IP Library › Granted Patent US 10,452,384
Granted Patent B2
US 10,452,384 · App. 15/888,899 · Granted Oct 22, 2019

Device health tickets

Inventor: Paul England (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F8/65G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,384
App. No.
15/888,899
Granted
Oct 22, 2019
Kind
B2
Abstract

Disclosed are systems that provide for secure and reliable remote management. Cryptographic health tickets provided by a management server are provided to a protected process executing on a computing device. In some examples, the health tickets reset an authenticated watchdog timer that resets the computing device if the timer expires. In some examples, the computing device may contact the management server prior to loading an operating system to receive instructions, but may omit contacting the management server if a valid health ticket is found.

Claims (71)

1. A method for facilitating remote monitoring of a computing device, the method comprising:

using a hardware processor of the computing device to execute a trusted process during a boot sequence of the computing device before a network stack is loaded by the computing device, the trusted process:

determining that a valid health ticket issued by a management server accessible over a computer network is not present on the computing device, the determining comprising:

retrieving a health ticket from a predetermined location in a non-volatile memory of the computing device; and

failing to validate a digital signature of the health ticket;

in response to determining that the valid health ticket is not on the computing device:

executing instructions to create a network stack;

requesting recovery instructions from a management server over a network;

receiving the recovery instructions; and

executing the recovery instructions.

2. The method of claim 1 , wherein on a second boot sequence of the computing device, the trusted process:

determining that a valid health ticket issued by the management server is present on the computing device; and

in response to determining that the valid health ticket is present, causing the computing device to execute an operating system without the trusted process loading the network stack, requesting recovery instructions, receiving the recovery instructions, and executing the recovery instructions.

3. The method of claim 2 , further comprising, using an operating system on the computing device, the operating system:

requesting a new health ticket from the management server over the computer network;

receiving the new health ticket from the management server; and

communicating the new health ticket to the trusted process.

4. The method of claim 1 , wherein the method further comprises:

causing a nonce value to be provided to a management server; and

failing to validate the digital signature of the health ticket based upon a mismatch between a value in the digital signature and the nonce.

5. The method of claim 4 , wherein causing the nonce value to be provided to the management server comprises:

providing the nonce value to an operating system, the operating system transmitting the nonce value to the management server.

6. The method of claim 5 , wherein the method further comprises:

generating a new nonce value at random every time the computing device boots.

7. A computing device comprising:

a hardware processor configured to execute a trusted process during a boot sequence of the computing device before a network stack is loaded by the computing device, the trusted process comprising instructions causing the computing device to perform operations comprising:

determining that a valid health ticket issued by a management server accessible over a computer network is not present on the computing device, the determining comprising:

retrieving a health ticket from a predetermined location in a non-volatile memory of the computing device; and

failing to validate a digital signature of the health ticket;

in response to determining that the valid health ticket is not on the computing device:

executing instructions to create a network stack;

requesting recovery instructions from a management server over a network;

receiving the recovery instructions; and

executing the recovery instructions.

8. The computing device of claim 7 , wherein the trusted process is one of: a bootloader or a firmware.

9. The computing device of claim 7 , wherein on a second boot sequence of the computing device, the trusted process comprising instructions causing the computing device to perform the operations comprising:

determining that a valid health ticket issued by the management server is present on the computing device; and

in response to determining that the valid health ticket is present, causing the computing device to execute an operating system without the trusted process loading the network stack, requesting recovery instructions, receiving the recovery instructions, and executing the recovery instructions.

10. The computing device of claim 9 , wherein the operating system comprises instructions to cause the computing device to perform operations comprising:

requesting a new health ticket from the management server over the computer network;

receiving the new health ticket from the management server; and

communicating the new health ticket to the trusted process.

11. The computing device of claim 7 , wherein the recovery instructions include instructions for updating a software object on the computing device.

12. The computing device of claim 7 , wherein the operations further comprise:

causing a nonce value to be provided to a management server; and

failing to validate the digital signature of the health ticket based upon a mismatch between a value in the digital signature and the nonce.

13. The computing device of claim 12 , wherein the operations of causing the nonce value to be provided to the management server comprises:

providing the nonce value to an operating system, the operating system transmitting the nonce value to the management server.

14. The computing device of claim 13 , wherein the operations further comprise:

generating a new nonce value at random every time the computing device boots.

15. A hardware machine-readable storage medium comprising instructions for a trusted process, the instructions, when executed by a hardware processor of a computing device causing the computing device to perform operations during a boot sequence of a computing device before a network stack is loaded, the operations comprising:

determining that a valid health ticket issued by a management server accessible over a computer network is not present on the computing device, the determining comprising:

retrieving a health ticket from a predetermined location in a non-volatile memory of the computing device; and

failing to validate a digital signature of the health ticket:

in response to determining that the valid health ticket is not on the computing device:

executing instructions to create a network stack;

requesting recovery instructions from a management server over a network;

receiving the recovery instructions; and

executing the recovery instructions.

16. The hardware machine-readable storage medium of claim 15 , wherein the trusted process is one of: a bootloader or a firmware.

17. The hardware machine-readable storage medium of claim 15 , wherein on a second boot sequence of the computing device, the operations comprise:

determining that a valid health ticket issued by the management server is present on the computing device; and

in response to determining that the valid health ticket is present, causing the computing device to execute an operating system without the trusted process loading the network stack, requesting recovery instructions, receiving the recovery instructions, and executing the recovery instructions.

18. The hardware machine-readable storage medium of claim 15 , wherein the recovery instructions include instructions for updating a software object on the computing device.

19. The hardware machine-readable storage medium of claim 15 , wherein the operations further comprise:

causing a nonce value to be provided to a management server; and

failing to validate the digital signature of the health ticket based upon a mismatch between a value in the digital signature and the nonce.

20. The hardware machine-readable storage medium of claim 19 , wherein the operations of causing the nonce value to be provided to the management server comprises:

providing the nonce value to an operating system, the operating system transmitting the nonce value to the management server.

21. The hardware machine-readable storage medium of claim 20 , wherein the operations further comprise:

generating a new nonce value at random every time the computing device boots.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2018
From: ENGLAND, PAUL
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 045381/0660 →
Continuity (1)
Related Publication 20190243630A1 · Aug 8, 2019
Cited By (1)
US 12,449,789