IP Library Granted Patent US 12,549,547
Granted Patent B2
US 12,549,547 · App. 18/441,676 · Granted Feb 10, 2026

Universal device identifiers and signal exchange collaboration

Inventors: Dan Cuddeford (Mill Valley, CA); Matthew Vlasach (Larkspur, CA); Mateusz Popialo (Katowice, PL)
Assignee: JAMF SOFTWARE, LLC
H04L63/0876H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,547
App. No.
18/441,676
Filed
Feb 14, 2024
Granted
Feb 10, 2026
Kind
B2
Art Unit
2499
USPC
726/4
Abstract

In certain aspects of the disclosure, a computer-implemented method includes enrolling, at a mobile device management service, at least one managed device. The method includes receiving a client certificate on the at least one managed device. The method includes integrating, via a trusted ecosystem vendor app on the at least one managed device, a universal device identifier SDK. The method includes retrieving, by the universal device identifier SDK based on a request from the trusted ecosystem vendor app, a pre-salted device identifier address associated with the at least one managed device. The method includes transmitting, by the at least one managed device via the trusted ecosystem vendor, the pre-salted device identifier address to a security vendor service for generating a universal device identifier address. The method includes receiving, from the security vendor service by the at least one managed device via the trusted ecosystem vendor, the universal device identifier address.

Claims (59)

1 . A computer-implemented method for generating universal device identifiers, the method comprising:

enrolling, at a mobile device management service, at least one managed device;

receiving a client certificate on the at least one managed device;

integrating, via a trusted ecosystem vendor app on the at least one managed device, a universal device identifier SDK (software development kit);

retrieving, by a universal device identifier endpoint SDK based on a request from the trusted ecosystem vendor app, a pre-salted device identifier address associated with the at least one managed device;

transmitting, by the at least one managed device via the trusted ecosystem vendor, the pre-salted device identifier address to a security vendor service for generating a universal device identifier address; and

receiving, from the security vendor service by the at least one managed device via the trusted ecosystem vendor, the universal device identifier address.

2 . The computer-implemented method of claim 1 , wherein receiving the client certificate comprises:

generating a private key for the client certificate on the at least one managed device.

3 . The computer-implemented method of claim 2 , wherein the private key is non-exportable.

4 . The computer-implemented method claim 2 , wherein the private key is generated via a hardware-backed keystore.

5 . The computer-implemented method of claim 4 , wherein retrieving the pre-salted device identifier address comprises:

validating a trust chain of the client certificate;

generating a nonce to challenge the hardware-backed keystore;

transmitting the nonce to the hardware-backed keystore referencing the client certificate;

receiving, based on the private key, a signed nonce challenge response and corresponding public key;

validating the nonce challenge response using the corresponding public key that was returned;

attesting integrity of the private key; and

returning the pre-salted device identifier.

6 . The computer-implemented method of claim 2 , wherein generating the universal device identifier address comprises:

generating a value by hashing the pre-salted device identifier with an administrator defined salt.

7 . The computer-implemented method of claim 6 , wherein generating the value comprises:

generating, via a SECP256K1 key generation algorithm, a universal device identifier keypair.

8 . The computer-implemented method of claim 1 , wherein the universal device identifier address comprises 42 characters in length and is represented as a hex address.

9 . The computer-implemented method of claim 1 , wherein the universal device identifier address is associated with the at least one managed device in a database associated with the security vendor service as a final correlating device identifier.

10 . A system comprising:

one or more memories comprising instructions; and

one or more processors configured to execute the instructions, which, when executed, cause the one or more processors to:

enroll, at a mobile device management service, at least one managed device;

receive a client certificate on the at least one managed device;

integrate, via a trusted ecosystem vendor app on the at least one managed device, a universal device identifier SDK;

retrieve, by a universal device identifier endpoint SDK based on a request from the trusted ecosystem vendor app, a pre-salted device identifier address associated with the at least one managed device;

transmit, by the at least one managed device via the trusted ecosystem vendor, the pre-salted device identifier address to a security vendor service for generating a universal device identifier address; and

receive, from the security vendor service by the at least one managed device via the trusted ecosystem vendor, the universal device identifier address.

