IP Library Granted Patent US 9,003,507
Granted Patent B2
US 9,003,507 · App. 13/454,653 · Granted Apr 7, 2015

System and method for providing a certificate to a third party request

Inventors: Kevin Lee Koster (Westminster, CO); Roger Lynn Haney (Denver, CO)
Assignee: Cloudpath Networks, Inc.
G06F21/51
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,003,507
App. No.
13/454,653
Granted
Apr 7, 2015
Kind
B2
Abstract

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system based on at least one criteria and an established identity with a first system. The method includes receiving criteria, such as at least one predefined attribute. Also received from a user known to a first system is a request for network access to a second system, the request having at least one identifier. The first system is then queried with the identifier for attributes associated with the user. The attributes associated with the user are evaluated to the predefined attribute(s). In response to at least one attribute associated with the user correlating to the predefined attribute(s), providing a certificate with at least one characteristic for network access on the second system to the user. An associated system for providing a Certificate is also provided.

Claims (62)

1. A method of providing a certificate for certificate based network access in response to a third party request comprising:

identifying a first system having at least one processor and a plurality of users, each user having at least one attribute;

receiving from a third party at least one required attribute for certificate based network access;

querying the first system to determine at least a first subset of users having the at least one required attribute, the querying performed by other than one of the plurality of users of the first system; and

providing from a system other than the first system, as requested by the third party a certificate with at least one characteristic for certificate based network access on a second system having at least one processor to each user of the first subset of users having the at least one required attribute, the second system distinct from the first system.

2. The method of claim 1 , wherein the first system has a plurality of subsections, each user having association with at least one subsection.

3. The method of claim 1 , wherein the required attribute is specified by the second system.

4. The method of claim 1 , wherein the third party is the second system.

5. The method of claim 1 , wherein the at least one required attribute is user information.

6. The method of claim 5 , wherein the user information is selected from a group consisting of: username, email address, city, state, gender, age, relationship status.

7. The method of claim 1 , wherein the at least one required attribute is an association.

8. The method of claim 7 , wherein the association is selected from a group consisting of: membership in a group, subscribing to another user, being a friend of another user, listing a school/company/employer, likes.

9. The method of claim 1 , wherein the at least one required attribute is an action taken by the user.

10. The method of claim 1 , wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlating attribute.

11. The method of claim 1 , wherein the first system is a federated web service.

12. The method of claim 1 , wherein the certificate is an X.509 certificate.

13. The method of claim 1 , wherein the network access is wireless network access.

14. The method of claim 1 , wherein the at least one characteristic of the certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

15. The method of claim 1 , wherein the querying of the first system is focused based on the at least one required attribute.

16. The method of claim 1 , wherein including:

subsequently querying the first system for attributes associated with each user who was previously issued a Certificate,

evaluating the attributes associated with each user to the at least one required attributes; and

in response to at least one prior correlation between an attribute of the attributes associated with the user and the at least one required attribute failing, revoking the certificate.

17. The method of claim 1 , wherein providing the user with the certificate further includes providing the user with a token to obtain the certificate.

18. The method of claim 1 , wherein providing the user with the certificate further includes providing the user with instructions to receive the certificate.

19. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for certificate based network access in response to a third party request, the computer program comprising instructions which when executed by a computer system having at least one processor performs the steps of:

an input routine operative associated with an input device for receiving from a third party at least one predefined required attribute as criteria for receiving a certificate for certificate based network access;

a query routine for querying a remote first system with a plurality of users each having at least one attribute to determine at least a first subset of users having the at least one predefined required attribute, the querying performed by other than one of the plurality of users of the remote first system; and

an output routine for providing by other than the remote first system, as requested by the third party a certificate with at least one characteristic for certificate based network access on a second system having at least one processor to each user of the first subset of users having the at least one predefined required attribute, the second system distinct from the remote first system.

20. The non-transitory machine readable medium of claim 19 , wherein the at least one predefined required attribute is specified by the second system.

