IP Library › Granted Patent US 12,615,245
Granted Patent B2
US 12,615,245 · App. 18/816,972 · Granted Apr 28, 2026

Systems and methods to orchestrate trusted enrollment

Inventors: Chooi Peng Low (Plano, TX); Michael Phillips (McKinney, TX)
Assignee: Dell Products L.P.
H04L63/08H04L9/30H04L9/3247H04L9/3263H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,245
App. No.
18/816,972
Granted
Apr 28, 2026
Kind
B2
Abstract

Systems and methods are provided that may be implemented to orchestrate trusted enrollment of an endpoint client information handling system by deploying a signed payload of an enrollment package to the endpoint client system, and by using a client software agent executing on the endpoint client system to first verify the distribution chain and/or signature of the deployed enrollment package before proceeding to use other information contained in the enrollment package to contact a registration server to enroll the endpoint client system.

Claims (32)

1 . A method, comprising:

receiving an enrollment request in a server from across one or more networks coupled to the server, the enrollment request including enrollment information including an identity of an endpoint client system, a designated network location of a remote registration server, an email domain of an originator of the enrollment request and an email domain of the endpoint client system; and in response to the enrollment request:

authenticating the email domain of the originator of the enrollment request;

comparing the email domain of the endpoint client system to the authenticated email domain of the originator of the enrollment request; and

then only performing the following if the email domain of the endpoint client system is the same as the authenticated email domain of the originator of the enrollment request:

provisioning an enrollment package having a payload comprising at least a portion of the enrollment information that comprises the identity of the endpoint client system and the designated network location of the remote registration server,

signing the enrollment package, and

deploying the signed enrollment package across at least one of the one or more networks directly or through an intermediary system to the endpoint client system.

2 . The method of claim 1 , further comprising attempting to verify one or more credentials presented by the originator of the enrollment request; and then only performing the provisioning, signing and deploying if the one or more credentials presented by the originator of the enrollment request are verified.

3 . The method of claim 1 , further comprising provisioning a private key that is unique to the originator of the enrollment request; where the provisioning further comprises including a public key in the enrollment package that corresponds to the private key that is unique to the originator of the enrollment request; and where the signing of the enrollment package further comprises signing the enrollment package with the private key that is unique to the originator of the enrollment request.

4 . The method of claim 1 , where the provisioning further comprises including a public key in the enrollment package that is unique to a software provider that deploys the signed enrollment package from the server.

5 . The method of claim 1 , where the provisioning comprises provisioning an enrollment package having a payload comprising at least a portion of the enrollment information that further comprises at least one of a uniform resource locator (URL) of the registration server, a tenant name for the endpoint client system, or a secure sockets layer (SSL) certificate of the registration server.

6 . The method of claim 1 , where an originator of the enrollment request is an enterprise software customer; and where a software vendor receives the enrollment request in the server and performs the provisioning, signing and deploying of the signed enrollment package from the server.

7 . A system, comprising:

a server information handling system comprising at least one programmable integrated circuit programmed to:

receive an enrollment request from across one or more networks, the enrollment request including enrollment information including an identity of an endpoint client system, a designated network location of a remote registration server, an email domain of an originator of the enrollment request and an email domain of the endpoint client system, and in response to the enrollment request:

authenticate the email domain of the originator of the enrollment request;

compare the email domain of the endpoint client system to the authenticated email domain of the originator of the enrollment request; and

then only perform the following if the email domain of the endpoint client system is the same as the authenticated email domain of the originator of the enrollment request:

provision an enrollment package having a payload comprising at least a portion of the enrollment information that comprises the identity of the endpoint client system and the designated network location of the remote registration server,

sign the enrollment package, and

deploy the signed enrollment package across at least one of the one or more networks directly or through an intermediary system to the endpoint client system.

8 . The system of claim 7 , where the at least one programmable integrated circuit is programmed to attempt to verify one or more credentials presented by an originator of the enrollment request; and then only provision, sign and deploy the enrollment package if the one or more credentials presented by the originator of the enrollment request are verified.

