Registration of cloud-based management service devices using intermediate cloud storage

By decrypting and registering user devices through an intermediate cloud storage system, the limitations of matrix barcode readers and the complexity of manual registration are resolved, enabling an efficient and secure device registration process and improving the efficiency of IT administrators and the user experience.

CN115918032BActive Publication Date: 2026-01-30MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180038405.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-30
Filing Date
2021-03-24
Publication Date
2026-01-30
Estimated Expiration
2041-03-24

AI Technical Summary

Technical Problem

In existing technologies, when registering computing devices using cloud-based management services, the matrix barcode reader's capabilities limit the amount of data, noise causes data block copying failures, and the manual registration process is complex, time-consuming, and resource-intensive.

Method used

By employing an intermediate cloud storage system, session identifiers, decryption keys, and related keys are obtained by scanning the matrix barcode of user devices. Encrypted data blocks are then decrypted and user devices are registered with cloud-based management services, simplifying and accelerating the registration process.

Benefits of technology

It improves the success rate and security of user device registration, reduces manual operations, lowers registration time and resource consumption, and enhances the efficiency of IT administrators and the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115918032B_ABST
    Figure CN115918032B_ABST
Patent Text Reader

Abstract

This document describes a technique for registering user devices with a cloud-based management service using intermediate cloud storage. For example, the intermediate cloud storage can store encrypted data blocks containing information identifying the user device. The intermediate cloud storage or the registration system can decrypt the encrypted data blocks so that the registration system can use the decrypted data blocks to register the user device with the cloud-based management service. For example, the registration system can retrieve the encrypted or decrypted data blocks from the intermediate cloud storage by providing the necessary confidentiality. The necessary confidentiality can be provided to the registration system by the user device (e.g., via a matrix barcode, such as a QR code).
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Cloud-based management services enable the management of computing devices using a network of servers known as the "cloud." Information technology (IT) administrators typically use cloud-based management services to manage computing devices used by company employees to access company resources. To support the use of cloud-based management services to manage computing devices, IT administrators register the computing devices with the cloud-based management service's tenant. A tenant of the cloud-based management service is an entity (e.g., a customer) whose data is isolated from and unknown to other tenants of the cloud-based management service. IT administrators typically register computing devices with the cloud-based management service's tenant before providing them to users. Therefore, this registration of computing devices is often referred to as "pre-registration."

[0002] IT administrators typically register the corresponding computing devices with tenants of cloud-based management services using data blobs located on each computing device. For example, an IT administrator can plug a removable storage device (e.g., a thumb drive) into each computing device, run a script to collect the corresponding data blob, log in to the cloud-based management service portal, and upload the corresponding data blob from the removable storage device to the cloud-based management service.

[0003] It might be desirable to extract data blocks from each computing device by reading matrix barcodes (e.g., Quick Response (QR) codes). However, the amount of information that can be read from a matrix barcode may be limited by the capabilities of the reader used to extract the data blocks. An increase in the amount of data stored in a data block corresponds to an increase in the resolution of the QR code representing the data block. Noise associated with the QR code may prevent the data block represented by the matrix barcode from being copied. Summary of the Invention

[0004] This article describes various methods for registering user devices to a cloud-based management service (also known as a cloud-based management system) using intermediate cloud storage. For example, the intermediate cloud storage can store encrypted data blocks containing information identifying the user device. The intermediate cloud storage or the registration system can decrypt these encrypted data blocks so that the registration system can use the decrypted data blocks to register the user device with the cloud-based management service. For example, the registration system can retrieve the encrypted or decrypted data blocks from the intermediate cloud storage by providing the necessary confidentiality. The necessary confidentiality can be provided to the registration system by the user device (e.g., via a matrix barcode, such as a QR code).

[0005] In the first example method, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with actions and / or records associated with the user device. By providing the session identifier, decryption key, and association key to an intermediate cloud storage, the intermediate cloud storage is triggered to use the decryption key to decrypt the encrypted data blocks, providing decrypted data blocks containing information identifying the user device. The decrypted data blocks are received from the intermediate cloud storage. The user device is registered with the cloud-based management service using the decrypted data blocks.

[0006] In the second example method, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with actions and / or records associated with the user device. An encrypted data block, including information identifying the user device, is retrieved from intermediate cloud storage, which receives the encrypted data block from the user device. The decryption key included in the matrix barcode is used to decrypt the encrypted data block retrieved from the intermediate cloud storage to provide a decrypted data block. The decrypted data block is then used to register the user device with the cloud-based management service.

[0007] The method described herein can be applied to any appropriate number of user devices (e.g., 5, 20, hundreds, or thousands) to register these user devices with a cloud-based management service.

[0008] This summary section introduces some concepts in a simplified form, which will be further described in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Furthermore, it should be noted that the invention is not limited to the specific embodiments described in the detailed description section and / or other sections of this document. The embodiments given herein are for illustrative purposes only. Other embodiments will be apparent to those skilled in the art based on the teachings of this document. Attached Figure Description

[0009] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the specification, further serve to explain the principles involved and enable those skilled in the art to make and use the disclosed technology.

[0010] Figure 1This is an example block diagram of a device registration system based on intermediate cloud storage according to one embodiment.

[0011] Figures 2 to 3 This is an example activity diagram for registering user devices with a cloud-based management service using intermediate cloud storage, according to an embodiment.

[0012] Figures 4 to 6 and Figures 8 to 9 A flowchart is described below illustrating an example method for registering user devices with a cloud-based management service using intermediate cloud storage, according to an embodiment.

[0013] Figure 7 and Figure 10 According to the embodiments Figure 1 A block diagram of an example implementation of the aforementioned management system.

[0014] Figure 11 This is a system diagram of an exemplary mobile device according to an embodiment.

[0015] Figure 12 An example computer for which an implementation embodiment can be carried out is depicted.

[0016] The features and advantages of the disclosed technology will become more apparent from the detailed description below when taken in conjunction with the accompanying drawings, in which similar reference numerals will always identify corresponding elements. In the figures, similar reference numerals generally indicate identical, functionally similar, and / or structurally similar elements. The first appearance of an element in the figure is indicated by the leftmost digit of the corresponding reference numeral. Detailed Implementation

[0017] I. Introduction

[0018] The following detailed description refers to the accompanying drawings, which illustrate exemplary embodiments of the invention. However, the scope of the invention is not limited to these embodiments, but is defined by the appended claims. Therefore, embodiments other than those shown in the drawings, such as modifications of the illustrated embodiments, may still be included in the invention.

[0019] References to "an embodiment," "embodiment," and "example embodiment," etc., in this specification indicate that the described embodiment may include a particular feature, structure, or characteristic, but each embodiment does not necessarily include that particular characteristic, structure, or characteristic. Furthermore, these phrases do not necessarily refer to the same embodiment. Moreover, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is understood that those skilled in the art, whether explicitly described or not, would know how to implement such a feature, structure, or characteristic in conjunction with other embodiments.

[0020] Descriptors such as “first,” “second,” and “third” are used to refer to some of the elements discussed herein. Such descriptors are used to facilitate the discussion of example embodiments and are not intended to indicate the desired order of the referenced elements unless such an order is explicitly stated herein.

[0021] II. Example Implementation

[0022] The example embodiments described herein enable the registration of user devices to a cloud-based management service (also known as a cloud-based management system) using intermediate cloud storage. For example, the intermediate cloud storage may store encrypted data blocks including information identifying the user device. The intermediate cloud storage or registration system can decrypt the encrypted data blocks so that the registration system can use the decrypted data blocks to register the user device with the cloud-based management service. For example, the registration system can retrieve the encrypted or decrypted data blocks from the intermediate cloud storage by providing the necessary confidentiality to the intermediate cloud storage. The user device may provide the necessary confidentiality to the registration system (e.g., via a matrix barcode, such as a QR code). The example techniques described herein can be applied to any suitable number of user devices (e.g., 5, 20, hundreds, or thousands) to register user devices with a shared (e.g., the same) cloud-based management service.

[0023] The example techniques described herein offer several advantages over traditional techniques for registering multiple user devices using cloud-based management services. For example, the example techniques may increase the likelihood of multiple user devices successfully registering with cloud-based management services. The example techniques may simplify the registration process for multiple user devices and / or expedite it in a secure manner. The example techniques may be at least as secure as manual techniques for registering multiple user devices with cloud-based management services.

[0024] This example technology enables each user device to upload encrypted data blocks (including information identifying the user device) to an unauthenticated intermediate cloud storage, allowing a caller providing the expected session identifier and expected correlation key to use the encrypted data blocks (or their decrypted version). The example technology may be able to pre-authorize the upload of each encrypted data block from the corresponding user device to the intermediate cloud storage, allowing the caller to authenticate using the session identifier and / or correlation key. For example, the intermediate cloud storage may have been previously notified (e.g., by a registration system) of an expected call, including the session identifier and correlation key.

[0025] These example technologies can reduce latency associated with registering user devices using cloud-based management services and / or improve the reliability of the device registration process. These example technologies can at least automate some manual operations characteristic of conventional techniques for registering user devices using cloud-based management services.

[0026] The example technology can reduce the time and / or resources (e.g., processor cycles, memory, network bandwidth) required to register user devices with cloud-based management services. This example technology can reduce the associated costs of registering user devices with cloud-based management services. For example, by utilizing intermediate cloud storage, the example technology can reduce the complexity of the device registration process and / or reduce IT administrator interactions (and the latency associated with such interactions), which can lower the cost of registering user devices with cloud-based management services. Reducing the complexity of device registration and / or the amount of IT administrator interaction may reduce the time and / or resource consumption associated with registering user devices using cloud-based management services. The example technology can improve the efficiency of computing systems used to register user devices with cloud-based management services.

[0027] These example technologies can improve the efficiency of IT administrators. For example, by using intermediate cloud storage, these technologies can reduce the number of steps IT administrators need to take, the amount of work they need to do, and / or the time they spend facilitating user device registration with cloud-based management services. These technologies can also improve the user experience for IT administrators (e.g., by automating or streamlining the device registration process).

[0028] Figure 1 This is an example block diagram of an intermediate cloud storage-based device registration system 100 according to one embodiment. Generally, the intermediate cloud storage-based device registration system 100 is used to provide information to a user in response to (e.g., based on) a request received by the user (e.g., a Hypertext Transfer Protocol (HTTP) request). The information may include documents (e.g., web pages, images, audio files, video files, etc.), executable file output, and / or any other suitable type of information. According to the example embodiment described herein, the intermediate cloud storage-based device registration system 100 registers multiple user devices 102A-102M using a cloud-based management service 116.

[0029] like Figure 1 As shown, the device registration system 100 based on intermediate cloud storage includes multiple user devices 102A-102M, a network 104, multiple servers 106A-106N, and a management system 108. Communication between the user devices 102A-102M, servers 106A-106N, and management system 108 is conducted on network 104 using known network communication protocols. Network 104 can be a wide area network (e.g., the Internet), a local area network (LAN), another type of network, or a combination thereof.

