IP Library Granted Patent US 7,032,110
Granted Patent B1
US 7,032,110 · App. 09/608,986 · Granted Apr 18, 2006

PKI-based client/server authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,032,110
App. No.
09/608,986
Granted
Apr 18, 2006
Kind
B1
Abstract

A client/server authentication system is disclosed. The system includes a filter, a plug-in, and an extension. The filter monitors sessions between a client and a server for proper authentication. The plug-in is coupled to the client and the server. The plug-in generates public and private key pairs, and receives and stores certificates. The extension is coupled to the filter. The extension generates script commands to cause the client and the server to perform required steps indicated by the filter.

Claims (56)

1. A method for providing a single sign-on authentication and privacy, comprising in order:

submitting a request to access a node, wherein the request is submitted by a client;

searching for a security token, wherein the searching is performed by a security filter on a server and operates to search for the security token sent from the client to the server, wherein the security token, if present, is stored on the client as a cookie;

directing the client to submit a certificate to the server, wherein the directing is performed by the security filter on the server;

verifying the submitted certificate with a trusted certificate, wherein the verifying is performed by a security extension on the server and operates to verify the submitted certificate sent from the client to the server;

performing a challenge, wherein the challenge is generated by the security extension on the server and is sent to the client;

generating a response to the challenge, wherein the response is generated by the client and is sent to the server; and

saving the response as a named cookie on the client, wherein the response is saved by the client.

2. The method of claim 1 , wherein said response is used as a security token.

3. The method of claim 2 , wherein said security token is used to propagate an initial authentication.

4. The method of claim 1 , further comprising:

creating a connection session if the certificate is valid.

5. The method of claim 1 , wherein said verifying the submitted certificate includes checking a signature on the submitted certificate with the trusted certificate.

6. The method of claim 1 , further comprising:

generating a key;

encrypting the key with a client's public key;

sending an encrypted key to a client; and

using the key to encrypt communication.

7. A method for providing a single sign-on authentication and privacy, comprising in order:

submitting a request to access a node, wherein the request is submitted by a client;

searching for a security token, wherein the searching is performed by a security filter on a server and operates to search for the security token sent from the client to the server, wherein the security token, if present, is stored on the client as a cookie;

directing the client to submit a certificate to the server, wherein the directing is performed by the security filter on the server;

verifying the submitted certificate with a trusted certificate, wherein the verifying is performed by a security extension on the server and operates to verify the submitted certificate sent from the client to the server;

performing a challenge, wherein the challenge is generated by the security extension in on the server and is sent to the client;

generating a response to the challenge, wherein the response is generated by the client and is sent to the server;

saving the response as a named cookie with an authentication token on the client, wherein the response is saved by the client; and

using standard Secure Socket Layer (SSL) library to provide communication privacy.

8. The method of claim 7 , wherein said verifying includes creating and registering a new authentication session.

9. The method of claim 8 , wherein said verifying includes validating the new authentication session with the authentication token.

10. The method of claim 7 , wherein said verifying includes indicating a failure status to a client if said verifying fails.

11. The method of claim 7 , wherein said performing said challenge includes generating a node challenge random number.

12. A method of claim 7 , wherein said directing includes receiving an address of the node; and

checking to determine if the address is protected.

13. The method of claim 7 , further comprising:

determining if the authentication token is already present.

14. The method of claim 13 , further comprising:

determining if a client is on an access control list if the authentication token is present and valid.

15. An apparatus comprising a computer-readable storage medium having executable instructions that enable the computer to, in order:

submit a request to access a node, wherein the request is submitted by a client;

search for a security token, wherein the search is performed by a security filter on a server and operates to search for the security token sent from the client to the server, wherein the security token, if present, is stored on the client as a cookie;

direct the client to submit a certificate to the server, wherein the directing is performed by the security filter on the server;

verify the submitted certificate with a trusted certificate, wherein the verifying is performed by a security extension on the server and operates to verify the submitted certificate sent from the client to the server;

perform a challenge, wherein the challenge is generated by the security extension on the server and is sent to the client;

generate a response to the challenge, wherein the response is generated by the client and is sent to the server; and

save the response as a named cookie on the client, wherein the response is saved by the client.

16. The apparatus of claim 15 , wherein said response is used as a security token.

17. An apparatus comprising a computer-readable storage medium having executable instructions that enable the computer to, in order:

submit a request to access a node, wherein the request is submitted by a client;

search for a security token, wherein the search is performed by a security filter on a server and operates to search for the security token sent from the client to the server, wherein the security token, if present, is stored on the client as a cookie;

direct the client to submit a certificate to the server, wherein the directing is performed by the security filter on the server;

verify the submitted certificate with a trusted certificate, wherein the verifying is performed by a security extension on the server and operates to verify the submitted certificate sent from the client to the server;

perform a challenge, wherein the challenge is generated by the security extension on the server and is sent to the client;

generate a response to the challenge, wherein the response is generated by the client and is sent to the server;

save the response as a named cookie with an authentication token on the client, wherein the response is saved by the client; and

use standard Secure Socket Layer (SSL) library to provide communication privacy.

18. The apparatus of claim 17 , wherein said verify the submitted certificate includes instructions to create and register new authentication session.

Assignments (25)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
NUNC PRO TUNC ASSIGNMENT Recorded Sep 21, 2016
From: LANDESK SOFTWARE, INC.
To: CRIMSON CORPORATION
Reel/Frame 039819/0845 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: LANDESK SOFTWARE, INC.
Reel/Frame 030993/0622 →
PATENT SECURITY AGREEMENT Recorded Jul 13, 2012
From: LANDESK SOFTWARE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028541/0782 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 29, 2012
From: D.E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C., AS AGENT
To: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
Reel/Frame 027783/0491 →
PATENT SECURITY AGREEMENT Recorded Sep 30, 2010
From: LAN DESK SOFTWARE, INC.; CRIMSON CORPORATION
To: D. E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C. AS AGENT
Reel/Frame 025095/0982 →
PATENT SECURITY AGREEMENT Recorded Sep 28, 2010
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 025056/0391 →
MERGER Recorded Mar 9, 2010
From: LANDESK HOLDINGS, INC.
To: LANDESK SOFTWARE, INC.
Reel/Frame 024045/0925 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2003
From: INTEL CORPORATION
To: LANDESK HOLDINGS, INC.
Reel/Frame 013600/0742 →