IP Library › Granted Patent US 12,235,938
Granted Patent B2
US 12,235,938 · App. 17/732,448 · Granted Feb 25, 2025

Device disabled until claimed

Inventors: Kirk Frey (Fleminton, NJ); Tommi Salli (Austin, TX); Dominique Prunier (Montreal, CA); Christopher Atkinson (Woodstock, GA); Sudhir V. Shetty (Cedar Park, TX); Elie A. Jreij (Pflugerville, TX); Eric Williams (Champaign, IL)
Assignee: Dell Products L.P.
G06F21/305G06F9/4416G06F21/445G06F21/606
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,938
App. No.
17/732,448
Granted
Feb 25, 2025
Kind
B2
Abstract

A system, method, and computer-readable medium for performing a communications management operation. The communications management operation includes: providing a data center asset with a connectivity management system client module; setting the data center asset to a disable until claimed status; providing the data center asset with proof of possession information; establishing a connection between the connectivity management system client module and a connectivity management system of a data center monitoring and management console, establishing a secure communication channel between the connectivity management system client module and a connectivity management system aggregator based upon the proof of ownership information; and, setting the data asset center to a claimed status based upon the information exchanged between the connectivity management system client module and the connectivity management system.

Claims (66)

1. A computer-implementable method for performing a connectivity management operation, comprising:

providing a data center asset with a connectivity management system client module;

setting the data center asset to a disable until claimed status;

providing the data center asset with proof of possession information, the proof of possession information consisting of a private key corresponding to an associated certificate, the proof of possession information indicating whether or not the connectivity management system client module possesses the private key corresponding to the associated certificate;

deploying the data center asset to a data center operating environment;

establishing a connection between the connectivity management system client module and a connectivity management system of a data center monitoring and management console, the connectivity management system comprising a connectivity management system aggregator and a connectivity management system service, the connectivity management system aggregator being implemented in combination with the connectivity system client module to provide a split proxy, the split proxy allowing the data center asset to securely communicate with the data center monitoring and management console;

exchanging the proof of possession information between the connectivity management system client module and the connectivity management system service of the connectivity management system;

establishing a secure communication channel between the connectivity management system client module and the connectivity management system aggregator based upon the proof of possession information; and,

exchanging information between the connectivity management system client module and the data center monitoring and management console via the secure communication channel between the connectivity management system client module and the connectivity management system aggregator;

setting the data center asset to a claimed status based upon the information exchanged between the connectivity management system client module and the connectivity management system, the claimed status indicating the connectivity management system client module is authenticated and has been bound to an account associated with a user, the setting the data center asset to the claimed status from the disable until claimed status ensuring that the data center asset has not been tampered with while in transit.

2. The method of claim 1 , wherein:

the data center asset comprises a baseboard management controller; and

the proof of possession information is stored on the baseboard management controller.

3. The method of claim 2 , wherein:

the proof of possession information is provided to a connectivity management system service of the connectivity management system from the baseboard management controller.

4. The method of claim 3 , wherein:

the connectivity management system client module communicates with the baseboard management controller via an internal data center asset communication channel.

5. The method of claim 3 , wherein:

the baseboard management controller provides an initial trust exchange with the connectivity management system.

6. The method of claim 3 , wherein:

the baseboard management controller stores the private key security information on behalf of the connectivity management system client module.

7. A system comprising:

a processor;

a data bus coupled to the processor;

a connectivity management system client module; and,

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

setting the data center asset to a disable until claimed status;

providing the data center asset with proof of possession information, the proof of possession information consisting of a private key corresponding to an associated certificate, the proof of possession information indicating whether or not the connectivity management system client module possesses the private key corresponding to the associated certificate;

deploying the data center asset to a data center operating environment;

establishing a connection between the connectivity management system client module and a connectivity management system of a data center monitoring and management console, the connectivity management system comprising a connectivity management system aggregator and a connectivity management system service, the connectivity management system aggregator being implemented in combination with the connectivity system client module to provide a split proxy, the split proxy allowing the data center asset to securely communicate with the data center monitoring and management console;

exchanging the proof of possession information between the connectivity management system client module and the connectivity management system service of the connectivity management system;

establishing a secure communication channel between the connectivity management system client module and the connectivity management system aggregator based upon the proof of possession information; and,

exchanging information between the connectivity management system client module and the data center monitoring and management console via the secure communication channel between the connectivity management system client module and the connectivity management system aggregator;

setting the data center asset to a claimed status based upon the information exchanged between the connectivity management system client module and the connectivity management system, the claimed status indicating the connectivity management system client module is authenticated and has been bound to an account associated with a user, the setting the data center asset to the claimed status from the disable until claimed status ensuring that the data center asset has not been tampered with while in transit.

