IP Library Granted Patent US 9,882,728
Granted Patent B2
US 9,882,728 · App. 15/279,191 · Granted Jan 30, 2018

Identity-based certificate management

Inventors: Garret Florian Grajek (Aliso Viejo, CA); Jeffrey Chiwai Lo (Irvine, CA); Mark V. Lambiase (Ladera Ranch, CA)
Assignee: SecureAuth Corporation
H04L9/3268H04L9/14H04L9/30H04L9/3252H04L9/3263H04L9/3271H04L9/3297H04L63/06H04L63/0823H04L2209/56H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,882,728
App. No.
15/279,191
Granted
Jan 30, 2018
Kind
B2
Abstract

Methods for managing digital certificates, including issuance, validation, and revocation are disclosed. Various embodiments involve querying a directory service with entries that correspond to a particular client identity and have attributes including certificate issuance limits and certificate validity time values. The validity time values are adjustable to revoke selectively the certificates based upon time intervals set forth in validity identifiers included therein.

Claims (31)

1. A method performed by a computer system for validating a digital certificate issued to a client system and associated with a specific client identity, the method comprising:

receiving the digital certificate from the client system, the digital certificate including a user identifier and a certificate validity period identifier, the user identifier corresponding to the specific client identity;

generating a first query to a directory service which includes a request for a first entry associated with the specific client identity, the first entry including a directory validity time value for the specific client identity;

receiving the directory validity time value for the specific client identity returned by the directory service in response to the first query;

validating the digital certificate, wherein validating the digital certificate comprises determining that a certificate validity period specified by the certificate validity period identifier is later than the received directory validity time value; and

revoking the digital certificate in response to a modification of the directory validity time value to a value associated with the current date and time.

2. The method of claim 1 , wherein the certificate validity period is defined by a validity start time and a validity end time.

3. The method of claim 2 , wherein the certificate validity period is later than the directory validity time value only if the validity start time is later than the directory validity time value.

4. The method of claim 2 , further comprising rejecting the digital certificate if the validity start time is prior to the received directory validity time value for the specific client identity.

5. The method of claim 2 , further comprising rejecting the digital certificate if the validity end time is prior to the received directory validity time value for the specific client identity.

6. The method of claim 1 , further comprising removing access restrictions to a network application resource upon validating the digital certificate.

7. The method of claim 1 , further comprising revoking the digital certificate in response to a modification to the directory validity time value to be later than the certificate validity period of the digital certificate.

8. The method of claim 1 , wherein the directory service is a Standard Query Language (SQL) database.

9. The method of claim 1 , wherein the directory validity time value comprises a dynamic certificate validation date.

10. The method of claim 9 , wherein the dynamic certificate validation date of a directory validity time value stored on a directory service may be modified through an administration panel user interface.

11. The method of claim 1 , wherein the directory validity time value comprises a set of date values that identify a specific year, month, and day, and a set of time values that identify a specific hour and minute.

12. A system for validating a digital certificate issued to a client system and associated with a specific client identity, the system comprising:

a computing system comprising one or more computing devices, said computing system programmed via executable instructions to at least:

receive the digital certificate from the client system, the digital certificate including a user identifier and a certificate validity period indicator, the user identifier corresponding to the specific client identity;

generate a first query to a directory service which includes a request for a first entry associated with the specific client identity, the first entry including a directory validity time value for the specific client identity;

receive the directory validity time value for the specific client identity returned by the directory service in response to the first query; and

validate the digital certificate, wherein the computing system is programmed via executable instructions to at least validate the digital certificate by determining that a certificate validity period specified by the certificate validity period identifier is later than the received directory validity time value, and wherein the directory validity time value is editable to revoke the digital certificate that includes the user identifier.

13. The system of claim 12 , wherein the certificate validity period is defined by a validity start time and a validity end time.

14. The system of claim 13 , wherein the computing system is further programmed via executable instructions to reject the digital certificate if the validity start time or the validity end time is prior to the received directory validity time value for the specific client identity.

15. A non-transitory computer storage medium that comprises executable instructions that when executed by a computing system, directs the computing system to at least:

receive a digital certificate from the client system, the digital certificate including a user identifier and a certificate validity period indicator, the user identifier corresponding to the specific client identity;

generate a first query to a directory service which includes a request for a first entry associated with the specific client identity, the first entry including a directory validity time value for the specific client identity;

receive the directory validity time value for the specific client identity returned by the directory service in response to the first query; and

validate the digital certificate, wherein validating the digital certificate comprises determining that a certificate validity period specified by the certificate validity period identifier is later than the received directory validity time value, and wherein the directory validity time value is editable to revoke the digital certificates that includes the user identifier.

16. The non-transitory computer storage medium of claim 15 , wherein the certificate validity period is defined by a validity start time and a validity end time.

17. The non-transitory computer storage medium of claim 16 , wherein the executable instructions, when executed by a computing system, further directs the computing system to reject the digital certificate if the validity start time or the validity end time is prior to the received directory validity time value for the specific client identity.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0011 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0158 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: SECUREAUTH CORPORATION
Reel/Frame 068288/0856 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 068251/0496 →
SECURITY INTEREST Recorded Oct 27, 2021
From: SECUREAUTH CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 057937/0732 →
SECURITY INTEREST Recorded Jan 3, 2018
From: SECUREAUTH CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044522/0031 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2017
From: GRAJEK, GARRET; LO, JEFF
To: MULTIFACTOR CORPORATION
Reel/Frame 044426/0601 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2017
From: LAMBIASE, MARK V.
To: SECUREAUTH CORPORATION
Reel/Frame 044426/0622 →
RELEASE OF SECURITY INTEREST Recorded Dec 18, 2017
From: WESTERN ALLIANCE BANK
To: SECUREAUTH CORPORATION
Reel/Frame 044899/0635 →
CHANGE OF NAME Recorded Dec 18, 2017
From: MULTIFACTOR CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 044906/0922 →
Continuity (3)
Continuation 14256270 · Apr 18, 2014
Continuation 12419951 · Apr 7, 2009
Related Publication 20170019260A1 · Jan 19, 2017