9 . The system of claim 7 , where the at least one programmable integrated circuit is programmed to:

provision a private key that is unique to the originator of the enrollment request by including a public key in the enrollment package that corresponds to the private key that is unique to the originator of the enrollment request; and

sign the enrollment package with the private key that is unique to the originator of the enrollment request.

10 . The system of claim 7 , where the at least one programmable integrated circuit is programmed to include a public key in the enrollment package that is unique to a software provider that deploys the signed enrollment package from the server information handling system.

11 . The system of claim 7 , where the at least one programmable integrated circuit is programmed to provision the enrollment package to have a payload comprising at least a portion of the enrollment information that further comprises at least one of a uniform resource locator (URL) of the registration server, a tenant name for the endpoint client system, or a secure sockets layer (SSL) certificate of the registration server.

12 . The system of claim 7 , where the at least one programmable integrated circuit is programmed to receive the enrollment request from an enterprise software customer.

13 . The system of claim 7 , further comprising the endpoint client system, the endpoint client system being an information handling system communicatively coupled to the server information handling system by at least one of the one or more networks.

14 . The system of claim 13 , further comprising the remote registration server, the remote registration server being an information handling system communicatively coupled to the server information handling system by at least one of the one or more networks.

15 . The system of claim 14 , further comprising an additional information handling system coupled to the server information handling system by at least one of the one or more networks, the additional information handling system originating and providing the enrollment request to the server information handling system across at least one of the one or more networks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2024
From: LOW, CHOOI PENG; PHILLIPS, MICHAEL
To: DELL PRODUCTS L.P.
Reel/Frame 068417/0434 →
Continuity (2)
Division 17458088 · Aug 26, 2021
Related Publication 20240422147A1 · Dec 19, 2024
References Cited (20)
US 11449887B2 · Durvasula · 2022 [cited by examiner]
US 20040117618A1 · Kawaguchi · 2004 [cited by examiner]
US 20130318343A1 · Bjarnason et al. · 2013 [cited by applicant]
US 20140058875A1 · Yanchenko · 2014 [cited by examiner]
US 20160353258A1 · Stuntebeck · 2016 [cited by examiner]
US 20180109418A1 · Cammarota et al. · 2018 [cited by applicant]
US 20220070002A1 · Turner · 2022 [cited by examiner]
US 20230061123A1 · Low et al. · 2023 [cited by applicant]
Prijmak, “Guide Deploying Configuration Manager Client Using Group Policy”, Jan. 17, 2020, 25 pgs. [cited by applicant]
Duo, “Duo Administration—Enroll Users”, Captured from Internet Aug. 15, 2021, 14 pgs. [cited by applicant]
Samsung Knox, “Enroll A Single Device”, Captured from Internet Feb. 25, 2021, 5 pgs. [cited by applicant]
Microsoft Docs, “Use Group Policy To Remotely Install Software”, Captured from Internet May 6, 2021, 6 pgs. [cited by applicant]
Microsoft Docs, “What Is Co-Management?”, Captured from Internet May 24, 2021, 7 pgs. [cited by applicant]
Microsoft Docs, “Set Up Enrollment For Windows Devices”, Captured from Internet Aug. 9, 2021, 8 pgs. [cited by applicant]
Microsoft Docs, “Enroll A Windows 10 Device Automatically Using Group Policy”, Captured from Internet Feb. 23, 2021, 20 pgs. [cited by applicant]
Tech Target, “Group Policy Object (GPO)”, Sep. 10, 2019, 3 pgs. [cited by applicant]
Microsoft Docs, “Group Policy Objects”, May 31, 2018, 2 pgs. [cited by applicant]
Dell, “Wyse Management Suite”, Sep. 2020, 8 pgs. [cited by applicant]
Microsoft Docs, RSA CryptoServiceProvider. VerifyData(Byte[], Object, Byte[]) Method (System, Security. Cryptography), Obtained from Internet Aug. 2, 2021, 2 pgs. [cited by applicant]
Boyapalle et al., “Systems And Methods For Associating Attested Information Handling Systems To End User Accounts”, U.S. Appl. No. 17/354,654, filed Jun. 22, 2021, DELL:323, 30 pgs. [cited by applicant]