IP Library Granted Patent US 12,355,878
Granted Patent B2
US 12,355,878 · App. 18/459,100 · Granted Jul 8, 2025

Secret management in distributed systems through onboarding

Inventors: Eric Joseph Bruno (Shirley, NY); Bradley K. Goodman (Nashua, NH); Joseph Caisse (Burlington, MA)
Assignee: Dell Products L.P.
H04L9/0894H04L9/0891H04L9/3073H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,878
App. No.
18/459,100
Granted
Jul 8, 2025
Kind
B2
Abstract

Methods and systems for managing secrets are disclosed. To manage secrets, backups of the secrets may be obtained to facilitate future recoveries of the secrets. The backups may be established by a manufacturer of a device. When ownership in the device is transferred to a new owner, the backups of the secrets may be added to an ownership used to complete onboarding of the device to systems managed by the new owner. The new owner may use the backups, in conjunction with decryption keys, to access and use the secrets in the event of the secrets becoming inaccessible.

Claims (67)

1. A method for managing a secret in a distributed system, the method comprising:

identifying, by an orchestrator tasked with managing an endpoint device, a recovery for the secret to the endpoint device;

based on the identified recovery for the secret and by the orchestrator:

obtaining a symmetric key retained in a storage system that:

is separate from the orchestrator and, that

comprises an access management system that restricts access to the symmetric key;

obtaining a public key of a device keypair maintained by the endpoint device;

decrypting an encrypted copy of the secret using the symmetric key to obtain the secret, the encrypted copy of the secret being obtained by the orchestrator from an ownership voucher used by the orchestrator to onboard a second endpoint device that maintained the secret;

re-encrypting the secret using the public key to obtain a re-encrypted secret; and

restoring the secret to the endpoint device using the re-encrypted secret.

2. The method of claim 1 , further comprising:

prior to identifying the recovery:

obtaining the ownership voucher comprising the encrypted secret;

extracting the encrypted secret from the ownership voucher to obtain an updated ownership voucher;

archiving the encrypted secret for future use; and

onboarding the second endpoint device using the updated ownership voucher, the second endpoint device comprising a trusted platform module that hosts the secret.

3. The method of claim 1 , wherein restoring the secret to the endpoint device comprises:

providing a copy of the re-encrypted secret to the endpoint device to allow the endpoint device to decrypt the re-encrypted secret using a private key of the device keypair to obtain a decrypted re-encrypted secret, and add the decrypted re-encrypted secret to a trusted platform module of the endpoint device.

4. The method of claim 1 , wherein the storage is maintained by a manufacturer of the endpoint device, and the access management system provides access to the symmetric key to an owner of the endpoint device.

5. The method of claim 4 , wherein the symmetric key is generated by the manufacturer, and the symmetric key is added to the ownership voucher by the manufacturer.

6. The method of claim 1 , wherein ownership voucher comprises the encrypted secret, and a certificate chain that defines delegations of authority.

7. The method of claim 6 , wherein the delegations of authority grant authority over the endpoint device to an entity that operates the orchestrator, and the certificate chain is cryptographically verifiable from a root of trust for the endpoint device.

8. A non-transitory machine-readable medium having instructions stored therein, which when executed by at least one processor, cause a system to perform system first operations for managing a secret in a distributed system, the first operations comprising:

identifying, by an orchestrator tasked with managing an endpoint device, a recovery for the secret to the endpoint device;

based on the identified recovery for the secret and by the orchestrator:

obtaining a symmetric key retained in a storage system that:

is separate from the orchestrator and, that

comprises an access management system that restricts access to the symmetric key;

obtaining a public key of a device keypair maintained by the endpoint device;

decrypting an encrypted copy of the secret using the symmetric key to obtain the secret, the encrypted copy of the secret being obtained by the orchestrator from an ownership voucher used by the orchestrator to onboard a second endpoint device that maintained the secret;

re-encrypting the secret using the public key to obtain a re-encrypted secret; and

restoring the secret to the endpoint device using the re-encrypted secret.

