IP Library Granted Patent US 11,251,974
Granted Patent B2
US 11,251,974 · App. 13/750,742 · Granted Feb 15, 2022

Provisioning multiple digital certificates

Inventors: Quentin Liu (San Jose, CA); Marc Williams (San Jose, CA); Richard F. Andrews (Menlo Park, CA)
Assignee: DigiCert, Inc.
H04L9/3263H04L9/0891H04L63/0823H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,251,974
App. No.
13/750,742
Granted
Feb 15, 2022
Kind
B2
Abstract

A method of provisioning a first digital certificate and a second digital certificate based on an existing digital certificate includes receiving information related to the existing digital certificate. The existing digital certificate includes a first name listed in a Subject field and a second name listed in a SubjectAltName extension. The method also includes receiving an indication from a user to split the existing digital certificate and extracting the first name from the Subject field and the second name from the SubjectAltName extension of the existing digital certificate. The method further includes extracting the public key from the existing digital certificate, provisioning the first digital certificate with the first name listed in a Subject field of the first digital certificate and the public key, and provisioning the second digital certificate with the second name listed in a Subject field of the second digital certificate and the public key.

Claims (65)

1. A method comprising:

receiving, over a network and from a client computing device associated with a user, a request to split a first digital certificate, wherein the user is approved to be associated with the first digital certificate, wherein the first digital certificate is used to verify an identity of the user by linking a public key, a first name, and a second name;

extracting, by at least one computer processor, the first name and the second name from the first digital certificate, wherein extracting the first and second names comprises extracting the first name from a Subject data field of the first digital certificate and the second name from a SubjectAltName extension of the first digital certificate;

in response to receiving the request to split the first digital certificate, and based at least in part on approval of the user to be associated with the first digital certificate, provisioning, by the at least one computer processor, a second digital certificate with the first name and a third digital certificate with the second name, wherein the first name is stored in a Subject data field of the second digital certificate, and wherein the second name is stored in a Subject data field of the third digital certificate;

issuing the second digital certificate and the third digital certificate to the user based at least in part on approval of the user to be associated with the first digital certificate; and

delivering authentication information using either the second digital certificate or the third digital certificate to verify the identity of the user.

2. The method of claim 1 , wherein the first digital certificate comprises a first public key, the method further comprising:

extracting the first public key from the first digital certificate,

wherein provisioning the second and third digital certificates comprises provisioning the second and third digital certificates with the first public key.

3. The method of claim 1 , wherein the first digital certificate comprises a first public key, the method further comprising:

receiving a first certificate signing request and a second certificate signing request, wherein:

the first certificate signing request comprises a second public key different from the first public key,

the second certificate signing request comprises a third public key different from the first public key,

provisioning the second digital certificate comprises provisioning the second digital certificate with the second public key, and

provisioning the third digital certificate comprises provisioning the third digital certificate with the third public key.

4. The method of claim 1 , wherein the first digital certificate further comprises a third name stored in the SubjectAltName extension, the method further comprising:

extracting the third name from the SubjectAltName extension of the first digital certificate; and

provisioning a fourth digital certificate with the third name, wherein the third name is stored in a Subject data field of the fourth digital certificate.

5. The method of claim 4 , wherein the first digital certificate comprises a first public key, the method further comprising:

extracting the first public key from the first digital certificate,

wherein provisioning the second, third, and fourth digital certificates comprises provisioning the second, third, and fourth digital certificates with the first public key.

6. The method of claim 4 , wherein the first digital certificate comprises a first public key, the method further comprising:

receiving a first certificate signing request, a second certificate signing request, and a third certificate signing request, wherein:

the first certificate signing request comprises a second public key different from the first public key,

the second certificate signing request comprises a third public key different from the first public key,

the third certificate signing request comprises a fourth public key different from the first public key,

provisioning the second digital certificate comprises provisioning the second digital certificate with the second public key,

provisioning the third digital certificate comprises provisioning the third digital certificate with the third public key, and

provisioning the fourth digital certificate comprises provisioning the fourth digital certificate with the fourth public key.

7. The method of claim 1 , wherein provisioning the second digital certificate with the first name and the third digital certificate with the second name comprises digitally signing the second and third digital certificates with a private key of a certificate authority.

