IP Library Granted Patent US 10,341,092
Granted Patent B2
US 10,341,092 · App. 15/594,806 · Granted Jul 2, 2019

Application specific certificate management

Inventor: Jonathan Blake Brannon (Mableton, GA)
Assignee: VMware, Inc.
H04L9/0822G06F21/335G06F21/606H04L9/006H04L9/0825H04L9/3268H04L29/06775H04L63/0823G06F15/16G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,092
App. No.
15/594,806
Granted
Jul 2, 2019
Kind
B2
Abstract

Application specific certificate deployment may be provided. An application may generate a security certificate comprising a public key and a first private key. The public key may be stored in a shared segment of a memory store, from where it may be retrieved and signed. The signed public key may be re-deployed and/or used to transmit securely encrypted resources.

Claims (37)

1. An apparatus comprising:

a memory store; and

a processor coupled to the memory store, wherein the processor is configured to:

generate a security certificate comprising a public key and a private key in response to a request to retrieve a plurality of resources that require decryption;

store the public key in a shared segment of the memory store;

retrieve a signed version of the public key from the shared segment of the memory store;

retrieve a plurality encrypted of resources that are encrypted according to the public key, the plurality of encrypted resources comprising a completed delivery of the requested plurality of resources; and

decrypt the plurality of encrypted resources according to the private key.

2. The apparatus of claim 1 , wherein the request to retrieve the plurality of resources cannot be completed because the plurality of resources comprises a plurality of secure resources.

3. The apparatus of claim 1 , wherein the security certificate comprises a one-time use security certificate.

4. The apparatus of claim 1 , wherein the processor is further configured to store a second private key for re-use.

5. The apparatus of claim 4 , wherein the processor is further configured to:

encrypt the second private key according to the public key; and

store the second private key in the shared segment of the memory store.

6. A non-transitory computer readable medium comprising program code that, when executed, performs stages comprising:

generating a security certificate comprising a public key and a first private key in response to a request to retrieve a plurality of resources that require decryption;

storing the public key in a shared segment of a memory store;

retrieving a second private key from the shared segment of the memory store, wherein the second private key is encrypted according to the public key;

decrypting the second private key according to the first private key;

retrieving a plurality of encrypted data, wherein the plurality of encrypted data comprises a completed delivery of the requested plurality of resources; and

decrypting the plurality of encrypted data according to the decrypted second private key.

7. The non-transitory computer readable medium of claim 6 , wherein the stages further comprise storing the second private key in a second segment of the memory store, and wherein the second segment of the memory store comprises a restricted access segment of the memory store.

8. The non-transitory computer readable medium of claim 7 , wherein access to the restricted access segment of the memory store is limited to a plurality of managed applications.

9. The non-transitory computer readable medium of claim 7 , wherein the plurality of managed applications each have access to the security certificate.

10. The non-transitory computer readable medium of claim 7 , wherein the shared segment of the memory store is located over a network from a client device that requests a resource and is accessible by a remote server that provides the plurality of encrypted data.

11. The non-transitory computer readable medium of claim 7 , the stages further comprising:

requesting a resource from a remote server, wherein the request includes a unique identifier of the security certificate that the remote server uses to determine which of a plurality of public keys to use in creating the plurality of encrypted data.

12. A method for encrypted resource access by managed applications, comprising:

generating a security certificate comprising a public key and a private key in response to a request to retrieve a plurality of resources that require decryption;

storing the public key in a shared segment of a memory store;

retrieving a signed version of the public key from the shared segment of the memory store;

retrieving a plurality of encrypted resources that are encrypted according to the public key, the plurality of encrypted resources comprising a completed delivery of the requested plurality of resources; and

decrypting the plurality of encrypted resources according to the private key.

13. The method of claim 12 , wherein the request to retrieve the plurality of resources cannot be completed because the plurality of resources comprises a plurality of secure resources.

14. The method of claim 12 , wherein the security certificate comprises a one-time use security certificate.

15. The method of claim 12 , further comprising storing the private key for re-use by a client device, wherein multiple managed applications use the private key.

16. The method of claim 15 , wherein the shared segment of a memory store is located over a network from the client device, wherein the client device that executes a managed application that requests a resource from the plurality of resources and is accessible by a remote server that provides the resource.

Assignments (5)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: AIRWATCH LLC
To: VMWARE, INC.
Reel/Frame 067879/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: BRANNON, JONATHAN BLAKE
To: AIRWATCH LLC
Reel/Frame 067879/0198 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (2)
Division 14282034 · May 20, 2014
Related Publication 20170250807A1 · Aug 31, 2017