9. The non-transitory machine-readable medium of claim 8 , wherein the operations further comprise:

prior to identifying the recovery:

obtaining the ownership voucher comprising the encrypted secret;

extracting the encrypted secret from the ownership voucher to obtain an updated ownership voucher;

archiving the encrypted secret for future use; and

onboarding the second endpoint device using the updated ownership voucher, the second endpoint device comprising a trusted platform module that hosts the secret.

10. The non-transitory machine-readable medium of claim 8 , wherein restoring the secret to the endpoint device comprises:

providing a copy of the re-encrypted secret to the endpoint device to allow the endpoint device to decrypt the re-encrypted secret using a private key of the device keypair to obtain a decrypted re-encrypted secret, and add the decrypted re-encrypted secret to a trusted platform module of the endpoint device.

11. The non-transitory machine-readable medium of claim 8 , wherein the storage is maintained by a manufacturer of the endpoint device, and the access management system provides access to the symmetric key to an owner of the endpoint device.

12. The non-transitory machine-readable medium of claim 11 , wherein the symmetric key is generated by the manufacturer, and the symmetric key is added to the ownership voucher by the manufacturer.

13. The non-transitory machine-readable medium of claim 8 , wherein ownership voucher comprises the encrypted secret, and a certificate chain that defines delegations of authority.

14. The non-transitory machine-readable medium of claim 13 , wherein the delegations of authority grant authority over the endpoint device to an entity that operates the orchestrator, and the certificate chain is cryptographically verifiable from a root of trust for the endpoint device.

15. An orchestrator, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the orchestrator to perform operations for managing a secret in a distributed system, the operations comprising:

identifying a recovery for the secret to an endpoint device, the orchestrator managing the endpoint device;

based on the identified recovery for the secret:

obtaining a symmetric key retained in a storage system that:

is separate from the orchestrator and, that

comprises an access management system that restricts access to the symmetric key;

obtaining a public key of a device keypair maintained by the endpoint device;

decrypting an encrypted copy of the secret using the symmetric key to obtain the secret, the encrypted copy of the secret being obtained by the orchestrator from an ownership voucher used by the orchestrator to onboard a second endpoint device that maintained the secret;

re-encrypting the secret using the public key to obtain a re-encrypted secret; and

restoring the secret to the endpoint device using the re-encrypted secret.

16. The orchestrator of claim 15 , wherein the operations further comprise:

prior to identifying the recovery:

obtaining the ownership voucher comprising the encrypted secret;

extracting the encrypted secret from the ownership voucher to obtain an updated ownership voucher;

archiving the encrypted secret for future use; and

onboarding the second endpoint device using the updated ownership voucher, the second endpoint device comprising a trusted platform module that hosts the secret.

17. The orchestrator of claim 15 , wherein restoring the secret to the endpoint device comprises:

providing a copy of the re-encrypted secret to the endpoint device to allow the endpoint device to decrypt the re-encrypted secret using a private key of the device keypair to obtain a decrypted re-encrypted secret, and add the decrypted re-encrypted secret to a trusted platform module of the endpoint device.

18. The orchestrator of claim 15 , wherein the storage is maintained by a manufacturer of the endpoint device, and the access management system provides access to the symmetric key to an owner of the endpoint device.

19. The orchestrator of claim 18 , wherein the symmetric key is generated by the manufacturer, and the symmetric key is added to the ownership voucher by the manufacturer.

20. The orchestrator of claim 15 , wherein ownership voucher comprises the encrypted secret, and a certificate chain that defines delegations of authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: BRUNO, ERIC JOSEPH; GOODMAN, BRADLEY K.; CAISSE, JOSEPH
To: DELL PRODUCTS L.P.
Reel/Frame 064844/0073 →
Continuity (1)
Related Publication 20250080344A1 · Mar 6, 2025
References Cited (4)
US 6044155A · Thomlinson · 2000 [cited by examiner]
US 6272632B1 · Carman · 2001 [cited by examiner]
US 20170142082A1 · Qian · 2017 [cited by examiner]
US 20230388115A1 · Carlisle · 2023 [cited by examiner]