IP Library Granted Patent US 12,199,971
Granted Patent B2
US 12,199,971 · App. 17/349,052 · Granted Jan 14, 2025

System and method for transferring device identifying information

Inventors: Emily Hong Xu (Palo Alto, CA); Lloyd Spencer Evans (Auburn, CA); Lakshman Rao Abburi (Pleasanton, CA); Tomas Boman (San Francisco, CA)
Assignee: Omnissa, LLC
H04L63/0823G06F16/24552G06F16/9535G06F21/33G06F21/73H04L63/0807H04L63/0815H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,971
App. No.
17/349,052
Granted
Jan 14, 2025
Kind
B2
Abstract

Disclosed are various examples for transferring device identifying information during authentication. An enrollment request is received from a management component executed by a client device. A management service generates a unique device identifier for the client device and embeds it within a certificate to generate a device-identifying certificate. The management service instructs a certificate authority service to generate a public key that includes the unique device identifier and a private key for the client device, and provides the device-identifying certificate and the private key to the client device.

Claims (43)

1. A system comprising:

a data store comprising executable instructions; and

at least one computing device comprising at least one processor, wherein the instructions, when executed by the at least one processor, cause the at least one computing device to at least;

receive, by a device management service for a corporate entity, an enrollment request to enroll in the device management service from a device management component executed by a client device, wherein the device management service manages access to corporate resources of the corporate entity and enforces corporate policies including one or more compliance rules on employee devices;

generate, by the device management service, a unique device identifier for the client device;

transmit over a network, from the device management service to a certificate authority service separate from the device management service, a message including instructions to generate a client key for the client device, the message further including the unique device identifier for the client device;

receive, at the device management service and from the certificate authority service, a private key for the client device and a device-identifying certificate generated from a public key for the client device, wherein the device identifier is embedded in the certificate and the device-identifying certificate enables authentication of the client device to access the corporate resources managed by the device management service;

transmit, by the device management service, the device-identifying certificate and the private key to the client device, wherein the client device uses the device-identifying certificate to obtain a ticket from a key distribution server;

receive a request to verify that the client device complies with the one or more compliance rules, the request including the unique device identifier of the client device extracted from the ticket that the client device obtained from the key distribution server; and

transmit a response to the request, the response containing an indication of whether the client device complies with the one or more compliance rules.

2. The system of claim 1 , wherein the instructions, when executed by the at least one processor, further cause the at least one computing device to at least:

generate, by the device management service, a managed device entry for the client device, the managed device entry comprising the unique device identifier, a user identification, and an indicium of enrollment of the client device.

3. The system of claim 1 , wherein the request to verify that the client device complies with the one or more compliance rules is received by the device management service from an identity provider service.

4. The system of claim 3 , wherein the response is transmitted from the device management service to the identity provider service.

5. The system of claim 1 , wherein the device management component of the client device sends the ticket to an identity provider service and wherein the identity provider service extracts the unique device identifier of the client device from the ticket.

6. The system of claim 5 , wherein the identity provider service is configured to cache the unique device identifier and session data that includes a most recent status of whether the client device complies with the one or more compliance rules.

7. A non-transitory computer-readable medium embodying executable instructions, wherein the instructions, when executed by at least one processor, cause at least one computing device to at least:

receive, by a device management service for a corporate entity, an enrollment request to enroll in the device management service from a device management component executed by a client device, wherein the device management service manages access to corporate resources of the corporate entity and enforces corporate policies on employee devices;

generate, by the device management service, a unique device identifier for the client device;

transmit over a network, from the device management service to a certificate authority service separate from the device management service, a message including instructions to generate a client key for the client device, the message further including the unique device identifier for the client device;

receive, at the device management service and from the certificate authority service, a private key for the client device and a device-identifying certificate generated from a public key for the client device, wherein the device identifier is embedded in the certificate and the device-identifying certificate enables authentication of the client device to access the corporate resources managed by the device management service;

transmit, by the device management service, the device-identifying certificate and the private key to the client device, wherein the client device uses the device-identifying certificate to obtain a ticket from a key distribution server;

receive a request to verify that the client device complies with one or more compliance rules, the request including the unique device identifier of the client device extracted from the ticket obtained from the key distribution server; and

transmit a response to the request, the response containing an indication of whether the client device complies with the one or more compliance rules.

8. The non-transitory computer-readable medium of claim 7 , wherein the instructions, when executed by the at least one processor, further cause the at least one computing device to at least:

generate, by the device management service, a managed device entry for the client device, the managed device entry comprising the unique device identifier, a user identification, and an indicia of enrollment of the client device.

9. The non-transitory computer-readable medium of claim 7 , wherein the request to verify that the client device complies with the one or more compliance rules is received by the device management service from an identity provider service.

10. The non-transitory computer-readable medium of claim 9 , wherein the response is transmitted from the device management service to the identity provider service.

