IP Library Granted Patent US 9,208,350
Granted Patent B2
US 9,208,350 · App. 13/737,451 · Granted Dec 8, 2015

Certificate information verification system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,208,350
App. No.
13/737,451
Granted
Dec 8, 2015
Kind
B2
Abstract

The invention discloses a system and apparatus for detecting problematic certificate action requests and digital certificates. Ideally, the invention will be used to detect a certificate request that will result in security problems and detect issued certificates that lack essential information. The invention uses a proxy system that intercepts certificate requests and transmitted certificates. The proxy system runs a series of checks on the intercepted request and/or certificate. The checks vary depending on the certificate contents, requester, and system providing the request or certificate.

Claims (31)

1. A method for checking a certificate request to verify a certificate's contents comprising:

receiving a request for a certificate action transmitted to a certificate services system;

choosing a verification package to determine if there are problems with the certificate's contents;

actively performing at least one check on the certificate to determine whether the certificate is problematic, including verifying whether the certificate contents comply with requirements in the verification package;

in response to the results of actively performing at least one check on the certificate, taking an action, including acting as a firewall to ensure the request or certificate is operated in accordance with the verification package, denying the request because of problematic certificate information, and/or notifying stakeholders responsible for evaluating certificate problems;

creating a notification of the result of the content check that is separate from the requested certificate action; and

storing the results of the verification in an auditing system that stores the results and provides notification of the verification status to a third-party requester.

2. The method of claim 1 , wherein the certificate action requested, before actively performing at least one check and taking an action, is to generate a new certificate.

3. The method of claim 1 , wherein choosing the verification package is based on information provided by a requester in the certificate request, and the at least one check is selected from the verification package.

4. The method of claim 1 , further comprising passing the verification package to a verification controller to perform the at least one check on the request.

5. The method of claim 1 , wherein the action to be taken in response to the verification results of the at least one check is determined based on one or more authorization decision points.

6. The method of claim 5 , wherein if the verification is successful, the one or more authorization decision points permit the request to proceed to the certificate services system where the request is fulfilled.

7. The method of claim 5 , wherein if the verification fails, the one or more authorization decision points determine the appropriate action to take based on the risk associated with the failed check.

8. The method of claim 1 , further comprising notifying a system administrator of a failed certificate verification.

9. The method of claim 1 , further comprising providing notification of actions taken during the checking on the certificate's contents.

10. The method of claim 1 , wherein performing at least one check comprises checking a certificate key size for the requested certificate.

11. A system for checking a certificate request to verify a certificate's contents comprising:

a proxy system configured to receive a request for a certificate action transmitted to a certificate services system and further configured to choose a verification package to determine if there are problems with a certificate's contents;

a workflow engine configured to actively perform at least one check on the certificate to determine whether the certificate is problematic, including verifying whether the certificate contents comply with requirements in the verification package;

a server configured to, in response to the results of the at least one check performed by the workflow engine, take an action, including acting as a firewall to ensure the request or certificate is operated in accordance with the verification package, denying the request because of problematic certificate information, and/or notifying stakeholders responsible for evaluating certificate problems;

a computer notification system configured to create a notification of the result of the content check that is separate from the requested certificate action; and

a computer storage system configured to store the results of the verification and provide notification of the verification status to a third-party requester.

12. The system of claim 11 , wherein the certificate action requested, before initiating the workflow engine and server, is to generate a new certificate.

13. The system of claim 11 , wherein the verification package is chosen based on information provided by the requester in the certificate request, and the at least one check is selected from the verification package.

14. The system of claim 11 , wherein the workflow engine is further configured to pass the verification package to a verification controller in the proxy system to perform the at least one check on the request.

15. The system of claim 11 , wherein one or more authorization decision points located on the proxy system determine the action to be taken in response to the verification results of the at least one check.

16. The system of claim 11 , wherein if the verification is successful, the one or more authorization decision points permit the request to proceed to the certificate services system where the request is fulfilled.

17. The system of claim 11 , wherein if the verification fails, the one or more authorization decision points determine the appropriate action to take based on the risk associated with the failed check.

18. The system of claim 11 , further configured to notify a system administrator of a failed certificate verification.

19. The system of claim 11 , further comprising an auditing system configured to provide notification of actions taken during the checking on the certificate's contents.

20. The system of claim 11 , where performing at least one check comprises checking a certificate key size for the requested certificate.

Assignments (19)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 036912/0839 Recorded Nov 1, 2017
From: OAKTREE FUND ADMINISTRATION, LLC (AS SUCCESSOR TO FIFTH STREET MANAGEMENT LLC)
To: DIGICERT, INC.
Reel/Frame 044348/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2017
From: JEFFERIES FINANCE LLC
To: DIGICERT, INC.
Reel/Frame 043990/0809 →
ASSIGNMENT OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 20, 2017
From: FIFTH STREET MANAGEMENT LLC
To: OAKTREE FUND ADMINISTRATION, LLC
Reel/Frame 044242/0788 →
RELEASE OF SECURITY INTEREST Recorded Oct 21, 2015
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: DIGICERT, INC.
Reel/Frame 036848/0402 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Oct 21, 2015
From: FIFTH STREET FINANCE CORP.
To: DIGICERT, INC.
Reel/Frame 036912/0633 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 21, 2015
From: DIGICERT, INC.
To: FIFTH STREET MANAGEMENT LLC
Reel/Frame 036912/0839 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 21, 2015
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 036908/0381 →
SECURITY INTEREST Recorded Jun 2, 2014
From: DIGICERT, INC.
To: SILICON VALLEY BANK
Reel/Frame 033009/0488 →
SECURITY INTEREST Recorded Jun 2, 2014
From: DIGICERT, INC.
To: FIFTH STREET FINANCE CORP.
Reel/Frame 033072/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2014
From: SABIN, JASON ALLEN; ROWLEY, RICHARD JEREMY
To: DIGICERT, INC.
Reel/Frame 032924/0441 →