8. The system of claim 7 , wherein:

the data center asset comprises a baseboard management controller; and

the proof of possession information is stored on the baseboard management controller.

9. The system of claim 8 , wherein:

the proof of possession information is provided to a connectivity management system service of the connectivity management system from the baseboard management controller.

10. The system of claim 9 , wherein:

the connectivity management system client module communicates with the baseboard management controller via an internal data center asset communication channel.

11. The system of claim 9 , wherein:

the baseboard management controller provides an initial trust exchange with the connectivity management system.

12. The system of claim 9 , wherein:

the baseboard management controller stores the private key security information on behalf of the connectivity management system client module.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

providing a data center asset with a connectivity management system client module;

setting the data center asset to a disable until claimed status;

providing the data center asset with proof of possession information, the proof of possession information consisting of a private key corresponding to an associated certificate, the proof of possession information indicating whether or not the connectivity management system client module possesses the private key corresponding to the associated certificate;

deploying the data center asset to a data center operating environment;

establishing a connection between the connectivity management system client module and a connectivity management system of a data center monitoring and management console, the connectivity management system comprising a connectivity management system aggregator and a connectivity management system service, the connectivity management system aggregator being implemented in combination with the connectivity system client module to provide a split proxy, the split proxy allowing the data center asset to securely communicate with the data center monitoring and management console;

exchanging the proof of possession information between the connectivity management system client module and the connectivity management system service of the connectivity management system;

establishing a secure communication channel between the connectivity management system client module and the connectivity management system aggregator based upon the proof of possession information; and,

exchanging information between the connectivity management system client module and the data center monitoring and management console via the secure communication channel between the connectivity management system client module and the connectivity management system aggregator;

setting the data center asset to a claimed status based upon the information exchanged between the connectivity management system client module and the connectivity management system, the claimed status indicating the connectivity management system client module is authenticated and has been bound to an account associated with a user, the setting the data center asset to the claimed status from the disable until claimed status ensuring that the data center asset has not been tampered with while in transit.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the data center asset comprises a baseboard management controller; and

the proof of possession information is stored on the baseboard management controller.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the proof of possession information is provided to a connectivity management system service of the connectivity management system from the baseboard management controller.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the connectivity management system client module communicates with the baseboard management controller via an internal data center asset communication channel.

17. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the connectivity management system client module communicates with the baseboard management controller via an internal data center asset communication channel.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the baseboard management controller stores the private key on behalf of the connectivity management system client module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: FREY, KIRK; SALLI, TOMMI; PRUNIER, DOMINIQUE; ATKINSON, CHRISTOPHER; SHETTY, SUDHIR V.; JREIJ, ELIE A.; WILLIAMS, ERIC
To: DELL PRODUCTS L.P.
Reel/Frame 059766/0038 →
Continuity (1)
Related Publication 20230350985A1 · Nov 2, 2023
References Cited (9)
US 10884759B2 · Lakshminarasimha · 2021 [cited by examiner]
US 20150222604A1 · Ylonen · 2015 [cited by examiner]
US 20170019387A1 · Ylonen · 2017 [cited by examiner]
US 20170366580A1 · Ylonen · 2017 [cited by examiner]
US 20220245222A1 · Boyd · 2022 [cited by examiner]
US 20230350985A1 · Frey · 2023 [cited by examiner]
US 20240097918A1 · Sharma · 2024 [cited by examiner]
Utkarsh Kukreti, “What is a Split proxy server?”, https://qproxy.blogspot.com/2007/09/what-is-split-proxy-server.html, Sep. 6, 2007; accessed Nov. 6, 2024, 2 pgs. (Year: 2007). [cited by examiner]
List of Patents or Applications Treated as Related, Aug. 2022. [cited by applicant]