IP Library › Granted Patent US 12,609,935
Granted Patent B2
US 12,609,935 · App. 18/541,259 · Granted Apr 21, 2026

Secure telemetry in a zero-trust computing environment

Inventors: Charles D. Robison (Buford, GA); Joseph Kozlowski (Broken Arrow, OK); Girish S. Dhoble (Toronto, CA)
Assignee: Dell Products, L.P.
H04L63/10H04L63/0435H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,935
App. No.
18/541,259
Granted
Apr 21, 2026
Kind
B2
Abstract

Systems and methods that operate an Information Handling System (IHS) support secure telemetry for use in a zero-trust environment. Upon being initialized, the IHS retrieves a factory-provisioned resource locator of a service that provides the location of a policy decision point of the zero-trust environment. The IHS establishes an encrypted session with the policy decision point that is located using the factory-provisioned resource locator. Via the encrypted session, the IHS receives a symmetric key from the policy decision point, where the key may be fleet-wide key for encryption of a customer's telemetry. Telemetry that is generated by the sensors is identified when ready for transmission and encrypted using the symmetric key received from the policy decision point. The customer's encrypted telemetry can then be securely transmitted.

Claims (41)

1 . An Information Handling System (IHS) supporting secure telemetry for use in a zero-trust environment, the IHS comprising:

one or more processors;

a plurality of sensors used to generate telemetry;

a memory coupled to the processors, the memory storing program instructions that, upon execution by the processors, cause the IHS to:

retrieve a factory-provisioned resource locator of a service that provides the location of a policy decision point of the zero-trust environment;

establish an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receive a symmetric key from the policy decision point;

identify telemetry generated by the sensors that is ready for transmission;

encrypt the telemetry using the symmetric key received from the policy decision point; and

transmit the encrypted telemetry.

2 . The IHS of claim 1 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted by a group of co-managed IHSs.

3 . The IHS of claim 1 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted to a particular destination by a group of co-managed IHSs.

4 . The IHS of claim 1 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted by a hardware component installed in the IHS.

5 . The IHS of claim 4 , wherein the hardware component comprises a hardware component supplied by a customer for which the IHS was factory-provisioned.

6 . The IHS of claim 4 , wherein the fleet key is used to encrypt telemetry being transmitted by all instances of the hardware component installed in a group of co-managed IHSs.

7 . The IHS of claim 1 , wherein the symmetric key comprises a fleet key used to encrypt user-presence telemetry being transmitted by a group of co-managed IHSs.

8 . The IHS of claim 1 , wherein the encrypted telemetry is transmitted to a destination specified in a telemetry definition that is provided by the policy decision point.

9 . The IHS of claim 1 , wherein updates to the telemetry definition adjust the telemetry that is encrypted by the IHS using the fleet key.

10 . The IHS of claim 9 , wherein updates to the telemetry definition are provided by the policy decision point.

11 . A method for secure telemetry collection by an Information Handling System (IHS), the method comprising:

retrieving a resource locator from a factory-provisioned storage of the IHS, wherein the resource locator identifies a service that provides the location of a policy decision point of the zero-trust environment;

establishing, by the IHS, an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receiving a symmetric key from the policy decision point;

identifying telemetry generated by one or more sensors of the IHS that is ready for transmission;

encrypting the telemetry using the symmetric key received from the policy decision point; and

transmitting the encrypted telemetry.

12 . The method of claim 10 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted by a group of co-managed IHSs.

13 . The method of claim 10 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted to a particular destination by a group of co-managed IHSs.

14 . The method of claim 10 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted by a hardware component installed in the IHS.

15 . The method of claim 14 , wherein the hardware component comprises a hardware component supplied by a customer for which the IHS was factory-provisioned.

16 . The method of claim 14 , wherein the fleet key is used to encrypt telemetry being transmitted by instances of the hardware component installed in a group of co-managed IHSs.

17 . A computer-readable storage device having instructions stored thereon for secure telemetry collection by an IHS (Information Handling System), wherein execution of the instructions by one or more processors causes the one or more processors to:

retrieve a factory-provisioned resource locator of a service that provides the location of a policy decision point of the zero-trust environment;

establish an encrypted session with the policy decision point that is located using the factory-provisioned resource locator;

via the encrypted session, receive a symmetric key from the policy decision point;

identify telemetry generated by the sensors that is ready for transmission;

encrypt the telemetry using the symmetric key received from the policy decision point; and

transmit the encrypted telemetry.

18 . The computer-readable storage device of claim 17 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted by a group of co-managed IHSs.

19 . The computer-readable storage device of claim 17 , wherein the symmetric key comprises a fleet key used to encrypt telemetry being transmitted to a particular destination by a group of co-managed IHSs.

20 . The computer-readable storage device of claim 17 , wherein the symmetric key comprises a fleet key used to encrypt all telemetry being transmitted by a hardware component installed in the IHS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: ROBISON, CHARLES D.; KOZLOWSKI, JOSEPH; DHOBLE, GIRISH S.
To: DELL PRODUCTS, L.P.
Reel/Frame 065882/0553 →
Continuity (1)
Related Publication 20250202895A1 · Jun 19, 2025
References Cited (3)
US 20160204992A1 · Wu · 2016 [cited by examiner]
US 20210409423A1 · Bhandari · 2021 [cited by examiner]
US 20220019561A1 · Jose · 2022 [cited by examiner]