IP Library Patent Application 13225371
Patent Application
App. No. 13/225,371

System and Web Security Agent Method for Certificate Authority Reputation Enforcement

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/225,371
Abstract

Network security administrators are enabled with their customizable certificate authority reputation policy store which is informed by an independent certificate authority reputation server. The custom policy store overrides trusted root certificate stores accessible to an operating system web networking layer or to a third party browser. Importing revocation lists or updating browsers or operating system is made redundant. Proactive remediation is enabled to delete or disable root certificates in trusted operating system root certificate stores or in trusted browser root certificate stores by a web security agent installed at distributed endpoints. This removes the need for additional hardware or synchronous remote access over the protected endpoints.

Claims (25)

1 . An apparatus to enforce trust policy for certificate authorities comprising:

a certificate authority reputation server;

a certificate authority reputation custom policy store coupled to the ca reputation server, and

a web security agent circuit

the web security agent circuit coupled to the custom policy store and further coupled to a operating system web networking layer circuit within an endpoint; wherein the apparatus is communicatively disposed between the endpoint and a website which presents a certificate signed by a certificate authority in response to a request from the endpoint.

2 . The apparatus of claim 2 wherein the Security Agent circuit is further coupled to a operating system web networking layer circuit of an endpoint wherein the operating system web networking layer circuit may be further coupled to an operating system root certificate store, and at least one of an operating system browser and an other application using port 80, 443 .

3 . The apparatus of claim 2 wherein the Security Agent circuit is further coupled to a third party browser circuit of and endpoint wherein the third party browser circuit is further coupled to browser trusted root certificate store.

4 . A method for operating a (barracuda web) Security Agent circuit coupled to an operating system web networking layer comprising:

reading a certificate authority reputation custom policy store, and

cleaning at least one local trusted root certificate store.

5 . A method for operating a (barracuda web) Security Agent circuit coupled to a third party browser comprising:

reading a certificate authority reputation custom policy store, and

cleaning at least one local trusted root certificate store.

6 . A method for operating a (barracuda web) Security Agent circuit coupled to an endpoint comprising:

receiving certificate authority signed certificate presented by a website,

reading a certificate authority reputation custom policy store and

providing a message to an endpoint without completing the connection to the website.

7 . The method of claim 6 wherein the message is a block message and further requests to or responses from the website are blocked.

8 . The method of claim 6 wherein the message is a warning message and further requests to or responses from the website are enabled after affirmative override.

9 . A method for operating a Certificate Authority Reputation Enforcement apparatus comprising

receiving an update to a barracuda certificate authority reputation server of fraudulent certificate generation at a certificate authority,

configuring a certificate authority reputation custom policy store with revised policies,

receiving a request for TLS connection to a website from an endpoint wherein the endpoint is coupled to an operating system trusted root certificate store or to a browser trusted root certificate store;

determining that the certificate presented by the website has been revoked or that the certificate authority has been deprecated in the custom policy store; and

blocking a TLS connection to the website.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jan 8, 2018
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 045027/0870 →
SECURITY INTEREST Recorded Oct 12, 2012
From: BARRACUDA NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 029218/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2011
From: PAO, STEPHEN; SHI, FLEMING
To: BARRACUDA NETWORKS, INC
Reel/Frame 026875/0626 →