11 . The system of claim 10 , wherein the instructions to receive the client certificate further comprise instructions to cause the one or more processors to:

generate a private key for the client certificate on the at least one managed device.

12 . The system of claim 11 , wherein the private key is non-exportable.

13 . The system of claim 11 , wherein the private key is generated via a hardware-backed keystore.

14 . The system of claim 13 , wherein the instructions to retrieve the pre-salted device identifier address comprise instructions to cause the one or more processors to:

validating a trust chain of the client certificate;

generating a nonce to challenge the hardware-backed keystore;

transmitting the nonce to the hardware-backed keystore referencing the client certificate;

receiving, based on the private key, a signed nonce challenge response and corresponding public key;

validating the nonce challenge response using the corresponding public key that was returned;

attesting integrity of the private key; and

returning the pre-salted device identifier.

15 . The system of claim 11 , wherein the instructions to generate the universal device identifier address comprise further instructions to cause the one or more processors to:

generate a value by hashing the pre-salted device identifier with an administrator defined salt.

16 . The system of claim 15 , wherein the instructions to generate the value comprise further instructions to cause the one or more processors to:

generate a value by hashing the pre-salted device identifier with an administrator defined salt.

17 . The system of claim 10 , wherein the universal device identifier address comprises 42 characters in length and is represented as a hex address.

18 . The system of claim 10 , wherein the universal device identifier address is associated with the at least one managed device in a database associated with the security vendor service as a final correlating device identifier.

19 . A non-transitory machine-readable storage medium comprising machine-readable instructions for causing one or more processors to execute a method, the method comprising:

enrolling, at a mobile device management service, at least one managed device;

receiving a client certificate on the at least one managed device;

integrating, via a trusted ecosystem vendor app on the at least one managed device, a universal device identifier SDK;

retrieving, by a universal device identifier endpoint SDK based on a request from the trusted ecosystem vendor app, a pre-salted device identifier address associated with the at least one managed device;

transmitting, by the at least one managed device via the trusted ecosystem vendor, the pre-salted device identifier address to a security vendor service for generating a universal device identifier address; and

receiving, from the security vendor service by the at least one managed device via the trusted ecosystem vendor, the universal device identifier address.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Mar 3, 2026
From: JAMF SOFTWARE, LLC
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 075025/0447 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2024
From: CUDDEFORD, DAN; VLASACH, MATTHEW; POPIALO, MATEUSZ
To: JAMF SOFTWARE, LLC
Reel/Frame 066545/0508 →
Continuity (2)
Provisional Application 63484997 · Feb 14, 2023
Related Publication 20240275782A1 · Aug 15, 2024
References Cited (16)
US 9246686B1 · Holland et al. · 2016 [cited by applicant]
US 20160037333A1 · Amundsen et al. · 2016 [cited by applicant]
US 20180034822A1 · Mistry · 2018 [cited by examiner]
US 20190109820A1 · Clark · 2019 [cited by examiner]
US 20190121988A1 · van de Ruit et al. · 2019 [cited by applicant]
US 20200374129A1 · Dilles · 2020 [cited by examiner]
US 20210329058A1 · Adams et al. · 2021 [cited by applicant]
US 20220385467A1 · Ramadasse et al. · 2022 [cited by applicant]
US 20240171567A1 · Perlman · 2024 [cited by examiner]
WO 2020076234A1 · 2020 [cited by applicant]
WO 2022050833A1 · 2022 [cited by applicant]
Mazhar et al, Role of Device Identification and Manufacturer Usage Description in IoT Security: A Survey, Mar. 10, 2021, IEEE, pp. 41757-41786. (Year: 2021). [cited by examiner]
Gamba et al, An Analysis of Pre-installed Android Software, May 21, 2020, IEEE, pp. 1039-1055. (Year: 2020). [cited by examiner]
Acar et al., Sok: Lessons Learned From Android Security Research for Appified Software Platforms, May 26, 2016, IEEE, pp. 433-451. (Year: 2016). [cited by examiner]
International Searching Authority dated May 6, 2024 for PCT/US2024/015789, 2 pages. [cited by applicant]
International Search Report and Written Opinion issued in International Patent Application No. PCT/US24/15789, mailing date Jul. 18, 2024. [cited by applicant]