IP Library Granted Patent US 10,277,406
Granted Patent B1
US 10,277,406 · App. 14/478,398 · Granted Apr 30, 2019

Authentication process for issuing sequence of short-lived digital certificates

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,277,406
App. No.
14/478,398
Granted
Apr 30, 2019
Kind
B1
Abstract

Embodiments presented herein provide techniques for managing a digital certificate enrollment process. In particular, embodiments presented herein provide techniques for a certificate authority to issue short-lived SSL certificates and an authentication method for validating certificate signing requests (CSR) for short-lived certificates.

Claims (32)

1. A computer-implemented method for issuing a sequence of short-lived digital certificates, the method comprising:

receiving, from a computing device associated with a party, a certificate signing request (CSR) that includes a public key to be listed in a first digital certificate, that is signed using at least a first private key and at least a portion of the CSR to generate a first digital signature, and that is signed using at least a second private key and at least a portion of a first version of the CSR to generate a second digital signature and a second version of the CSR that includes the second digital signature;

validating that the first digital signature was generated using the first private key, the first private key corresponding to the public key to be listed in the first digital certificate;

validating that the second digital signature was generated using the second private key, the second private key corresponding to a public key listed in a second digital certificate previously issued to the party; and

based on validating that the first digital signature was generated using the first private key and validating that the second digital signature was generated using the second private key, issuing the first digital certificate to the party.

2. The method of claim 1 , wherein the first digital signature is generated by signing, with the first private key, the second version of the CSR that includes the second digital signature to generate a third version of the CSR that includes both the first and second digital signatures, and wherein receiving the CSR comprises receiving the third version of the CSR.

3. The method of claim 1 , wherein receiving the CSR comprises receiving the second version of the CSR.

4. The method of claim 1 , further comprising prior to issuing the first digital certificate, determining that the second digital certificate is currently valid and not revoked.

5. The method of claim 1 , further comprising, including a subject distinguished name in the first digital certificate from the second digital certificate.

6. The method of claim 1 , wherein attributes listed in the CSR also include the second digital signature.

7. A non-transitory computer-readable storage medium storing instructions, which, when executed on a processor, performs an operation for issuing a sequence of short-lived digital certificates, the operation comprising:

receiving, from a computing device associated with a party, a certificate signing request (CSR) that includes a public key to be listed in a first digital certificate, that is signed using at least a first private key and at least a portion of the CSR to generate a first digital signature, and that is signed using at least a second private key and at least a portion of a first version of the CSR to generate a second digital signature and a second version of the CSR that includes the second digital signature;

validating that the first digital signature was generated using the first private key, the first private key corresponding to the public key to be listed in the first digital certificate;

validating that the second digital signature was generated using the second private key, the second private key corresponding to a public key listed in a second digital certificate previously issued to the party; and

based on validating that the first digital signature was generated using the first private key and validating that the second digital signature was generated using the second private key, issuing the first digital certificate to the party.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the first digital signature is generated by signing, with the first private key, the second version of the CSR that includes the second digital signature and generating a third version of the CSR that includes both the first and second digital signatures and wherein receiving the CSR comprises receiving the third version of the CSR.

9. The non-transitory computer-readable storage medium of claim 7 , wherein receiving the CSR comprises receiving the second version of the CSR.

10. The non-transitory computer-readable storage medium of claim 7 , wherein the operation further comprises, prior to issuing the first digital certificate, determining that the second digital certificate is currently valid and not revoked.

11. The non-transitory computer-readable storage medium of claim 7 , wherein the operation further comprises, including a subject distinguished name in the first digital certificate from the second digital certificate.

12. The non-transitory computer-readable storage medium of claim 7 , wherein attributes listed in the CSR also include the second digital signature.

13. A system, comprising:

a processor; and

a memory storing computer-executable instructions, which, when executed by the processor, causes the processor to perform an operation for issuing a sequence of short-lived digital certificates, the operation comprising:

receiving, from a computing device associated with a party, a certificate signing request (CSR) that includes a public key to be listed in a first digital certificate, that is signed using at least a first private key and at least a portion of the CSR to generate a first digital signature, and that is signed using at least a second private key and at least a portion of a first version of the CSR to generate a second digital signature and a second version of the CSR that includes the second digital signature,

validating that the first digital signature was generated using a first private key, the first private key corresponding to the public key to be listed in the first digital certificate,

validating that the second digital signature was generated using a second private key, the second private key corresponding to a public key listed in a second digital certificate previously issued to the party, and

based on validating that the first digital signature was generated using the first private key and validating that the second digital signature was generated using the second private key, issuing the first digital certificate to the party.

14. The system of claim 13 , wherein the first digital signature is generated by signing, with the first private key, the second version of the CSR that includes the second digital signature to generate a third version of the CSR that includes both the first and second digital signatures, and wherein receiving the CSR comprises receiving the third version of the CSR.

15. The system of claim 13 , wherein receiving the CSR comprises receiving the second version of the CSR.

16. The system of claim 13 , wherein the operation further comprises, prior to issuing the first digital certificate, determining that the second digital certificate is currently valid and not revoked.

17. The system of claim 13 , wherein the operation further comprises, including a subject distinguished name in the first digital certificate from the second digital certificate.

18. The system of claim 13 , wherein attributes listed in the CSR include the second digital signature.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2014
From: VELADANDA, HARI; LY, HOA; KHANNA, GAURAV
To: SYMANTEC CORPORATION
Reel/Frame 033678/0154 →
Cited By (4)
US 12,355,757 US 12,500,778 US 12,609,840 US 12,695,631