Late-bound licensing of endpoint devices
Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboard the endpoint devices, ownership vouchers may be used to cryptographically verify to which entities authority over the endpoint devices have been delegated. The ownership vouchers may also include licenses to be applied by the endpoint devices during the onboarding. The licenses may be applied during the onboarding with zero intervention by a current owner of the endpoint devices.
1 . A method for managing endpoint devices, the method comprising:
during an onboarding of an endpoint device of the endpoint devices:
obtaining, by the endpoint device, an ownership voucher, the ownership voucher comprising a certificate that includes a license payload with a component license associated with a component of the endpoint device;
validating, by the endpoint device and using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and
applying, by the endpoint device and in response to validating that the component license is signed by the trusted entity, the component license for utilizing the component as part of completing the onboarding of the endpoint device, wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.
2 . The method of claim 1 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.
3 . The method of claim 2 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS).
4 . The method of claim 2 , wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.
5 . The method of claim 4 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and
the certificate is cryptographically signed by the trusted entity.
6 . The method of claim 5 , wherein
the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and
validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.
7 . The method of claim 1 , wherein
the component license comprises an activation key or a license file.
8 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing endpoint devices, the operations comprising:
during an onboarding of an endpoint device of the endpoint devices:
obtaining, by the endpoint device, an ownership voucher, the ownership voucher comprising a certificate that comprises a license payload including a component license associated with a component of the endpoint device;
validating, by the endpoint device and using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and
applying, by the endpoint device and in response to validating that the component license is signed by the trusted entity, the component license to the component as part of completing the onboarding of the endpoint device,
wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.
9 . The non-transitory machine-readable medium of claim 8 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.
10 . The non-transitory machine-readable medium of claim 9 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS).
11 . The non-transitory machine-readable medium of claim 9 , wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.
12 . The non-transitory machine-readable medium of claim 11 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and
the certificate is cryptographically signed by the trusted entity.
13 . The non-transitory machine-readable medium of claim 12 , wherein
the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and
validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.
14 . The non-transitory machine-readable medium of claim 8 , wherein
the component license comprises an activation key or a license file.
15 . An endpoint device, comprising:
a processor; and
a memory coupled to the processor to store instructions, which when executed by the processor, cause the endpoint device to perform operations for onboarding, the operations comprising:
during an onboarding of the endpoint device:
obtaining an ownership voucher, the ownership voucher comprising a certificate that comprises a license payload including a component license associated with a component of the endpoint device;
validating, using the ownership voucher, that the component license is signed by a trusted entity associated with the endpoint device that delegated an ownership of the endpoint device to a current owner of the endpoint device; and
applying, in response to validating that the component license is signed by the trusted entity, the component license to the component as part of completing the onboarding of the endpoint device,
wherein applying the component license to the component comprises using, by the endpoint device and without any intervention by the current owner, the component license to activate one or more functions of the component.
16 . The endpoint device of claim 15 , wherein, prior to the onboarding being started and completed, the endpoint device is in a state that is unable to provide any computer-implemented services for the current owner.
17 . The endpoint device of claim 16 , wherein the state is a late-bounding state where the endpoint device, prior to the onboarding being started, is not provisioned with a host operating system (OS), and wherein the onboarding is part of a late bound zero-touch secure provisioning (ZTSP) process.
18 . The endpoint device of claim 17 , wherein the certificate comprises a delegation of the ownership of the endpoint device from the trusted entity to the current owner, and
the certificate is cryptographically signed by the trusted entity.
19 . The endpoint device of claim 18 , wherein
the certificate is part of a certificate chain comprising one or more instances of the certificate, the certificate chain delegates authority from a root of trust of the endpoint device to the current owner, the root of trust being associated with the trusted entity, and the certificate chain being cryptographically verifiable back to the root of trust using respective public private key pairs of the current owner and the trusted entity, and
validating that the component license is associated with a trusted entity comprises using the respective public private key pairs of the current owner and the trusted entity to cryptographically validate the certificate chain back to the root of trust.
20 . The endpoint device of claim 19 , wherein
the component license comprises an activation key or a license file.