8. A system comprising:

a network interface configured to receive, over a network and from a client computing device associated with a user, a request to split a first digital certificate, wherein the user is approved to be associated with the first digital certificate, wherein the first digital certificate is used to verify an identity of the user by linking a public key, a first name, and a second name;

one or more memories that store instructions and the first digital certificate; and

at least one computer processor, operatively coupled to the one or more memories and the network interface, configured to execute the instructions to:

extract the first name and the second name from the first digital certificate, wherein, to extract the first and second names, the at least one computer processor is configured to extract the first name from a Subject data field of the first digital certificate and the second name from a SubjectAltName extension of the first digital certificate;

based at least in part on approval of the user to be associated with the first digital certificate, provision a second digital certificate with the first name and a third digital certificate with the second name, wherein the first name is stored in a Subject data field of the second digital certificate, and wherein the second name is stored in a Subject data field of the third digital certificate;

issue the second digital certificate and the third digital certificate to the user based at least in part on approval of the user to be associated with the first digital certificate; and

deliver authentication information using either the second digital certificate or the third digital certificate to verify the identity of the user.

9. The system of claim 8 , wherein the first digital certificate comprises a first public key, and wherein the at least one computer processor is further configured to extract the first public key from the first digital certificate and to provision the second and third digital certificates with the first public key.

10. The system of claim 8 , wherein the first digital certificate comprises a first public key, and wherein the at least one computer processor is further configured to:

receive a first certificate signing request and a second certificate signing request, wherein:

the first certificate signing request comprises a second public key different from the first public key;

the second certificate signing request comprises a third public key, different from the first public key; and

the at least one computer processor is further configured to provision the second digital certificate with the second public key and the third digital certificate with the third public key.

11. The system of claim 8 , wherein the first digital certificate further comprises a third name stored in the SubjectAltName extension, wherein the at least one computer processor is further configured to extract the third name from the SubjectAltName extension of the first digital certificate and to provision a fourth digital certificate with the third name, wherein the third name is stored in a Subject data field of the fourth digital certificate.

12. The system of claim 11 , wherein the first digital certificate comprises a first public key, wherein the at least one computer processor is further configured to extract the first public key from the first digital certificate and to provision the second, third, and fourth digital certificates with the first public key.

13. The system of claim 11 , wherein the first digital certificate comprises a first public key, and wherein the at least one computer processor is further configured to:

receive a first certificate signing request, a second certificate signing request, and a third certificate signing request, wherein:

the first certificate signing request comprises a second public key different from the first public key;

the second certificate signing request comprises a third public key different from the first public key;

the third certificate signing request comprises a fourth public key different from the first public key; and

the at least one computer processor is further configured to provision the second digital certificate with the second public key, the third digital certificate with the third public key, and the fourth digital certificate with the fourth public key.

14. The system of claim 8 , wherein the at least one computer processor is further configured to digitally sign the second and third digital certificates with a private key of a certificate authority.

15. A method for a certificate authority to facilitate efficient splitting of a first digital certificate into at least second and third digital certificates, the method comprising:

receiving, with at least one computer processor, from a client computing device associated with a user, a request to split the first digital certificate, the first digital certificate including a first name in a Subject data field and a second name in a SubjectAltName extension, wherein the user is approved to possess the first digital certificate, wherein the first digital certificate is used to verify an identity of the user by linking a public key, a first name, and a second name;

extracting, with the at least one computer processor, the first name from a Subject field of the first digital certificate and the second name from a SubjectAltName extension of the first digital certificate;

in response to the request to split the first digital certificate and based at least in part on approval of the user to possess the first digital certificate, provisioning, by the at least one computer processor, a second digital certificate with the first name and a third digital certificate with the second name, wherein the first name is stored in a Subject data field of the second digital certificate and wherein the second name is stored in a Subject data field of the third digital certificate;

issuing the second digital certificate and the third digital certificate to the user based at least in part on approval of the user to possess the first digital certificate; and

delivering authentication information using either the second digital certificate or the third digital certificate to verify the identity of the user.

16. The method of claim 15 , further comprising:

determining, with the at least one computer processor, a validity end date of the first digital certificate, wherein provisioning the second and third digital certificates comprises provisioning the second and third digital certificates with the same validity end date as the first digital certificate.

17. The method of claim 15 , wherein provisioning the second and third digital certificates comprises provisioning the second and third digital certificates with different validity end dates.

18. The method of claim 15 , wherein provisioning comprises digitally signing the second and third digital certificates with a private key of a certificate authority.

19. The method of claim 15 , wherein the first digital certificate comprises a first public key, the method further comprising:

extracting the first public key from the first digital certificate, wherein provisioning the second and third digital certificates comprises provisioning the second and third digital certificates with the first public key.

Assignments (10)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
Continuity (2)
Continuation 12639771 · Dec 16, 2009
Related Publication 20130145155A1 · Jun 6, 2013
Cited By (1)
US 12,701,117