IP Library Granted Patent US 12712872
Granted Patent B2
US 12712872 · App. 18/516,180 · Granted Aug 18, 2026

Authentication procedures between network devices and clients

Inventors: Feng Ding (Beijing, CN); Hao Lu (Fremont, CA); Youhe Zhang (Beijing, CN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/0823H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712872
App. No.
18/516,180
Granted
Aug 18, 2026
Kind
B2
Abstract

In some examples, a network device receives, from an orchestration server, a name for use in obtaining a certificate. The network device sends, to a certificate enrollment server, a certificate request comprising the name, and receives, from the certificate enrollment server, a response to the certificate request, the response including information of the certificate that is based on the name in the certificate request. The network device detects that an authentication server is unavailable for an authentication procedure for a client coupled to the network device. Based on detecting that the authentication server is unavailable, the network device uses the certificate based on the name in the certificate request as part of the authentication procedure between the network device and the client.

Claims (51)

1 . A non-transitory machine-readable storage medium comprising instructions that upon execution cause a network device to:

receive, at the network device from an orchestration server, a name for use in obtaining a certificate, the network device to establish connectivity with electronic devices seeking access to a network;

send, from the network device to a certificate enrollment server, a certificate request comprising the name;

receive, at the network device from the certificate enrollment server, a response to the certificate request, the response comprising a signed certificate signed by a certificate authority (CA) associated with the certificate enrollment server, the signed certificate produced from the certificate that is based on the name in the certificate request;

derive the certificate from the signed certificate;

receive, at the network device, a message that is part of an authentication procedure between a first electronic device connected to the network device and an authentication server, the network device to forward the message to the authentication server if the authentication server is available;

detect that the authentication server is unavailable for the authentication procedure between the first electronic device and the authentication server;

based on detecting that the authentication server is unavailable, use the certificate based on the name in the certificate request as part of the authentication procedure between the network device and the first electronic device; and

after performing the authentication procedure, communicate data of the first electronic device through the network device.

2 . The non-transitory machine-readable storage medium of claim 1 , wherein the certificate request sent from the network device is a first certificate request, and wherein the name included in the first certificate request is the same as a name included in a second certificate request from the authentication server to the certificate enrollment server.

3 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the network device to:

detect that a second electronic device is connected to the network device; and

based on detecting that the authentication server is available for an authentication procedure for the second electronic device, act as an intermediary for the authentication procedure for the second electronic device that is performed between the second electronic device and the authentication server.

4 . The non-transitory machine-readable storage medium of claim 3 , wherein the authentication procedure for the second electronic device that is performed between the second electronic device and the authentication server comprises the authentication server sending, to the second electronic device, a certificate obtained by the authentication server from the certificate enrollment server based on a certificate request comprising the name sent from the authentication server to the certificate enrollment server.

5 . The non-transitory machine-readable storage medium of claim 1 , wherein the certificate enrollment server comprises an Enrollment over Secure Transport protocol (EST) server.

6 . The non-transitory machine-readable storage medium of claim 5 , wherein the network device and the authentication server are EST clients to obtain certificates from the EST server.

7 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the network device to:

in the authentication procedure, send, from the network device, the certificate to the first electronic device for use by the first electronic device in verifying an identity of the network device based on the certificate.

8 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the network device to:

receive, from the orchestration server, information of the certificate enrollment server; and

access the certificate enrollment server using the received information.

9 . The non-transitory machine-readable storage medium of claim 8 , wherein the received information of the certificate enrollment server comprises a uniform resource identifier (URI) of the certificate enrollment server.

10 . The non-transitory machine-readable storage medium of claim 9 , wherein the instructions upon execution cause the network device to:

establish a secure connection between the network device and the certificate enrollment server accessible at the URI; and

send the certificate request comprising the name from the network device to the certificate enrollment server over the secure connection.

11 . The non-transitory machine-readable storage medium of claim 8 , wherein the certificate enrollment server was selected by the orchestration server from among a plurality of certificate enrollment servers based on a location of the network device.

12 . The non-transitory machine-readable storage medium of claim 1 , wherein the name comprises a common name (CN) of a domain of a network provider of the network device.

13 . The non-transitory machine-readable storage medium of claim 1 , wherein the name comprises a common name (CN) and a Subject Alternative Name (SAN) of domains of a network provider of the network device.

14 . The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the network device to take over providing an authentication service for electronic devices based on detecting that the authentication server is unavailable.

15 . A network device comprising:

a hardware processor; and

a non-transitory storage medium storing instructions executable on the hardware processor to:

receive, at the network device from an orchestration server, a name of a network provider that operates the network device, the name of the network provider for use in obtaining a first certificate of the network device, the name of the network provider received from the orchestration server being a same name as used by an authentication server to obtain a second certificate of the authentication server;

send, from the network device to a certificate enrollment server, a certificate request comprising the name of the network provider;

receive, at the network device from the certificate enrollment server, a response to the certificate request, the response comprising a signed certificate signed by a certificate authority (CA) associated with the certificate enrollment server, the signed certificate produced from the first certificate that is based on the name of the network provider in the certificate request;

derive the first certificate from the signed certificate;

receive, at the network device, a message that is part of an authentication procedure between an electronic device connected to the network device and the authentication server, the network device to forward the message to the authentication server if the authentication server is available;

detect that the authentication server is unavailable for the authentication procedure between the electronic device and the authentication server;

based on detecting that the authentication server is unavailable, use the first certificate based on the name in the certificate request as part of the authentication procedure between the network device and the electronic device; and

after performing the authentication procedure, communicate data of the electronic device through the network device.

16 . The network device of claim 15 , wherein the name comprises a common name (CN) of a domain of the network provider of the network device.

17 . A method comprising:

receiving, at a network device from an orchestration server, identifying information identifying a certificate enrollment server and parameters for inclusion in a certificate request, the parameters comprising a name for use in obtaining a certificate, the network device to establish connectivity with electronic devices seeking access to a network;

sending, from the network device to the certificate enrollment server identified by the identifying information, a certificate request comprising the parameters;

receiving, at the network device from the certificate enrollment server, a response to the certificate request, the response comprising a signed certificate signed by a certificate authority (CA) associated with the certificate enrollment server, the signed certificate produced from the certificate that is based on the name included as one of the parameters in the certificate request;

deriving, by the network device, the certificate from the signed certificate;

receiving, at the network device, a message that is part of an authentication procedure between an electronic device connected to the network device and an authentication server, the network device to forward the message to the authentication server if the authentication server is available;

detecting, by the network device, that the authentication server is unavailable for the authentication procedure between the electronic device and the authentication server;

based on detecting that the authentication server is unavailable, using, by the network device, the certificate based on the name in the certificate request as part of the authentication procedure between the network device and the electronic device; and

after performing the authentication procedure, communicating data of the electronic device through the network device.

18 . The method of claim 17 , wherein the authentication procedure between the network device and the electronic device is performed by an authentication service in the network device invoked for authentication survivability responsive to the authentication server being unavailable.