21. The non-transitory machine readable medium of claim 19 , wherein the third party is the second system.

22. The non-transitory machine readable medium of claim 19 , wherein the at least one predefined required attribute is user information.

23. The non-transitory machine readable medium of claim 19 , wherein the at least one predefined required attribute is an association.

24. The non-transitory machine readable medium of claim 19 , wherein the at least one predefined required attribute is a user action.

25. The non-transitory machine readable medium of claim 19 , wherein the remote first system is a federated web service.

26. The non-transitory machine readable medium of claim 19 , wherein the at least one characteristic of the certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

27. The non-transitory machine readable medium of claim 19 , wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlating attribute.

28. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for certificate based network access in response to a third party request, the computer program comprising instructions which when executed by a computer system having at least one processor performs the steps of:

identifying a remote first system having at least one processor and a plurality of users, each user having at least one attribute;

receiving from a third party at least one required attribute for certificate based network access;

querying the remote first system to determine at least a first subset of users having the at least one required attribute, the querying performed by other than one of the plurality of users of the remote first system; and

providing from a system other than the remote first system, as requested by the third party a certificate with at least one characteristic for certificate based network access on a second system having at least one processor to each user of the first subset of users having the at least one required attribute, the second system distinct from the remote first system.

29. The non-transitory machine readable medium of claim 28 , wherein the at least one required attribute is specified by the second system.

30. The non-transitory machine readable medium of claim 28 , wherein the third party is the second system.

31. The non-transitory machine readable medium of claim 28 , wherein the at least one required attribute is user information.

32. The non-transitory machine readable medium of claim 28 , wherein the at least one required attribute is an association.

33. The non-transitory machine readable medium of claim 28 , wherein the at least one required attribute is a user action.

34. The non-transitory machine readable medium of claim 28 , wherein the remote first system is a federated web service.

35. The non-transitory machine readable medium of claim 28 , wherein the at least one characteristic of the certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

36. The non-transitory machine readable medium of claim 28 , wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlating attribute.

37. A system for providing a certificate for certificate based network access in response to a third party request comprising:

a first system having at least one processor structured and arranged as a single sign on system having a plurality of user accounts corresponding to a plurality of users;

a third party structured and arranged to establish at least one predefined required attribute for receiving a certificate permitting network access on a second system having at least one processor, the second system distinct from the first system; and

an authorizing system having at least one processor and distinct from the first system, the authorizing system structured and arranged to receive from the third party the at least one predefined required attribute, and in response to a request from the third party to generate certificates for users of the first system having the at least one predefined required attribute, the authorizing system further structured and arranged to access the first system to query user accounts for attributes associated with at least one user of the first system, the authorizing system providing a certificate with at least one characteristic for certificate based network access on the second system to the at least one user of the first system having at least one attribute associated with the at least user correlated to the at least one predefined required attribute.

38. The system of claim 37 , wherein the third party is the second system.

39. The system of claim 37 , wherein the third party is distinct from the second system.

40. The system of claim 37 , wherein the at least one predefined required attribute is user information.

41. The system of claim 37 , wherein the at least one predefined required attribute is an association.

42. The system of claim 37 , wherein the at least one predefined attribute is a user action.

43. The system of claim 37 , wherein the first system is a federated web service.

44. The system of claim 37 , wherein the at least one characteristic of the certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

45. The system of claim 37 , wherein a first user having a first set of correlated attributes is provided with a certificate permitting different access than a second user having a second set of correlated attributes, the first and second sets being different with respect to at least one correlated attribute.

Assignments (14)
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 2, 2026
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075892/0107 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2016
From: CLOUDPATH NETWORKS, INC.
To: RUCKUS WIRELESS, INC.
Reel/Frame 037679/0278 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: KOSTER, KEVIN LEE; HANEY, ROGER LYNN
To: CLOUDPATH NETWORKS, INC.
Reel/Frame 028098/0467 →
Continuity (2)
Provisional Application 61614990 · Mar 23, 2012
Related Publication 20130254865A1 · Sep 26, 2013