IP Library Granted Patent US 9,712,516
Granted Patent B2
US 9,712,516 · App. 14/310,539 · Granted Jul 18, 2017

Monitoring signed resources transferred over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,712,516
App. No.
14/310,539
Granted
Jul 18, 2017
Kind
B2
Abstract

A system for monitoring resources transferred over a network includes a capture module that is configured to capture content transferred over a network between a requestor device and a server device. The content includes a resource, a digital signature associated with the resource and a digital certificate associated with the digital signature. The system includes a resource monitor module that is configured to receive the captured content from the capture module. The resource monitor module includes at least one memory, at least one processor and a resource analyzer module that is configured to use the at least one processor to inspect one or more attributes of the digital certificate and inspect the digital signature and verify the digital certificate using the attributes and verify the digital signature.

Claims (50)

1. A system for monitoring resources transferred over a network, the system comprising:

at least one memory including instructions on a computing device; and

at least one processor on the computing device, wherein the processor is operably coupled to the at least one memory and is arranged and configured to execute the instructions that, when executed, cause the processor to implement:

a capture module that is arranged and configured to capture content transferred over a network between a requestor device and a server device, wherein the content includes:

a resource,

a digital signature associated with the resource, and

a digital certificate associated with the digital signature; and

a resource monitor module that is operably coupled to the capture module and that is configured to receive the captured content from the capture module, wherein the resource monitor module comprises:

a resource analyzer module that is configured to:

inspect one or more attributes of the digital certificate and inspect the digital signature, and

verify the digital certificate using the attributes and verify the digital signature; and

a notifier module that is operably coupled to the resource analyzer module and that is configured to provide a notification back to the server device in response to the resource analyzer module verifying an error with the digital certificate or an error with the digital signature.

2. The system of claim 1 wherein:

the attributes of the digital certificate include an expiration date; and

the resource monitor analyzer module is configured to verify the digital certificate using the expiration date.

3. The system of claim 2 wherein the notifier module is configured to notify the server device when the resource analyzer module verifies the expiration date of the digital certificate is expired.

4. The system of claim 2 wherein the notifier module is configured to notify the server device when the resource analyzer module verifies the expiration date of the digital certificate is within a predetermined period of time before the expiration date.

5. The system of claim 1 wherein the notifier module is configured to notify the server device when the resource analyzer module verifies the digital signature is not valid.

6. The system of claim 1 wherein the resource monitor module further includes a cache module that is operably coupled to the resource analyzer module and that is configured to store verification results from the resource analyzer module.

7. The system of claim 6 wherein the resource analyzer module is further configured to analyze content having an identical resource as previously captured content using the cached verification result of the previously captured content.

8. A computer-implemented method for executing instructions stored on a non-transitory computer readable storage medium, the method comprising:

capturing content transferred over a network between a requestor device and a server device, wherein the content includes:

a resource,

a digital signature associated with the resource, and

a digital certificate associated with the digital signature;

inspecting one or more attributes of the digital certificate and inspecting the digital signature;

verifying the digital certificate using the attributes and verifying the digital signature; and

providing a notification back to the server device in response to verifying an error with the digital certificate or an error with the digital signature.

9. The method as in claim 8 wherein the attributes of the digital certificate include an expiration date, the method further comprising:

verifying the digital certificate using the expiration date.

10. The method as in claim 9 wherein notifying the server device comprises notifying the server device when the verification of the expiration date indicates the digital certificate is expired.

11. The method as in claim 9 wherein notifying the server device comprises notifying the server device when the verification of the expiration date indicates the digital certificate is within a predetermined period of time before the expiration date.

12. The method as in claim 8 wherein notifying the server device comprises notifying the server device when the verification of the digital signature is not valid.

13. The method as in claim 8 further comprising storing verification results in a cache module.

14. The method as in claim 13 further comprising analyzing content having an identical resource as previously captured content using the cached verification result of the previously captured content.

15. A computer program product, the computer program product being tangibly embodied on a non-transitory computer-readable storage medium and comprising instructions that, when executed by at least one computing device, are configured to cause the at least one computing device to:

capture content transferred over a network between a requestor device and a server device, wherein the content includes:

a resource,

a digital signature associated with the resource, and

a digital certificate associated with the digital signature;

inspect one or more attributes of the digital certificate and inspect the digital signature;

verify the digital certificate using the attributes and verify the digital signature; and

provide a notification back to the server device in response to verifying an error with the digital certificate or an error with the digital signature.

16. The computer program product of claim 15 wherein the attributes of the digital certificate include an expiration date, and further comprising instructions that, when executed by the at least one computing device, are configured to cause the at least one computing device to:

verify the digital certificate using the expiration date; and

notify the server device when the verification of the expiration date indicates the digital certificate is expired.

17. The computer program product of claim 15 wherein the attributes of the digital certificate include an expiration date, and further comprising instructions that, when executed by the at least one computing device, are configured to cause the at least one computing device to:

verify the digital certificate using the expiration date; and

notify the server device when the verification of the expiration date indicates the digital certificate is within a predetermined period of time before the expiration date.

18. The computer program product of claim 15 further comprising instructions that, when executed by the at least one computing device, are configured to cause the at least one computing device to notify the server device when the verification of the digital signature is not valid.

Assignments (14)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2025
From: BMC SOFTWARE, INC.
To: BMC HELIX, INC.
Reel/Frame 070442/0197 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Jul 27, 2017
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043351/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2014
From: DESCHENES, DANNY; LAROSE, PIERRE
To: BMC SOFTWARE, INC.
Reel/Frame 033248/0597 →