IP Library Granted Patent US 11,843,601
Granted Patent B2
US 11,843,601 · App. 16/999,967 · Granted Dec 12, 2023

Methods, systems, and computer readable mediums for securely establishing credential data for a computing device

Inventors: Jonathan Peter Streete (San Jose, CA); Christopher Michael Davis (Frisco, TX)
Assignee: EMC IP HOLDING COMPANY LLC
H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,843,601
App. No.
16/999,967
Granted
Dec 12, 2023
Kind
B2
Abstract

Methods, systems, and computer readable mediums for securely establishing credential data for a computing device are disclosed. According to one example, a method includes assigning, by a credential manager, credential set data to a computing device and mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager. The method further includes receiving, from a provisioning service client, a credential set request message including the device identifier key by the credential manager in response to an activation of the computing device at a customer location site and sending, by the credential manager to the provisioning service client, the credential set data for authenticating the computing device at the customer location site.

Claims (32)

1. A method comprising:

establishing, by a credential manager, credential set data corresponding to a computing device at a manufacturing site, wherein the credential set data is encrypted using a public key corresponding to a customer user of the computing device;

mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager, wherein the computing device is not provisioned with the credential data set at the manufacturing site;

receiving, by the credential manager from the computing device, a credential set request message that includes the device identifier key and that is generated by a provisioning service client in the computing device in response to an activation of the computing device at a customer location site, wherein the credential set request message is sent from the provisioning service client to the credential manager in response to the provisioning service client receiving an activation notification message from the computing device upon the activation of the computing device; and

sending, by the credential manager to the computing device, the credential set data that includes a username and password for authenticating the computing device at the customer location site, causing the provisioning service client to decrypt the credential set data using a private key corresponding to the customer user of the computing device.

2. The method of claim 1 comprising prompting a user entity to reset the credential set data in accordance to an established security policy.

3. The method of claim 1 comprising deleting an entry containing the credential set data from the credential data store after the credential manager sends the credential set data to a provisioning service client.

4. The method of claim 1 comprising transporting the computing device from a manufacturer location site associated with the credential manager to the customer location site.

5. The method of claim 1 wherein the credential set data includes a unique username and a unique password solely associated to the computing device.

6. The method of claim 1 wherein the provisioning service client resides in at least one of the computing device and a host device supporting the computing device.

7. A system comprising:

at least one physical computer; and

a credential manager implemented using the at least one physical computer for performing operations comprising:

establishing credential set data corresponding to a computing device at a manufacturing site, wherein the credential set data is encrypted using a public key corresponding to a customer user of the computing device;

mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager, wherein the computing device is not provisioned with the credential data set at the manufacturing site;

receiving from the computing device a credential set request message that includes the device identifier key and that is generated by a provisioning service client in the computing device in response to an activation of the computing device at a customer location site, wherein the credential set request message is sent from the provisioning service client to the credential manager in response to the provisioning service client receiving an activation notification message from the computing device upon the activation of the computing device; and

sending to the computing device the credential set data that includes a username and password for authenticating the computing device at the customer location site, causing the provisioning service client to decrypt the credential set data using a private key corresponding to the customer user of the computing device.

8. The system of claim 7 wherein a provisioning service client is further configured to prompt a user entity to reset or replace the credential set in accordance to an established security policy.

9. The system of claim 7 wherein the credential manager is further configured to delete the credential set data from the credential data store after the credential manager sends the credential set data to a provisioning service client.

10. The system of claim 7 wherein the computing device is transported from a manufacturer location site associated with the credential manager to the customer location site.

11. The system of claim 7 wherein the credential set data includes a unique username and a unique password solely associated to the computing device.

12. The system of claim 7 wherein the provisioning service client resides on at least one of a computing device and a host device supporting the computing device.

13. A non-transitory computer readable medium having stored thereon executable instructions which, when executed by a processor of a computer, cause the computer to perform steps comprising:

establishing, by a credential manager, credential set data corresponding to a computing device at a manufacturing site, wherein the credential set data is encrypted using a public key corresponding to a customer user of the computing device;

mapping the credential set data to a device identifier key associated with the computing device in a credential data store accessible by the credential manager, wherein the computing device is not provisioned with the credential data set at the manufacturing site;

receiving, by the credential manager from the computing device, a credential set request message that includes the device identifier key and that is generated by a provisioning service client in the computing device in response to an activation of the computing device at a customer location site, wherein the credential set request message is sent from the provisioning service client to the credential manager in response to the provisioning service client receiving an activation notification message from the computing device upon the activation of the computing device; and

sending, by the credential manager to the computing device, the credential set data that includes a username and password for authenticating the computing device at the customer location site, causing the provisioning service client to decrypt the credential set data using a private key corresponding to the customer user of the computing device.

14. The computer readable medium of claim 13 comprising prompting a user entity to reset the credential set data in accordance to an established security policy.

15. The computer readable medium of claim 13 comprising deleting an entry containing the credential set data from the credential data store after the credential manager sends the credential set data to a provisioning service client.

16. The computer readable medium of claim 13 comprising transporting the computing device from a manufacturer location site associated with the credential manager to the customer location site.

17. The computer readable medium of claim 13 wherein the credential set data includes a unique username and a unique password solely associated to the computing device.

18. The computer readable medium of claim 13 wherein the provisioning service client resides on at least one of the computing device and a host device supporting the computing device.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
MERGER Recorded Oct 28, 2020
From: VCE IP HOLDING COMPANY LLC
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054202/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2020
From: VCE COMPANY, LLC
To: VCE IP HOLDING COMPANY LLC
Reel/Frame 054202/0228 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2020
From: STREETE, JONATHAN PETER; DAVIS, CHRISTOPHER MICHAEL
To: VCE COMPANY, LLC
Reel/Frame 054185/0153 →