IP Library Granted Patent US 12,149,520
Granted Patent B2
US 12,149,520 · App. 17/499,639 · Granted Nov 19, 2024

Device enrollment in a unified endpoint management system over a closed network

Inventors: Gaurav Verma (Bangalore, IN); Karthikeyan Palanisamy (Bangalore, IN)
Assignee: Omnissa, LLC
H04L63/0823G06F8/61G06F16/9566G06K7/1417G06K19/06037G06F9/44505G06F9/4451
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,149,520
App. No.
17/499,639
Granted
Nov 19, 2024
Kind
B2
Abstract

Systems and methods are described for enrolling a user device in a Unified Endpoint Management (“UEM”) system over a closed network. After an initial boot or factory reset of a user device, a user can scan a Quick Response code, or other scannable code, that is embedded with enrollment configuration data that includes configuration settings for communicating with a UEM server in the UEM system. Using the enrollment configuration data, the user device can retrieve an installation file for a management application. The user device can install the management application and give the management application access to the enrollment configuration data. The management application can disable hardcoded open network endpoints on the user device and configure the user device for UEM communications on the closed network. The user device can connect to the UEM server over the closed network and request enrollment in the UEM system.

Claims (51)

1. A method for enrolling a user device in a unified endpoint management (UEM) system over a closed network, the method comprising:

scanning a code to acquire enrollment configuration data including a first uniform resource locator (URL) of a management application installation file, a second URL of a UEM server, information indicating that one or more hardcoded open network endpoints of an operating system (OS) of the user device are to be disabled, and access credentials for connecting to the closed network;

downloading the management application installation file from a location specified by the first URL in the acquired enrollment configuration data, and then installing the management application on the user device using the downloaded management application installation file; and

performing the following steps using the installed management application:

disabling access for the one or more hardcoded open network endpoints on the OS of the user device in response to the information in the acquired enrollment configuration data indicating that the one or more hardcoded open network endpoints are to be disabled;

connecting to the closed network using the access credentials in the acquired enrollment configuration data; and

sending an enrollment request over the closed network to the UEM server, which is at a location specified by the second URL in the acquired enrollment configuration data.

2. The method of claim 1 , wherein the acquired enrollment configuration data further includes proxy settings, the method further comprising:

before sending the enrollment request to the UEM server, configuring settings of the user device to match the proxy settings in the acquired enrollment configuration data.

3. The method of claim 1 , wherein the acquired enrollment configuration data further includes a third URL of a certificate server, the method further comprising:

downloading a certificate from the certificate server, which is at a location specified by the third URL in the acquired enrollment configuration data, wherein the enrollment request includes the downloaded certificate.

4. The method of claim 1 , wherein the UEM server authenticates the user device in response to the enrollment request, to enable the user device to access services of the UEM system.

5. The method of claim 1 , wherein the acquired enrollment configuration data further includes permission settings for the installed management application, the method further comprising:

upon installing the management application, configuring settings of the user device to match the permission settings in the acquired enrollment configuration data.

6. The method of claim 1 , further comprising:

prior to scanning the code, factory resetting the user device.

7. The method of claim 1 , wherein the code is a quick response (QR) code.

8. A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, cause the processor to perform a method for enrolling a user device in a unified endpoint management (UEM) system over a closed network, wherein the method comprises:

scanning a code to acquire enrollment configuration data including a first uniform resource locator (URL) of a management application installation file, a second URL of a UEM server, information indicating that one or more hardcoded open network endpoints of an operating system (OS) of the user device are to be disabled, and access credentials for connecting to the closed network;

downloading the management application installation file from a location specified by the first URL in the acquired enrollment configuration data, and then installing the management application on the user device using the downloaded management application installation file; and

performing the following steps using the installed management application:

disabling access for the one or more hardcoded open network endpoints on the OS of the user device in response to the information in the acquired enrollment configuration data indicating that the one or more hardcoded open network endpoints are to be disabled;

connecting to the closed network using the access credentials in the acquired enrollment configuration data; and

sending an enrollment request over the closed network to the UEM server, which is at a location specified by the second URL in the acquired enrollment configuration data.

9. The non-transitory, computer-readable medium of claim 8 , wherein the acquired enrollment configuration data further includes proxy settings, and the method further comprises:

before sending the enrollment request to the UEM server, configuring settings of the user device to match the proxy settings in the acquired enrollment configuration data.

10. The non-transitory, computer-readable medium of claim 8 , wherein the acquired enrollment configuration data further includes a third URL of a certificate server, and the method further comprises:

downloading a certificate from the certificate server, which is at a location specified by the third URL in the acquired enrollment configuration data, wherein the enrollment request includes the downloaded certificate.

11. The non-transitory, computer-readable medium of claim 8 , wherein the UEM server authenticates the user device in response to the enrollment request, to enable the user device to access services of the UEM system.

12. The non-transitory, computer-readable medium of claim 8 , wherein the acquired enrollment configuration data further includes permission settings for the installed management application, and the method further comprises:

upon installing the management application, configuring settings of the user device to match the permission settings in the acquired enrollment configuration data.

13. The non-transitory, computer-readable medium of claim 8 , wherein the method further comprises:

prior to scanning the code, factory resetting the user device.

14. The non-transitory, computer-readable medium of claim 8 , wherein the code is a quick response (QR) code.

15. A user device comprising memory and a hardware-based processor configured to execute instructions stored in the memory to enroll the user device in a unified endpoint management (UEM) system over a closed network, by performing the following steps:

scanning a code to acquire enrollment configuration data including a first uniform resource locator (URL) of a management application installation file, a second URL of a UEM server, information indicating that one or more hardcoded open network endpoints of an operating system (OS) of the user device are to be disabled, and access credentials for connecting to the closed network;

downloading the management application installation file from a location specified by the first URL in the acquired enrollment configuration data, and then installing the management application on the user device using the downloaded management application installation file; and

performing the following using the installed management application:

disabling access for the one or more hardcoded open network endpoints on the OS of the user device in response to the information in the acquired enrollment configuration data indicating that the one or more hardcoded open network endpoints are to be disabled;

connecting to the closed network using the access credentials in the acquired enrollment configuration data; and

sending an enrollment request over the closed network to the UEM server, which is at a location specified by the second URL in the acquired enrollment configuration data.

16. The user device of claim 15 , wherein the acquired enrollment configuration data further includes proxy settings, and the steps further include:

before sending the enrollment request to the UEM server, configuring settings of the user device to match the proxy settings in the acquired enrollment configuration data.

17. The user device of claim 15 , wherein the acquired enrollment configuration data further includes a third URL of a certificate server, and the steps further include:

downloading a certificate from the certificate server, which is at a location specified by the third URL in the acquired enrollment configuration data, wherein the enrollment request includes the downloaded certificate.

18. The user device of claim 15 , wherein the acquired enrollment configuration data further includes permission settings for the installed management application, and the steps further include:

upon installing the management application, configuring settings of the user device to match the permission settings in the acquired enrollment configuration data.

19. The user device of claim 15 , wherein the steps further include:

prior to scanning the code, factory resetting the user device.

20. The user device of claim 15 , wherein the acquired enrollment configuration data further includes an indication that a certificate is required for enrolling in the UEM system, and the steps further include:

downloading the certificate from a certificate server in response to the indication in the acquired enrollment configuration data that the certificate is required for enrolling in the UEM system, wherein the enrollment request includes the downloaded certificate.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2021
From: VERMA, GAURAV; PALANISAMY, KARTHIKEYAN
To: VMWARE, INC.
Reel/Frame 057769/0797 →