IP Library Granted Patent US 8,316,229
Granted Patent B2
US 8,316,229 · App. 11/958,253 · Granted Nov 20, 2012

Secure certificate installation on IP clients

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,316,229
App. No.
11/958,253
Granted
Nov 20, 2012
Kind
B2
Abstract

According to one embodiment of the invention, a method is deployed for loading a user CA certificate into the trusted certificate storage of a network device. The method comprises a number of operations. A first operation involves a downloading of addressing information. Thereafter, a communication session is established using the addressing information for retrieval of a bootstrapping digital certificate that can be digitally verified by the network device using its factory settings. Keying information is extracted from the bootstrapping digital certificate and the keying information can be used to verify that the communication session is between the network device and a certificate server being different than a source for the addressing information. Upon verification that the network device is in communication with the certificate server, the user CA certificate is downloaded from the certificate server using a secure channel that is established based on the bootstrapping digital certificate.

Claims (30)

1. A method for loading a user CA certificate into a network device, comprising:

downloading addressing information of a certificate server, wherein the addressing information is one of a domain name and an Internet Protocol (IP) address of the certificate server, wherein downloading addressing information of a certificate server includes:

identifying the certificate server based on a network provider associated with an existing certificate embedded in the network device, wherein the existing certificate is pre-stored in the network device;

retrieving a bootstrapping digital certificate from the certificate server upon establishing a communication session with the certificate server based on the addressing information;

verifying the bootstrapping digital certificate using the existing certificate embedded in the network device, wherein the verifying of the bootstrapping digital certificate includes recovering a public key of the certificate server from the bootstrapping digital certificate and engaging in a challenge/response communication session to verify that the certificate server has access to a private key of the certificate server;

establishing a secure channel with the certificate server using the bootstrapping digital certificate; and

downloading the user CA certificate from the certificate server.

2. The method of claim 1 wherein the network device is an Internet Protocol (IP) based device.

3. The method of claim 1 , wherein the user CA certificate includes at least a public key associated with a user that is digitally signed with a private key of a certificate authority.

4. The method of claim 1 , wherein the downloading of the addressing information includes retrieving an Internet Protocol (IP) address from a configuration server.

5. The method of claim 4 further comprising: discontinuing the communication session upon determining that the configuration server and the certificate server are in the same subnet.

6. The method of claim 1 , wherein the downloading of the addressing information includes retrieving a domain name from a configuration server and using the domain name to retrieve an Internet Protocol (IP) address of the certificate server from a Domain Name Service (DNS) server.

7. The method of claim 6 further comprising: discontinuing the communication session upon determining that the DNS server and the configuration server are in the same subnet; and

after a user CA certificate is downloaded into the network device, manually verifying at least one from a group consisting of: a certificate thumbprint or a public key fingerprint.

8. The method of claim 1 further comprising: verifying the user CA certificate downloaded into the network device with either a certificate thumbprint or public key fingerprint.

9. A system comprising:

a configuration server to download addressing information of the certificate server to a network device, wherein the configuration server identifies the certificate server based on a network provider associated with a pre-stored certificate embedded in the network device, wherein the addressing information is one of a domain name and an Internet Protocol (IP) address of the certificate server, wherein the network device establishes a communication session with the certificate server based on the addressing information and to retrieve a bootstrapping digital certificate;

wherein the network device includes the pre-stored embedded certificate to be used to verify the bootstrapping digital certificate by using a public key of the certificate server, wherein the public key is included in the bootstrapping digital certificate;

wherein the network device engages in a challenge/response communication session to verify that the certificate server has access to a private key of the certificate server;

wherein the network device establishes a secure channel with the certificate server using the bootstrapping digital certificate; and

wherein the network device downloads the user CA certificate from the certificate server.

10. A method comprising:

receiving addressing information from a first network device by a second network device, wherein receiving the addressing information includes: identifying a third network device based on a network provider associated with an existing certificate embedded pre-stored in the network device, wherein the addressing information is an Internet Protocol (IP) address of the third network device, wherein the first network device is a Dynamic Host Configuration Protocol (DHCP) server;

establishing a communication session between the second network device and a third network device to retrieve a bootstrapping digital certificate from the third network device, the third network device being different from the first network device;

continuing the communication session upon a determination that the first network device is in a different subnet as the third network device by verifying the bootstrapping digital certificate using an existing digital certificate embedded and pre-stored in the second network device,

establishing a secure channel, between the second network device and the third network device, using the bootstrapping digital certificate; and

downloading a user CA certificate from the third network device for storage within a trusted certificate list stored within the second network device, wherein the user CA certificate includes at least a public key associated with a user of the second network device digitally signed with a private key of a certificate authority.

11. The method of claim 10 wherein the second network device supports Internet Protocol (IP) telephony.

12. The method of claim 10 , wherein after receiving the addressing information from the first network device and the addressing information being a domain name of the third network device, the method further comprises fetching an Internet Protocol (IP) address of the third network device from a Domain Name Service (DNS) server based on the domain name and establishing the communication session with the third network device using the IP address.

13. The method of claim 12 further comprising: discontinuing the communication session upon determining that the DNS server and the first network device are in the same subnet.

Assignments (23)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2010
From: NORTEL NETWORKS LIMITED
To: AVAYA INC.
Reel/Frame 023998/0878 →
SECURITY AGREEMENT Recorded Feb 5, 2010
From: AVAYA INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 023905/0001 →
SECURITY AGREEMENT Recorded Feb 4, 2010
From: AVAYA INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 023892/0500 →