ENROLLING A VIRTUAL DEVICE AS AN UNPRIVILEGED USER

    公开(公告)号:US20230185929A1

    公开(公告)日:2023-06-15

    申请号:US17546160

    申请日:2021-12-09

    Applicant: VMware, Inc.

    Abstract: Examples of enrollment of virtual devices for unprivileged users are described. In some examples, a virtual device includes an enrollment agent, encrypted enrollment credentials, and a user mode privilege elevation component that elevates privilege of the enrollment agent. A privilege elevated token is created to include an administrative privilege of a local security authority service, and a security context of an unprivileged user account logged in to the virtual device. The enrollment agent is launched using the privilege elevated token rather than a user token of a user that is logged in. The enrollment agent decrypts the encrypted enrollment credentials based on administrative privilege of the privilege elevated token, and enrolls the virtual device with a management service using decrypted enrollment credentials.

    VIRTUAL DEVICE ENROLLMENT AND MANAGEMENT
    2.
    发明公开

    公开(公告)号:US20230195493A1

    公开(公告)日:2023-06-22

    申请号:US17644873

    申请日:2021-12-17

    Applicant: VMware, Inc.

    CPC classification number: G06F9/45558 G06F21/73 G06F21/602 G06F2009/4557

    Abstract: Enrollment management for virtual devices is described. In some examples, an enrollment agent of a virtual device retrieves a serial number using an operating system command that identifies the serial number locally to the virtual device. A request to identify device records with the management service is transmitted along with the serial number. A management identifier is received for a device record that is associated with the serial number. A local device management parameter of the virtual device is set to specify the management identifier. An enrollment request is transmitted to the management service.

    Enrolling a virtual device as an unprivileged user

    公开(公告)号:US12153689B2

    公开(公告)日:2024-11-26

    申请号:US17546160

    申请日:2021-12-09

    Applicant: VMware, Inc.

    Abstract: Examples of enrollment of virtual devices for unprivileged users are described. In some examples, a virtual device includes an enrollment agent, encrypted enrollment credentials, and a user mode privilege elevation component that elevates privilege of the enrollment agent. A privilege elevated token is created to include an administrative privilege of a local security authority service, and a security context of an unprivileged user account logged in to the virtual device. The enrollment agent is launched using the privilege elevated token rather than a user token of a user that is logged in. The enrollment agent decrypts the encrypted enrollment credentials based on administrative privilege of the privilege elevated token, and enrolls the virtual device with a management service using decrypted enrollment credentials.

Patent Agency Ranking