response to execution by the processor, the computer-executable instructions cause the processor to

obtain a plurality of hardware parameters associated with the user device;

utilize the plurality of hardware parameters to determine a hardware fingerprint of the user device; and

utilize the hardware fingerprint for a plurality of enrollment and management of the user device in a cloud service.

9. The user device of claim 8 , wherein the computer-executable instructions further cause the processor to

obtain a unique identifier of a user from the user device; and

utilize the hardware fingerprint and the unique identifier of the user for the plurality of enrollment and management of the device in a cloud service.

10. The user device of claim 9 , wherein the unique identifier of the user is based on a user account in an operating system of the user device.

11. The user device of claim 8 , wherein the plurality of hardware parameters are obtained through any of assembly code, operating system Application Programming Interfaces (APIs).

12. The user device of claim 8 , wherein the plurality of hardware parameters relate to any of a processor identifier, a manufacturer serial number, a hard drive serial number, hard drive parameters, and battery.

13. The user device of claim 8 , wherein the computer-executable instructions further cause the processor to

subsequent to the enrollment of the user device in the cloud service, redetermining the hardware fingerprint locally on the user device for operation of the cloud service, such that the hardware fingerprint is recomputed and not stored on the user device.

14. The user device of claim 8 , wherein the hardware fingerprint is determined based on a bit computation of the plurality of hardware parameters that is unique for every device.

15. A method comprising:

obtaining a plurality of hardware parameters associated with a user device;

utilizing the plurality of hardware parameters to determine a hardware fingerprint of the user device; and

utilizing the hardware fingerprint for a plurality of enrollment and management of the user device in a cloud service.

16. The method of claim 15 , further comprising

obtaining a unique identifier of a user from the user device; and

utilizing the hardware fingerprint and the unique identifier of the user for the plurality of enrollment and management of the device in a cloud service.

17. The method of claim 15 , wherein the plurality of hardware parameters are obtained through any of assembly code, operating system Application Programming Interfaces (APIs).

18. The method of claim 15 , wherein the plurality of hardware parameters relate to any of a processor identifier, a manufacturer serial number, a hard drive serial number, hard drive parameters, and battery.

19. The method of claim 15 , further comprising

subsequent to the enrollment of the user device in the cloud service, redetermining the hardware fingerprint locally on the user device for operation of the cloud service, such that the hardware fingerprint is recomputed and not stored on the user device.

20. The method of claim 15 , wherein the hardware fingerprint is determined based on a bit computation of the plurality of hardware parameters that is unique for every device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2019
From: SINGH, AJIT; RAMAN, VIVEK ASHWIN; BANSAL, ABHINAV
To: ZSCALER, INC.
Reel/Frame 050915/0020 →
Continuity (3)
Continuation In Part 16252961 · Jan 21, 2019
Continuation 15377126 · Dec 13, 2016
Related Publication 20200077265A1 · Mar 5, 2020
Cited By (2)
US 12,463,970 US 12,665,856