[0030] User equipment 102A-102M is a processing system capable of communicating with servers 106A-106N and management system 108. For example, the processing system includes a processor capable of manipulating data according to a set of instructions. For example, the processing system may be a computer, a personal digital assistant, etc. User equipment 102A-102M is configured to provide requests to servers 106A-106N, requests for information stored on servers 106A-106N (or accessible via servers 106A-109N). For example, a user may initiate a request to execute a computer program (e.g., an application) using a client (e.g., a web browser, web crawler, or other type of client) deployed on user equipment 102, which is owned by the user or otherwise accessible to the user. According to some example embodiments, user equipment 102A-102M is able to access domains (e.g., websites) hosted by servers 106A-106N so that user equipment 102A-102M can access information available through these domains. These domains may include web pages, which can be provided as Hypertext Markup Language (HTML) documents and objects (e.g., files) linked within them.

[0031] Each user equipment 102A-102M may include any client-enabled system or device, including but not limited to desktop computers, laptops, tablets, wearable computers (such as smartwatches or head-mounted computers), personal digital assistants, cellular phones, Internet of Things (IoT) devices, etc. It is understood that any one or more user equipments 102A-102M may communicate with any one or more servers 106A-106N.

[0032] User equipments 102A-102M are shown as including respective registration agents 110A-110M. Registration agents 110A-110M are configured to provide corresponding matrix barcodes 122A-122M and corresponding encrypted data blocks 124A-124M to facilitate registration of user equipments 102A-102M with the cloud-based management service 116. Matrix barcodes 122A-122M include corresponding session identifiers, corresponding decryption keys, and corresponding association keys. Each session identifier identifies a session during which the corresponding user equipment is registered with the cloud-based management service 116. For example, the session identifier can be a random number or a string. In another example, the session identifier can be a semi-random number or a string. Each decryption key is configured to be used to decrypt the corresponding encrypted data block provided by the corresponding user equipment. Each association key can be used to associate the corresponding user equipment with actions and / or records associated with the corresponding user equipment. For example, each association key can be used to track, audit, and / or troubleshoot the corresponding user equipment and / or generate reports about the corresponding user equipment. Each related key may include a product key associated with the corresponding user equipment. Each product key may identify the operating system (OS) license used by the corresponding user equipment (e.g., deployed on the corresponding user equipment). For example, the product key associated with each user equipment may be a convenient association because it may be obtained from a purchase order related to the user equipment, may be included in the user equipment's reference information by the original equipment manufacturer (OEM) that manufactures the user equipment, may be used in support tickets for the user equipment, and / or may be embedded in the user equipment (e.g., copied to the user equipment's motherboard) so that the user equipment's operating system can use the product key. Each decryption key and / or each related key may be a symmetric key or an asymmetric public key. For example, each decryption key and / or each related key may be an encryption key generated according to the Advanced Encryption Standard (AES), which was developed by the National Institute of Standards and Technology (NIST) in 2001. According to this example, each decryption key and / or each related key may be an AES-128, AES-192, or AES-256 key. Each encrypted data block includes information identifying the user equipment that provided the corresponding encrypted data block.

[0033] Servers 106A-106N are processing systems capable of communicating with user devices 102A-102M. Servers 106A-106N are configured to execute computer programs that provide information to user devices 102A-102M. For example, servers 106A-106N may push such information to user devices 102A-102M or provide information in response to requests received from user devices 102A-102M. Requests may be generated by the user or without user involvement. The information provided by servers 106A-106N may include documents (e.g., web pages, images, audio files, video files, etc.), executable file output, or any other suitable type of information. According to some example embodiments, servers 106A-106N are configured to host their respective websites so that users of the device registration system 100, based on intermediate cloud storage, can access these websites.

[0034] For ease of illustration, (multiple) first servers 106A are shown as including intermediate cloud storage 112. Intermediate cloud storage 112 is configured to receive encrypted data blocks 124A-124M from respective registration agents 110A-110M. In one example implementation, intermediate cloud storage 112 is configured to provide access to encrypted data blocks 124A-124M in response to receiving a respective designated secret from an entity requesting access to encrypted data blocks 124A-122M. For example, intermediate cloud storage 112 may provide access to a first encrypted data block 124A in response to receiving a corresponding first designated secret. Intermediate cloud storage 112 may provide access to a second encrypted data block 124B in response to receiving a corresponding second designated key, etc. Each secret may include a session identifier and a related key, which are included in a matrix barcode provided by a user equipment providing a corresponding matrix barcode. In another example implementation, intermediate cloud storage 112 is configured to decrypt encrypted data blocks 124A-124M to provide a corresponding decrypted data block. According to this implementation, intermediate cloud storage 112 is configured to provide access to the decrypted data block in response to receiving a specified secret from an entity requesting access to the decrypted data block.

[0035] For ease of illustration, multiple second servers 106B are shown as including a cloud-based management service 116. The cloud-based management service 116 is configured to enable management of user devices 102A-102M. For example, the cloud-based management service 116 can enable an IT administrator associated with the management system 108 to manage user devices 102A-102M. To this end, in response to receiving a specified secret and decryption data block identifying the corresponding user device, the cloud-based management service 116 provides a deployment platform profile identifier to each user device 102A-102M. The specified secret for each user device may include a session identifier associated with the corresponding user device. The cloud-based management service 116 can receive the specified secret and decryption data block from the management system 108. Each deployment platform profile identifier specifies the settings and policies to be applied to the corresponding user device for configuring the corresponding user device.

[0036] The cloud-based management service 116 is configured to obtain deployment platform profile identifiers from the Device Directory Service (DDS) 118. For example, in response to receiving a specified secret and a corresponding decrypted data block, the cloud-based management service 116 can provide the DDS 118 with a decrypted data block for each user equipment 102A-102M. The cloud-based management service 116 can receive each deployment platform profile identifier from the DDS 118 based on the decrypted data blocks of the user equipment for which it is to be provided with the corresponding deployment platform profile identifier.

[0037] For ease of illustration, the Nth server 106N is shown as including DDS 118. DDS 118 is configured to provide the cloud-based management service 116 with a deployment platform profile identifier for each user device in response to receiving decrypted data blocks from various user devices. For example, DDS 118 may maintain a cross-reference list that uses the deployment platform profile identifiers of user devices 102A-102M to cross-reference decrypted data blocks of user devices 102A-102M. Upon receiving a decrypted data block from a user device, DDS 118 may iterate through the cross-reference list to determine which deployment platform profile identifier cross-references the user device's decrypted data block. DDS 118 may then provide the deployment platform profile identifier that cross-references the user device's decrypted data block to the cloud-based management service 116 for forwarding to the user device.

[0038] The management system 108 is a processing system capable of communicating with user devices 102A-102M and servers 106A-106N. The management system 108 is configured to perform operations to facilitate the registration of user devices 102A-102M with a cloud-based management service 116 (e.g., in response to instructions received from an IT administrator associated with the IT management system 108). The management system 108 includes a registration system 114 configured to communicate with registration agents 110A-110M of the respective user devices 102A-102M, intermediate cloud storage 112, and the cloud-based management service 116 to facilitate the registration of user devices 102A-102M with the cloud-based management service 116. The registration system 108 is configured to scan matrix barcodes 122A-122M received from the respective registration agents 110A-110M. For example, registration system 114 includes a matrix barcode scanner 120 configured to scan matrix barcodes 122A-122M. Using pairing between the matrix barcode scanner 120 and the corresponding user equipment 102A-102M, the matrix barcode scanner 120 can scan the matrix barcodes 122A-122M. For example, wireless technology standards (such as...) can be used. or Pairing is achieved. According to this example, registration system 114 can analyze matrix barcodes 122A-122M scanned by a matrix barcode scanner to identify the corresponding session identifier, corresponding decryption key, and corresponding relevance key.

[0039] In the first example implementation, registration system 114 receives encrypted data blocks 124A-124M from the corresponding registration agents 110A-110M. According to this implementation, registration system 114 triggers intermediate cloud storage 112 to decrypt encrypted data blocks 124A-124M using the corresponding decryption key, thus providing the corresponding decrypted data blocks. For example, registration system 114 can trigger intermediate cloud storage 122 to decrypt each encrypted data block by providing the intermediate cloud storage 112 with the corresponding session identifier, the corresponding decryption key, and the corresponding relevance key. Further according to this implementation, registration system 114 receives decrypted data blocks from intermediate cloud storage 112.

[0040] In the second example implementation, registration system 114 retrieves encrypted data blocks 124A-124M from intermediate cloud storage 112 (e.g., in response to intermediate cloud storage 122 receiving encrypted data blocks 124A-124M from the corresponding registration agents 110A-110M). According to this implementation, registration system 114 uses the corresponding decryption key included in the corresponding matrix barcodes 122A-122M to decrypt the encrypted data blocks 124A-124M to provide the corresponding decrypted data blocks.

[0041] In both implementations, the registration system 114 uses the corresponding decrypted data block to register user equipment 102A-102M with the cloud-based management service 116.

[0042] Each of the registration agents 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and DDS 118 can be implemented in various ways to register any one or more of user equipment 102A-102M to the cloud-based management service 116, including implementation in hardware, software, firmware, or any combination thereof. For example, each of the registration agents 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and DDS 118 can be implemented as computer program code configured to be executed in one or more processors. In another example, each of the registration agents 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and DDS 118 can be implemented at least partially as a hardware logic / circuit system. For example, each of the registration agent 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and DDS 118 can be at least partially implemented in a field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), application-specific standard product (ASSP), system-on-a-chip (SoC), complex programmable logic device (CPLD), etc. Each SoC may include an integrated circuit chip that includes a processor (e.g., microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or other circuitry and / or embedded firmware to perform its functions.

[0043] For illustrative purposes, intermediate cloud storage 112, cloud-based management service 116, and DDS 118 are shown as being merged into separate servers or server groups, but this is not intended to be limiting. It will be appreciated that each of intermediate cloud storage 112, cloud-based management service 116, and DDS 118 can be merged into any one or more servers 106A-106N. For example, any two or more of intermediate cloud storage 112, cloud-based management service 116, and / or DDS 118 can be partially or entirely merged into shared (e.g., identical) servers.

[0044] Figure 2 Figure 200 is an example activity diagram illustrating the use of intermediate cloud storage to register user devices with a cloud-based management service according to an embodiment. Figure 2 Depicting Figure 1The registration agent 110, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and device catalog service (DDS) 118 are shown. Activities 222, 224, 226, 228, 230, 232, 234, 236, 238, 240, 242, 244, 246, 248, 250, 252, 254, and 256 will now be described with reference to the registration agent 110, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and DDS 118.

[0045] In activity 222, registration system 114 scans a matrix barcode (e.g., a QR code). The matrix barcode includes a session identifier (also called a session ID), a decryption key, and an association key. The session ID identifies a session during which the user device is registered with the cloud-based management service 116. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The decryption key can be a symmetric key or an asymmetric public key. The association key is configured to be used to associate the user device with a record associated with the user device. Activity 226 may include analyzing the matrix barcode, for example, identifying the session ID, decryption key, and association key.

[0046] In one example embodiment, registration system 114 displays a message on a display of a management system that includes registration system 114. The message prompts a user of the management system (e.g., an IT administrator using registration system 114 to pre-provision cloud-based management services 116 for user devices) to initiate a matrix barcode scan. For example, a user could initiate a matrix barcode scan by pointing a matrix barcode scanner at the display of a user device on which registration agent 110 is deployed and providing user input, thereby causing the matrix barcode scanner to scan the matrix barcode from the user device's display.

