IP Library Granted Patent US 11,032,265
Granted Patent B2
US 11,032,265 · App. 14/087,842 · Granted Jun 8, 2021

System and method for automated customer verification

Inventors: Michael Klieman (Belmont, CA); Jessica Crewse (Sunnyvale, CA); Gautam Kanaparthi (Mountain View, CA)
Assignee: DigiCert, Inc.
H04L63/0823G06F21/33G06Q30/0258G06F2221/2117
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,032,265
App. No.
14/087,842
Granted
Jun 8, 2021
Kind
B2
Abstract

Techniques are disclosed for identifying and authenticating prospective certificate authority customers of a secure socket layer (SSL) certificate prior to receiving an order from the customer. The CA generates a list of prospective customers of digital certificates (e.g., by scanning networked servers via the Internet for the presence of an installed digital certificate). The CA retrieves data for each customer on the list and determines, based on a set of approval criteria, which prospective customers to target in enrollment campaigns. For each approved customer, the CA initiates an enrollment process prior to receiving a request from the customer to provide a certificate.

Claims (49)

1. A computer-implemented method for identifying and authenticating a domain name associated with a computer server prior to receiving a request for a digital certificate, the method comprising:

scanning, by a processor associated with a first certificate authority, a communication port of a plurality of computer servers, each of the plurality of computer servers hosting a respective website;

identifying, by the processor, a group of computer servers of the plurality of computer servers that include a first digital certificate generated by a second certificate authority and installed thereon based on said scanning the communication port of the plurality of computer servers, wherein the second certificate authority is different from the first certificate authority; and

for at least one computer server of the group of computer servers:

performing, by the processor, a security handshake,

receiving, by the processor, the first digital certificate based on said performing the security handshake,

parsing, by the processor, the first digital certificate;

identifying, by the processor, a domain name and organization information of an organization associated with the website hosted by the at least one computer server based on said parsing the first digital certificate,

verifying, by the processor, in one or more databases, the domain name and the organization information of the organization,

prior to receiving a request for a second digital certificate that associates the organization with the domain name, performing a first partial authentication, by the processor, of the organization for the second digital certificate based on said verifying the domain name and the organization information, wherein authentication of the organization is based on the first partial authentication and a second partial authentication, wherein the first partial authentication comprises performing one or more initial steps of the authentication of the organization,

receiving, by the processor, the request for the second digital certificate from the organization,

based on receiving the request for the second digital certificate and performing the first partial authentication, performing, by the processor, the second partial authentication of the organization for the second digital certificate, wherein the second partial authentication comprises performing one or more subsequent steps of the authentication of the organization, and

generating, by the processor, the second digital certificate based on the first partial authentication and the second partial authentication.

2. The method of claim 1 , further comprising, prior to receiving the request for the second digital certificate from the organization, sending a message to the organization, wherein the message indicates an availability of a partially approved second digital certificate.

3. The method of claim 1 , wherein the second partial authentication is based on information obtained from the organization after said receiving the request for the second digital certificate from the organization.

4. A non-transitory computer-readable storage medium storing computer-executable instructions for identifying and authenticating a domain name associated with a computer server prior to receiving, at a first certificate authority, a request for a digital certificate that, when executed by a processor, cause the processor to:

scan a communication port of a plurality of computer servers, each of the computer servers hosting a respective website;

identify a group of computer servers of the plurality of computer servers that include a first digital certificate generated by a second certificate authority and installed thereon based on the scan of the communication port of the plurality of computer servers; and

for at least one computer server of the group of computer servers:

perform a security handshake,

receive the first digital certificate based on said performing the security handshake,

parse the first digital certificate,

identify a domain name and organization information of an organization associated with the website hosted by the at least one computer server based on parsing of the first digital certificate,

verify, in one or more databases, the domain name and the organization information of the organization, and

prior to receiving a request for a second digital certificate from the organization, perform a first partial authentication of the organization for the second digital certificate based on verification of the domain name and the organization information, wherein the second digital certificate associates the organization with the domain name, wherein authentication of the organization is based on the first partial authentication and a second partial authentication, wherein the first partial authentication comprises performing one or more initial steps of the authentication of the organization.

5. The computer-readable storage medium of claim 4 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to send a message to the organization, wherein the message indicates an availability of a partially approved second digital certificate.

6. The non-transitory computer-readable storage medium of claim 4 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to, receive the request for the second digital certificate from the organization.

7. The non-transitory computer-readable storage medium of claim 6 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to, generate the second digital certificate based on the first partial authentication of the organization for the second digital certificate and the request for the second digital certificate.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to, after reception of the request for the second digital certificate, perform the second partial authentication of the organization for the second digital certificate.

9. The non-transitory computer-readable storage medium of claim 7 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to, based on receiving the request for the second digital certificate and performing the first partial authentication, perform the second partial authentication of the organization for the second digital certificate, wherein the second partial authentication comprises performing one or more subsequent steps of the authentication of the organization.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the second partial authentication is based on information obtained from the organization after reception of the request for the second digital certificate from the organization.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to generate the second digital certificate based on the first partial authentication and the second partial authentication.

12. A system, comprising:

a processor associated with a first certificate authority; and

non-transitory, computer readable media storing computer-executable instructions for identifying and authenticating potential customers of digital certificates prior to receiving, at the first certificate authority, a request for a digital certificate from the potential customers, wherein the computer-executable instructions when executed by the processor, cause the processor to:

scan a communication port of a plurality of computer servers, each of the computer servers hosting a respective website,

identify at least one computer server of the plurality of computer servers that includes a first digital certificate generated by a second certificate authority and installed thereon based on said scanning the communication port of the plurality of computer servers, and

for the at least one computer server:

perform a security handshake,

receive the first digital certificate based on the security handshake,

parse the first digital certificate,

identify a domain name and organization information of an organization associated with the website hosted by the at least one computer server based on parsing the first digital certificate,

verify, in one or more databases, the domain name and the organization information of the organization,

prior to receiving a request for a second digital certificate that associates the organization with the domain name, perform a first partial authentication of the organization for the second digital certificate based on verification of the domain name and the organization information, wherein authentication of the organization is based on the first partial authentication and a second partial authentication, wherein the first partial authentication comprises performing one or more initial steps of the authentication of the organization,

receive the request for the second digital certificate from the organization,

based on receiving the request for the second digital certificate and performing the first partial authentication, perform the second partial authentication of the organization for the second digital certificate, wherein the second partial authentication comprises performing one or more subsequent steps of the authentication of the organization, and

generate the second digital certificate based on the first partial authentication and the second partial authentication.

13. The system of claim 12 , wherein the computer-executable instructions, when executed by the processor, further cause the processor to send a message to the organization, wherein the message indicates an availability of a partially approved second digital certificate.

14. The system of claim 12 , wherein the second partial authentication is based on information obtained from the organization after reception of the request for the second digital certificate from the organization.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2013
From: KLIEMAN, MICHAEL; CREWSE, JESSICA; KANAPARTHI, GAUTAM
To: SYMANTEC CORPORATION
Reel/Frame 031661/0379 →
Continuity (1)
Related Publication 20150149768A1 · May 28, 2015
Cited By (1)
US 12,701,016