IP Library Granted Patent US 12,724,852
Granted Patent B2
US 12,724,852 · App. 18/899,308 · Granted Sep 1, 2026

Late-bound licensing of endpoint devices

Inventors: Bradley K. Goodman (Nashua, NH); Mahesh Babu Ramaiah (Bangalore, IN)
Assignee: Dell Products L.P.
G06F21/1011H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,852
App. No.
18/899,308
Granted
Sep 1, 2026
Kind
B2
Abstract

Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboard the endpoint devices, ownership vouchers may be used to cryptographically verify to which entities authority over the endpoint devices have been delegated. The ownership vouchers may also include licenses to be applied by the endpoint devices during the onboarding. The licenses may be applied during the onboarding with zero intervention by a current owner of the endpoint devices.

Claims (48)

1 . A method for managing endpoint devices, the method comprising:

during an onboarding of an endpoint device of the endpoint devices:

obtaining, by the endpoint device, an ownership voucher, the ownership voucher comprising a certificate that includes a license payload with a component license associated with a component of the endpoint device;

validating, by the endpoint device and using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and

applying, by the endpoint device and in response to validating that the component license is signed by the trusted entity, the component license for utilizing the component as part of completing the onboarding of the endpoint device, wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.

2 . The method of claim 1 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.

3 . The method of claim 2 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS).

4 . The method of claim 2 , wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.

5 . The method of claim 4 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and

the certificate is cryptographically signed by the trusted entity.

6 . The method of claim 5 , wherein

the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and

validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.

7 . The method of claim 1 , wherein

the component license comprises an activation key or a license file.

8 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing endpoint devices, the operations comprising:

during an onboarding of an endpoint device of the endpoint devices:

obtaining, by the endpoint device, an ownership voucher, the ownership voucher comprising a certificate that comprises a license payload including a component license associated with a component of the endpoint device;

validating, by the endpoint device and using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and

applying, by the endpoint device and in response to validating that the component license is signed by the trusted entity, the component license to the component as part of completing the onboarding of the endpoint device,

wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.

9 . The non-transitory machine-readable medium of claim 8 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.

10 . The non-transitory machine-readable medium of claim 9 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS).

11 . The non-transitory machine-readable medium of claim 9 , wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.

12 . The non-transitory machine-readable medium of claim 11 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and

the certificate is cryptographically signed by the trusted entity.

13 . The non-transitory machine-readable medium of claim 12 , wherein

the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and

validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.

14 . The non-transitory machine-readable medium of claim 8 , wherein

the component license comprises an activation key or a license file.

15 . An endpoint device, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the endpoint device to perform operations for onboarding, the operations comprising:

during an onboarding of the endpoint device:

obtaining an ownership voucher, the ownership voucher comprising a certificate that comprises a license payload including a component license associated with a component of the endpoint device;

validating, using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and

applying, in response to validating that the component license is signed by the trusted entity, the component license to the component as part of completing the onboarding of the endpoint device,

wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.

16 . The endpoint device of claim 15 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.

17 . The endpoint device of claim 16 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS), and wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.

18 . The endpoint device of claim 17 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and

the certificate is cryptographically signed by the trusted entity.

19 . The endpoint device of claim 18 , wherein

the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and

validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.

20 . The endpoint device of claim 19 , wherein

the component license comprises an activation key or a license file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2024
From: GOODMAN, BRADLEY K.; RAMAIAH, MAHESH BABU
To: DELL PRODUCTS L.P.
Reel/Frame 068744/0222 →
Continuity (1)
Related Publication 20260093786A1 · Apr 2, 2026
References Cited (31)
US 11552803B1 · Simkhada · 2023 [cited by applicant]
US 20040193917A1 · Drews · 2004 [cited by applicant]
US 20050257058A1 · Yoshida et al. · 2005 [cited by applicant]
US 20060236111A1 · Bodensjöet al. · 2006 [cited by applicant]
US 20140298040A1 · Ignatchenko et al. · 2014 [cited by applicant]
US 20150334109A1 · Kasai · 2015 [cited by applicant]
US 20170279806A1 · Marttinen et al. · 2017 [cited by applicant]
US 20180041484A1 · Gifford et al. · 2018 [cited by applicant]
US 20190384916A1 · Shah et al. · 2019 [cited by applicant]
US 20200186357A1 · Laitinen et al. · 2020 [cited by applicant]
US 20200327231A1 · Smith · 2020 [cited by applicant]
US 20210409231A1 · Fedorkow et al. · 2021 [cited by applicant]
US 20220116229A1 · Jones et al. · 2022 [cited by applicant]
US 20220131711A1 · Jatti et al. · 2022 [cited by applicant]
US 20220303123A1 · Cabre et al. · 2022 [cited by applicant]
US 20230016837A1 · Gamishev et al. · 2023 [cited by applicant]
US 20230034615A1 · Detienne et al. · 2023 [cited by applicant]
US 20230049512A1 · Mandal · 2023 [cited by examiner]
US 20230229758A1 · Terpstra · 2023 [cited by examiner]
US 20230229779A1 · Terpstra · 2023 [cited by examiner]
US 20230367489A1 · Dover · 2023 [cited by applicant]
US 20230370454A1 · Mohammed et al. · 2023 [cited by applicant]
US 20230394493A1 · Rao et al. · 2023 [cited by applicant]
US 20240039723A1 · Ito · 2024 [cited by applicant]
US 20240064028A1 · Fedorkow et al. · 2024 [cited by applicant]
US 20240086205A1 · Haddad · 2024 [cited by examiner]
US 20240193250A1 · Chen et al. · 2024 [cited by applicant]
JP 2005277951A · 2005 [cited by applicant]
WO 2021195219A1 · 2021 [cited by applicant]
K. Watsen et al., “A Voucher Artifact for Bootstrapping Protocols”, May 2018, Internet Engineering Task Force (IETF) Request for Comments: 8366 (Year: 2018), pp. 1-23. [cited by applicant]
“Detailed Protocol Description—Secure Device Onboard”, Apr. 28, 2021, obtained online from <https://secure-device-onboard.github.io/docs/1.8.0/protocol-specification/detailed-protocol-description/>, retrieved on Jul. 13… [cited by applicant]