Zero-touch bootstrap of an endpoint without admin pre-provisioning

    公开(公告)号:US11140149B2

    公开(公告)日:2021-10-05

    申请号:US16227798

    申请日:2018-12-20

    Abstract: An authorized local domain service (ALDS) is deployed in a local network and is authorized to provision endpoints with a cloud-based service on behalf of an organization. The ALDS receives, from a local domain service (LDS) deployed in the local network and configured to connect with and register endpoints in the local network for communications on behalf of the organization, an identity of an endpoint acquired by the LDS when the endpoint registered with the LDS. The ALDS identifies for the organization an account associated with the identity, creates in the cloud-based service for the organization an association between the identity and the account, and notifies the endpoint via the local domain service to onboard against the cloud-based service for access to the cloud-based service.

    ENABLING ZERO-TOUCH BOOTSTRAP FOR DEVICES ACROSS NETWORK PERIMETER FIREWALLS

    公开(公告)号:US20190149538A1

    公开(公告)日:2019-05-16

    申请号:US15946003

    申请日:2018-04-05

    Abstract: A method includes establishing an application layer transport layer security (ATLS) connection between a network device and a cloud server by sending, from the network device, TLS records in transport protocol (e.g., HTTP) message bodies to the cloud server, the ATLS connection transiting at least one transport layer security (TLS) proxy device, receiving, from the cloud server via the ATLS connection, an identifier for a certificate authority, establishing a connection with the certificate authority associated with the identifier and, in turn, receiving from the certificate authority credentials to access an application service different from the cloud server and the certificate authority, and connecting to the application service using the credentials received from the certificate authority.

    Seamless guest access to spaces and meetings

    公开(公告)号:US11233797B2

    公开(公告)日:2022-01-25

    申请号:US16430098

    申请日:2019-06-03

    Abstract: Seamless guest access to spaces and meetings may be provided. A trusted user device may send an identity object and may receive an identifier and an authorization token in response to sending the identity object. Then the trusted user device may send a request to add a guest user associated with the identifier to a collaboration event and may receive, in response to sending the request to add the guest user, location data associated with the collaboration event. The trusted user device may then send collaboration space data to a guest user device associated with the guest user. The collaboration space data may comprise the authorization token, the location data, and an application indicator associated with the collaboration event.

    Secure bootstrapping of client device with trusted server provided by untrusted cloud service

    公开(公告)号:US10382413B1

    公开(公告)日:2019-08-13

    申请号:US15389534

    申请日:2016-12-23

    Abstract: A client device bootstraps against a trusted server by obtaining an activation code that includes an identifier and a one time password. The client device sends a message to a public server requesting an address of a trusted server associated with the identifier. The client device receives the address of the trusted server from the public server and initiates a communication session with the trusted server at the address provided by the public server. The one time password is used as a shared secret to secure the communication session. The client device downloads cryptographic information from the trusted server.

    SECURE BOOTSTRAPPING OF CLIENT DEVICE WITH TRUSTED SERVER PROVIDED BY UNTRUSTED CLOUD SERVICE

    公开(公告)号:US20190312856A1

    公开(公告)日:2019-10-10

    申请号:US16451235

    申请日:2019-06-25

    Abstract: A trusted server receives a request for an activation code, which includes an identifier associated with the trusted server and a one-time password, for a client device. The trusted server obtains the identifier from a public server, generates the one-time password, and combines the one-time password with the identifier to create the activation code. The trusted server provides the activation code to a provisioning client, which presents the activation code to the client device. The trusted server and client device secure a communication session using the one-time password as a shared secret. The trusted server downloads trusted cryptographic information to the client device over the secure communication session.

    Secure bootstrapping of client device with trusted server provided by untrusted cloud service

    公开(公告)号:US11265302B2

    公开(公告)日:2022-03-01

    申请号:US16451235

    申请日:2019-06-25

    Abstract: A trusted server receives a request for an activation code, which includes an identifier associated with the trusted server and a one-time password, for a client device. The trusted server obtains the identifier from a public server, generates the one-time password, and combines the one-time password with the identifier to create the activation code. The trusted server provides the activation code to a provisioning client, which presents the activation code to the client device. The trusted server and client device secure a communication session using the one-time password as a shared secret. The trusted server downloads trusted cryptographic information to the client device over the secure communication session.

    Enabling zero-touch bootstrap for devices across network perimeter firewalls

    公开(公告)号:US11025608B2

    公开(公告)日:2021-06-01

    申请号:US15946003

    申请日:2018-04-05

    Abstract: A method includes establishing an application layer transport layer security (ATLS) connection between a network device and a cloud server by sending, from the network device, TLS records in transport protocol (e.g., HTTP) message bodies to the cloud server, the ATLS connection transiting at least one transport layer security (TLS) proxy device, receiving, from the cloud server via the ATLS connection, an identifier for a certificate authority, establishing a connection with the certificate authority associated with the identifier and, in turn, receiving from the certificate authority credentials to access an application service different from the cloud server and the certificate authority, and connecting to the application service using the credentials received from the certificate authority.

Patent Agency Ranking