11. The non-transitory computer-readable medium of claim 7 , wherein the device management component of the client device sends the ticket to an identity provider service and wherein the identity provider service extracts the unique device identifier of the client device from the ticket.

12. The non-transitory computer-readable medium of claim 11 , wherein the identity provider service is configured to cache the unique device identifier and session data that includes a most recent status of whether the client device complies with the one or more compliance rules.

13. A method performed by instructions executed in at least one computing device, the method comprising:

receiving, by a device management service for a corporate entity, an enrollment request to enroll in the device management service from a device management component executed by a client device, wherein the device management service manages access to corporate resources of the corporate entity and enforces corporate policies on employee devices;

generating, by the device management service, a unique device identifier for the client device;

transmitting over a network, from the device management service to a certificate authority service separate from the device management service, a message including instructions to generate a client key for the client device, the message further including the unique device identifier for the client device;

receiving, at the device management service and from the certificate authority service, a private key for the client device and a device-identifying certificate generated from a public key for the client device, wherein the device identifier is embedded in the certificate and the device-identifying certificate enables authentication of the client device to access the corporate resources managed by the device management service;

transmitting, by the device management service, the device-identifying certificate and the private key to the client device, wherein the client device uses the device-identifying certificate to obtain a ticket from a key distribution server;

receiving a request to verify that the client device complies with one or more compliance rules, the request including the unique device identifier of the client device extracted from the ticket obtained from the key distribution server; and

transmitting a response to the request, the response containing an indication of whether the client device complies with the one or more compliance rules.

14. The method of claim 13 , further comprising:

generating, by the device management service, a managed device entry for the client device, the managed device entry comprising the unique device identifier, a user identification, and an indicia of enrollment of the client device.

15. The method of claim 13 , wherein the request to verify that the client device complies with the one or more compliance rules is received by the device management service from an identity provider service.

16. The method of claim 15 , wherein the response is transmitted from the device management service to the identity provider service.

17. The method of claim 13 , wherein the device management component of the client device sends the ticket to an identity provider service and wherein the identity provider service extracts the unique device identifier of the client device from the ticket.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
Continuity (4)
Continuation 16426383 · May 30, 2019
Continuation 15197997 · Jun 30, 2016
Provisional Application 62288928 · Jan 29, 2016
Related Publication 20210314312A1 · Oct 7, 2021
References Cited (33)
US 8776209B1 · Kumar et al. · 2014 [cited by applicant]
US 9258295B1 · Nedeltchev · 2016 [cited by examiner]
US 9424547B2 · Gazdzinski et al. · 2016 [cited by applicant]
US 9646309B2 · Goldschlag et al. · 2017 [cited by applicant]
US 9866591B1 · Statica et al. · 2018 [cited by applicant]
US 10362021B2 · Newell et al. · 2019 [cited by applicant]
US 20040167984A1 · Herrmann · 2004 [cited by applicant]
US 20040230797A1 · Ofek et al. · 2004 [cited by applicant]
US 20060041761A1 · Neumann et al. · 2006 [cited by applicant]
US 20070079113A1 · Kulkarni et al. · 2007 [cited by applicant]
US 20100125897A1 · Jain et al. · 2010 [cited by applicant]
US 20110321152A1 · Tor et al. · 2011 [cited by applicant]
US 20140109175A1 · Barton et al. · 2014 [cited by applicant]
US 20140136838A1 · Mossbarger · 2014 [cited by examiner]
US 20150052595A1 · Murphy · 2015 [cited by applicant]
US 20150096010A1 · Pollutro et al. · 2015 [cited by applicant]
US 20150271013A1 · Singh et al. · 2015 [cited by applicant]
US 20150295892A1 · Fox · 2015 [cited by applicant]
US 20160036804A1 · Moore · 2016 [cited by applicant]
US 20160052595A1 · Dommsch · 2016 [cited by applicant]
US 20160088021A1 · Jayanti Venkata et al. · 2016 [cited by applicant]
US 20160099969A1 · Angus et al. · 2016 [cited by applicant]
US 20160191567A1 · Chahal et al. · 2016 [cited by applicant]
US 20160285858A1 · Li et al. · 2016 [cited by applicant]
US 20160292694A1 · Goldschlag et al. · 2016 [cited by applicant]
US 20160366121A1 · Rykowski et al. · 2016 [cited by applicant]
US 20170223012A1 · Xu et al. · 2017 [cited by applicant]
US 20180131719A1 · Amit et al. · 2018 [cited by applicant]
US 20180332003A1 · Deriso · 2018 [cited by applicant]
US 20180337887A1 · Aluvala et al. · 2018 [cited by applicant]
US 20180337889A1 · Panchapakesan et al. · 2018 [cited by applicant]
WO WO2013133840A1 · 2013 [cited by examiner]
WO 2015154066 · 2015 [cited by applicant]