[0047] In activity 224, registration system 114 pre-authorizes registration agent 110 (e.g., a user device including registration agent 110) to upload encrypted data blocks to intermediate cloud storage 112. Pre-authorizing registration agent 110 to upload encrypted data blocks means that registration agent 110 is authorized to upload encrypted data blocks prior to registration agent 110's own upload of encrypted data blocks. Registration system 114 may pre-authorize registration agent 110 at least in part based on matrix barcodes (e.g., the correlation key therein) to verify registration agent 110 with registration system 114. Registration system 114 can instruct the user device to be pre-authorized to upload encrypted data blocks to intermediate cloud storage 122 by providing a shared secret (e.g., a session ID) associated with the user device to intermediate cloud storage 112. For example, intermediate cloud storage 112 can be configured to ignore (and therefore not store) each data block (whether encrypted or not) unless the user device providing the data block has been pre-authorized by registration system 114. By pre-authorizing user devices in this way, intermediate cloud storage 112 can be protected from large-scale attacks in which malicious applications can bombard intermediate cloud storage 122 with data blocks, each of which may include 4 kilobytes (kB) or more of data, until the performance of intermediate cloud storage 112 is substantially impaired.

[0048] In activity 226, registration agent 110 provides encrypted data blocks and session IDs to intermediate cloud storage 112. For example, registration agent 110 can use a POST command to provide encrypted data blocks and session IDs. The encrypted data blocks serve as identifiers to identify user devices. For example, the encrypted data blocks can uniquely identify a user device. Registration agent 110 can authenticate intermediate cloud storage 112 before providing the encrypted data blocks and session IDs to intermediate cloud storage 112.

[0049] In one example embodiment, registration agent 110 displays a webpage associated with the device pre-configuration service of cloud-based management service 116 on the display of the user device on which registration agent 110 is deployed. This webpage prompts the user of the user device (e.g., an IT administrator who has pre-configured cloud-based management service 116 for the user device using registration system 114) to provide specified input through the user device's interface (e.g., display, keyboard, or mouse) to continue registering the user device with cloud-based management service 116. For example, the user can provide specified input by selecting a specified interface item on the user interface. According to this embodiment, registration agent 110, in response to (e.g., based on) the specified input provided by the user, provides encrypted data blocks and session IDs to intermediate cloud storage 112.

[0050] In Activity 226, intermediate cloud storage 112 provides confirmation to registration agent 110, confirming that intermediate cloud storage has received the encrypted data block and session ID.

[0051] In activity 230, registration system 114 uses a session ID to authenticate intermediate cloud storage 112. In activity 230, registration system 144 also provides intermediate cloud storage 122 with hashes of decryption keys and correlation keys. For example, registration system 114 may generate a hash of the correlation key by performing a hash operation on the correlation key in response to receiving the correlation key from registration agent 110 in activity 222.

[0052] In activity 232, intermediate cloud storage 112 provides confirmation to registration system 114, confirming the verification of registration system 114 and the receipt of the hash of decryption key and related key from registration system 114 in activity 230.

[0053] In activity 234, intermediate cloud storage 112 uses a session ID to authenticate registration agent 110, which is received by intermediate cloud storage 122 from registration system 114 in activity 230.

[0054] In Activity 236, Registration Agent 110 provides confirmation to Intermediate Cloud Storage 112 to confirm the verification of Intermediate Cloud Storage 122 in Activity 234.

[0055] In activity 238, registration system 114 sends a request to intermediate cloud storage 112, requesting the intermediate cloud storage to use a decryption key to decrypt the encrypted data block. This request includes a session ID and a related key.

[0056] In activity 240, intermediate cloud storage 112 compares the session ID received in activity 230 with the session ID received in activity 238 to determine if the session IDs are the same. In activity 240, intermediate cloud storage 112 also compares the hash of the relevant key received in activity 230 with the key hash received in activity 238 to determine if the hashes are the same. For example, intermediate cloud storage 112 can perform a hash operation on the relevant key received in activity 238 to generate its hash. If the session IDs are the same and the hashes are the same, intermediate cloud storage 112 uses the decryption key to decrypt the encrypted data block. If the session IDs are different and / or the hashes are different, intermediate cloud storage 112 does not decrypt the encrypted data block. For clarity, it is assumed that the session IDs are the same and the hashes are the same, and intermediate cloud storage 112 decrypts the encrypted data block.

[0057] In activity 242, intermediate cloud storage 112 provides the decrypted data block to the registration system 114.

[0058] In activity 244, registration system 114 uses session ID to authenticate with cloud-based management service 116.

[0059] In activity 248, cloud-based management service 116 forwards the decrypted data block to DDS 118.

[0060] In activity 250, DDS 118 provides a deployment platform profile ID to the cloud-based management service 116. The deployment platform profile ID identifies the configuration policy to be applied to the user device during user device configuration. In one example embodiment, DDS 118 cross-references the decrypted data block associated with the corresponding user device and the corresponding deployment platform profile ID associated with the corresponding user device to provide corresponding hash ID pairs. Each deployment platform profile ID identifies the configuration policy to be applied to the corresponding user device. According to this embodiment, DDS 118 iterates through hash ID pairs to identify the hash ID pairs of the decrypted data blocks received in activity 248. Further according to this embodiment, DDS 118 identifies the deployment platform profile ID to be provided to the cloud-based management service based on the cross-reference between the deployment platform profile ID and the decrypted data block in the identified hash ID pair.

[0061] In Activity 252, the cloud-based management service 116 provides the registration agent 110 with the deployment platform profile ID received by the cloud-based management service in Activity 250, in order to enable the configuration of the user device using a configuration policy.

[0062] In activity 254, registration agent 110 requests authorization from the user of the user equipment to configure the user equipment. For example, registration agent 110 may display a prompt on the user equipment's display requesting authorization. This prompt may indicate that the user equipment has been registered with the cloud-based management service 116 and is therefore authenticated to be configured using a configuration policy identified by the deployment platform profile ID.

[0063] Activity 254 may include asking the user which configurations and / or policies identified by the deployment platform profile ID should be applied to the user device. For example, the registration agent 110 may present a list of configurations and / or policies and enable the device user to select which configurations and / or policies to apply to the user device, or deselect which configurations and / or policies should not be applied to the user device. Therefore, the user device user can asynchronously change the configurations and / or policies to be applied to the user device.

[0064] In activity 256, registration agent 110 configures the user device according to the configuration policy identified by the deployment platform profile ID. For example, the deployment platform profile ID may include a configuration policy or a location indicator indicating the location from which the configuration policy can be retrieved. Performing activity 256 is in response to a user of the user device providing the authorization requested in activity 254. For example, the user may provide this authorization by providing specified input through the user device's user interface (e.g., a display, keyboard, or mouse).

[0065] For each user device to register with the cloud-based management service 116, activities 222, 224, 226, 228, 230, 232, 234, 236, 238, 240, 242, 244, 246, 248, 250, 252, 254, and 256 can be performed. It can be appreciated that any one or more activities can be performed in batches (e.g., for more than one user device at a time) to improve the speed and efficiency of the registration process. It will be further appreciated that any one or more activities can be performed iteratively, such that activities are performed for these user devices in the corresponding iterations. Any two or more iterations can be performed consecutively.

[0066] In some exemplary embodiments, one or more steps shown in Activity Figure 200 may not be performed. Furthermore, steps other than those shown in Activity Figure 200, or alternative steps, may be performed.

[0067] Figure 3 This is another example of an activity diagram 300, which uses intermediate cloud storage to register user devices with a cloud-based management service according to an embodiment. Figure 3 Described Figure 1 The registration agent 110, intermediate cloud storage 112, registration system 114, cloud-based management service 116, and device catalog service (DDS) 118 are shown. Activity diagram 300 includes activities 222, 224, 226, 228, 230, 232, 234, 236, 244, 246, 248, 250, and 252, which are related to... Figure 2 The activities shown with the same reference numerals are identical. Activity diagram 300 does not include... Figure 2 Activities 238, 240, and 242 are shown in activity diagram 200. Conversely, Figure 3 Activity diagram 300 includes activities 362, 364, 366, and 368. Activities 362, 364, 366, and 368 will now be described with reference to intermediate cloud storage 112 and registration system 114.

[0068] In Activity 362, the registration system 114 sends a request to the intermediate cloud storage 112 for encrypted data blocks. This request includes a session ID and a related key.

[0069] In activity 364, intermediate cloud storage 112 compares the session ID received in activity 230 with the session ID received in activity 362 to determine if the session IDs are the same. In activity 364, intermediate cloud storage 112 also compares the hash of the relevant key received in activity 230 with the hash of the relevant key received in activity 362 to determine if the hashes are the same. For example, intermediate cloud storage 112 can perform a hash operation on the relevant key received in activity 362 to generate its hash. If the session IDs are the same and the hashes are the same, intermediate cloud storage 112 provides an encrypted data block. If the session IDs are different and / or the hashes are different, intermediate cloud storage 112 does not provide an encrypted data block. For ease of illustration, it is assumed that the session IDs are the same, the hashes are the same, and intermediate cloud storage 112 provides an encrypted data block.

[0070] In Activity 366, intermediate cloud storage 112 provides encrypted data blocks to registration system 114.

[0071] In Activity 368, Registration System 114 uses a decryption key to decrypt the encrypted data block in order to provide the decrypted data block.

[0072] In some exemplary embodiments, one or more steps shown in Activity Figure 300 may not be performed. Furthermore, steps other than those shown in Activity Figure 300, or alternative steps, may be performed. For example, Activity Figure 300 may also include... Figure 2 Activities 254 and 256 are shown in Activity Figure 200.

[0073] Figures 4 to 6 Flowcharts 400, 500, and 600 describe an example method for registering user devices with a cloud-based management service using intermediate cloud storage according to embodiments. Flowcharts 400, 500, and 600 may be derived, for example, from... Figures 1 to 3 The registration system 114 shown is executed. For ease of explanation, [the following is] for... Figure 7 The management system 700 is illustrated in flowcharts 400, 500, and 600. Management system 700 includes registration system 714, which is... Figures 1 to 3 The example implementation of registration system 114 is shown. Registration system 714 includes scanning logic 732, triggering logic 734, and registration logic 736. Based on the discussion of flowcharts 400, 500, and 600, further structural and operational embodiments will be apparent to those skilled in the art.

[0074] like Figure 4As shown, the method in flowchart 400 begins at step 402. In step 402, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and an association key. For example, the matrix barcode could be a QR code. In another example, the matrix barcode might include a JavaScript Object Notation (JSON) block that includes the session identifier and the association key. The session identifier identifies (e.g., a unique identifier) ​​a session during which the user device is registered with a cloud-based management service. The session identifier could be a globally unique identifier (GUID). The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. In an example implementation, scanning logic 732 scans a matrix barcode 738 identifying the user device. According to this implementation, the matrix barcode 738 includes a session identifier (also called a session ID) 748, an association key 750, and a decryption key 754. Scanning logic 732 can generate trigger instruction 742 based on (for example, at least in part on) the receipt of matrix barcode 739. Trigger instruction 742 instructs triggering logic 734 to provide decryption request 744 to intermediate cloud storage.

