IP Library Granted Patent US 12683808
Granted Patent B2
US 12683808 · App. 17/402,187 · Granted Jul 14, 2026

Certificate management

Inventors: Suresh Bysani Venkata Naga (San Jose, CA); Apurv Gupta (Bangalore, IN)
Assignee: Cohesity, Inc.
H04L9/3268G06F9/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683808
App. No.
17/402,187
Granted
Jul 14, 2026
Kind
B2
Abstract

Metadata included in a certificate received from an application or service is analyzed. The application or service is permitted to communicate with other applications or services associated with a data management as a service infrastructure based on a version number associated with a storage tenant included in the analyzed metadata.

Claims (42)

1 . A method, comprising:

distributing, to an application or service associated with a storage tenant that interfaces with a data management as a service infrastructure that includes a private certificate authority, a private certificate including metadata;

maintaining, in a control plane environment of the data management as a service infrastructure, a data structure including a reference certificate version number corresponding to the private certificate, wherein the storage tenant is outside the control plane environment;

analyzing, by the data management as a service infrastructure, the metadata included in the private certificate received from the application or service associated with the storage tenant;

comparing a certificate version number included in the analyzed metadata to the reference certificate version number;

permitting the application or service to communicate with other applications or services associated with the data management as a service infrastructure based on comparing the certificate version number to the reference certificate version number, wherein the reference certificate version number is particular to the storage tenant; and

renewing the private certificate by modifying, with a certificate manager of the control plane environment, the reference certificate version number at the control plane environment and modifying, with the certificate manager of the control plane environment, the certificate version number included in the metadata included in the private certificate at the storage tenant to match the reference certificate version number.

2 . The method of claim 1 , further comprising receiving the private certificate from the application or service associated with the storage tenant.

3 . The method of claim 1 , further comprising permitting the application or service associated with the storage tenant to communicate with the other applications or services associated with the data management as a service infrastructure in response to determining that the certificate version number is equal to the reference certificate version number particular to the storage tenant.

4 . The method of claim 1 , further comprising denying the application or service associated with the storage tenant to communicate with the other applications or services associated with the data management as a service infrastructure in response to determining that the certificate version number is less than the reference certificate version number particular to the storage tenant.

5 . The method of claim 1 , further comprising monitoring a plurality of private certificates that are stored in the data structure, wherein the plurality of private certificates includes the private certificate received from the application or service.

6 . The method of claim 5 , further comprising determining the private certificate is set to expire within a threshold period of time.

7 . The method of claim 1 , further comprising:

based on determining the private certificate is set to expire within a threshold period of time, sending via a message bus a notification to a certificate management service associated with the private certificate,

wherein renewing the private certificate comprises renewing the private certificate based on a response received from the certificate management service.

8 . The method of claim 7 , wherein the message bus includes a message buffer.

9 . The method of claim 8 , wherein the notification remains in the message buffer until the response to the notification is received from the certificate management service associated with the private certificate or the threshold period of time has passed.

10 . The method of claim 7 , wherein the response received from the certificate management service indicates that the private certificate should be renewed.

11 . The method of claim 10 , wherein renewing the private certificate includes increasing, with the certificate manager of the control plane environment, the reference certificate version number at the control plane environment and modifying, with the certificate manager of the control plane environment, the certificate version number included in the metadata included in the private certificate at the storage tenant to be equal to the reference certificate version number.

12 . The method of claim 11 , further comprising providing the renewed private certificate to the application or service that requested the private certificate to be renewed.

13 . The method of claim 7 , wherein renewing the private certificate based on the response received from the certificate management service includes revoking the private certificate in response to not receiving the response within the threshold period of time.

14 . The method of claim 7 , wherein the response received from the certificate management service indicates the private certificate is to be revoked, the method further comprising revoking, based on the response received from the certificate management service, the private certificate by modifying, with the certificate manager of the control plane environment, the reference certificate version number at the control plane environment and without modifying the certificate version number included in the metadata such that the reference certificate version number is different than the certificate version number.

15 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions that, when executed by processing circuitry, cause the processing circuitry to:

distribute, to an application or service associated with a storage tenant that interfaces with a data management as a service infrastructure that includes a private certificate authority, a private certificate including metadata;

maintain, in a control plane environment of the data management as a service infrastructure, a data structure including a reference certificate version number corresponding to the private certificate, wherein the storage tenant is outside the control plane environment;

analyze, by the data management as a service infrastructure, the metadata included in the private certificate received from the application or service associated with the storage tenant;

compare a certificate version number included in the analyzed metadata to the reference certificate version number;

permit the application or service to communicate with other applications or services associated with the data management as a service infrastructure based comparing the certificate version number to the reference certificate version number, wherein the reference certificate version number is particular to the storage tenant; and

renew the private certificate by modifying, with a certificate manager of the control plane environment, the reference certificate version number at the control plane environment and modifying, with the certificate manager of the control plane environment, the certificate version number included in the metadata included in the private certificate at the storage tenant to match the reference certificate version number.

16 . The computer program product of claim 15 , wherein the computer instructions, when executed by processing circuitry, cause the processing circuitry to receive the private certificate from the application or service associated with the storage tenant.

17 . The computer program product of claim 15 , wherein the computer instructions, when executed by processing circuitry, cause the processing circuitry to permit the application or service associated with the storage tenant to communicate with the other applications or services associated with the data management as a service infrastructure in response to determining that the certificate version number is equal to reference certificate version number particular to the storage tenant.

18 . The computer program product of claim 15 , wherein the computer instructions, when executed by processing circuitry, cause the processing circuitry to deny the application or service associated with the storage tenant to communicate with the other applications or services associated with the data management as a service infrastructure in response to determining that the certificate version number associated with the private certificate is less than the reference certificate version number particular to the storage tenant.

19 . The computer program product of claim 15 , wherein the computer instructions, when executed by processing circuitry, cause the processing circuitry to monitor a plurality of private certificates that are stored in the data structure, wherein the plurality of private certificates includes the private certificate received from the application or service.

20 . A system, comprising:

one or more processors configured to:

distribute, to an application or service associated with a storage tenant that interfaces with a data management as a service infrastructure that includes a private certificate authority, a private certificate including metadata;

maintain, in a control plane environment of the data management as a service infrastructure, a data structure including a reference certificate version number corresponding to the private certificate, wherein the storage tenant is outside the control plane environment;

analyze, by the data management as a service infrastructure, metadata included in the private certificate received from the application or service associated with the storage tenant;

compare a certificate version number included in the analyzed metadata to the reference certificate version number;

permit the application or service to communicate with other applications or services associated with the data management as a service infrastructure based on a comparison of the certificate version number associated with the certificate to the reference certificate version number, wherein the reference certificate version number is particular to the storage tenant; and

renew the private certificate by modifying, with a certificate manager of the control plane environment, the reference certificate version number at the control plane environment and modifying, with the certificate manager of the control plane environment, the certificate version number included in the metadata included in the private certificate at the storage tenant to match the reference certificate version number; and

a memory coupled to the one or more processors and configured to provide the one or more processor with instructions.