Distributed Endpoint Onboarding With Ownership Voucher Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint devices intended for late-binding scenarios lack the ability to determine what provisioning data or onboarding instructions can or cannot be implemented, leading to potential security breaches and loss of curated state due to unauthorized software installations.

Innovation Solution

Implementing configuration policies within ownership vouchers that are specified by each owner in the ownership chain, allowing endpoint devices to determine permissible operations during onboarding, ensuring secure and curated device management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If endpoint devices allow flexible onboarding operations, then device adaptability improves, but security and device integrity deteriorate due to unauthorized software installations

Engineering Contradiction:
Improveonboarding flexibilityVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by embedding configuration policies and ownership vouchers into the device before it enters the onboarding process. These pre-configured security parameters and authorized operation lists are established in advance, allowing the device to autonomously evaluate and control onboarding operations without real-time intervention, thus maintaining security while enabling flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The configuration policy acts as an intermediary between the flexible onboarding operations and the security requirements. It mediates by evaluating each onboarding operation against predefined security criteria and authorized operation lists, allowing permitted operations to proceed while blocking unauthorized ones, thus resolving the contradiction between flexibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If configuration policies are enforced during onboarding, then device integrity is maintained, but onboarding operation freedom is restricted

Engineering Contradiction:
Improvedevice integrityVSAvoidonboarding operation freedom
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The endpoint device performs self-service by autonomously evaluating onboarding operations against its embedded configuration policies and ownership vouchers. The device independently determines whether operations are permitted without requiring external validation, thus maintaining device integrity while enabling smooth onboarding operations within the authorized scope.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures the device with ownership vouchers and configuration policies that define permitted operations before onboarding begins. This preliminary setup allows the device to freely execute authorized operations without real-time restrictions, while automatically blocking unauthorized ones, thus maintaining both integrity and operational freedom.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If ownership vouchers are validated during onboarding, then unauthorized operations are prevented, but onboarding time increases due to validation overhead

Engineering Contradiction:
Improveauthorization accuracyVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The ownership voucher validation is performed as a preliminary action during the initial onboarding phase, establishing the device's authorized operation list and configuration policies upfront. Once validated, the device can autonomously execute permitted operations without repeated validation overhead, thus ensuring authorization accuracy while minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The endpoint device performs self-service validation by autonomously checking onboarding operations against its embedded ownership voucher and configuration policies. This eliminates the need for continuous external validation, maintaining high authorization accuracy while significantly reducing validation time and overhead during the onboarding process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250328835A1Device onboarding in distributed systems
Publication Date: 2025.10.23 DELL PROD LP
  • US20250328835A1 patent drawing
  • US20250328835A1 patent drawing
  • US20250328835A1 patent drawing

AI summary

Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboard the endpoint devices, ownership vouchers may be configured by a current owner of the endpoint device to include configuration policies when the endpoint device is being transferred from the current owner to a subsequent owner. Such configuration policies may be included in delegation information stored in the ownership voucher that the endpoint device can use for ascertaining of the endpoint device's current and previous owners. Such configuration policies may also specify what actions the endpoint device can or cannot implement during the onboarding.