IP Library Granted Patent US 11,012,858
Granted Patent B1
US 11,012,858 · App. 16/775,925 · Granted May 18, 2021

Endpoint computing device network slice secure certificate provisioning and management system

Inventors: Joseph Kozlowski (Hutto, TX); Anantha Boyapalle (Cedar Park, TX); Carlton Andrews (Austin, TX); Abeye Teshome (Austin, TX)
Assignee: Dell Products L.P.
H04W12/069H04L63/0823H04L63/12H04W4/50H04W12/08H04W12/108H04W48/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,858
App. No.
16/775,925
Granted
May 18, 2021
Kind
B1
Abstract

An endpoint computing device network slice certificate provisioning and management system includes a core network system that is coupled to a Radio Access Network (RAN) system and configured to allocate a plurality of a network slices and make each of the network slices available for use in wireless communications via the RAN system. An endpoint computing device is configured to establish a first network connection with a first network slice included in the plurality of network slices and perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device. The endpoint computing device may then use the certificate to verify at least one server device to provide at least one verified server device, and perform secure network communications with the at least one verified server device.

Claims (83)

1. An endpoint computing device network slice certificate provisioning and management system, comprising:

a Radio Access Network (RAN) system;

a core network system that is coupled to the RAN system and that is configured to allocate a plurality of a network slices and make each of the plurality of network slices available for use in wireless communications via the RAN system; and

an endpoint computing device that is configured to:

establish a first network connection with a first network slice included in the plurality of network slices;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device;

establish a second network connection with a second network slice included in the plurality of network slices;

perform, via out-of-band management wireless communications over the second network connection with the second network slice, out-of-band management operations for the endpoint computing device with the at last one verified server device; and

end, subsequent to verifying the at least one server device to provide at least one verified server device, the first network connection with the first network slice.

2. The system of claim 1 , wherein the first network slice is isolated from the second network slice.

3. An endpoint computing device network slice certificate provisioning and management system, comprising:

a Radio Access Network (RAN) system;

a core network system that is coupled to the RAN system and that is configured to allocate a plurality of a network slices and make each of the plurality of network slices available for use in wireless communications via the RAN system; and

an endpoint computing device that is configured to:

establish a first network connection with a first network slice included in the plurality of network slices;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device; and

perform, via out-of-band management wireless communications over the first network connection with the first network slice subsequent to verifying the at least one server device to provide at least one verified server device, out-of-band management operations for the endpoint computing device with the at least one verified server device.

4. An endpoint computing device network slice certificate provisioning and management system, comprising:

a Radio Access Network (RAN) system;

a core network system that is coupled to the RAN system and that is configured to allocate a plurality of a network slices and make each of the plurality of network slices available for use in wireless communications via the RAN system; and

an endpoint computing device that is configured to:

establish a first network connection with a first network slice included in the plurality of network slices;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device;

establish, while the endpoint computing device is operating in an endpoint computing device runtime environment, a second connection; and

perform, via in-band wireless communications over the second network connection, the secure network communications with the at least one verified server device.

5. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a network slice certificate provisioning and management engine that is configured to:

establish a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate in association with the processing system;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device;

establish a second network connection with a second network slice included in the plurality of network slices that are available via the RAN system;

perform, via out-of-band management wireless communications over the second network connection with the second network slice, out-of-band management operations with the at last one verified server device; and

end, subsequent to verifying the at least one server device to provide at least one verified server device, the first network connection with the first network slice.

6. The IHS of claim 5 , wherein the first network slice is isolated from the second network slice.

7. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a network slice certificate provisioning and management engine that is configured to:

establish a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate in association with the processing system;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device; and

perform, via out-of-band management wireless communications over the first network connection with the first network slice subsequent to verifying the at least one server device to provide at least one verified server device, out-of-band management operations with the at least one verified server device.

8. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a network slice certificate provisioning and management engine that is configured to:

establish a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate in association with the processing system;

perform, using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

perform secure network communications with the at least one verified server device;

establish, while the endpoint computing device is operating in an endpoint computing device runtime environment, a second connection; and

perform, via in-band wireless communications over the second network connection, the secure network communications with the at least one verified server device.

9. The IHS of claim 8 , wherein the second connection is established with a second network slice included in the plurality of network slices that are available via the RAN system.

10. A method for provisioning a certificate on and managing an endpoint computing device, comprising:

establishing, by an endpoint computing device, a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

performing, by the endpoint computing device via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

performing, by the endpoint computing device using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

performing, by the endpoint computing device, secure network communications with the at least one verified server device;

establishing, by the endpoint computing device, a second network connection with a second network slice included in the plurality of network slices that are available via the RAN system;

performing, by the endpoint computing device via out-of-band management wireless communications over the second network connection with the second network slice, out-of-band management operations for the endpoint computing device with the at last one verified server device; and

ending, by the endpoint computing device subsequent to verifying the at least one server device to provide at least one verified server device, the first network connection with the first network slice.

11. The method of claim 10 , wherein the first network slice is isolated from the second network slice.

12. A method for provisioning a certificate on and managing an endpoint computing device, comprising:

establishing, by an endpoint computing device, a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

performing, by the endpoint computing device via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

performing, by the endpoint computing device using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

performing, by the endpoint computing device, secure network communications with the at least one verified server device; and

performing, by the endpoint computing device via out-of-band management wireless communications over the first network connection with the first network slice subsequent to verifying the at least one server device to provide at least one verified server device, out-of-band management operations for the endpoint computing device with the at least one verified server device.

13. A method for provisioning a certificate on and managing an endpoint computing device, comprising:

establishing, by an endpoint computing device, a first network connection with a first network slice included in a plurality of network slices that are available via a Radio Access Network (RAN) system;

performing, by the endpoint computing device via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device;

performing, by the endpoint computing device using the certificate provisioned on the endpoint computing device, verification operations with at least one server device to provide at least one verified server device;

performing, by the endpoint computing device, secure network communications with the at least one verified server device;

establishing, by the endpoint computing device while the endpoint computing device is operating in an endpoint computing device runtime environment, a second connection; and

performing, by the endpoint computing device via in-band wireless communications over the second network connection, the secure network communications with the at least one verified server device.

14. The method of claim 13 , wherein the second connection is established with a second network slice included in the plurality of network slices that are available via the RAN system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: KOZLOWSKI, JOSEPH; BOYAPALLE, ANANTHA; ANDREWS, CARLTON; TESHOME, ABEYE
To: DELL PRODUCTS L.P.
Reel/Frame 051660/0765 →
Cited By (1)
US 12,625,965