Systems, methods, and apparatuses for transmission of verification certificates in an electronic network
The present invention provides for implementing an internal entity intermediate certificate authority via a mutual transport layer security conversation to allow an entity-specific certificate authority to generate its own certificate which is transmitted to a second point in the internal transmission for sending of the external certificate authority generated certificate to the external entity for mutual authentication. Further, in this way, the first point of internal transmission does not have to store the certificate in its own hardware security module.
1 . A system for securely electronically transmitting verification certificates, the system comprising:
at least one network communication interface;
at least one non-transitory storage device; and
at least one processing device coupled to the at least one non-transitory storage device and the at least one network communication interface, wherein the at least one processing device is configured to:
assign an external certificate of one or more external third party entity servers to an internal certificate of one or more internal entity servers allowing for management of external certificates with keys stored in a hardware security module;
receive a request to establish a secure connection between an internal entity server of the one or more internal entity servers and an external third party entity server of the one or more external third party entity servers, wherein the request comprises transmission of an external certificate of the external third party entity server;
initiate an intermediate certificate authority module to generate a unique verification certificate from a match of the external certificate to an external certificate assigned to the internal server;
map the unique verification certificate to a second internal point from the internal entity server and provision the unique verification certificate to permit connectivity between the second internal point and the third party entity server, wherein mapping the unique verification certificate to the second internal point further comprises authenticating device permissions associated with the internal entity server and the external third party entity server based on internal and external certificate provisioning for connectivity between the internal entity server and the external third party entity server;
transmit the unique verification certificate to the second internal point, wherein the second internal point is not the internal entity server and does not store the unique verification certificate in a hardware security module, wherein the second internal point comprises an application proxy; and
simultaneously transmit the unique verification certificate to the external third party entity server for implementing the internal entity verification certificate mutual transport layer security and connect the external third party entity server to the second internal point.
2 . The system of claim 1 , wherein the application proxy communicates directly with the internal entity server.
3 . The system of claim 1 , wherein the unique verification certificate is transmitted over a mutual transport layer security protocol.
4 . The system of claim 1 , wherein the intermediate certificate authority module exists within a network boundary of a same entity as the internal entity server.
5 . A computer program product for securely electronically transmitting verification certificates, the computer program product comprising a non-transitory computer-readable storage medium having computer executable instructions for causing a computer processor to perform the steps of:
assign an external certificate of one or more external third party entity servers to an internal certificate of one or more internal entity servers allowing for management of external certificates with keys stored in a hardware security module;
receive a request to establish a secure connection between an internal entity server of the one or more internal entity servers and an external third party entity server of the one or more external third party entity servers, wherein the request comprises transmission of an external certificate of the external third party entity server;
initiate an intermediate certificate authority module to generate a unique verification certificate from a match of the external certificate to an external certificate assigned to the internal server;
map the unique verification certificate to a second internal point from the internal entity server and provision the unique verification certificate to permit connectivity between the second internal point and the third party entity server, wherein mapping the unique verification certificate to the second internal point further comprises authenticating device permissions associated with the internal entity server and the external third party entity server based on internal and external certificate provisioning for connectivity between the internal entity server and the external third party entity server;
transmit the unique verification certificate to the second internal point, wherein the second internal point is not the internal entity server and does not store the unique verification certificate in a hardware security module, wherein the second internal point comprises an application proxy; and
simultaneously transmit the unique verification certificate to the external third party entity server for implementing the internal entity verification certificate mutual transport layer security and connect the external third party entity server to the second internal point.
6 . The computer program product of claim 5 , wherein the application proxy communicates directly with the internal entity server.
7 . The computer program product of claim 5 , wherein the unique verification certificate is transmitted over a mutual transport layer security protocol.
8 . The computer program product of claim 5 , wherein the intermediate certificate authority module exists within a network boundary of a same entity as the internal entity server.
9 . A computer implemented method for securely electronically transmitting verification certificates, wherein the method comprises:
assigning an external certificate of one or more external third party entity servers to an internal certificate of one or more internal entity servers allowing for management of external certificates with keys stored in a hardware security module;
receiving a request to establish a secure connection between an internal entity server of the one or more internal entity servers and an external third party entity server of the one or more external third party entity servers, wherein the request comprises transmission of an external certificate of the external third party entity server;
initiating an intermediate certificate authority module to generate a unique verification certificate from a match of the external certificate to an external certificate assigned to the internal server;
mapping the unique verification certificate to a second internal point from the internal entity server and provisioning the unique verification certificate to permit connectivity between the second internal point and the third party entity server, wherein mapping the unique verification certificate to the second internal point further comprises authenticating device permissions associated with the internal entity server and the external third party entity server based on internal and external certificate provisioning for connectivity between the internal entity server and the external third party entity server;
transmitting the unique verification certificate to the second internal point, wherein the second internal point is not the internal entity server and does not store the unique verification certificate in a hardware security module, wherein the second internal point comprises an application proxy; and
simultaneously transmitting the unique verification certificate to the external third party entity server for implementing the internal entity verification certificate mutual transport layer security and connect the external third party entity server to the second internal point.
10 . The computer implemented method of claim 9 , wherein the application proxy communicates directly with the internal entity server.
11 . The computer implemented method of claim 9 , wherein the unique verification certificate is transmitted over a mutual transport layer security protocol.