IP Library Granted Patent US 7,937,583
Granted Patent B2
US 7,937,583 · App. 12/486,704 · Granted May 3, 2011

Method of aggregating multiple certificate authority services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,937,583
App. No.
12/486,704
Granted
May 3, 2011
Kind
B2
Abstract

The disclosure relates to the management of PKI digital certificates, including certificate discovery, installation, verification and replacement for endpoints over an insecure network. A database of certificates may be maintained through discovery, replacement and other activities. Certificate discovery identifies certificates and associated information including network locations, methods of access, applications of use and non-use, and may produce logs and reports. Automated requests to certificate authorities for new certificates, renewals or certificate signing requests may precede the installation of issued certificates to servers using installation scripts directed to a particular application or product, which may provide notification or require approval or intervention. An administrator may be notified of expiring certificates, using a database or scanning or server agents. Detailed information on various example embodiments of the inventions are provided in the Detailed Description below, and the inventions are defined by the appended claims.

Claims (22)

1. A method for providing a unified certificate request interface to a plurality of certificate authorities, said method comprising the steps of:

presenting a uniform interface for receiving information pertaining to the submission of an individual certificate signing request to the plurality of certificate authorities, said interface providing a uniform set of entries for information items required in a certificate signing request generally;

presenting a selectable object whereby a choice of one of the plurality of certificate authorities may be entered;

receiving entry items through the uniform interface and a selection of a certificate authority;

storing items of identification sufficient to identify a requesting entity to each of the plurality of certificate authorities; and

communicating with a certificate authority interface of the selected certificate authority, the communicating presenting at least the received entry items required by the selected certificate authority, the communication in its totality presenting a certificate signing request to the selected certificate authority, the communication further presenting items of identification whereby a requesting entity may be associated to the certificate signing request.

2. A method according to claim 1 , further comprising the steps of:

providing for the setting of a default certificate authority of the plurality of certificate authorities; and

in presenting a selectable object, providing a selection of the default certificate authority setting.

3. A method according to claim 1 , further comprising the step of executing a script from a stored set of scripts whereby a selected certificate authority of a plurality of certificate authorities may be communicated with to present a certificate signing request.

4. A method according to claim 1 , further comprising the step of reading a certificate authority records containing at least one default setting usable in presenting a certificate signing request to the selected certificate authority of the plurality of certificate authorities.

5. A method according to claim 1 , wherein the uniform interface presented has an interaction substantially similar to the interaction of a true certificate authority.

6. A method for providing a unified certificate request interface to a plurality of certificate authorities, said method comprising the steps of:

providing for the setting of a default certificate authority of the plurality of certificate authorities;

presenting a uniform interface for receiving information pertaining to the submission of an individual certificate signing request to the plurality of certificate authorities, said interface providing a uniform set of entries for information items required in a certificate signing request generally;

presenting a selectable object whereby a choice of one of the plurality of certificate authorities may be entered, whereby the selectable object is presented with the default certificate authority selected;

reading at least one of a set of certificate authority records, each of the certificate authority records containing at least one default setting usable in presenting a certificate signing request to one of the certificate authorities of the plurality of certificate authorities;

receiving entry items through the uniform interface and a selection of a certificate authority;

storing items of identification sufficient to identify a requesting entity to each of the plurality of certificate authorities; and

communicating with a certificate authority interface of the selected certificate authority, the communicating presenting at least the received entry items required by the selected certificate authority, the communication in its totality presenting a certificate signing request to the selected certificate authority, the communication further presenting items of identification whereby a requesting entity may be associated to the certificate signing request.

7. A method according to claim 6 , further comprising the step of executing a script from a stored set of scripts whereby a selected certificate authority of a plurality of certificate authorities may be communicated with to present a certificate signing request.

8. A method according to claim 6 , wherein the uniform interface presented has an interaction substantially similar to the interaction of a true certificate authority.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2026
From: VENAFI, INC.; VENAFI BUYER, LLC; VENAFI INTERMEDIATE, LLC; VENAFI HOLDINGS, INC.
To: CYBERARK SOFTWARE, INC.
Reel/Frame 073400/0651 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 054892, FRAME 0430 Recorded Oct 1, 2024
From: TRUIST BANK, AS ADMINISTRATIVE AGENT
To: VENAFI, INC.
Reel/Frame 069065/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2021
From: THORNTON, RUSSELL; HODSON, BENJAMIN; SEEGMILLER, JAYSON
To: IMCENTRIC, INC.
Reel/Frame 056705/0152 →
CHANGE OF NAME Recorded Jun 29, 2021
From: IMCENTRIC, INC.
To: VENAFI, INC.
Reel/Frame 056705/0512 →
PATENT SECURITY AGREEMENT Recorded Jan 4, 2021
From: VENAFI, INC.
To: TRUIST BANK
Reel/Frame 054892/0430 →