IP Library Granted Patent US 9,137,234
Granted Patent B2
US 9,137,234 · App. 13/454,691 · Granted Sep 15, 2015

System and method for providing a certificate based on granted permissions

Inventors: Kevin Lee Koster (Westminster, CO); Roger Lynn Haney (Denver, CO)
Assignee: Cloudpath Networks, Inc.
H04L63/0823G06F21/00G06F21/51H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,137,234
App. No.
13/454,691
Filed
Apr 24, 2012
Granted
Sep 15, 2015
Kind
B2
Art Unit
2493
USPC
726/10
Abstract

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system based on at least one criteria and an established identity with a first system. The method includes receiving criteria, such as at least one predefined attribute. Also received from a user known to a first system is a request for network access to a second system, the request having at least one identifier. The first system is then queried with the identifier for attributes associated with the user. The attributes associated with the user are evaluated to the predefined attribute(s). In response to at least one attribute associated with the user correlating to the predefined attribute(s), providing a certificate with at least one characteristic for network access on the second system to the user. An associated system for providing a Certificate is also provided.

Claims (48)

1. A method of providing a certificate for certificate based network access comprising:

receiving from a third party at least one predefined permission to act on behalf of a user within a first system having at least one processor as criteria for receiving a certificate for certificate based network access upon a second system;

querying the first system having a plurality of users to determine permissions, which enable the second system to act on behalf of a user within the first system, granted to a second system by at least a first subset of users of the plurality of users; and

in response to at least one permission granted by a user in the first subset correlating to the at least one predefined permission, providing the user with a certificate with at least one characteristic for certificate based network access on the second system, the certificate provided from a system other than the first system and the second system distinct from the first system;

wherein the permission is selected from the group consisting of: permission to read the user's data upon the first system, permission to communicate with users within the first system on behalf of the user, permission to manipulate the user's data upon the first system, permission to perform action on behalf of the user within the first system.

2. The method of claim 1 , wherein determining the granted permission includes attempting to use a desired permission.

3. The method of claim 1 , wherein determining the granted permission includes reviewing permissions granted to the second system.

4. The method of claim 1 , further including receiving from a user known to the first system a request for network access to the second system, the request having at least one identifier, the request triggering the querying of the first system with the at least one identifier to determine permissions granted to the second system by the requesting user.

5. The method of claim 1 , further including an authorizing system receiving the at least one predefined permission from the second system, the authorizing system querying the first system to determine permission granted to a second system by at least a subset of users.

6. The method of claim 1 , wherein the predefined permission is specified by the second system.

7. The method of claim 1 , wherein the predefined permission is specified by a third party.

8. A method of providing a certificate for certificate based network access comprising:

receiving from a third party at least one predefined permission to act on behalf of a user within a first system having at least one processor as criteria for receiving a certificate for certificate based network access upon a second system;

receiving from a user known to a first system a request for network access to a second system, the request having at least one identifier;

querying the first system with the at least one identifier to determine granted permissions associated with the user which enables the second system to act on behalf of the user within the first system;

evaluating the determined granted permissions to the at least one predefined permission; and

in response to at least one permission granted by the user correlating to the at least one predefined permission, providing the user with a certificate with at least one characteristic for certificate based network access on the second system;

wherein the permission is selected from the group consisting of: permission to read the user's data upon the first system, permission to communicate with users within the first system on behalf of the user, permission to manipulate the user's data upon the first system, permission to perform action on behalf of the user within the first system.

9. The method of claim 8 , wherein evaluating the granted permission includes attempting to use a desired permission.

10. The method of claim 8 , wherein evaluating the granted permission includes reviewing the permissions granted to the second system.