[0075] In step 404, by providing a session identifier, decryption key, and relevant key to the intermediate cloud storage, the intermediate cloud storage is triggered to decrypt the encrypted data block using the decryption key to provide a decrypted data block. The encrypted data block includes information identifying the user equipment. For example, the information in the encrypted data block may identify hardware included in the user equipment. The encrypted data block may have been encrypted using AES-256 encryption. Therefore, the intermediate cloud storage may be triggered to decrypt the encrypted data block using AES-256 encryption. Depending on the encryption technology used to generate the encrypted data block, any suitable encryption technology can be used to decrypt the encrypted data block. For example, the decryption key can be an asymmetric public key or a symmetric key, depending on whether the encrypted data was encrypted using an asymmetric private key corresponding to an asymmetric public key. In an example implementation, triggering logic 734 triggers the intermediate cloud storage to decrypt the encrypted data block using decryption key 754 to provide a decrypted data block 746. For example, triggering logic 744 may trigger the intermediate cloud storage to decrypt the encrypted data block based on receipt of trigger instruction 742. According to this implementation, triggering logic 734 triggers the intermediate cloud storage by providing a decryption request 744 (including a session identifier 748, a correlation key 750, and a decryption key 754) to the intermediate cloud storage. The decryption request 744 requests the intermediate cloud storage to decrypt the encrypted data block.

[0076] In one example embodiment, triggering the intermediate cloud storage in step 404 includes enabling the intermediate cloud storage to locate the encrypted data block by providing a session identifier to the intermediate cloud storage.

[0077] In step 406, a decrypted data block is received from the intermediate cloud storage. In one example implementation, registration logic 736 receives a decrypted data block 746 from the intermediate cloud storage in response to providing a decryption request 744 to the intermediate cloud storage.

[0078] In step 408, the user device is registered with the cloud-based management service using a decrypted data block. In one example implementation, registration logic 736 registers the user device with the cloud-based management service using a decrypted data block 746. For example, registration logic 746 may provide registration instruction 752 to the cloud-based management service, which includes the decrypted data block 746. For example, registration instruction 752 may instruct the cloud-based management service to confirm the registration of the user device with the cloud-based management service. In another example, registration instruction 752 may instruct the cloud-based management service to request a deployment platform profile ID from a device catalog service, which identifies the configuration policy that will be applied to the user device during configuration.

[0079] In one example embodiment, registering the user equipment in step 408 includes initiating the configuration of the user equipment using a configuration policy by triggering the provision of a deployment platform profile identifier to the user equipment. According to this embodiment, the deployment platform profile identifier is based on decrypted data blocks and identifies a policy. For example, the deployment platform profile identifier may include a policy, or it may include a pointer to a location where the policy is stored. The deployment platform profile identifier may further identify the application to be deployed on the user equipment. Initiating the configuration of the user equipment may include embedding information about the policy in the Unified Extensible Firmware Interface (UEFI) interface of the user equipment's motherboard.

[0080] In another example embodiment, a session identifier is used to authenticate intermediate cloud storage to the user device.

[0081] In some exemplary embodiments, one or more steps 402, 404, 406, and / or 408 of flowchart 400 may not be performed. Furthermore, steps other than or alternative to steps 402, 404, 406, and / or 408 may be performed. For example, in one example embodiment, the method of flowchart 400 further includes logging a registration system scanning a matrix barcode to a tenant of a cloud-based management service. For example, registration logic 736 may log registration system 714 to a tenant. According to this embodiment, the decrypted data block includes the serial number of the user device. Further according to this embodiment, registering the user device with the cloud-based management service includes calling the application programming interface (API) of the cloud-based management service and passing the user device's associated key and serial number to the API.

[0082] In another example embodiment, the method of flowchart 400 further includes pre-authorizing the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. For example, scanning logic 732 may pre-authorize the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode 738 from the user equipment.

[0083] In yet another example embodiment, the method of flowchart 400 includes Figure 5 One or more steps are shown in flowchart 500. Figure 5 As shown, the method in flowchart 500 begins at step 502. In step 502, the registration system for scanning the matrix barcode is authenticated to the intermediate cloud storage using a session identifier. In an example implementation, scanning logic 732 uses session ID 748 to authenticate the registration system 714 for scanning the matrix barcode 738 to the intermediate cloud storage. For example, scanning logic 742 can provide verification information 740, including session ID 748, to the intermediate cloud storage to verify the registration system 714 to the intermediate cloud storage.

[0084] In step 504, the hash of the relevant key is provided to the intermediate cloud storage. In one example implementation, scan logic 732 provides key hash 752 to the intermediate cloud storage, which is a hash of the relevant key 750. For example, key hash 752 may be included in the authentication information 740 provided by scan logic 732 to the intermediate cloud storage. According to this implementation, scan logic 732 can generate key hash 752 by performing a hash operation on the relevant key 750. For example, scan logic 722 can use a Secure Hash Algorithm 2 (SHA-2) technique (e.g., SHA-256) to generate the hash of the relevant key 750.

[0085] In step 506, a request is provided to the intermediate cloud storage. This request includes a session identifier, a decryption key, and a correlation key. This request requests the intermediate cloud storage to use the decryption key included in the request to decrypt the encrypted data block. In an example implementation, triggering logic 734 provides a decryption request 744 to the intermediate cloud storage. The decryption request 744 includes a session identifier 748, a correlation key 750, and a decryption key 754. The decryption request 744 requests the intermediate cloud storage to use the decryption key 754 included in the decryption request 744 to decrypt the encrypted data block.

[0086] In step 508, the intermediate cloud storage verifies whether the session identifier used by the authentication registration system is the same as the session identifier included in the request. For example, verifying whether the session identifier used by the intermediate cloud storage in step 508 is the same as the session identifier included in the request could be the result of providing a request to the intermediate cloud storage in step 506. In an example implementation, trigger logic 734 verifies whether the session ID used by the intermediate cloud storage in authentication registration system 714 is the same as the session ID 748 included in decryption request 744.

[0087] In step 510, the relevant key on which the hash of the intermediate cloud storage verification relevant key is based is compared to the relevant key included in the request. For example, the hash of the relevant key provided to the intermediate cloud storage in step 504 can be compared to the hash of the relevant key included in the request provided to the intermediate cloud storage in step 506. Step 510 also compares the relevant key on which the hash of the intermediate cloud storage verification relevant key is based with the relevant key included in the request; this could be a result of providing the request to the intermediate cloud storage in step 506. In one example implementation, trigger logic 734 compares the relevant key on which the hash of the intermediate cloud storage verification relevant key is based with the relevant key 750 included in the decryption request 744.

[0088] In one aspect of this embodiment, the decryption of the encrypted data block is based on the successful completion of steps 508 and 510.

[0089] In another example embodiment, the method of flowchart 400 includes Figure 6 One or more steps are shown in flowchart 600. Figure 6As shown, the method in flowchart 600 begins at step 602. In step 602, a matrix barcode identifying the corresponding user device is scanned. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device is registered with a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with actions and / or records associated with the corresponding user device. In an example embodiment, scanning logic 732 scans the matrix barcode.

[0090] In step 604, by providing the intermediate cloud storage with a corresponding session identifier, a corresponding decryption key, and a related key, the intermediate cloud storage is triggered to use the corresponding decryption key to decrypt the encrypted data block, thereby providing the corresponding decrypted data block. The intermediate cloud storage receives the encrypted data block from the corresponding user equipment, and the encrypted data block includes information identifying the corresponding user equipment. In one example implementation, triggering logic 734 triggers the intermediate cloud storage to use the corresponding decryption key to decrypt the encrypted data block, thereby providing the corresponding decrypted data block.

[0091] In step 606, a decrypted data block is received from the intermediate cloud storage. In one example implementation, registration logic 736 receives the decrypted data block from the intermediate cloud storage.

[0092] In step 608, the user equipment is registered with the cloud-based management service using the corresponding decrypted data block. In one example implementation, registration logic 736 registers the user equipment with the cloud-based management service using the corresponding decrypted data block.

[0093] In one aspect of this embodiment, the method of flowchart 500 further includes logging the registration system scanning the matrix barcode to a tenant of the cloud-based management service. For example, registration logic 736 can log the registration system 714 to the tenant. According to this aspect, the decrypted data block includes the corresponding serial number of the respective user device. Further according to this aspect, registering the user device with the cloud-based management service in step 608 includes: performing a batch call to the application programming interface (API) of the cloud-based management service and passing the relevant key and the serial number of each user device to the API.

[0094] It can be recognized that the management system 700 may not include one or more of the scan logic 732, trigger logic 734, and / or registration logic 736. Furthermore, the management system 700 may include components other than the scan logic 732, trigger logic 734, and / or registration logic 736, or components that replace the scan logic 732, trigger logic 734, and / or registration logic 736.

[0095] Figures 8 to 9Flowcharts 800 and 900 describe an example method for registering user devices with a cloud-based management service using intermediate cloud storage according to embodiments. Flowcharts 800 and 900 may be derived, for example, from... Figures 1 to 3 The registration system 114 shown is executed. For ease of explanation, regarding... Figure 10 The management system 1000 shown is illustrated in flowcharts 800 and 900. Management system 1000 includes a registration system 1014, which is... Figures 1 to 3 The example implementation of registration system 114 is shown. Registration system 1014 includes scanning logic 732, decryption logic 1056, and registration logic 736. Based on the discussion of flowcharts 800 and 900, further structural and operational embodiments will be apparent to those skilled in the art.

[0096] like Figure 8 As shown, the method in flowchart 800 begins at step 802. In step 802, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and a correlation key. The session identifier identifies (e.g., uniquely identifies) the session registered by the user device in a cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The correlation key can be used to associate the user device with actions and / or records associated with the user device. In an example implementation, scanning logic 1032 scans the matrix barcode 738 identifying the user device. According to this implementation, the matrix barcode 738 includes a session identifier (also known as a session ID) 748, a decryption key 754, and a correlation key 750.

[0097] In step 804, the registration system authenticates the scanned matrix barcode to the intermediate cloud storage using a session identifier. In one example implementation, scanning logic 732 uses session ID 748 to authenticate the registration system 1014 to the intermediate cloud storage. For example, scanning logic 722 may provide authentication information 740, including session ID 747, to the intermediate cloud storage to authenticate the registration system 1014. The authentication information may also include a key hash 752, which is a hash of the associated key 750. Scanning logic 732 may further use key hash 7502 to authenticate the registration system 1014 to the intermediate cloud storage.

[0098] In one example implementation, a session identifier is used to authenticate intermediate cloud storage to a user device.

[0099] In step 806, an encrypted data block is retrieved from the intermediate cloud storage. This encrypted data block includes information identifying the user equipment, and the intermediate cloud storage receives the encrypted data block from the user equipment. In one example implementation, decryption logic 1056 retrieves an encrypted data block 1066 from the intermediate cloud storage, which includes information identifying the user equipment, and the intermediate cloud storage receives the encrypted data block 1066 from the user equipment. For example, decryption logic 1056 may receive a session ID 748 and an association key 750 from scanning logic 732. According to this implementation, decryption logic 1056 may generate a block request 1064, which includes a session ID 747 and an association key 750. According to this implementation, decryption logic 1056 may provide block request 1064 to the intermediate cloud storage. Further according to this implementation, decryption logic 1056 may receive encrypted data block 1066 from the intermediate cloud storage in response to providing block request 1064 to the intermediate cloud storage. For example, based on the fact that the session ID 748 in the intermediate cloud storage confirmation verification information 740 is the same as the session ID 748 in the block request 1064, and further based on the fact that the key hash 752 in the intermediate cloud storage confirmation verification information 740 is the same as the hash of the related key 750 in the block request 1064, the decryption logic 1056 can receive the encrypted data block 1066 from the intermediate cloud storage.

