IP Library Patent Application 10917964
Patent Application
App. No. 10/917,964

Remote management of client installed digital certificates

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/917,964
Abstract

Disclosed herein are several digital certificate discovery and management systems. Detailed information on various example embodiments of the inventions are provided in the Detailed Description below, and the inventions are defined by the appended claims.

Claims (48)

1 . A method for automatically managing placement of digital certificates to client devices from a certificate management system, the certificate management system including network facilities for communication over an electronic communication network, the method comprising the steps of:

receiving requests for connections from clients,

attempting to retrieve a digital certificate from the client device by way of the network facilities and a client executable component,

if in said attempting a digital certificate is retrieved, checking for expiration of the retrieved digital certificate,

if in said attempting a digital certificate is retrieved, querying a revocation server by way of said network facilities for revocation of the retrieved digital certificate,

if the retrieved digital certificate is expired or revoked, retrieving a newly issued certificate from a network certificate server,

if in said attempting a digital certificate is not retrieved, accessing a certificate store to retrieve an authentication certificate,

following said accessing a network certificate server to retrieve an authentication certificate, placing the retrieved authentication certificate in the certificate store of said client device, and

authenticating the client device for data transfer.

2 . A method according to claim 1 , wherein said authenticating indicates authentication of an individual for a financial transaction.

3 . A method according to claim 1 , wherein said authenticating indicates authentication of an individual for a contractual transaction.

4 . A method according to claim 1 , wherein said authenticating indicates authentication of an individual for a loan application.

5 . A method according to claim 1 , further comprising the step of providing access to resources within an organization based on an authenticated individual's access rights.

6 . A method according to claim 1 , further comprising the step of providing access to email messages for authenticated individuals.

7 . A method according to claim 1 , further comprising the step of providing access to applications on the client device for authenticated individuals.

8 . A method for automatically managing placement of digital certificates to client devices from a certificate management system, the certificate management system including network facilities for communication over an electronic communication network, the method comprising the steps of:

receiving requests for connections from clients,

attempting to retrieve a digital certificate from the client device by way of the network facilities and said client executable component,

if in said attempting a digital certificate is retrieved, checking for expiration of the retrieved digital certificate,

if in said attempting a digital certificate is retrieved, querying a revocation server by way of said network facilities for revocation of the retrieved digital certificate,

if the retrieved digital certificate is expired or revoked, retrieving a newly issued certificate from a network certificate server,

if in said attempting a digital certificate is not retrieved, accessing a certificate store to retrieve an authentication certificate,

following said accessing a network certificate server to retrieve an authentication certificate, placing the retrieved authentication certificate in the certificate store of said client device, and

authenticating the client device for data transfer.

9 . A method according to claim 8 , wherein said authenticating indicates authentication of an individual for a financial transaction.

10 . A method according to claim 8 , wherein said authenticating indicates authentication of an individual for a contractual transaction.

11 . A method according to claim 8 , wherein said authenticating indicates authentication of an individual for a loan application.

12 . A method according to claim 8 , further comprising the step of providing access to resources within an organization based on an authenticated individual's access rights.

13 . A method according to claim 8 , further comprising the step of providing access to email messages for authenticated individuals.

14 . A method according to claim 8 , further comprising the step of providing access to applications on the client device for authenticated individuals.

15 . A method according to claim 8 , further comprising the step of providing an access rights configuration interface operable from the client device upon authentication.

16 . A method for automatically managing placement of digital certificates to client devices from a certificate management system, the certificate management system including network facilities for communication over an electronic communication network, the method comprising the steps of:

receiving requests for connections from clients,

attempting to retrieve a digital certificate from the client device by way of the network facilities and said client executable component,

if in said attempting a digital certificate is retrieved, checking for expiration of the retrieved digital certificate,

if in said attempting a digital certificate is retrieved, querying a revocation server by way of said network facilities for revocation of the retrieved digital certificate,

if the retrieved digital certificate is expired or revoked, retrieving a newly issued certificate from a network certificate server,

if in said attempting a digital certificate is not retrieved, accessing a certificate store to retrieve an authentication certificate,

following said accessing a network certificate server to retrieve an authentication certificate, placing the retrieved authentication certificate in the certificate store of said client device,

authenticating the client device for data transfer, said authenticating identifying the client device to the certificate management system, said authenticating further identifying a user to the certificate management system;

providing access to services conditioned on the enablement of the services for the identified client device and user.

17 . A method according to claim 16 , further comprising the step of providing an access rights configuration interface operable from the client device upon authentication.

18 . A method according to claim 16 , wherein said authenticating indicates authentication of an individual for a financial transaction.

19 . A method according to claim 16 , wherein said authenticating indicates authentication of an individual for a contractual transaction.

20 . A method according to claim 16 , wherein said authenticating indicates authentication of an individual for a loan application.

21 . A method according to claim 16 , further comprising the step of providing access to resources within an organization based on an authenticated individual's access rights.

22 . A method according to claim 16 , further comprising the step of providing access to email messages for authenticated individuals.

23 . A method according to claim 16 , further comprising the step of providing access to applications on the client device for authenticated individuals.

Assignments (5)
SECURITY INTEREST Recorded May 13, 2014
From: VENAFI, INC.
To: SILICON VALLEY BANK
Reel/Frame 032875/0450 →
SECURITY AGREEMENT Recorded Jul 15, 2011
From: VENAFI, INCORPORATED
To: SILICON VALLEY BANK
Reel/Frame 026597/0819 →
CHANGE OF NAME Recorded Oct 21, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON; HOLLOBON, TIMOTHY
To: VENAFI, INC.
Reel/Frame 017111/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2005
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON
To: IMCENTRIC, INC
Reel/Frame 016566/0888 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2004
From: THORNTON, RUSSELL S.; HODSON, BENJAMIN; SEEGMILLER, JAYSON
To: IMCENTRIC, INC.
Reel/Frame 016080/0355 →