IP Library Granted Patent US 11,151,253
Granted Patent B1
US 11,151,253 · App. 15/982,501 · Granted Oct 19, 2021

Credentialing cloud-based applications

Inventors: Brian J. Hanafee (Pleasanton, CA); Phillip John Crump (Roseville, MN)
Assignee: WELLS FARGO BANK, N.A.
G06F21/57G06F9/45558G06F21/44H04L9/0825H04L9/0894H04L63/0823H04L63/12G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,151,253
App. No.
15/982,501
Granted
Oct 19, 2021
Kind
B1
Abstract

The innovation disclosed and claimed herein, in one aspect thereof, comprises systems and methods of credentialing an application in a cloud environment. The application is determined to be a trusted application type. The application is provided with a certificate service process dedicated to request and receive a certificate from a source outside the cloud environment. An integration component retrieves the secret and provides it to the application that is inside the cloud environment. The secret is verified within the cloud environment and the application is deployed as a trusted application instance inside the cloud environment.

Claims (33)

1. A method, comprising:

receiving a request to launch an application instance in a cloud environment;

determining the application instance is a trusted type of application that employs a secret to authenticate the application instance as a trusted type of application, wherein the secret is a digital certificate, a password, or a code;

copying a certificate service master stored in the cloud environment to the application instance as a certificate service process, wherein the certificate service master is permanent entity stored in the cloud that keeps a copy of the certificate service process;

providing the application instance with the certificate service process within the cloud environment;

receiving the secret from an external secrets store outside the cloud environment; and

providing a continuous heartbeat function from the certificate service process to continuously request the secret, wherein the heartbeat function is an exclusive function of requesting the secret.

2. The method of claim 1 , comprising:

integrating the secret into the certificate service process.

3. The method of claim 2 , comprising:

verifying the application instance as a trusted application instance using the secret integrated into the certificate service process.

4. The method of claim 1 , wherein the secret is a digital certificate that credentials the application instance as a trusted application.

5. The method of claim 1 , comprising:

verifying the certificate service process by confirming a public key in a certificate trust store.

6. A system, comprising:

one or more hardware processors having instructions to control:

a cloud controller that receives a request to open an application instance in a cloud environment, wherein the cloud controller determines the application instance is a trusted type of application that employs a secret to authenticate the application instance as a trusted type of application;

a certificate service master that provides the application instance with a certificate service component within the cloud environment, wherein the certificate service component copies the certificate service master stored in the cloud environment to the application instance, wherein the certificate service master is permanent entity stored in the cloud that keeps a copy of the certificate service component; and

an integration component that provides a secret from a secrets store outside the cloud environment, wherein the certificate service component provides a continuous heartbeat function to the integration component to continuously request the secret, wherein the heartbeat function is an exclusive function of requesting the secret.

7. The system of claim 6 , wherein the integration component integrates the secret into the certificate service component.

8. The system of claim 7 , comprising:

a verification component that verifies the application instance as a trusted application instance using the secret integrated into the certificate service component.

9. The system of claim 8 , wherein the verification component verifies the secret by confirming a public key in a certificate trust store.

10. The system of claim 6 , wherein the secret is a digital certificate that credentials the application instance as a trusted application.

11. A non-transitory computer readable medium having instructions to control one or more processors configured to:

receive a request to launch an application instance in a cloud environment wherein, the cloud controller determines the application instance is a trusted type of application that requires a secret to authenticate the application instance as a trusted type of application;

copy a certificate service master stored in the cloud environment to the application instance, wherein the certificate service master is permanent entity stored in the cloud that keeps a copy of a certificate service process;

provide the application instance with a certificate service component within the cloud environment;

provide a secret from a secrets store that is outside the cloud environment;

integrate the secret into the certificate service component;

authenticate the application instance as a trusted application instance using the secret integrated into the certificate service component; and

provide a continuous heartbeat function to an integration component to continuously request the secret, wherein the heartbeat function is an exclusive function of requesting the secret.

12. The non-transitory computer readable medium of claim 11 , wherein the processors are configured to: verify the secret by confirming a public key in a certificate trust store.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2018
From: HANAFEE, BRIAN J.; CRUMP, PHILLIP JOHN
To: WELLS FARGO BANK, N.A.
Reel/Frame 047207/0790 →
Continuity (1)
Provisional Application 62508033 · May 18, 2017
Cited By (2)
US 12,231,430 US 12,271,461