IP Library Granted Patent US 12,061,688
Granted Patent B2
US 12,061,688 · App. 17/193,431 · Granted Aug 13, 2024

Device provisioning using secure credentials for a first deployment

Inventors: Arkady Kanevsky (Cedar Park, TX); Jonathan Peter Streete (San Jose, CA)
Assignee: Dell Products L.P.
G06F21/45G06F8/60H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,061,688
App. No.
17/193,431
Granted
Aug 13, 2024
Kind
B2
Abstract

A disclosed method includes assigning a unique identifier to a computer product instance, such as a server, switch, router, or storage device, to be deployed at a data center or other location on behalf of a customer, generating security credentials for the computer product dependent on the identifier, obtaining the credentials by a customer-side automated deployment agent, and using them by the deployment agent during deployment of the computer product. The credentials may be generated by a supplier-side credential management system, then requested and received by the deployment agent over a secure communication channel. The credentials may be generated by a program shared between the supplier-side credential management system and the deployment agent. The identifier may identify a hardware or software component or be selected by the supplier or customer. The credentials may include a username, password, token, cryptographic key, or digital certificate for a first login.

Claims (77)

1. A method, comprising:

assigning a unique identifier to a computer product instance to be deployed at a customer site;

generating, by a supplier of the computer product instance, security credentials for the computer product instance dependent on i) the assigned unique identifier and ii) a customer identifier associated with the computer product instance;

obtaining, by a customer-side automated deployment agent, the security credentials, at a first time, for the computer product instance that were generated dependent on the assigned unique identifier and the customer identifier;

using, by the customer-side automated deployment agent, the security credentials during deployment of the computer product instance;

after using the security credentials, attempting to obtain the security credentials, at a second time after the first time, from the supplier of the computer product instance; and

in response to attempting to obtain the security credentials at the second time after the first time, preventing use of the security credentials at the second time.

2. The method of claim 1 wherein:

generating the security credential comprises:

a supplier-side credential management system generating the security credentials; and

the supplier-side credential management system storing the security credentials; and

obtaining the security credentials comprises the customer-side automated deployment agent requesting and receiving the security credentials from the supplier-side credential management system over a secure communication channel.

3. The method of claim 1 , wherein:

generating the security credential comprises generating the security credentials using a shared credential generation program;

the method further comprises providing the shared credential generation program to the customer-side automated deployment agent; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the provided shared credential generation program.

4. The method of claim 1 , wherein:

generating the security credential comprises:

receiving a shared credential generation program from the customer-side automated deployment agent; and

generating the security credentials using the received shared credential generation program; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the shared credential generation program.

5. The method of claim 1 , wherein the unique identifier assigned to the computer product instance comprises an identifier of a hardware of software component of the computer product instance.

6. The method of claim 1 , wherein assigning the unique identifier to the computer product instance comprises the supplier or customer selecting the unique identifier.

7. The method of claim 1 , wherein using the security credentials during deployment of the computer product instance comprises using the security credentials for a first login to an operating system executing on the computer product instance, a first login to application software executing on the computer product instance, a first login to a management environment executing on the computer product instance, or a first login to a baseboard management controller of the computer product instance.

8. The method of claim 1 , wherein the computer product instance comprises a compute server, network switch, router device, or storage device to be deployed at the customer site.

9. The method of claim 1 , wherein the security credentials comprise one or more of an access username, an access password, an access cookie, an access token, a cryptographic key, a public key token, or a digital certificate.

10. The method of claim 1 , further comprising generating, by the customer-side automated deployment agent and subsequent to using the security credentials during deployment of the computer product instance, new security credentials for the computer product instance.

11. A system, comprising:

at least one computing device implementing a supplier-side credential management system for performing:

assigning a unique identifier to a computer product instance to be deployed at a customer site; and

generating security credentials for the computer product instance dependent on i) the assigned unique identifier and ii) a customer identifier associated with the computer product instance; and

at least one computing device implementing a customer-side automated deployment agent for performing:

obtaining the security credentials, at a first time, for the computer product instance that were generated dependent on the assigned unique identifier and the customer identifier;

using the security credentials during deployment of the computer product instance;

after using the security credentials, attempting to obtain the security credentials, at a second time after the first time, from the supplier of the computer product instance; and

in response to attempting to obtain the security credentials at the second time after the first time, preventing use of the security credentials at the second time.

12. The system of claim 11 , wherein:

generating the security credential comprises:

the supplier-side credential management system generating the security credentials; and

the supplier-side credential management system storing the security credentials; and

obtaining the security credentials comprises the customer-side automated deployment agent requesting and receiving the security credentials from the supplier-side credential management system over a secure communication channel.

13. The system of claim 11 , wherein:

generating the security credential comprises the supplier-side credential management system generating the security credentials using a shared credential generation program;

the supplier-side credential management system further performs providing the shared credential generation program to the customer-side automated deployment agent; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the provided shared credential generation program.

14. The system of claim 11 , wherein:

generating the security credential comprises:

receiving a shared credential generation program from the customer-side automated deployment agent; and

generating the security credentials using the shared credential generation program; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the shared credential generation program.

15. The system of claim 11 , wherein:

the unique identifier assigned to the computer product instance comprises an identifier of a hardware or software component of the computer product instance or a unique identifier selected by a supplier or customer; and

the security credentials comprise one or more of an access username, an access password, an access cookie, an access token, a cryptographic key, a public key token, or a digital certificate.

16. Non-transitory computer readable memory media storing instructions executable to implement:

a supplier-side credential management system configured to perform:

assigning a unique identifier to a computer product instance to be deployed at a customer site; and

generating security credentials for the computer product instance dependent on i) the assigned unique identifier and ii) a customer identifier associated with the computer product instance; and

a customer-side automated deployment agent configured to perform:

obtaining the security credentials, at a first time, for the computer product instance that were generated dependent on the assigned unique identifier and the customer identifier;

using the security credentials during deployment of the computer product instance;

after using the security credentials, attempting to obtain the security credentials, at a second time after the first time, from the supplier of the computer product instance; and

in response to attempting to obtain the security credentials at the second time after the first time, preventing use of the security credentials at the second time.

17. The media of claim 16 , wherein:

generating the security credential comprises:

the supplier-side credential management system generating the security credentials; and

the supplier-side credential management system storing the security credentials; and

obtaining the security credentials comprises the customer-side automated deployment agent requesting and receiving the security credentials from the supplier-side credential management system over a secure communication channel.

18. The media of claim 16 , wherein:

generating the security credential comprises the supplier-side credential management system generating the security credentials using a shared credential generation program;

the supplier-side credential management system is further configured to perform providing the shared credential generation program to the customer-side automated deployment agent; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the provided shared credential generation program.

19. The media of claim 16 , wherein:

generating the security credential comprises:

receiving a shared credential generation program from the customer-side automated deployment agent; and

generating the security credentials using the shared credential generation program; and

obtaining the security credentials comprises the customer-side automated deployment agent generating the security credentials using the shared credential generation program.

20. The method of claim 1 , wherein the unique identifier assigned to the computer product instance comprises a randomly generated alphanumeric identifier that is mutually agreed upon by the supplier of the computer product instance and the customer-side automated deployment agent.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2021
From: KANEVSKY, ARKADY; STREETE, JONATHAN PETER
To: DELL PRODUCTS L.P.
Reel/Frame 055508/0347 →
Continuity (1)
Related Publication 20220284089A1 · Sep 8, 2022