IP Library Granted Patent US 8,365,257
Granted Patent B1
US 8,365,257 · App. 11/757,117 · Granted Jan 29, 2013

Secure web portal with delegated secure administration

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,365,257
App. No.
11/757,117
Granted
Jan 29, 2013
Kind
B1
Abstract

A web portal for issuing multiple digital certificates to users of an entity (e.g., a law-enforcement agency or corporation) is described herein. The digital certificates enable users to access confidential records—such as telecommunication records—by requesting the records through a web site. A master digital certificate is issued for the entity, and a user associated with the master digital certificate can request slave certificates to be issued to other employees or affiliates of the entity. A certificate provisioning server is configured to only issue slave certificates at the request of the user with the master digital certificate. Once issued, a slave certificate is communicated to an authentication server, which notifies the assignee of the slave certificate of its online location.

Claims (34)

1. One or more non-transitory computer-readable media (“media”) having computer-executable instructions embodied thereon for creating a slave digital certificate comprising:

receiving a request from a first user assigned to a master profile to create the slave digital certificate for a second user;

authenticating the request from the first user;

creating the slave digital certificate for the second user, the second user not being able to request records from the telecommunications provider without the slave digital certificate, the telecommunications provider only authenticating the requests for records and not the second user submitting the request; and

transmitting the slave digital certificate;

wherein receiving a second request from the first user to lock the slave digital certificate and based on the second request, locking the slave digital certificate;

and further wherein receiving a third request from the first user to modify a role associated with the slave digital certificate and based on the third request, modifying the role associated with the slave digital certificate.

2. The media of claim 1 , wherein the first and second user are associated with a common entity.

3. The media of claim 2 , wherein the common entity is a law-enforcement agency.

4. The media of claim 1 , wherein the one or more telecommunication records include at least one of a telecommunication subscriber's phone records, incoming calls, outgoing calls, text messages, voice messages, geographic location, GPS location, or subscriber number.

5. The media of claim 1 , further comprising submitting fourth request from the second user to retrieve the one or more telecommunication records, wherein the second request comprises an indicia of a subpoena.

6. The media of claim 1 , further comprising transmitting a notification of the slave digital certificate, wherein the notification comprises a reference that allows access to the slave digital certificate.

7. The media of claim 1 , wherein the master profile comprises a software certificate based on the X.509 standard for a public key infrastructure.

8. One or more non-transitory computer-readable media (“media”) having computer-executable instructions embodied thereon for issuing a slave digital certificate at the request of a first user for a second user, comprising:

assigning a master profile to an entity, wherein the master profile enables a first user associated with the entity to authorize the issuance of slave digital certificates for other users associated with the entity;

receiving a request from the first user to create the slave digital certificate for the second user using the master profile;

authenticating the request from the first user;

creating the slave digital certificate for the second user, the second user not being able to submit requests for records to a telecommunications provider without the slave digital certificate; and

transmitting the slave digital certificate;

wherein receiving a second request from the first user to lock the slave digital certificate and based on the second request, locking the slave digital certificate;

and further wherein receiving a third request from the first user to modify a role associated with the slave digital certificate and based on the third request, modifying the role associated with the slave digital certificate.

9. The media of claim 8 , wherein the slave digital certificate is a software certificate based on the X.509 standard for a public key infrastructure.

10. A system for creating a slave digital certificate, comprising:

a certificate provisioning server configured to receive a request to issue the slave digital certificate to a second user and determine whether the request was submitted by a first user with a master profile, wherein the second user is not able to request records from a telecommunications provider without the slave digital certificate, and further wherein the telecommunications provider only needs to authenticate the requests for records and does not need to authenticate the second user submitting the request; and

an authentication server configured to authenticate the request and communicate a notification to the first user when the slave digital certificate is issued, wherein the notification includes a reference that allows access to the slave digital certificate, the authentication server being further configured to receive a second request from the first user to lock the slave digital certificate and based on the second request the authentication server locks the slave digital certificate, the authentication server being further configured to receive a third request from the first user to modify a role associated with the slave digital certificate and based on the third request the authentication server modifies the role associated with the slave digital certificate.

11. The system of claim 10 , further comprising a web server hosting a web site, which is accessible to the first user, wherein the first user can access the telecommunications records by submitting record requests on the web site.

12. The system of claim 10 , further comprising a tracking server configured to return indications of the telecommunication records to the first user if the first user submits a second request for the telecommunication records and has downloaded the slave digital certificate.

13. The system of claim 10 , further comprising a client computing device configured to communicate the request for the slave digital certificate.

14. The system of claim 13 , wherein the request is entered on the client computing device by the second user.

15. The system of claim 10 , wherein the authentication server is further configured to:

receive a fourth request from the first user to revoke at least one slave digital certificate; and

based on the request, revoking the at least one slave digital certificate.

16. The system of claim 10 , wherein the role may be at least one of an administrator, a viewer of all cases related to an entity with the first user, or a viewer of only cases associated with the first user.

17. The system of claim 10 , wherein the slave digital certificate is a software certificate based on the X.509 standard for a public key infrastructure.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2007
From: CAUSEY, STANLEY EUGENE; DUONG, CUONG PHAT; SOWELL, BRYAN SCOTT
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 019370/0929 →