IP Library Granted Patent US 9,900,157
Granted Patent B2
US 9,900,157 · App. 13/965,184 · Granted Feb 20, 2018

Object signing within a cloud-based architecture

Inventor: Jason Allen Sabin (Lehi, UT)
Assignee: DigiCert, Inc.
H04L9/3247H04L9/0894G06F9/45558
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,900,157
App. No.
13/965,184
Granted
Feb 20, 2018
Kind
B2
Abstract

A system and method for digitally signing an object. An object signing agent sends a signing request for an object to remote signing server, which, in response to receiving the request, generates a virtual machine executing code for signing the object. The object is signed within the virtual machine and returned to the object signing agent.

Claims (37)

1. A system for cloud-based object signing, the system comprising:

an object signing agent that receives an object to be signed;

a remote signing system that communicates with the object signing agent and validates an identity associated with the object provided by the object signing agent using one or more policies to verify the integrity and sign-ability of the object, the remote signing system configured to, in response to determining that the object is not in compliance for signing, one or more of present an alert to a user requesting the object to be signed, and lock the user out of the remote signing system; and

an isolated virtual machine dynamically created by the remote signing system in response to receiving a request for object signing, the isolated virtual machine signing the object using a digital certificate within a new encrypted store space generated using an encryption store key, the isolated virtual machine being one or more of deleted and archived in response to signing the object,

wherein at least a portion of the object signing agent, the remote signing system, and the isolated virtual machine comprises one or more of logic hardware and executable code, the executable code stored on one or more non-transitory computer readable storage media.

2. A system according to claim 1 , wherein the remote signing system further creates a signing key in response to receiving a request for signing.

3. A system according to claim 1 , wherein the remote signing system further creates a tenancy specific to the entity requesting the object signing and wherein the isolated virtual machine is created in the created tenancy.

4. A system according to claim 1 , wherein the remote signing system further comprises a compliance engine that runs one or more compliance checks against the object to verify the integrity and sign-ability of the object.

5. A system according to claim 1 , further comprising an identity service that verifies the identity of one or more of an organization and a signer associated with the object based on one or more provided credentials.

6. A system according to claim 1 , further comprising an object signing manager that executes within the isolated virtual machine and signs the object in response to verification of the validity of the object.

7. A method for cloud-based object signing, the method comprising:

receiving a request for object signing from an object signing agent;

receiving, from the object signing agent at a remote signing system, an object that is designated to be signed;

validating, at the remote signing system, an identity associated with the object using one or more policies to verify the integrity and sign-ability of the object;

in response to determining that the object is not in compliance for signing, one or more of:

presenting an alert to a user requesting the object to be signed; and

locking the user out of the remote signing system;

in response to determining that the object is in compliance for signing:

creating, dynamically, by the remote signing system, an isolated virtual space in response to receiving the request to sign the object, the isolated virtual space comprising an object signing manager that signs the object using a digital certificate within a new encrypted store space generated using an encryption store key, the isolated virtual space being one or more of deleted and archived in response to signing the object; and

sending the signed object to the object signing agent.

8. A method according to claim 7 , further comprising authenticating the request for signing the object.

9. A method according to claim 7 , further comprising authenticating one or more credentials for signing the object, the one or more credentials associated with one or more of an organization and a signer associated with the object.

10. A method according to claim 7 , wherein the determination that the object is not in compliance for signing is performed by a compliance engine, the compliance engine running one or more compliance checks against the object to verify the integrity and sign-ability of the object.

11. A method according to claim 10 , wherein the determination that the object is not in compliance for signing is based on information in the one or more policies, the one or more policies provided by a policy engine.

12. A method according to claim 7 , further comprising generating a signing key in response to the request for signing the object.

13. A method according to claim 12 , wherein the signing key is stored in a tenancy specific to the entity requesting the object signing.

14. A method according to claim 7 , wherein the virtual space is encrypted.

15. A method according to claim 14 , wherein the signing key is created in the virtual space.

16. A method according to claim 7 , wherein a key used to sign the object is destroyed in response to one or more of deleting and archiving the isolated virtual space.

17. A method according to claim 7 , wherein a key used to sign the object is transferred to a separate location before one or more of deleting and archiving the isolated virtual space.

18. A method according to claim 10 , wherein the one or more compliance checks comprise one or more of:

running one or more security scans against the object;

running one or more vulnerability scans against the object;

running one or more Payment Card Industry/Sarbanes-Oxley (PCI/SOX) scans against the object;

verifying that the object is in a correct format; and

verifying that the object is free of malware.

19. A method according to claim 10 , further comprising evaluating one or more risks associated with the object based on the one or more compliance checks.

Assignments (19)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 036912/0839 Recorded Nov 1, 2017
From: OAKTREE FUND ADMINISTRATION, LLC (AS SUCCESSOR TO FIFTH STREET MANAGEMENT LLC)
To: DIGICERT, INC.
Reel/Frame 044348/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2017
From: JEFFERIES FINANCE LLC
To: DIGICERT, INC.
Reel/Frame 043990/0809 →
ASSIGNMENT OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 20, 2017
From: FIFTH STREET MANAGEMENT LLC
To: OAKTREE FUND ADMINISTRATION, LLC
Reel/Frame 044242/0788 →
RELEASE OF SECURITY INTEREST Recorded Oct 21, 2015
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: DIGICERT, INC.
Reel/Frame 036848/0402 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Oct 21, 2015
From: FIFTH STREET FINANCE CORP.
To: DIGICERT, INC.
Reel/Frame 036912/0633 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 21, 2015
From: DIGICERT, INC.
To: FIFTH STREET MANAGEMENT LLC
Reel/Frame 036912/0839 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 21, 2015
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 036908/0381 →
SECURITY INTEREST Recorded Jun 2, 2014
From: DIGICERT, INC.
To: SILICON VALLEY BANK
Reel/Frame 033009/0488 →
SECURITY INTEREST Recorded Jun 2, 2014
From: DIGICERT, INC.
To: FIFTH STREET FINANCE CORP.
Reel/Frame 033072/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2014
From: SABIN, JASON ALLEN
To: DIGICERT, INC.
Reel/Frame 032924/0211 →
Continuity (2)
Provisional Application 61683839 · Aug 16, 2012
Related Publication 20140052994A1 · Feb 20, 2014