[0100] In one example embodiment, retrieving the encrypted data block in step 806 includes: enabling the intermediate cloud storage to locate the encrypted data block by providing a session identifier to the intermediate cloud storage.

[0101] In step 808, the encrypted data block retrieved from intermediate cloud storage is decrypted using the decryption key included in the matrix barcode to provide a decrypted data block. In one example implementation, decryption logic 1056 decrypts the encrypted data block 1066 using the decryption key 754 included in the matrix barcode 738 to provide a decrypted data block 746. For example, decryption logic 1056 may receive the decryption key 754 from scanning logic 732.

[0102] In step 810, the user device is registered with the cloud-based management service using a decrypted data block. In one example implementation, registration logic 736 registers the user device with the cloud-based management service using a decrypted data block 746. For example, registration logic 746 may provide registration instruction 752 to the cloud-based management service, which includes the decrypted data block 746. For example, registration instruction 752 may instruct the cloud-based management service to confirm the registration of the user device with the cloud-based management service. In another example, registration instruction 752 may instruct the cloud-based management service to request a deployment platform profile ID from the device catalog service, which identifies the deployment platform profile identifier applied to the user device's configuration policy during configuration.

[0103] In one example embodiment, registering the user equipment in step 810 includes initiating the configuration of the user equipment using a configuration policy by triggering the provision of a deployment platform profile identifier to the user equipment. According to this embodiment, the deployment platform profile identifier is based on a decrypted data block and identifies the policy.

[0104] In some exemplary embodiments, one or more steps 802, 804, 806, 808, and / or 810 of flowchart 800 may not be performed. Furthermore, steps other than or alternative to steps 802, 804, 806, 808, and / or 810 may be performed. For example, in one example embodiment, the method of flowchart 800 further includes: logging a registration system scanning a matrix barcode to a tenant of a cloud-based management service. For example, registration logic 736 can log registration system 1014 to a tenant. According to this embodiment, the decrypted data block includes the serial number of the user device. Further according to this embodiment, registering the user device with the cloud-based management service includes: invoking the application programming interface (API) of the cloud-based management service and passing the relevant key and the serial number of the user device to the API.

[0105] In another example embodiment, the method of flowchart 800 further includes pre-authorizing the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on receiving a matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. For example, scanning logic 732 may pre-authorize the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on receiving a matrix barcode 738 from the user equipment.

[0106] In yet another example embodiment, the method of flowchart 800 includes Figure 9 One or more steps are shown in flowchart 900. Figure 9 As shown, the method in flowchart 900 begins at step 902. In step 902, a matrix barcode identifying the corresponding user device is scanned. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device registers with a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with actions and / or records associated with the corresponding user device. In an example embodiment, scanning logic 732 scans the matrix barcode.

[0107] In step 904, an encrypted data block including information identifying the corresponding user device is retrieved from the intermediate cloud storage, which receives the encrypted data block from the corresponding user device. In one example implementation, decryption logic 1056 retrieves the encrypted data block, which includes information identifying the corresponding user device from the intermediate cloud storage.

[0108] In step 906, the encrypted data block retrieved from the intermediate cloud storage is decrypted using the corresponding decryption key included in the corresponding matrix barcode, to provide the corresponding decrypted data block. In one example implementation, decryption logic 1056 decrypts the encrypted data block using the corresponding decryption key.

[0109] In step 908, the user equipment is registered with the cloud-based management service using the corresponding decrypted data block. In one example implementation, registration logic 736 registers the user equipment with the cloud-based management service using the corresponding decrypted data block.

[0110] In one aspect of this embodiment, the method of flowchart 900 further includes: logging the registration system scanning the matrix barcode to a tenant of the cloud-based management service. For example, registration logic 736 can log the registration system 1014 to the tenant. According to this aspect, the decrypted data block includes the corresponding serial number of the corresponding user device. Further according to this aspect, registering the user device with the cloud-based management service in step 908 includes performing a batch call to the application programming interface (API) of the cloud-based management service and passing the relevant key and the serial number of the corresponding user device to the API.

[0111] It can be recognized that, Figure 10 The management system 1000 may not include one or more of the scanning logic 732, decryption logic 1056, and / or registration logic 736. Furthermore, the management system 1000 may also include components other than the scanning logic 732, decryption logic 1056, and / or registration logic 736, or components that replace the scanning logic 732, decryption logic 1056, and / or registration logic 736.

[0112] Figure 11 This is a system diagram of an exemplary mobile device 1100, which includes various optional hardware and software components, collectively shown as 1102. Any component 1102 in the mobile device can communicate with any other component, although not all connections are shown for ease of illustration. The mobile device 1100 can be any of a variety of computing devices (e.g., mobile phone, smartphone, handheld computer, personal digital assistant (PDA), etc.) and can allow for wireless bidirectional communication with one or more mobile communication networks 1104 (e.g., cellular or satellite networks), or local area networks or wide area networks.

[0113] Mobile device 1100 may include processor 1110 (e.g., signal processor, microprocessor, ASIC, or other control and processing logic circuitry) for performing tasks such as signal encoding, data processing, input / output processing, power control, and / or other functions. Operating system 1112 may control the allocation and use of component 1102 and support one or more applications 1114 (i.e., applications). Applications 1114 may include general mobile computing applications (e.g., email applications, calendars, contact managers, web browsers, messaging applications) and any other computing applications (e.g., word processing applications, map applications, media player applications).

[0114] Mobile device 1100 may include memory 1120. Memory 1120 may include non-removable memory 1122 and / or removable memory 1124. Non-removable memory 1122 may include RAM, ROM, flash memory, hard disk, or other well-known memory storage technologies. Removable memory 1124 may include flash memory or a Subscriber Identification Module (SIM) card well-known in GSM communication systems, or other well-known memory storage technologies such as a "smart card". Memory 1120 may store data and / or code for running operating system 1112 and applications 1114. Example data may include web pages, text, images, sound files, video data, or other datasets that are sent to and / or received from one or more network servers or other devices via one or more wired or wireless networks. Memory 1120 may store subscriber identifiers, such as International Mobile Subscriber Identity (IMSI), and device identifiers, such as International Mobile Equipment Identity (IMEI). Such identifiers may be transmitted to a network server to identify users and devices.

[0115] Mobile device 1100 may support one or more input devices 1130, such as touchscreen 1132, microphone 1134, camera 1136, physical keyboard 1138 and / or trackball 1140, and one or more output devices 1150, such as speaker 1152 and display 1154. Touchscreens, such as touch 1132, may detect input in different ways. For example, a capacitive touchscreen detects touch input when an object (such as a fingertip) twists or interrupts the current flowing through its surface. Another example is that a touchscreen may use an optical sensor to detect touch input when a beam of light from an optical sensor is interrupted. Some touchscreens do not require physical contact with the screen surface to detect input. For example, touchscreen 1132 may use capacitive sensing to support finger hover detection, as is well known in the art. Other detection techniques may be used, including but not limited to camera-based detection and ultrasonic-based detection. To enable finger hovering, the user's finger is typically positioned within a predetermined interval above the touchscreen, such as between 0.1 and 0.25 inches, or between 0.25 and 0.05 inches, or between 0.5 and 0.75 inches, or between 0.75 and 1 inch, or between 1 and 1.5 inches, and so on.

[0116] Mobile device 1100 may include registration system 1192. Registration system 1192 is configured to register user devices(s) with a cloud-based management system according to any one or more technologies described herein.

[0117] Other possible output devices (not shown) may include piezoelectric or other tactile output devices. Some devices may provide more than one input / output function. For example, touchscreen 1132 and display 1154 may be combined into a single input / output device. Input device 1130 may include a Natural User Interface (NUI). NUI is any interface technology that enables users to interact with a device in a “natural” way, free from the artificial limitations imposed by input devices such as mice, keyboards, remote controls, etc. Examples of NUI methods include those that rely on voice identification, touch and stylus identification, on-screen and near-screen gesture identification, air gestures, head and eye tracking, voice and speech, vision, touch, gestures, and machine intelligence. Other examples of NUI include motion pose detection using accelerometers / gyroscopes, facial recognition, 3D displays, head, eye and gaze tracking, immersive augmented reality and virtual reality systems, all of which provide a more natural interface, as well as technologies that use electric field sensing electrodes to sense brain activity (EEG and related methods). Therefore, in a specific example, the operating system 1112 or application 1114 may include voice identification software as part of a voice control interface that allows a user to operate the mobile device 1100 via voice commands. Furthermore, the mobile device 1100 may include input devices and software that allow a user to interact via spatial gestures, such as detecting and interpreting gestures to provide input to gaming applications.

[0118] Multiple wireless modems 1160 may be coupled to multiple antennas (not shown) and may support bidirectional communication between processor 1110 and external devices, as understood in the art. Multiple modems 1160 are generally shown and may include those for use with mobile communication network 1104 and / or other radio-based modems (e.g., Cellular modem 1166 communicating with Wi-Fi 1164 and / or Wi-Fi 1162. At least one of the wireless modems 1160 is typically configured to communicate with one or more cellular networks, such as GSM networks, for data and voice communication within a single cellular network, between cellular networks, or between a mobile device and the Public Switched Telephone Network (PSTN).

[0119] The mobile device may also include at least one input / output port 1180, a power supply 1182, a satellite navigation system receiver 1184, such as a Global Positioning System (GPS) receiver, an accelerometer 1186, and / or a physical connector 1190, which may be a USB port, an IEEE 1394 (FireWire) port, and / or an RS-232 port. The components 1102 shown are not essential or all included, as any component may be removed, and other components that can be identified by those skilled in the art may be added.

[0120] Although some operations of the disclosed methods are described in a specific order for ease of presentation, it should be understood that this description includes rearrangement unless the specific language used herein requires a particular order. For example, in some cases, the sequentially described operations may be rearranged or executed concurrently. Furthermore, for simplicity, the accompanying figures may not show the various ways in which the disclosed methods can be combined with other methods.

[0121] Registration Agent 110A-110M, Intermediate Cloud Storage 112, Registration System 114, Cloud-based Management Service 116, DDS 118, Registration System 714, Scanning Logic 732, Trigger Logic 734, Registration Logic 736, Registration System 1014, Decryption Logic 1056, Activity Diagram 200, Activity Diagram 300, Flowchart 400, Flowchart 500, Flowchart 600, Flowchart 800 and / or Flowchart 900, any one or more of these can be implemented using hardware, software, firmware or any combination thereof.

[0122] For example, any one or more of the following can be implemented, at least in part, as computer program code, configured to be executed in one or more processors: registration agent 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, DDS 118, registration system 714, scanning logic 732, triggering logic 734, registration logic 736, registration system 1014, decryption logic 1056, activity diagram 200, activity diagram 300, flowchart 400, flowchart 500, flowchart 600, flowchart 800 and / or flowchart 900.

[0123] In another example, any one or more of the following components may be implemented at least partially as a hardware logic / circuit system: registration agent 110A-110M, intermediate cloud storage 112, registration system 114, cloud-based management service 116, DDS 118, registration system 714, scanning logic 732, triggering logic 734, registration logic 736, registration system 1014, decryption logic 1056, activity diagram 200, activity diagram 300, flowchart 400, flowchart 500, flowchart 600, flowchart 800, and / or flowchart 900. Such a hardware logic / circuit system may include one or more hardware logic components. Examples of hardware logic components include, but are not limited to, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), etc. For example, a SoC may include an integrated circuit chip that includes one or more processors (e.g., microcontrollers, microprocessors, digital signal processors (DSPs), etc.), memory, one or more communication interfaces, and / or other circuitry and / or embedded firmware to perform its functions.

