IP Library Granted Patent US 9,961,073
Granted Patent B2
US 9,961,073 · App. 14/042,294 · Granted May 1, 2018

Dynamic certificate generation on a certificate authority cloud

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,961,073
App. No.
14/042,294
Granted
May 1, 2018
Kind
B2
Abstract

Techniques are disclosed for dynamically generating a digital certificate for a customer server. A customer server creates a certificate profile and receives an associated profile identifier from a certificate authority (CA). The customer server installs an agent application received from the CA. The agent application generates a public/private key pair and an identifier associated with the customer server. The agent application sends a signed request to the CA that includes the profile identifier, server identifier, and the public key corresponding to the key pair. Upon receiving the credentials, the CA generates a dynamically updatable certificate. Thereafter, if the customer changes information associated with the certificate (or if external conditions require a change to the certificate, such as a key compromise or change in security standards), the CA may generate an updated certificate based on the certificate profile changes and the public key.

Claims (39)

1. A method for updating a digital certificate, the method comprising:

monitoring a certificate profile and a first key pair, each used to generate a first certificate, to detect a change in the certificate profile, the certificate profile including a plurality of digital certificate attributes for generating a digital certificate by a certificate authority (CA);

detecting a change in the certificate profile, wherein the change is to at least a first attribute in the plurality of digital certificate attributes, wherein the change in the certificate profile is made by a user;

in response to the detected change in the certificate profile:

generating a second key pair, and

sending a request to the CA to generate a second certificate based on the changed certificate profile, wherein the request includes a second public key associated with the second key pair, a server identifier, and a profile identifier associated with the changed certificate profile, and wherein attributes of the second certificate reflect the detected change to the at least the first attribute;

receiving the second certificate from the CA; and

deploying the second certificate on a server in place of the first certificate.

2. The method of claim 1 , wherein the change in the certificate profile modifies one or more subject alternative names (SANs) named in the first certificate.

3. The method of claim 1 , further comprising:

upon determining the second certificate has expired, sending the first public key, the server identifier, and the profile identifier to the CA; and

receiving a third certificate that includes the first public key from the CA; and

deploying the third certificate on the server in place of the second certificate.

4. A non-transitory computer-readable storage medium storing instructions, which, when executed on a processor, performs an operation for updating a digital certificate, the operation comprising:

monitoring a certificate profile and a first key pair, each used to generate a first certificate, to detect a change in the certificate profile, the certificate profile including a plurality of digital certificate attributes for generating a digital certificate by a certificate authority (CA);

detecting a change in the certificate profile, wherein the change is to at least a first attribute in the plurality of digital certificate attributes, wherein the change in the certificate profile is made by a user;

in response to the detected change in the certificate profile:

generating a second key pair, and

sending a request to the CA to generate a second certificate based on the changed certificate profile, wherein the request includes a second public key associated with the second key pair, a server identifier, and a profile identifier associated with the changed certificate profile, and wherein attributes of the second certificate reflect the detected change to the at least the first attribute;

receiving the second certificate from the CA; and

deploying the second certificate on a server in place of the first certificate.

5. The computer-readable storage medium of claim 4 , wherein the change in the certificate profile modifies one or more subject alternative names (SANs) named in the first certificate.

6. The computer-readable storage medium of claim 4 , wherein the operation further comprises:

upon determining the second certificate has expired, sending the first public key, the server identifier, and the profile identifier to the CA; and

receiving a third certificate signing the first public key from the CA; and

deploying the third certificate on the server in place of the second certificate.

7. A system, comprising:

a processor; and

a memory hosting an application, which, when executed on the processor, performs an operation for updating a digital certificate, the operation comprising:

monitoring a certificate profile and a first key pair, each used to generate a first certificate, to detect a change in the certificate profile, the certificate profile including a plurality of digital certificate attributes for generating a digital certificate by a certificate authority (CA);

detecting a change in the certificate profile, wherein the change is to at least a first attribute in the plurality of digital certificate attributes, wherein the change in the certificate profile is made by a user;

in response to the detected change in the certificate profile:

generating a second key pair, and

sending a request to the CA to generate a second certificate based on the changed certificate profile, wherein the request includes a second public key associated with the second key pair, a server identifier, and a profile identifier associated with the changed certificate profile, and wherein attributes of the second certificate reflect the detected change to the at least the first attribute,

receiving the second certificate from the CA; and deploying the second certificate on a server in place of the first certificate.

8. The system of claim 7 , wherein the operation further comprises:

upon determining the second certificate has expired, sending the first public key, the server identifier, and the profile identifier to the CA; and

receiving a third certificate that includes the first public key from the CA; and

deploying the third certificate on the server in place of the second certificate.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2013
From: BHALERAO, KOKIL
To: SYMANTEC CORPORATION
Reel/Frame 031312/0477 →