IP Library Granted Patent US 9,479,338
Granted Patent B2
US 9,479,338 · App. 14/659,889 · Granted Oct 25, 2016

Method and system for certificate discovery and ranking certificate authorities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,338
App. No.
14/659,889
Granted
Oct 25, 2016
Kind
B2
Abstract

Certificate detectors scan a network for certificate resource information and send the information to a certificate database. A correlation engine extracts and correlates this information. A ranker uses the information about the certificates and certificate authorities to generate and provide a security score and/or ranking. A requester may view the certificate ranking and/or and certificate authority ranking after passing a domain validation authorization. An Internet browser may obtain a security score and/or ranking for a certificate authority and, based on this information, may determine to trust or not trust some or all certificates issued by that certificate authority, or to require corroborating evidence before trusting a certificate.

Claims (61)

1. A method for determining trustworthiness of a certificate authority, comprising:

obtaining a security score for the certificate authority, comprising;

obtaining certificate resource information from one or more networks;

analyzing the certificate resource information;

assigning a security score to the certificate authority based at least in part on the analysis of the certificate resource information; and

relying, based on the security score, on a certificate issued by the certificate authority, comprising at least two of:

determining to trust the certificate, based on the security score, for a set of some but not all websites;

determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate; and

determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available;

wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, at least two of:

that a domain from which the at least one certificate was received is a phishing attempt;

that the certificate has internal names in the certificate's subject alternative name field;

that the issuing certificate authority has received bad press.

2. The method of claim 1 , wherein the security score is a ranking for the certificate authority.

3. The method of claim 1 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, for a set of some but not all websites.

4. The method of claim 1 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate.

5. The method of claim 1 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available.

6. The method of claim 1 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, that a domain from which the at least one certificate was received is a phishing attempt.

7. The method of claim 1 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, that the issuing certificate authority has received bad press.

8. The method of claim 1 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, at least one of:

that the domain from which the at least one certificate was received has received bad press; and

that the owner of the domain has received bad press.

9. A computing device for determining trustworthiness of a certificate authority, the computing device comprising a processor and a memory, wherein the memory stores instructions that, when executed on the processor, cause the computing device to perform a method comprising:

obtaining a security score for the certificate authority, comprising;

obtaining certificate resource information from one or more networks;

analyzing the certificate resource information;

assigning a security score to the certificate authority based at least in part on the analysis of the certificate resource information; and

relying, based on the security score, on a certificate issued by the certificate authority, comprising at least two of:

determining to trust the certificate, based on the security score, for a set of some but not all websites;

determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate; and

determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available;

wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, at least two of:

that a domain from which the at least one certificate was received is a phishing attempt;

that the certificate has internal names in the certificate's subject alternative name field;

that the issuing certificate authority has received bad press

that a that the issuing certificate authority has received bad press.

10. The computing device of claim 9 , wherein the security score is a ranking for the certificate authority.

11. The computing device of claim 9 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, for a set of some but not all websites.

12. The computing device of claim 9 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate.

13. The computing device of claim 9 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available.

14. The computing device of claim 9 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, that a domain from which the at least one certificate was received is a phishing attempt.

15. The computing device of claim 9 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, that the issuing certificate authority has received bad press.

16. The computing device of claim 9 , wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, at least one of:

that the domain from which the at least one certificate was received has received bad press; and

that the owner of the domain has received bad press.

17. A non-transitory computer-readable medium storing instructions that, when executed on a processor of a computing device, cause the computing device to perform a method for determining trustworthiness of a certificate authority, comprising:

obtaining a security score for the certificate authority, comprising;

obtaining certificate resource information from one or more networks;

analyzing the certificate resource information;

assigning a security score to the certificate authority based at least in part on the analysis of the certificate resource information; and

relying, based on the security score, on a certificate issued by the certificate authority, comprising at least two of:

determining to trust the certificate, based on the security score, for a set of some but not all websites;

determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate; and

determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available;

wherein analyzing the certificate resource information comprises determining, for at least one certificate in the certificate resource information, at least two of:

that a domain from which the at least one certificate was received is a phishing attempt;

that the certificate has internal names in the certificate's subject alternative name-field;

that the issuing certificate authority has received bad press.

18. The non-transitory computer-readable medium of claim 17 , wherein the security score is a ranking for the certificate authority.

19. The non-transitory computer-readable medium of claim 17 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if a second certificate from a second certificate authority corroborates the certificate.

20. The non-transitory computer-readable medium of claim 17 , wherein relying, based on the security score, on a certificate issued by the certificate authority, comprises determining to trust the certificate, based on the security score, if no certificates from higher-ranked certificate authorities are available.

Assignments (10)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2016
From: SABIN, JASON ALLEN
To: DIGICERT, INC.
Reel/Frame 038444/0131 →