11. The method of claim 8 , wherein the predefined permission is received from the second system.

12. The method of claim 8 , wherein the predefined permission is received from a third party.

13. A method of providing a certificate for certificate based network access comprising:

identifying a first system having at least one processor and a plurality users, at least one user having at least one user adjustable permission permitting the user to specify a party who may act on behalf of the user within the first system;

receiving from a third party at least one predefined permission to act on behalf of a user within the first system as criteria for receiving a certificate for certificate based network access upon a second system;

querying the first system to determine at least a first subset of users having the at least one predefined permission which enables the second system to act on behalf of the user within the first system, and

providing a certificate with at least one characteristic for certificate based network access on a second system to each user having the at least one predefined permission the second system distinct from the first system;

wherein the permission is selected from the group consisting of: permission to read the user's data upon the first system, permission to communicate with users within the first system on behalf of the user, permission to manipulate the user's data upon the first system, permission to perform action on behalf of the user within the first system.

14. The method of claim 13 , wherein evaluating the granted permission includes attempting to use a desired permission.

15. The method of claim 13 , wherein evaluating the granted permission includes reviewing the permissions granted to the second system.

16. The method of claim 13 , wherein the predefined permission is specified by the second system.

17. The method of claim 13 , wherein the predefined permission is specified by a third party.

18. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for certificate based network system having at least one processor performs the steps of:

receiving from a third party at least one predefined permission to act on behalf of a user within a first system having at least one processor as criteria for receiving a certificate for certificate based network access upon a second system;

querying the first system having a plurality of users to determine permissions, which enable the second system to act on behalf of a user within the first system, granted to a second system by at least a first subset of users of the plurality of users; and

in response to at least one permission granted by a user in the first subset correlating to the at least one predefined permission, providing the user with a certificate with at least one characteristic for certificate based network access on the second system, the certificate provided from a system other than the first system and the second system distinct from the first system;

wherein the permission is selected from the group consisting of: permission to read the user's data upon the first system, permission to communicate with users within the first system on behalf of the user, permission to manipulate the user's data upon the first system, permission to perform action on behalf of the user within the first system.

19. The non-transitory machine readable medium of claim 18 , wherein determining the granted permission includes attempting to use a desired permission.

20. The non-transitory machine readable medium of claim 18 , wherein determining the granted permission includes reviewing permissions granted to the second system.

21. The non-transitory machine readable medium of claim 18 , wherein the predefined permission is received from the second system.

22. The non-transitory machine readable medium of claim 18 , wherein the predefined permission is received from a third party.

23. A system for providing a certificate for certificate based network access comprising:

a first system having at least one processor structured and arranged as a single sign on system having a plurality of user accounts corresponding to a plurality of users;

a third party structured and arranged to establish at least one predefined required permission for receiving a certificate permitting network access on a second system; and

an authorizing system structured and arranged to receive from the third party the at least one predefined required permission to act on behalf of a user within the first system, and in response to a request from the third party to generate certificates for users of the first system having the at least one predefined required permission, the authorizing system further structured and arranged to access the first system to query user accounts for permissions, which enable a second system to act on behalf of a user within the first system, associated with at least one user, the authorizing system providing a certificate with at least one characteristic for certificate based network access on the second system to at least one user having at least one permission associated with the user correlated to the at least one predefined required permission;

wherein the permission is selected from the group consisting of: permission to read the user's data upon the first system, permission to communicate with users within the first system on behalf of the user, permission to manipulate the user's data upon the first system, permission to perform action on behalf of the user within the first system.

24. The system of claim 23 , wherein the third party is the second system.

25. The system of claim 23 , wherein the third party is distinct from the second system.

Assignments (14)
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 2, 2026
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075892/0107 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2016
From: CLOUDPATH NETWORKS, INC.
To: RUCKUS WIRELESS, INC.
Reel/Frame 037679/0278 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: KOSTER, KEVIN LEE; HANEY, ROGER LYNN
To: CLOUDPATH NETWORKS, INC.
Reel/Frame 028098/0823 →
Continuity (2)
Provisional Application 61614990 · Mar 23, 2012
Related Publication 20130254866A1 · Sep 26, 2013