[0124] III. Further discussion of some example embodiments

[0125] A first example system for registering user devices with a cloud-based management system using intermediate cloud storage includes: a memory and one or more processors coupled to the memory. The one or more processors are configured to: analyze a matrix barcode identifying the user device, the matrix barcode including a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. The one or more processors are further configured to trigger the intermediate cloud storage to use the decryption key to decrypt the encrypted data blocks by providing the session identifier, decryption key, and association key to provide a decrypted data block containing information identifying the user device. The one or more processors are further configured to register the user device with the cloud-based management service using the decrypted data block received from the intermediate cloud storage.

[0126] In a first aspect of the first example system, one or more processors are configured to: authenticate the first example system to an intermediate cloud storage using a session identifier. According to the first aspect, the one or more processors are configured to provide a hash of a correlation key to the intermediate cloud storage. According to the first aspect, the one or more processors are configured to provide a request to the intermediate cloud storage. The request includes a session identifier, a decryption key, and a correlation key. The request is used to request the intermediate cloud storage to decrypt an encrypted data block using the decryption key included in the request. Further according to the first aspect, the one or more processors are configured to cause the intermediate cloud storage to verify whether the session identifier used to authenticate the first example system to the intermediate cloud storage is the same as the session identifier included in the request. Further according to the first aspect, the one or more processors are configured to cause the intermediate cloud storage to verify whether the correlation key on which the hash of the correlation key is based is the same as the correlation key included in the request.

[0127] In a second aspect of the first example system, intermediate cloud storage is authenticated to the user device using a session identifier. This second aspect of the first example system can be implemented in conjunction with the first aspect of the first example system, although the example embodiments are not limited in this respect.

[0128] In a third aspect of the first example system, one or more processors are configured to analyze multiple matrix barcodes identifying multiple corresponding user devices. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device is registered with a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with a record associated with the corresponding user device. According to the third aspect, one or more processors are configured to: trigger an intermediate cloud storage to use the corresponding decryption key to decrypt multiple encrypted data blocks by providing the corresponding session identifier, the corresponding decryption key, and the corresponding association key to an intermediate cloud storage, thereby providing multiple corresponding decrypted data blocks, the intermediate cloud storage receiving multiple encrypted data blocks from the multiple corresponding user devices, the multiple encrypted data blocks including information identifying the multiple corresponding user devices. Further according to the third aspect, one or more processors are configured to: register multiple user devices with the cloud-based management service using the multiple corresponding decrypted data blocks received from the intermediate cloud storage. The third aspect of the first example system can be implemented in combination with the first and / or second aspects of the first example system, although the example embodiments are not limited in this respect.

[0129] In an implementation of the third aspect of the first example system, one or more processors are configured to log the first example system to a tenant of a cloud-based management service. According to this implementation, the one or more processors are configured to perform batch calls to the application programming interface (API) of the cloud-based management service. Further according to this implementation, the one or more processors are configured to pass a relevant key and multiple serial numbers of multiple corresponding user devices to the API, wherein the multiple serial numbers are included in multiple corresponding decrypted data blocks.

[0130] In a fourth aspect of the first example system, one or more processors are configured to enable the intermediate cloud storage to locate encrypted data blocks by providing a session identifier to the intermediate cloud storage. This fourth aspect of the first example system may be implemented in conjunction with the first, second, and / or third aspects of the first example system, although the example embodiments are not limited in this respect.

[0131] In a fifth aspect of the first example system, one or more processors are configured to initiate configuration of the user equipment using a configuration policy by triggering the provision of a deployment platform profile identifier to the user equipment, the identifier being based on a decrypted data block and identifying the policy. The fifth aspect of the first example system may be implemented in conjunction with the first, second, third, and / or fourth aspects of the first example system, although the example embodiments are not limited in this respect.

[0132] In a sixth aspect of the first example system, one or more processors are configured to log the first example system to a tenant of a cloud-based management service. According to the sixth aspect, the one or more processors are configured to invoke the application programming interface (API) of the cloud-based management service. Further according to the sixth aspect, the one or more processors are configured to pass an associated key and a user device serial number to the API, wherein the user device serial number is included in a decrypted data block. The sixth aspect of the first example system may be implemented in combination with the first, second, third, fourth, and / or fifth aspects of the first example system, although the example embodiments are not limited in this respect.

[0133] In a seventh aspect of the first example system, one or more processors are further configured to: pre-authorize the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. The seventh aspect of the first example system may be implemented in combination with the first, second, third, fourth, fifth, and / or sixth aspects of the first example system, although the example embodiments are not limited in this respect.

[0134] A second example system for registering user devices with a cloud-based management system using intermediate cloud storage includes: a memory and one or more processors coupled to the memory. The one or more processors are configured to: analyze a matrix barcode identifying the user device. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. The one or more processors are further configured to retrieve encrypted data blocks from the intermediate cloud storage, the encrypted data blocks including information identifying the user device, the intermediate cloud storage receiving the encrypted data blocks from the user device. The one or more processors are further configured to use the decryption key included in the matrix barcode to decrypt the encrypted data blocks retrieved from the intermediate cloud storage to provide decrypted data blocks. The one or more processors are further configured to use the decrypted data blocks to register the user device with the cloud-based management service.

[0135] In a first aspect of the second example system, one or more processors are further configured to authenticate the second example system to the intermediate cloud storage using a session identifier.

[0136] In a second aspect of the second example system, intermediate cloud storage is authenticated to the user device using a session identifier. This second aspect of the second example system can be implemented in conjunction with the first aspect of the second example system, although the exemplary embodiments are not limited thereto.

[0137] In a third aspect of the second example system, one or more processors are configured to analyze multiple matrix barcodes identifying multiple corresponding user devices. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device is registered with a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with a record associated with the corresponding user device. According to the third aspect, one or more processors are configured to retrieve multiple encrypted data blocks from an intermediate cloud storage, the multiple encrypted data blocks including information identifying multiple corresponding user devices, the intermediate cloud storage receiving the multiple encrypted data blocks from the multiple corresponding user devices. Further according to the third aspect, one or more processors are configured to use the corresponding decryption keys included in the multiple corresponding matrix barcodes to decrypt the multiple encrypted data blocks retrieved from the intermediate cloud storage to provide multiple corresponding decrypted data blocks. According to the third aspect, one or more processors are configured to register multiple user devices with the cloud-based management service using the multiple corresponding decrypted data blocks. The third aspect of the second example system can be implemented in combination with the first and / or second aspects of the second example system, although the exemplary embodiments are not limited in this respect.

[0138] In the third aspect of the second example system implementation, one or more processors are configured to log the second example system to a tenant of a cloud-based management service. According to this implementation, the one or more processors are configured to perform batch calls to the application programming interface (API) of the cloud-based management service. Further according to this implementation, the one or more processors are configured to pass a relevant key and multiple serial numbers of multiple corresponding user devices to the API, wherein multiple decrypted data blocks include multiple corresponding serial numbers.

[0139] In a fourth aspect of the second example system, one or more processors are configured to enable the intermediate cloud storage to locate encrypted data blocks by providing a session identifier to the intermediate cloud storage. This fourth aspect of the second example system may be implemented in conjunction with the first, second, and / or third aspects of the second example system, although the example embodiments are not limited in this respect.

[0140] In a fifth aspect of the second example system, one or more processors are configured to initiate configuration of the user equipment using a configuration policy by triggering the supply of a deployment platform profile identifier to the user equipment, the identifier being based on a decrypted data block and identifying the policy. The fifth aspect of the second example system may be implemented in conjunction with the first, second, third, and / or fourth aspects of the second example system, although the exemplary embodiments are not limited thereto.

[0141] In a sixth aspect of the second example system, one or more processors are configured to log the second example system to a tenant of a cloud-based management service. According to the sixth aspect, the one or more processors are configured to invoke the application programming interface (API) of the cloud-based management service. Further according to the sixth aspect, the one or more processors are configured to pass an associated key and a user device serial number to the API, wherein the user device serial number is included in a decrypted data block. The sixth aspect of the second example system can be implemented in combination with the first, second, third, fourth, and / or fifth aspects of the second example system, although the example embodiments are not limited in this respect.

[0142] In a seventh aspect of the second example system, one or more processors are further configured to pre-authorize the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. The seventh aspect of the second example system may be implemented in conjunction with the first, second, third, fourth, fifth, and / or sixth aspects of the second example system, although the example embodiments are not limited in this respect.

[0143] In a first example method for registering a user device with a cloud-based management system using intermediate cloud storage, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. By providing the session identifier, decryption key, and association key to the intermediate cloud storage, the intermediate cloud storage is triggered to use the decryption key to decrypt the encrypted data blocks, providing decrypted data blocks containing information identifying the user device. The decrypted data blocks are received from the intermediate cloud storage. The user device is then registered with the cloud-based management service using the decrypted data blocks.

[0144] In a first aspect of the first example method, the registration system that scans the matrix barcode is authenticated to an intermediate cloud storage using a session identifier. According to the first aspect, a hash of a correlation key is provided to the intermediate cloud storage. Further according to the first aspect, triggering the intermediate cloud storage to decrypt the encrypted data block includes: providing a request to the intermediate cloud storage. The request includes a session identifier, a decryption key, and a correlation key. The request is used to request the intermediate cloud storage to decrypt the encrypted data block using the decryption key included in the request. Further according to the first aspect, triggering the intermediate cloud storage to decrypt the encrypted data block includes: causing the intermediate cloud storage to verify whether the session identifier used by the registration system that scans the matrix barcode to authenticate to the intermediate cloud storage is the same as the session identifier included in the request. Further according to the first aspect, triggering the intermediate cloud storage to decrypt the encrypted data block includes: causing the intermediate cloud storage to verify whether the correlation key on which the hash of the correlation key is based is the same as the correlation key included in the request.

[0145] In a second aspect of the first example method, the intermediate cloud storage is authenticated to the user device using a session identifier. This second aspect of the first example method can be implemented in conjunction with the first aspect of the first example method, although the example embodiments are not limited in this respect.

[0146] In a third aspect of the first example method, scanning matrix barcodes includes: scanning multiple matrix barcodes identifying multiple corresponding user devices. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device is registered to a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with a record associated with the corresponding user device. According to the third aspect, triggering intermediate cloud storage includes providing the intermediate cloud storage with the corresponding session identifier, the corresponding decryption key, and the corresponding association key, triggering the intermediate cloud storage to use the corresponding decryption key to decrypt multiple encrypted data blocks to provide multiple corresponding decrypted data blocks, the intermediate cloud storage receiving multiple encrypted data blocks from the multiple corresponding user devices, the multiple encrypted data blocks including information identifying the multiple corresponding user devices. Further according to the third aspect, receiving decrypted data blocks includes: receiving multiple decrypted data blocks from the intermediate cloud storage. Further according to the third aspect, registering user devices includes: registering multiple user devices with the cloud-based management service using the multiple corresponding decrypted data blocks. The third aspect of the first example method may be implemented in combination with the first and / or second aspects of the first example method, although the example embodiments are not limited in this respect.

