IP Library Granted Patent US 9,641,344
Granted Patent B1
US 9,641,344 · App. 14/493,237 · Granted May 2, 2017

Multiple factor authentication in an identity certificate service

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,641,344
App. No.
14/493,237
Granted
May 2, 2017
Kind
B1
Abstract

Multiple factor authentication in an identity certificate service is disclosed. A certificate including a cryptographically-obscured identifier associated with the end entity is sent from an end entity to a service node. The service node uses both the certificate and the identifier to authenticate the end entity at least in part by comparing the identifier to a reference identifier. A service associated with the service node is accessed based at least in part on the authentication.

Claims (54)

1. A method, comprising:

sending, from an end entity to a service node, a certificate including a cryptographically-obscured identifier associated with the end entity, wherein the certificate is received by the end entity from a device management server that is separate from the end entity and the service node, wherein the service node uses both the certificate and the cryptographically-obscured identifier to authenticate the end entity at least in part by comparing the cryptographically-obscured identifier to a reference identifier and in response to the cryptographically-obscured identifier matching the reference identifier, the service node is configured to validate the certificate at least in part by communicating with a certificate authority, wherein the certificate authority reviews the validity of the certificate itself, wherein the service node is configured to deny the end entity with access to a service associated with the service node in the event the cryptographically-obscured identifier is validated and the certificate is not validated; and

accessing, based at least in part on the authentication and the validation, the service associated with the service node.

2. The method of claim 1 , wherein the device management server generates the certificate including the cryptographically-obscured identifier on behalf of the end entity.

3. The method of claim 2 , wherein the device management server generates the certificate on behalf of the end entity at least in part by:

generating the cryptographically-obscured identifier;

sending, to a certificate authority, a certificate request including the cryptographically-obscured identifier; and

receiving the certificate including the cryptographically-obscured identifier from the certificate authority.

4. The method of claim 1 , further comprising:

receiving the cryptographically-obscured identifier;

sending a certificate request including the cryptographically-obscured identifier to a certificate authority; and

receiving the certificate including the cryptographically-obscured identifier.

5. The method of claim 1 , further comprising:

sending a certificate request to a certificate authority; and

receiving the certificate including the cryptographically-obscured identifier, wherein the certificate authority generates the certificate at least in part by injecting the cryptographically-obscured identifier into the certificate.

6. The method of claim 1 , wherein the end entity includes one or more of a mobile device and an application included on the mobile device.

7. The method of claim 1 , wherein the cryptographically-obscured identifier is generated at a device management server.

8. The method of claim 1 , wherein the cryptographically-obscured identifier includes a hash of an identifier associated with the end entity.

9. The method of claim 1 , wherein the cryptographically-obscured identifier is generated by encrypting an identifier associated with the end entity using a public key associated with the service node.

10. The method of claim 1 , wherein the cryptographically-obscured identifier is generated by encrypting an identifier associated with the end entity using a shared secret associated with the service node and a device management server.

11. The method of claim 1 , wherein the cryptographically-obscured identifier includes one or more of a media access control (MAC) address, a mobile device serial number, an application universally unique identifier (UUID), a user identifier, and a mobile device international mobile station equipment identity (IMEI).

12. The method of claim 1 , wherein the reference identifier includes a device or application identifier included in a protocol-related communication between the end entity and the service node.

13. The method of claim 1 , wherein the service node uses both the certificate and the identifier to authenticate the end entity at least in part by:

extracting the cryptographically-obscured identifier from the certificate;

determining that the extracted identifier matches the reference identifier;

validating the certificate with a certificate authority that issued the certificate; and

providing access to the service based at least in part on the determined match and the validated certificate.

14. The method of claim 1 , wherein the service node uses both the certificate and the identifier to authenticate the end entity at least in part by:

extracting a hashed identifier from the certificate;

retrieving a hashed reference identifier;

determining that the hashed identifier from the certificate matches the hashed reference identifier;

validating the certificate with a certificate authority that issued the certificate; and

providing access to the service based at least in part on the determined match and the validated certificate.

15. The method of claim 1 , wherein the service node uses both the certificate and the identifier to authenticate the end entity at least in part by:

decrypting an encrypted identifier included in the certificate;

determining that the decrypted identifier matches a reference identifier;

validating the certificate with a certificate authority that issued the certificate; and

providing access to the service based at least in part on the determined match and the validated certificate.

16. The method of claim 15 , wherein decrypting the encrypted identifier included in the certificate includes decrypting the encrypted identifier using one or more of a private key associated with the service node and a shared secret associated with the service node and a device management server.

17. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

send, from an end entity to a service node, a certificate including a cryptographically-obscured identifier associated with the end entity, wherein the certificate is received by the end entity from a device management server that is separate from the end entity and the service node, wherein the service node uses both the certificate and the cryptographically-obscured identifier to authenticate the end entity at least in part by comparing the cryptographically-obscured identifier to a reference identifier and in response to the cryptographically-obscured identifier matching the reference identifier, the service node is configured to validate the certificate at least in part by communicating with a certificate authority, wherein the certificate authority reviews the validity of the certificate itself, wherein the service node is configured to deny the end entity with access to a service associated with the service node in the event the cryptographically-obscured identifier is validated and the certificate is not validated; and

access, based at least in part on the authentication and the validation, the service associated with the service node.

18. The system recited in claim 17 , wherein the service node uses both the certificate and the identifier to authenticate the end entity at least in part by:

extracting the cryptographically-obscured identifier from the certificate;

determining that the extracted identifier matches the reference identifier;

validating the certificate with a certificate authority that issued the certificate; and

providing access to the service based at least in part on the determined match and the validated certificate.

19. The system recited in claim 17 , wherein the device management server generates the certificate including the cryptographically-obscured identifier on behalf of the end entity.

20. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

sending, from an end entity to a service node, a certificate including a cryptographically-obscured identifier associated with the end entity, wherein the certificate is received by the end entity from a device management server that is separate from the end entity and the service node, wherein the service node uses both the certificate and the cryptographically-obscured identifier to authenticate the end entity at least in part by comparing the cryptographically-obscured identifier to a reference identifier and in response to the cryptographically-obscured identifier matching the reference identifier, the service node is configured to validate the certificate at least in part by communicating with a certificate authority, wherein the certificate authority reviews the validity of the certificate itself, wherein the service node is configured to deny the end entity with access to a service associated with the service node in the event the cryptographically-obscured identifier is validated and the certificate is not validated; and

accessing, based at least in part on the authentication and the validation, the service associated with the service node.

21. The computer program product recited in claim 20 , wherein the device management server generates the certificate including the cryptographically-obscured identifier on behalf of the end entity.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2014
From: KIM, MANSU
To: MOBILE IRON, INC.
Reel/Frame 034241/0886 →