SaaS Deployment for Userless Devices via Deterministic Host References

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying software as a service (SaaS) to userless and headless devices poses security and manageability challenges due to the absence of user verification and established certificate-based trust relationships, making it difficult to securely link agents to tenant accounts in cloud services.

Innovation Solution

A secure userless device software deployment method that constructs a host reference using a client's public key to create a deterministic URL, enabling a management system to broker SaaS service deployment through a connection plug-in and temporary/ephemeral URL architecture, ensuring secure attachment of managed devices to tenant-based SaaS offerings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If software is deployed to userless and headless devices without user verification, then deployment automation is improved, but security and trust verification deteriorate

Engineering Contradiction:
Improvedeployment automationVSAvoidsecurity and trust verification
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces a device management system as an intermediary between the headless device and the SaaS service. This intermediary broker establishes trust relationships and verifies identities without requiring direct user interaction. The management system acts as a mediator that can programmatically establish secure connections and verify device identities through certificate-based authentication, thus maintaining security while enabling automated deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The headless device performs self-verification through automated certificate-based authentication with the device management system. The device can independently establish its identity and trust relationships without human intervention. The system enables self-service deployment where the device automatically verifies its credentials and establishes secure connections to appropriate SaaS services through the management broker.

Inventive Principle:
Principle #25Self-service

2Productivity

If tenant specific information is sent programmatically without user verification, then deployment efficiency is improved, but security deteriorates

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary certificate-based authentication and trust relationship establishment before any tenant-specific information is transmitted. The device management system pre-verified the device's identity and established secure credentials prior to deployment. This preliminary verification ensures that only authenticated devices can receive and access tenant information, maintaining security while enabling efficient automated information delivery.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If domain join and domain based authentication are used, then trust security is improved, but adaptability to cloud services deteriorates

Engineering Contradiction:
Improvetrust securityVSAvoidcloud service adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal device management system that can handle multiple authentication scenarios across different cloud services. The management system provides a unified interface for certificate-based authentication that works across various SaaS platforms and cloud services. This universal approach maintains the security of domain-based authentication while extending adaptability to multiple cloud service providers and deployment scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10564951B2Managed software as a service deployment utilizing a client key to generate a one-time use reference for delivery
Publication Date: 2020.02.18 DELL PROD LP
  • US10564951B2 patent drawing
  • US10564951B2 patent drawing
  • US10564951B2 patent drawing

AI summary

A system, method, and computer-readable medium for performing a secure userless device software deployment operation. The secure userless device software deployment operation enables a client information handing system and a server information handling system to independently and deterministically construct a host reference (such as a host universal resource locator (URL)). In certain embodiments, the host reference is used for the SaaS connection based on a fixed portion plus a unique portion created using a client's public key as an identifier. In certain embodiments, the secure userless device software deployment operation leverages a management system to broker a SaaS service deployment. In certain embodiments, the secure userless device software deployment operation securely attaches a managed userless device to a tenant based SaaS offering by leveraging a connection plug-in and temporary/ephemeral URL architecture with a one-time use construct.