[0147] In an implementation of a first aspect of the first example method, the first example method further includes: logging a registration system that scans multiple matrix barcodes to a tenant of a cloud-based management service. According to this implementation, the multiple decrypted data blocks include multiple corresponding serial numbers of multiple corresponding user devices. Further according to this implementation, registering multiple user devices to the cloud-based management service includes: performing a batch call to an application programming interface (API) of the cloud-based management service. According to this implementation, registering multiple user devices to the cloud-based management service includes: passing an associated key and the serial number of the corresponding user device to the API.

[0148] In a fourth aspect of the first example method, triggering the intermediate cloud storage to decrypt the encrypted data block includes: enabling the intermediate cloud storage to locate the encrypted data block by providing a session identifier to the intermediate cloud storage. The fourth aspect of the first example method may be implemented in combination with the first, second, and / or third aspects of the first example method, although the example embodiments are not limited in this respect.

[0149] In a fifth aspect of the first example method, registering a user device includes: initiating configuration of the user device using configuration policies by triggering the provision of a deployment platform profile identifier to the user device, the deployment platform profile identifier being based on decrypted data blocks and identifying these policies. The fifth aspect of the first example method may be implemented in combination with the first, second, third, and / or fourth aspects of the first example method, although the example embodiments are not limited in this respect.

[0150] In a sixth aspect of the first example method, the method further includes: logging the registration system that scans the matrix barcode to a tenant of the cloud-based management service. According to the sixth aspect, the decrypted data block includes the serial number of the user device. Further according to the sixth aspect, registering the user device with the cloud-based management service includes: invoking the application programming interface (API) of the cloud-based management service. According to the sixth aspect, registering the user device with the cloud-based management service includes: passing an associated key and the serial number of the user device to the API. The sixth aspect of the first example method can be implemented in combination with the first, second, third, fourth, and / or fifth aspects of the first example method, although the example embodiments are not limited in this respect.

[0151] In a seventh aspect of the first example method, the first example method further includes: pre-authorizing the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. The seventh aspect of the first example method may be implemented in combination with the first, second, third, fourth, fifth, and / or sixth aspects of the first example method, although the example embodiments are not limited in this respect.

[0152] In a second example method for registering a user device with a cloud-based management system using intermediate cloud storage, a matrix barcode identifying the user device is scanned. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. An encrypted data block, including information identifying the user device, is retrieved from the intermediate cloud storage, which receives the encrypted data block from the user device. The decryption key included in the matrix barcode is used to decrypt the encrypted data block retrieved from the intermediate cloud storage to provide a decrypted data block. The decrypted data block is then used to register the user device with the cloud-based management service.

[0153] In a first aspect of the second example method, the second example method also includes an authentication registration system that uses a session identifier to scan matrix barcodes to intermediate cloud storage.

[0154] In a second aspect of the second example method, the intermediate cloud storage is authenticated to the user device using a session identifier. This second aspect of the second example method can be implemented in conjunction with the first aspect of the second example method, although the example embodiments are not limited in this respect.

[0155] In a third aspect of the second example method, scanning matrix barcodes includes: scanning a plurality of matrix barcodes identifying a plurality of corresponding user devices. Each matrix barcode includes a session identifier, a decryption key, and an association key. Each session identifier identifies a session during which the corresponding user device is registered to a cloud-based management service. Each decryption key is configured to be used to decrypt encrypted data blocks received from the corresponding user device. Each association key can be used to associate the corresponding user device with a record associated with the corresponding user device. According to the third aspect, retrieving encrypted data blocks includes: retrieving a plurality of encrypted data blocks from intermediate cloud storage, the plurality of encrypted data blocks including information identifying the plurality of corresponding user devices, the intermediate cloud storage receiving the plurality of encrypted data blocks from the plurality of corresponding user devices. Further according to the third aspect, decrypting encrypted data blocks includes: using a corresponding decryption key included in the plurality of corresponding matrix barcodes to decrypt the plurality of encrypted data blocks retrieved from the intermediate cloud storage to provide a plurality of corresponding decrypted data blocks. Further according to the third aspect, registering user devices includes: registering the plurality of user devices with the cloud-based management service using the plurality of corresponding decrypted data blocks. The third aspect of the second example method can be implemented in combination with the first and / or second aspects of the second example method, although the example embodiments are not limited in this respect.

[0156] In implementing the first aspect of the second example method, the second example method further includes: logging a registration system that scans multiple matrix barcodes to a tenant of a cloud-based management service. According to this implementation, the multiple decrypted data blocks include multiple corresponding serial numbers of multiple corresponding user devices. Further according to this implementation, registering multiple user devices to the cloud-based management service includes: performing a batch call to the application programming interface (API) of the cloud-based management service. According to this implementation, registering multiple user devices to the cloud-based management service includes: passing an associated key and the serial number of the corresponding user device to the API.

[0157] In a fourth aspect of the second example method, retrieving the encrypted data block from the intermediate cloud storage includes: enabling the intermediate cloud storage to locate the encrypted data block using the session identifier by providing the session identifier to the intermediate cloud storage. This fourth aspect of the second example method may be implemented in combination with the first, second, and / or third aspects of the second example method, although the example embodiments are not limited in this respect.

[0158] In a fifth aspect of the second example method, registering a user equipment includes: initiating configuration of the user equipment using configuration policies by triggering the supply of a deployment platform profile identifier to the user equipment, the deployment platform profile identifier being based on decrypted data blocks and identifying those policies. The fifth aspect of the second example method may be implemented in conjunction with the first, second, third, and / or fourth aspects of the second example method, although the example embodiments are not limited in this respect.

[0159] In a sixth aspect of the second example method, the second example method further includes: logging the registration system that scans the matrix barcode to a tenant of the cloud-based management service. According to the sixth aspect, the decrypted data block includes the serial number of the user device. Further according to the sixth aspect, registering the user device with the cloud-based management service includes: invoking the application programming interface (API) of the cloud-based management service. According to the sixth aspect, registering the user device with the cloud-based management service includes: passing an associated key and the serial number of the user device to the API. The sixth aspect of the second example method can be implemented in combination with the first, second, third, fourth, and / or fifth aspects of the second example method, although the example embodiments are not limited in this respect.

[0160] In a seventh aspect of the second example method, the second example method further includes pre-authorizing the user equipment to upload the encrypted data block to the intermediate cloud storage, at least in part based on the receipt of the matrix barcode from the user equipment, before the user equipment uploads the encrypted data block to the intermediate cloud storage. The seventh aspect of the second example method may be implemented in combination with the first, second, third, fourth, fifth, and / or sixth aspects of the second example method, although the example embodiments are not limited in this respect.

[0161] The first example computer program product includes a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to register a user device with a cloud-based management system using intermediate cloud storage by performing operations. The operations include: analyzing a matrix barcode identifying the user device. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. The operations also include: triggering the intermediate cloud storage to use the decryption key to decrypt the encrypted data block by providing the session identifier, decryption key, and association key to provide a decrypted data block, the encrypted data block including information identifying the user device. The operations further include: registering the user device with the cloud-based management service using the decrypted data block received from the intermediate cloud storage.

[0162] The second example computer program product includes a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to register a user device with a cloud-based management system using intermediate cloud storage by performing operations. The operations include: analyzing a matrix barcode identifying the user device. The matrix barcode includes a session identifier, a decryption key, and an association key. The session identifier identifies a session during which the user device is registered with the cloud-based management service. The decryption key is configured to be used to decrypt encrypted data blocks received from the user device. The association key can be used to associate the user device with a record associated with the user device. The operations also include: retrieving an encrypted data block from the intermediate cloud storage, the encrypted data block including information identifying the user device, the intermediate cloud storage receiving the encrypted data block from the user device. The operations further include: using the decryption key included in the matrix barcode to decrypt the encrypted data block retrieved from the intermediate cloud storage to provide a decrypted data block. The operations also include: registering the user device with the cloud-based management service using the decrypted data block.

[0163] IV. Example Computer System

[0164] Figure 12 An example computer 1200 in which embodiments can be implemented is depicted. Figure 1 Any one or more of the user equipment 102A-102M, any one or more of the servers 106A-106N, and / or the management system 108 shown; Figure 7 The management system 700 shown; and / or Figure 10 The management system 1000 shown can be implemented using a computer 1200, including one or more features and / or alternative features of the computer 1200. The computer 1200 can be a general-purpose computing device in the form of a conventional personal computer, mobile computer, or workstation, or it can be a dedicated computing device. The description of the computer 1200 provided herein is for illustrative purposes only and is not intended to be limiting. As those skilled in the art will recognize, embodiments can be implemented in other types of computer systems.

[0165] like Figure 12 As shown, computer 1200 includes a processing unit 1202, a system memory 1204, and a bus 1206 that couples various system components (including system memory 1204) to the processing unit 1202. Bus 1206 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using various bus architectures. System memory 1204 includes read-only memory (ROM) 1208 and random access memory (RAM) 1210. Basic Input / Output System 1212 (BIOS) is stored in ROM 1208.

[0166] Computer 1200 also includes one or more of the following drivers: a hard disk driver 1214 for reading and writing to a hard disk, a disk driver 1216 for reading or writing to a removable disk 1218, and an optical disc driver 1220 for reading or writing to a removable optical disc 1222 (such as a CD-ROM, DVD-ROM, or other optical disc media). Hard disk driver 1214, disk driver 1216, and optical disc driver 1220 are connected to bus 1206 via hard disk driver interface 1224, disk driver interface 1226, and optical disc driver interface 1228, respectively. The drivers and their associated computer-readable storage media provide the computer with non-volatile storage of computer-readable instructions, data structures, program modules, and other data. While hard disks, removable disks, and removable optical discs have been described, other types of computer-readable storage media may also be used to store data, such as flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc.

[0167] Some program modules can be stored on a hard disk, magnetic disk, optical disk, ROM, or RAM. These programs include an operating system 1230, one or more application programs 1232, other program modules 1234, and program data 1236. Application 1232 or program module 1234 may include, for example, any one or more of the following as described herein: registration agents 110A-110M (e.g., at least a portion of these registration agents), intermediate cloud storage 112, registration system 114, cloud-based management service 116, DDS 118, registration system 714, scanning logic 732, triggering logic 734, registration logic 736, registration system 1014, decryption logic 1056, activity diagram 200 (including any activity in activity diagram 200), activity diagram 300 (including any activity in activity diagram 300), flowchart 400 (including any step in flowchart 400), flowchart 500 (including any step in flowchart 500), flowchart 600 (including any step in flowchart 600), flowchart 800 (including any step in flowchart 800), and / or flowchart 900 (including any step in flowchart 900).

[0168] Users can input commands and information into computer 1200 using input devices such as keyboard 1238 and pointing device 1240. Other input devices (not shown) may include microphone, joystick, gamepad, satellite dish, scanner, touchscreen, camera, accelerometer, gyroscope, etc. These and other input devices are typically connected to processing unit 1202 via serial port interface 1242 connected to bus 1206, but may also be connected via other interfaces such as parallel port, game port, or universal serial bus (USB).

[0169] Display device 1244 (e.g., a monitor) is also connected to bus 1206 via an interface, such as video adapter 1246. In addition to display device 1244, computer 1200 may also include other peripheral output devices (not shown), such as speakers and printers.

