IP Library Granted Patent US 11,159,316
Granted Patent B2
US 11,159,316 · App. 16/743,558 · Granted Oct 26, 2021

Self-service device encryption key access

Inventors: John Richards (Atlanta, GA); Craig Farley Newell (Atlanta, GA)
Assignee: VMware, Inc.
H04L9/0894H04L9/0861H04L9/3297H04L63/068H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,316
App. No.
16/743,558
Granted
Oct 26, 2021
Kind
B2
Abstract

Disclosed are various embodiments for providing access to a recovery key of a managed device and rotating the recovery key after it has been accessed. In one example, among others, a system includes a computing device and program instructions. The program instructions can cause the computing device to store a first recovery key for a first managed computing device. The first recovery key is configured to access an encrypted data store of the first managed computing device. A request is received for the first recovery key from a second managed computing device. The first recovery key is transmitted for display on the second managed computing device. A key rotation command is generated for a command queue of the first managed computing device to rotate the first recovery key after transmitting the first recovery key. The second recovery key is received from the second computing device.

Claims (46)

1. A system, comprising:

a computing device; and

program instructions executable in the computing device that, when executed by the computing device, cause the computing device to:

store a first recovery key for a first managed client device, wherein the first recovery key is configured to access an encrypted data store of the first managed client device;

receive a request for the first recovery key from a second managed client device, wherein the first managed client device and the second managed client device are associated with a managed user profile of a management service;

transmit the first recovery key for display to the second managed client device;

place a key rotation command into a command queue of the first managed client device, the key rotation command instructing the first managed client device to rotate the first recovery key in an instance in which the first recovery key has been transmitted; and

receive a second recovery key from the first managed client device.

2. The system of claim 1 , wherein the key rotation command comprises an instruction for executing an application programming interface command of an operating system for generating the second recovery key.

3. The system of claim 1 , further comprising program instructions executable in the computing device that, when executed, further cause the computing device to:

generate an entry for an event log in an instance in which the first recovery key has been transmitted for display, wherein the entry comprises a time stamp for when the first recovery key was transmitted.

4. The system of claim 1 , further comprising program instructions executable in the computing device that, when executed, further cause the computing device to:

validate a credential provided by the second managed client device in an instance in which the request for the first recovery key has been received.

5. The system of claim 1 , wherein the key rotation command comprises an instruction to rotate the first recovery key in an instance in which a period of time has expired from the first recovery key being transmitted to the second managed client device.

6. The system of claim 1 , further comprising program instructions executable in the computing device that, when executed, further cause the computing device to:

transmit the key rotation command to the first managed client device in an instance in which the first managed client device has become accessible on a network.

7. The system of claim 6 , wherein the key rotation command comprises an instruction for the first management device to transmit the second recovery key to the computing device.

8. A non-transitory computer-readable medium embodying program instructions executable in at least one computing device that, when executed by the at least one computing device, cause the at least one computing device to:

store a first recovery key for a first managed client device, wherein the first recovery key is configured to access an encrypted data store of the first managed client device;

receive a request for the first recovery key from a second managed client device, wherein the first managed client device and the second managed client device are associated with a managed user account of a management service;

transmit the first recovery key for display to the second managed client device;

place a key rotation command into a command queue of the first managed client device, the key rotation command instructing the first managed client device to rotate the first recovery key in an instance in which the first recovery key has been transmitted; and

receive a second recovery key from the first managed client device.

9. The non-transitory computer-readable medium of claim 8 , wherein the key rotation command comprises an instruction for executing an application programming interface command of an operating system for generating the second recovery key.

10. The non-transitory computer-readable medium of claim 8 , wherein the program instructions, when executed, further cause the at least one computing device to:

generate an entry for an event log in an instance in which the first recovery key for display has been transmitted, wherein the entry comprises a time stamp for when the first recovery key was transmitted.

11. The non-transitory computer-readable medium of claim 8 , wherein the program instructions, when executed, further cause the at least one computing device to:

validate a credential provided by the second managed client device in an instance in which the request for the first recovery key has been received.

12. The non-transitory computer-readable medium of claim 8 , wherein the key rotation command comprises an instruction to rotate the first recovery key in an instance in which a period of time has expired from the first recovery key being transmitted to the second managed client device.

13. The non-transitory computer-readable medium of claim 8 , wherein the program instructions, when executed, further cause the at least one computing device to:

transmit the key rotation command to the first managed client device in an instance in which the first managed client device has become accessible on a network.

14. The non-transitory computer-readable medium of claim 13 , wherein the key rotation command comprises an instruction for the first managed client device to transmit the second recovery key to the at least one computing device.

15. A computer-implemented method, comprising:

storing a first recovery key for a first managed client device, wherein the first recovery key is configured to access an encrypted data store of the first managed client device;

receiving a request for the first recovery key from a second managed client device, wherein the first managed client device and the second managed client device are associated with a managed user account of a management service;

transmitting the first recovery key for display to the second managed client device;

placing a key rotation command into a command queue of the first managed client device, the key rotation command instructing the first managed client device to rotate the first recovery key in an instance in which the first recovery key has been transmitted; and

receiving a second recovery key from the first managed client device.

16. The computer-implemented method of claim 15 , wherein the key rotation command comprises an instruction for executing an application programming interface command of an operating system for generating the second recovery key.

17. The computer-implemented method of claim 16 , further comprising:

generating an entry for an event log in an instance in which the first recovery key for display has been transmitted, wherein the entry comprises a time stamp for when the first recovery key was transmitted.

18. The computer-implemented method of claim 16 , further comprising:

validating a credential provided by the second managed client device in an instance in which the request for the first recovery key has been received.

19. The computer-implemented method of claim 15 , wherein the key rotation command comprises an instruction to rotate the first recovery key in an instance in which a period of time has expired from the first recovery key being transmitted to the second managed client device.

20. The computer-implemented method of claim 15 , further comprising:

transmit the key rotation command to the first managed client device in an instance in which the first managed client device has become accessible on a network.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2020
From: RICHARDS, JOHN; NEWELL, CRAIG FARLEY
To: VMWARE, INC.
Reel/Frame 051809/0492 →
Continuity (1)
Related Publication 20210218567A1 · Jul 15, 2021