IP Library › Granted Patent US 12,506,590
Granted Patent B2
US 12,506,590 · App. 18/404,562 · Granted Dec 23, 2025

Methods for trusted platform module based secure device enrollment in cloud services for managed devices

Inventors: Bhoomika Nathani (Ajmer, IN); Tarak Ranjan Mukherjee (Banaglore, IN); Arindam Gupta (Bangalore, IN); Shiladitya Dey (Kolkata, IN)
Assignee: Cisco Technology, Inc.
H04L9/0618H04L9/0825H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,590
App. No.
18/404,562
Granted
Dec 23, 2025
Kind
B2
Abstract

A method for secure enrollment of a device in a cloud service includes establishing trust between a trusted platform module (TPM) of a device and a cloud service by bypassing a plain text exposure of an endorsement key (EK) of the TPM. The method also includes establishing secure communication between a cloud service agent of the device and the cloud service by using mutual Transport Layer Security (mTLS) to present a device certificate from the cloud service agent to the cloud service.

Claims (82)

1 . A method for secure enrollment of a device in a cloud service comprising:

establishing trust between a trusted platform module (TPM) of a device and a cloud service by bypassing a plain text exposure of an endorsement key (EK) of the TPM;

establishing secure communication between a cloud service agent of the device and the cloud service by using mutual Transport Layer Security (mTLS) to present a device certificate from the cloud service agent to the cloud service;

wherein the establishing trust between the TPM of the device and the cloud service includes:

creating, by a mobile device management (MDM) agent of the device, keys in an owner hierarchy for accessing the device;

authorizing, by the MDM agent, the cloud service agent of the device to access the owner hierarchy based on a successful validation of a secret by a certificate enrollment service of the cloud service; and

delegating, by the MDM agent, control of the device to the cloud service upon authorizing the cloud service agent to access the owner hierarchy.

2 . The method of claim 1 , further comprising:

taking, by the MDM agent, ownership of the TPM of the device, wherein the device comprises the TPM, the cloud service agent in communication with the TPM, and the MDM agent in communication with the cloud service agent.

3 . The method of claim 2 , wherein the creating, by the MDM agent, keys in an owner hierarchy further comprises:

creating, by the MDM agent, a public key (PK); and

creating, by the MDM agent, an asymmetric non-migratable child key (CK).

4 . The method of claim 2 , wherein the establishing trust between a TPM of the device and a cloud service comprises establishing trust between the MDM agent of the device and the certificate enrollment service for the cloud service.

5 . The method of claim 4 , wherein the establishing trust between the MDM agent of the device and the certificate enrollment service for the cloud service comprises:

starting, by the MDM agent, enrollment with the certificate enrollment service for the cloud service;

validating, by the MDM agent, a proof of possession of the TPM; and

receiving, by the MDM agent, a challenge with an encrypted blob from the certificate enrollment service.

6 . The method of claim 4 , wherein the authorizing, by the MDM agent, the cloud service agent of the device to access the owner hierarchy further comprises:

starting, by the MDM agent, an authorization session to the TPM;

establishing, by the MDM agent, policy secret for the authorization session;

receiving, by the MDM agent, the secret in plain text over TLS from the TPM;

responding, by the MDM agent, a challenge from the certificate enrollment service with the secret in plain text over TLS; and

receiving, by the MDM agent, an acknowledgement that indicates the successful validation of the secret from the certificate enrollment service.

7 . The method of claim 6 , further comprising:

receiving, by the certificate enrollment service, the secret from the MDM agent; and

matching, by the certificate enrollment service, the secret to validate the secret.

8 . The method of claim 4 , after authorizing the cloud service agent of the device to access the owner hierarchy, the method further comprising:

generating, by the cloud service agent, a certificate signing request (CSR) based on a child key (CK); and

signing, by the cloud service agent, the CSR with a CK private key without loading the CK private key in plain text form.

9 . The method of claim 8 , further comprising:

receiving, by the certificate enrollment service, a signed certificate signing request (CSR) with device ID from the cloud service agent;

matching, by the certificate enrollment service, a CK name with a CK public key;

validating, by the certificate enrollment service, a signature with the CK public key;

requesting, by the certificate enrollment service, a certificate authority for signing a certificate chain;

delivering, by the certificate enrollment service, a signed certificate chain to the cloud service agent; and

issuing, by the certificate enrollment service, the device certificate to the cloud service agent.

10 . The method of claim 9 , wherein the requesting a certificate authority for signing a certificate chain further comprises:

receiving, by the certificate authority, a request for signing from the certificate enrollment service; and

approving, by the certificate authority, a request for signing the CSR.

11 . The method of claim 1 , wherein the device certificate for mTLS authorization comprises an X.509 certificate.

