IP Library Granted Patent US 9,276,887
Granted Patent B2
US 9,276,887 · App. 14/268,111 · Granted Mar 1, 2016

Systems and methods for managing security certificates through email

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,276,887
App. No.
14/268,111
Granted
Mar 1, 2016
Kind
B2
Abstract

The disclosed computer-implemented method for managing security certificates through email may include (1) receiving an encrypted email that contains both identifying information that identifies a security certificate for authenticating a website and a management command relating to the security certificate, (2) determining whether authentication of the encrypted email succeeded such that the management command is authorized, and (3) when a determination is made that authentication of the encrypted email succeeded, identifying the security certificate using the identifying information and executing the management command with respect to the identified security certificate. Various other methods, systems, and computer-readable media are also disclosed.

Claims (48)

1. A computer-implemented method for managing security certificates through email, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving an encrypted email that contains both identifying information that identifies a security certificate for authenticating a website and a management command relating to the security certificate, the encrypted email comprising a reply to a notification email, from a security certificate management service, that indicated an offer to issue the security certificate;

determining whether authentication of the encrypted email succeeded such that the management command is authorized;

when a determination is made that authentication of the encrypted email succeeded, identifying the security certificate using the identifying information and executing the management command with respect to the identified security certificate.

2. The computer-implemented method of claim 1 , further comprising, when a determination is made that authentication of the encrypted email failed, declining to execute the management command.

3. The computer-implemented method of claim 1 , wherein the management command comprises one of:

an accept command to accept the security certificate;

a revoke command to revoke the security certificate;

a reject command to reject the security certificate.

4. The computer-implemented method of claim 3 , wherein the encrypted email contains, as the management command, literal text of at least one of:

“accept”;

“revoke”;

“reject”.

5. The computer-implemented method of claim 1 , wherein the management command is contained within at least one of:

a body of the encrypted email;

a subject line of the encrypted email;

an attachment to the encrypted email.

6. The computer-implemented method of claim 1 , wherein the encrypted email is digitally signed to authenticate an author of the encrypted email.

7. The computer-implemented method of claim 6 , wherein the encrypted email is digitally signed using a SECURE/MULTIPURPOSE INTERNET MAIL EXTENSIONS standard.

8. The computer-implemented method of claim 1 , wherein the identifying information that identifies the security certificate comprises at least one of:

a serial number for the security certificate;

a domain name that the security certificate authenticates.

9. The computer-implemented method of claim 1 , further comprising executing the management command based on the determination that authentication of the encrypted email succeeded without further input from an author of the encrypted email.

10. The computer-implemented method of claim 1 , further comprising, upon executing the management command, automatically sending a reply email to a source of the encrypted email, the reply email indicating that the management command was executed.

11. The computer-implemented method of claim 1 , wherein the security certificate comprises a TRANSPORT LAYER SECURITY certificate.

12. The computer-implemented method of claim 1 , wherein the security certificate management service sent the notification email that indicated the offer to issue the security certificate in response to a certificate signing request.

13. The computer-implemented method of claim 1 , wherein the security certificate comprises

a SECURE SOCKETS LAYER certificate.

14. The computer-implemented method of claim 1 , wherein the identifying information that identifies the security certificate comprises a copy of the security certificate.

15. A system for managing security certificates through email, the system comprising:

a reception module, stored in memory, that receives an encrypted email that contains both identifying information that identifies a security certificate for authenticating a website and a management command relating to the security certificate, the encrypted email comprising a reply to a notification email, from a security certificate management service, that indicated an offer to issue the security certificate;

a determination module, stored in memory, that determines whether authentication of the encrypted email succeeded such that the management command is authorized;

an execution module, stored in memory, that, when a determination is made that authentication of the encrypted email succeeded, identifies the security certificate using the identifying information and executes the management command with respect to the identified security certificate;

at least one processor that executes the reception module, the determination module, and the execution module.

16. The system of claim 15 , wherein the execution module, when a determination is made that authentication of the encrypted email failed, declines to execute the management command.

17. The system of claim 15 , wherein the management command comprises one of:

an accept command to accept the security certificate;

a revoke command to revoke the security certificate;

a reject command to reject the security certificate.

18. The system of claim 15 , wherein the management command is contained within at least one of:

a body of the encrypted email;

a subject line of the encrypted email;

an attachment to the encrypted email.

19. The system of claim 15 , wherein the encrypted email is digitally signed to authenticate an author of the encrypted email.

20. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive an encrypted email that contains both identifying information that identifies a security certificate for authenticating a website and a management command relating to the security certificate, the encrypted email comprising a reply to a notification email, from a security certificate management service, that indicated an offer to issue the security certificate;

determine whether authentication of the encrypted email succeeded such that the management command is authorized;

when a determination is made that authentication of the encrypted email succeeded, identify the security certificate using the identifying information and execute the management command with respect to the identified security certificate.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2014
From: JALISATGI, PRADEEP; NAIK, ALOK
To: SYMANTEC CORPORATION
Reel/Frame 032808/0039 →