[0170] Computer 1200 connects to network 1248 (e.g., the Internet) via a network interface or adapter 1250, modem 1252, or other means for establishing communication over the network. Modem 1252 may be internal or external and is connected to bus 1206 via serial port interface 1242.

[0171] As used herein, the terms "computer program medium" and "computer-readable storage medium" generally refer to media such as hard disks associated with hard disk drive 1214, removable disk 1218, and removable optical disk 1222 (e.g., non-temporary media), as well as other media such as flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc. A computer-readable storage medium is not a signal, such as a carrier signal or a propagating signal. For example, a computer-readable storage medium may not include a signal. Therefore, a computer-readable storage medium does not constitute a signal itself. A computer-readable storage medium is distinct from and does not overlap with a communication medium (it does not include a communication medium). A communication medium embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal (such as a carrier wave). The term "modulated data signal" refers to a signal in which one or more characteristics are set or altered in such a way that information is encoded in the signal. For example, but not limited to, communication media include wireless media such as acoustic, RF, infrared, and other wireless media, as well as wired media. Example embodiments also relate to such communication media.

[0172] As described above, computer programs and modules (including application program 1232 and other program modules 1234) can be stored on a hard disk, magnetic disk, optical disk, ROM, or RAM. Such computer programs can also be received via network interface 1250 or serial interface 1242. When an application executes or loads such a computer program, computer 1200 is able to implement the features of the embodiments discussed herein. Therefore, these computer programs represent the controller of computer 1200.

[0173] The example embodiments also relate to computer program products, which include software (e.g., computer-readable instructions) stored on any computer-usable medium. When the software is executed in one or more data processing devices, the software causes the data processing devices to operate as described herein. Embodiments may use any computer-usable or computer-readable medium currently known or to be known in the future. Examples of computer-readable media include, but are not limited to, storage devices such as RAM, hard disk drives, floppy disks, CD-ROMs, DVD-ROMs, compressed disks, magnetic tapes, magnetic storage devices, optical storage devices, MEMS-based storage devices, nanotechnology-based storage devices, etc.

[0174] It should be recognized that the disclosed technology is not limited to any particular type of computer or hardware. Certain details of suitable computers and hardware are well known and do not need to be elaborated in this disclosure.

[0175] V. Conclusion

[0176] Although the subject matter has been described in language specific to structural features and / or behavior, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or behaviors described above. Rather, the specific features and behaviors described above are disclosed as examples of implementing the claims, while other equivalent features and actions are also considered to be within the scope of the claims.

Claims

1. A system for registering a user device with a cloud-based management system using an intermediary cloud storage, the system comprising: a memory; and one or more processors coupled to the memory, the one or more processors configured to: analyze a matrix barcode identifying a user device, the matrix barcode comprising a session identifier, a decryption key, and a correlation key, the session identifier identifying a session during which the user device is registered to the cloud-based management service, the decryption key configured to decrypt an encrypted data block from the user device, the correlation key configured to correlate the user device with a record associated with the user device; trigger, by providing the session identifier, the decryption key, and the correlation key to the intermediary cloud storage, the intermediary cloud storage to decrypt the encrypted data block using the decryption key to provide a decrypted data block, the encrypted data block comprising information identifying the user device; and register the user device with the cloud-based management service using the decrypted data block received from the intermediary cloud storage.

2. The system of claim 1, wherein the one or more processors are configured to: pre-authorize the user device to upload the encrypted data block to the intermediary cloud storage based at least in part on receipt of the matrix barcode from the user device prior to the user device uploading the encrypted data block to the intermediary cloud storage.

3. The system of claim 1, wherein the one or more processors are configured to: authenticate the system to the intermediary cloud storage using the session identifier; provide a hash of the correlation key to the intermediary cloud storage; provide a request to the intermediary cloud storage, the request comprising the session identifier, the decryption key, and the correlation key, the request to request the intermediary cloud storage to decrypt the encrypted data block using the decryption key included in the request; cause the intermediary cloud storage to verify whether the session identifier used to authenticate the system to the intermediary cloud storage is the same as the session identifier included in the request; and cause the intermediary cloud storage to verify whether the correlation key on which the hash of the correlation key is based is the same as the correlation key included in the request.

4. The system of claim 1, wherein the intermediary cloud storage is authenticated to the user device using the session identifier.

5. The system of claim 1, wherein the one or more processors are configured to: analyze a plurality of matrix barcodes identifying a plurality of respective user devices, each matrix barcode comprising a session identifier, a decryption key, and a correlation key, each session identifier identifying a session during which a respective user device is registered to the cloud-based management service, each decryption key configured to decrypt an encrypted data block from a respective user device, each correlation key configured to correlate a respective user device with a record associated with the respective user device; ​ triggering, by providing respective session identifiers, respective decryption keys, and respective correlation keys to the intermediate cloud storage, the intermediate cloud storage to use the respective decryption keys to decrypt a plurality of encrypted data blocks to provide a plurality of respective decrypted data blocks, the intermediate cloud storage receiving the plurality of encrypted data blocks from the plurality of respective user devices, the plurality of encrypted data blocks including information identifying the plurality of respective user devices; and registering, using the plurality of respective decrypted data blocks received from the intermediate cloud storage, the plurality of user devices with the cloud-based management service.

6. The system of claim 5, wherein the one or more processors are configured to: log the system into a tenant of the cloud-based management service; perform a batch invocation of an application programming interface (API) of the cloud-based management service; and pass the correlation key and a plurality of serial numbers of the plurality of respective user devices to the API, wherein the plurality of serial numbers are included in the plurality of respective decrypted data blocks.

7. The system of claim 1, wherein the one or more processors are configured to: enable, by providing the session identifier to the intermediate cloud storage, the intermediate cloud storage to use the session identifier to locate the encrypted data blocks.

8. The system of claim 1, wherein the one or more processors are configured to: initiate configuration of the user device with a configuration policy by triggering provision of a deployment platform profile identifier to the user device, the deployment platform profile identifier being based on the decrypted data block and identifying the policy.

9. The system of claim 1, wherein the one or more processors are configured to: log the system into a tenant of the cloud-based management service; invoke an application programming interface (API) of the cloud-based management service; and pass the correlation key and a serial number of the user device to the API, wherein the serial number of the user device is included in the decrypted data block.

10. A method of registering a user device with a cloud-based management system using an intermediate cloud storage, the method comprising: scanning a matrix barcode identifying the user device, the matrix barcode including a session identifier, a decryption key, and a correlation key, the session identifier identifying a session during which the user device is registered to the cloud-based management service, the decryption key configured to decrypt an encrypted data block from the user device, the correlation key configured to correlate the user device with a record associated with the user device; fetching the encrypted data block from the intermediate cloud storage, the encrypted data block including information identifying the user device, the intermediate cloud storage receiving the encrypted data block from the user device; decrypting the encrypted data block fetched from the intermediate cloud storage using the decryption key included in the matrix barcode to provide a decrypted data block; and registering the user device with the cloud-based management service using the decrypted data block.

11. The method of claim 10, further comprising: prior to the user device uploading the encrypted data block to the intermediate cloud storage, pre-authorizing the user device to upload the encrypted data block to the intermediate cloud storage based at least in part on receipt of the matrix barcode from the user device.

12. The method of claim 10, further comprising: using the session identifier to authenticate the registration system that scanned the matrix barcode to the intermediate cloud storage.

13. The method of claim 10, wherein the intermediate cloud storage is authenticated to the user device using the session identifier.

14. The method of claim 10, wherein scanning the matrix barcode comprises: scanning a plurality of matrix barcodes that identify a plurality of respective user devices, each matrix barcode including a session identifier, a decryption key, and a correlation key, each session identifier identifying a session in which a respective user device is registered to the cloud-based management service, each decryption key configured to decrypt an encrypted data block from a respective user device, each correlation key configured to correlate a respective user device with a record associated with the respective user device; wherein retrieving the encrypted data block comprises: retrieving a plurality of encrypted data blocks from the intermediate cloud storage, the plurality of encrypted data blocks including information that identifies the plurality of respective user devices, the intermediate cloud storage receiving the plurality of encrypted data blocks from the plurality of respective user devices; wherein decrypting the encrypted data block comprises: decrypting the plurality of encrypted data blocks retrieved from the intermediate cloud storage using respective decryption keys included in the plurality of respective matrix barcodes to provide a plurality of respective decrypted data blocks; and wherein registering the user device comprises: registering the plurality of user devices to the cloud-based management service using the plurality of respective decrypted data blocks.

15. The method of claim 14, further comprising: logging the registration system into a tenant of the cloud-based management service, the registration system scanning the plurality of matrix barcodes; wherein the plurality of decrypted data blocks include a plurality of respective serial numbers of the plurality of respective user devices; and wherein registering the plurality of user devices with the cloud-based management service comprises: performing a batch call to an application programming interface (API) of the cloud-based management service; and passing the correlation key and the serial number of the respective user device to the API.

16. The method of claim 10, wherein retrieving the encrypted data block from the intermediate cloud storage comprises: enabling the intermediate cloud storage to locate the encrypted data block using the session identifier by providing the session identifier to the intermediate cloud storage.

17. The method of claim 10, wherein registering the user device comprises: initiating configuration of the user device with a configuration policy by triggering provision of a deployment platform profile identifier to the user device, the deployment platform profile identifier based on the decrypted data block and identifying the policy.

18. The method of claim 10, further comprising: logging into a tenant of the cloud-based management service by the registration system, the registration system scanning the matrix barcode; wherein the decrypted data block comprises a serial number of the user device; and wherein registering the user device with the cloud-based management service using the cloud-based management service comprises: invoking an application programming interface (API) of the cloud-based management service; and passing the correlation key and the serial number of the user device to the API.

19. A computer program product comprising a computer readable storage medium having instructions recorded thereon for enabling a processor-based system to register a user device with a cloud-based management system using an intermediate cloud storage by performing operations comprising: analyzing a matrix barcode identifying a user device, the matrix barcode comprising a session identifier, a decryption key, and a correlation key, the session identifier identifying a session during which the user device is registered to the cloud-based management service, the decryption key configured to decrypt an encrypted data block from the user device, the correlation key configured to correlate the user device with a record associated with the user device; triggering the intermediate cloud storage to decrypt the encrypted data block using the decryption key to provide a decrypted data block, the encrypted data block comprising information identifying the user device, by providing the session identifier, the decryption key, and the correlation key to the intermediate cloud storage; and registering the user device with the cloud-based management service using the decrypted data block received from the intermediate cloud storage.

20. The computer program product of claim 19, wherein the operations comprise: authenticating a registration system that scanned the matrix barcode to the intermediate cloud storage using the session identifier; providing a hash of the correlation key to the intermediate cloud storage; providing a request to the intermediate cloud storage, the request comprising the session identifier, the decryption key, and the correlation key, the request for the intermediate cloud storage to decrypt the encrypted data block using the decryption key included in the request; causing the intermediate cloud storage to verify whether the session identifier used to authenticate the registration system to the intermediate cloud storage is the same as the session identifier included in the request; and causing the intermediate cloud storage to verify whether the correlation key on which the hash of the correlation key is based is the same as the correlation key included in the request.

Citation Information

Patent Citations

  • A method and system of electronic identity registration and authentication login

    CN104270338A

  • Method and system for authentication

    US20170244676A1