Analyzing risk for devices within a managed environment

US12591689B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12591689-B2
Application numberUS-202318535915-A
CountryUS
Kind codeB2
Filing dateDec 11, 2023
Priority dateDec 11, 2023
Publication dateMar 31, 2026
Grant dateMar 31, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for analyzing risk for devices within a managed environment are described. One example method includes receiving a provisioning request from a device including a device identifier, device credentials, and a current firmware revision, wherein the provisioning request indicates that the device is newly connected to the managed environment; verifying the authenticity of the device based at least in part on the device identifier and the device credentials; verifying that the current firmware revision of the device matches a master firmware revision associated with a type of the device; and determining a risk score associated with the device based at least in part on the device identifier, the device credentials, the current firmware revision of the device, and on whether any known vulnerabilities are associated with the type of the device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving, by a server including at least one processor from a network, a provisioning request from a device including a device identifier, device credentials, and a current firmware revision, wherein the device is a peripheral device, wherein the provisioning request is received by the server after being sent by the device upon being first connected to another device within a managed environment, and wherein the provisioning request indicates that the device is newly connected to the managed environment; verifying, by the server, the authenticity of the device based at least in part on the device identifier and the device credentials; determining, by the server, a risk score associated with the device based at least in part on the device identifier, the device credentials, the current firmware revision of the device, and on whether any known vulnerabilities are associated with the device; and in response to the risk score, the server implementing a policy to be applied to the device, wherein the policy includes a restriction on use of the device outside of a virtual private network (VPN). 2 . The method of claim 1 , wherein the provisioning request is received by the server at a factory provisioned network address present in the device. 3 . The method of claim 1 , further comprising: determining, by the server, that the risk score associated with the device exceeds a threshold risk score; and in response, performing, by the server, at least one security action. 4 . The method of claim 3 , wherein the at least one security action includes at least one of notifying an administrator of the managed environment that the risk score associated with the device exceeds a threshold risk score, or excluding the device from the managed environment. 5 . The method of claim 1 , further comprising: determining, by the server, that the risk score associated with the device does not exceed a threshold risk score; and in response, allowing the device to operate within the managed environment. 6 . The method of claim 1 , further comprising: receiving, by the server, a report of a potential vulnerability associated with the type of the device; and in response, updating, by the server, the risk score associated with the device based on the potential vulnerability. 7 . A system comprising: a computer system including at least one processor and a memory, and configured to perform operations including: receiving, from a network, a provisioning request from a device including a device identifier, device credentials, and a current firmware revision, wherein the device is a peripheral device, wherein the provisioning request is received by the server after being sent by the device upon being first connected to another device within a managed environment, and wherein the provisioning request indicates that the device is newly connected to the managed environment; verifying the authenticity of the device based at least in part on the device identifier and the device credentials; determining a risk score associated with the device based at least in part on the device identifier, the device credentials, the current firmware revision of the device, and on whether any known vulnerabilities are associated with the device; and in response to the risk score, implementing a policy to be applied to the device, wherein the policy includes a restriction on use of the device outside of a virtual private network (VPN). 8 . The system of claim 7 , wherein the provisioning request is received by the server at a factory provisioned network address present in the device. 9 . The system of claim 7 , the operations further comprising: determining that the risk score associated with the device exceeds a threshold risk score; and in response, performing at least one security action. 10 . The system of claim 9 , wherein the at least one security action includes at least one of notifying an administrator of the managed environment that the risk score associated with the device exceeds a threshold risk score, or excluding the device from the managed environment. 11 . The system of claim 7 , the operations further comprising: determining that the risk score associated with the device does not exceed a threshold risk score; and in response, allowing the device to operate within the managed environment. 12 . The system of claim 7 , the operations further comprising: receiving a report of a potential vulnerability associated with the type of the device; and in response, updating the risk score associated with the device based on the potential vulnerability. 13 . An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable instructions thereon that are executable by a processor of a computer system to perform operations comprising: receiving, from a network, a provisioning request from a device including a device identifier, device credentials, and a current firmware revision, wherein the device is a peripheral device, wherein the provisioning request is received by the server after being sent by the device upon being first connected to another device within a managed environment, and wherein the provisioning request indicates that the device is newly connected to the managed environment; verifying the authenticity of the device based at least in part on the device identifier and the device credentials; determining a risk score associated with the device based at least in part on the device identifier, the device credentials, the current firmware revision of the device, and on whether any known vulnerabilities are associated with the device; and in response to the risk score, implementing a policy to be applied to the device, wherein the policy includes a restriction on use of the device outside of a virtual private network (VPN). 14 . The article of claim 13 , wherein the provisioning request is received by the server at a factory provisioned network address present in the device. 15 . The article of claim 13 , the operations further comprising: determining that the risk score associated with the device exceeds a threshold risk score; and in response, performing at least one security action. 16 . The article of claim 15 , wherein the at least one security action includes at least one of notifying an administrator of the managed environment that the risk score associated with the device exceeds a threshold risk score, or excluding the device from the managed environment. 17 . The article of claim 13 , the operations further comprising: determining that the risk score associated with the device does not exceed a threshold risk score; and in response, allowing the device to operate within the managed environment.

Assignees

Inventors

Classifications

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12591689B2 cover?
Techniques for analyzing risk for devices within a managed environment are described. One example method includes receiving a provisioning request from a device including a device identifier, device credentials, and a current firmware revision, wherein the provisioning request indicates that the device is newly connected to the managed environment; verifying the authenticity of the device based…
Who is the assignee on this patent?
Dell Products Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).