12 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

establish trust between a trusted platform module (TPM) of a device and a cloud service by bypassing a plain text exposure of an endorsement key (EK) of the TPM;

establish secure communication between a cloud service agent of the device and the cloud service by using mutual Transport Layer Security (mTLS) to present a device certificate from the cloud service agent to the cloud service;

wherein the establishing trust between the TPM of the device and the cloud service includes:

create, by a mobile device management (MDM) agent of the device, keys in an owner hierarchy for accessing the device;

authorize, by the MDM agent, the cloud service agent of the device to access the owner hierarchy based on a successful validation of a secret by a certificate enrollment service of the cloud service; and

delegate, by the MDM agent, control of the device to the cloud service upon authorizing the cloud service agent to access the owner hierarchy.

13 . The non-transitory computer-readable storage medium of claim 12 , wherein the instructions further configure the computer to:

take, by the MDM agent of the device, ownership of the TPM of the device, wherein the device comprises the TPM, the cloud service agent in communication with the TPM, and the MDM agent in communication with the cloud service agent.

14 . The non-transitory computer-readable storage medium of claim 13 , the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

create, by the MDM agent, a public key (PK); and

create, by the MDM agent, an asymmetric non-migratable child key (CK).

15 . The non-transitory computer-readable storage medium of claim 13 , the computer-readable storage medium including instructions that when executed by a computer, cause the computer to establish trust between the MDM agent of the device and the certificate enrollment service for the cloud service.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein the establishing trust between the MDM agent of the device and a certificate enrollment service for the cloud service comprises:

start, by the MDM agent, enrollment with the certificate enrollment service for the cloud service;

validate, by the MDM agent, a proof of possession of the TPM; and

receive, by the MDM agent, a challenge with an encrypted blob from the certificate enrollment service.

17 . The non-transitory computer-readable storage medium of claim 15 , the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

start, by the MDM agent, an authorization session to the TPM;

establish, by the MDM agent, policy secret for the authorization session;

receive, by the MDM agent, the secret in plain text over TLS from the TPM;

respond, by the MDM agent, a challenge from the certificate enrollment service with the secret in plain text over TLS; and

receive, by the MDM agent, an acknowledgement that indicates the successful validation of the secret from the certificate enrollment service.

18 . The non-transitory computer-readable storage medium of claim 15 , the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

generate, by the cloud service agent, a certificate signing request (CSR) based on a child key (CK); and

sign, by the cloud service agent, the CSR with a CK private key without loading the CK private key in plain text form.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein the instructions further configure the computer to:

receive, by the certificate enrollment service, a signed certificate signing request (CSR) with device ID from the cloud service agent;

match, by the certificate enrollment service, a CK name with a CK public key;

validate, by the certificate enrollment service, a signature with the CK public key;

request, by the certificate enrollment service, a certificate authority for signing a certificate chain;

deliver, by the certificate enrollment service, a signed certificate chain to the cloud service agent; and

issue, by the certificate enrollment service, the device certificate to the cloud service agent.

20 . A computing apparatus comprising:

a processor; and

a memory storing instructions that, when executed by the processor, configure the apparatus to:

establish trust between a trusted platform module (TPM) of a device and a cloud service by bypassing a plain text exposure of an endorsement key (EK) of the TPM;

establish secure communication between a cloud service agent of the device and the cloud service by using mutual Transport Layer Security (mTLS) to present a device certificate from the cloud service agent to the cloud service;

wherein the establishing trust between the TPM of the device and the cloud service includes:

create, by a mobile device management (MDM) agent of the device, keys in an owner hierarchy for accessing the device;

authorize, by the MDM agent, the cloud service agent of the device to access the owner hierarchy based on a successful validation of a secret by a certificate enrollment service of the cloud service; and

delegate, by the MDM agent, control of the device to the cloud service upon authorizing the cloud service agent to access the owner hierarchy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2024
From: NATHANI, BHOOMIKA; MUKHERJEE, TARAK RANJAN; GUPTA, ARINDAM; DEY, SHILADITYA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066024/0430 →
Continuity (1)
Related Publication 20250226969A1 · Jul 10, 2025
References Cited (13)
US 8176336B1 · Mao · 2012 [cited by examiner]
US 10735190B1 · Khare · 2020 [cited by examiner]
US 20050166051A1 · Buer · 2005 [cited by examiner]
US 20060242428A1 · Tarkkala · 2006 [cited by examiner]
US 20070003064A1 · Wiseman · 2007 [cited by examiner]
US 20110093693A1 · Ibrahim · 2011 [cited by examiner]
US 20110099367A1 · Thom et al. · 2011 [cited by applicant]
US 20110099625A1 · Thom · 2011 [cited by examiner]
US 20200067915A1 · Kumar et al. · 2020 [cited by applicant]
US 20210243030A1 · Robison · 2021 [cited by examiner]
US 20210392111A1 · Sole et al. · 2021 [cited by applicant]
US 20220182374A1 · Peddada et al. · 2022 [cited by applicant]
US 20230062888A1 · Colombano · 2023 [cited by applicant]