IP Library Granted Patent US 10,552,827
Granted Patent B2
US 10,552,827 · App. 14/843,551 · Granted Feb 4, 2020

Dynamic digital certificate updating

Inventors: Denis M. Sheridan (Alexandria, VA); Weimin Tsai (Irving, TX); Neil Edward Bergman (Astoria, NM)
Assignee: Google LLC
G06Q20/363G06Q20/1235G06Q30/0185
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,552,827
App. No.
14/843,551
Granted
Feb 4, 2020
Kind
B2
Abstract

Providing backup digital certificates comprises an application provider, such as a digital wallet system, that obtains signed digital certificates from a certificate authority. The digital wallet system provides an application, such as a digital wallet application, to a user computing devise along with a primary digital certificate and a backup digital certificate. The user computing device utilizes the primary digital certificate to ensure a secure connection with the digital wallet system. If the primary digital certificate is compromised, the digital wallet system may communicate the backup digital certificate to the digital wallet system when a subsequent secure connection is requested. The user computing device may access the backup digital certificate and verify the provided digital certificate. The digital wallet system provides a new backup digital certificate to the user computing device, and the user computing device deletes the compromised digital certificate.

Claims (39)

1. A computer-implemented method to execute digital wallet applications using backup digital certificates when primary digital certificates are compromised, without updating the digital wallet applications, comprising:

receiving, by a digital wallet system, a primary digital certificate and a first backup digital certificate from a certificate authority system, the primary digital certificate and the first backup digital certificate being associated with a digital wallet application managed by the digital wallet system;

communicating concurrently, by the digital wallet system and to a user computing device, the digital wallet application, the primary digital certificate and the first backup digital certificate to be stored on the user computing device for use with the application;

receiving, by the digital wallet system, a request from the user computing device to provide a secure communication between the digital wallet application and a payment processing system;

determining, by the digital wallet system, that the primary digital certificate is compromised;

in response to determining that the primary digital certificate is compromised, promoting, by the digital wallet system, the first backup digital certificate to primary digital certificate status;

receiving, by the digital wallet system, a second backup digital certificate from the certificate authority system;

communicating concurrently, by the digital wallet system and to the user computing device, the first backup digital certificate and the second backup digital certificate, the first backup digital certificate to be matched to the first backup digital certificate stored by the user computing device, wherein the user computing device stores the second backup digital certificate to use with the application as an updated backup digital certificate; and

completing, by the digital wallet system, a financial transaction associated with the request for a secure communication using the promoted first backup digital certificate without updating the digital wallet application.

2. The computer-implemented method of claim 1 , wherein the primary digital certificate is compromised because the primary digital certificate is expired.

3. The computer-implemented method of claim 1 , further comprising: verifying, by the digital wallet system, the first backup digital certificate by comparing the first backup digital certificate to the stored first backup digital certificate and determining that a match exists.

4. The computer-implemented method of claim 1 , wherein the data storage device is a secure element.

5. The computer-implemented method of claim 1 , further comprising communicating, by the digital wallet system, instructions to the user computing device to delete the primary digital certificate after determining that the primary digital certificate is compromised.

6. A computer program product, comprising:

a non-transitory computer-readable storage device having computer-executable program instructions embodied thereon that when executed by a computer cause the computer to execute digital wallet applications using backup digital certificates when primary digital certificates are compromised, without updating the digital wallet applications, the computer-executable program instructions comprising:

computer-executable program instructions to receive concurrently a digital wallet application, a primary digital certificate, and a first backup digital certificate from a digital wallet application computing system, the digital certificate and the first backup digital certificate being associated with the digital wallet application;

computer-executable program instructions to request a secure communication between the digital wallet application and the digital wallet application computing system;

computer-executable program instructions to receive a response from the digital wallet application computing system, the response comprising the first backup digital certificate and a second backup digital certificate;

computer-executable program instructions to compare the received first backup digital certificate to the stored primary digital certificate;

computer-executable program instructions to determine that the received first backup digital certificate and the stored primary digital certificate are not a match;

computer-executable program instructions to compare the received first backup digital certificate to the stored first backup digital certificate;

computer-executable program instructions to determine that the received first backup digital certificate and the stored first backup digital certificate are a match and to execute the digital wallet application based on the match;

computer-executable program instructions to promote the stored first backup digital certificate to primary digital certificate status for subsequent execution of the application; and

computer-executable program instructions to complete a financial transaction associated with the request for a secure communication using the promoted first backup digital certificate without updating the digital wallet application.

7. The computer program product of claim 6 , further comprising computer-executable program instructions to initiate a communication between the digital wallet application and the digital wallet application computing system via the secure connection.

8. The computer program product of claim 6 , wherein the primary digital certificate and the first backup digital certificate are stored on a data storage device on the computer.

9. The computer program product of claim 8 , wherein the data storage device is a secure memory.

10. The computer program product of claim 6 , further comprising computer-executable program instructions to delete the stored primary digital certificate.

11. A system to execute digital wallet applications using backup digital certificates when primary digital certificates are compromised, without updating the digital wallet applications, comprising:

a storage device; and

a processor communicatively coupled to the storage device, wherein the processor executes application code instructions that are stored in the storage device to cause the processor to:

communicate concurrently, to a user computing device, a digital wallet application, a primary digital certificate associated with the digital wallet application, and a first backup digital certificate associated with the digital wallet application to store on a data storage device on the user computing device;

receive a request from the user computing device to provide a secure communication;

determine that the primary digital certificate is compromised;

promote the first backup digital certificate to primary digital certificate;

communicate to the user computing device, the first backup digital certificate and a second backup digital certificate, the first backup digital certificate to be matched to the stored first backup digital certificate; and

complete a financial transaction associated with the request for a secure communication using the promoted first backup digital certificate without updating the digital wallet application.

12. The system of claim 11 , wherein the processor executes application code instructions that are stored in the storage device to cause the system to receive the primary digital certificate and the first backup digital certificate from a certificate authority system.

13. The system of claim 11 , wherein the primary digital certificate is compromised because the primary digital certificate is expired.

Assignments (2)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2015
From: SHERIDAN, DENIS M.; TSAI, WEIMIN; BERGMAN, NEIL EDWARD
To: GOOGLE INC.
Reel/Frame 036633/0973 →
Continuity (2)
Provisional Application 62044528 · Sep 2, 2014
Related Publication 20160063466A1 · Mar 3, 2016
Cited By (1)
US 12,413,572