IP Library Granted Patent US 10,911,226
Granted Patent B2
US 10,911,226 · App. 16/436,383 · Granted Feb 2, 2021

Application specific certificate management

Inventor: Jonathan Blake Brannon (Mableton, GA)
Assignee: AirWatch, LLC
H04L9/0822G06F21/335G06F21/606H04L9/006H04L9/0825H04L9/3268H04L29/06775H04L63/0823G06F15/16G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,911,226
App. No.
16/436,383
Granted
Feb 2, 2021
Kind
B2
Abstract

Application specific certificate deployment may be provided. An application may generate a security certificate comprising a public key and a first private key. The public key may be stored in a shared segment of a memory store, from where it may be retrieved and signed. The signed public key may be re-deployed and/or used to transmit securely encrypted resources.

Claims (43)

1. A method for encrypted resource access by managed applications, comprising:

generating, based on an application requesting to retrieve encrypted resources, a public key and a private key, wherein the public and private keys are generated from a security certificate that is created for the request;

storing the public key in a shared segment of a memory store, wherein the memory store is accessible by the requesting application and at least one other application, and wherein a server remote from the requesting application retrieves the public key from the memory store and sends it to a certificate authority for signature;

receiving, at a computing device, a signed version of the public key from the certificate authority;

retrieving the encrypted resources from the remote server, wherein the encrypted resources are encrypted according to the public key by the remote server; and

decrypting the encrypted resources according to the private key.

2. The method of claim 1 , wherein the shared segment of the memory store is located on a different physical device.

3. The method of claim 1 , wherein the public and private keys are generated from the security certificate based on a determination that the encrypted resources require secure retrieval.

4. The method of claim 3 , wherein the security certificate comprises a one-time use security certificate.

5. The method of claim 1 , further comprising storing a second private key for re-use.

6. The method of claim 5 , further comprising:

encrypting the second private key according to the public key; and

storing the second private key in the shared segment of the memory store.

7. The method of claim 1 , further comprising placing the signed version of the public key in a memory segment accessible by the requesting application.

8. A non-transitory, computer-readable medium containing instructions that are executed by a processor, causing the processor to perform stages comprising:

generating, based on an application requesting to retrieve encrypted resources, a public key and a private key, wherein the public and private keys are generated from a security certificate that is created for the request;

storing the public key in a shared segment of a memory store, wherein the memory store is accessible by the requesting application and at least one other application, and wherein a server remote from the requesting application retrieves the public key from the memory store and sends it to a certificate authority for signature;

receiving, at a computing device, a signed version of the public key from the certificate authority;

retrieving the encrypted resources from the remote server, wherein the encrypted resources are encrypted according to the public key by the remote server; and

decrypting the encrypted resources according to the private key.

9. The non-transitory, computer-readable medium of claim 8 , wherein the shared segment of the memory store is located on a different physical device.

10. The non-transitory, computer-readable medium of claim 8 , wherein the public and private keys are generated from the security certificate based on a determination that the encrypted resources require secure retrieval.

11. The non-transitory, computer-readable medium of claim 10 , wherein the security certificate comprises a one-time use security certificate.

12. The non-transitory, computer-readable medium of claim 8 , the stages further comprising storing a second private key for re-use.

13. The non-transitory, computer-readable medium of claim 12 , the stages further comprising:

encrypting the second private key according to the public key; and

storing the second private key in the shared segment of the memory store.

14. The non-transitory, computer-readable medium of claim 8 , the stages further comprising placing the signed version of the public key in a memory segment accessible by the requesting application.

15. An apparatus comprising:

a memory store; and

a processor coupled to the memory store, wherein the processor is configured to perform stages comprising:

generating, based on an application requesting to retrieve encrypted resources, a public key and a private key, wherein the public and private keys are generated from a security certificate that is created for the request;

storing the public key in a shared segment of the memory store, wherein the memory store is accessible by the requesting application and at least one other application, and wherein a server remote from the requesting application retrieves the public key from the memory store and sends it to a certificate authority for signature;

receiving, at a computing device, a signed version of the public key from the certificate authority;

retrieving the encrypted resources from the remote server, wherein the encrypted resources are encrypted according to the public key at the remote server; and

decrypting the encrypted resources according to the private key.

16. The apparatus of claim 15 , wherein the shared segment of the memory store is located on a different physical device.

17. The apparatus of claim 15 , wherein the public and private keys are generated from the security certificate based on a determination that the encrypted resources require secure retrieval.

18. The apparatus of claim 17 , wherein the security certificate comprises a one-time use security certificate.

19. The apparatus of claim 15 , the stages further comprising storing a second private key for re-use.

20. The apparatus of claim 19 , the stages further comprising:

encrypting the second private key according to the public key; and

storing the second private key in the shared segment of the memory store.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: AIRWATCH LLC
To: VMWARE, INC.
Reel/Frame 067879/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: BRANNON, JONATHAN BLAKE
To: AIRWATCH LLC
Reel/Frame 067879/0208 →
Continuity (3)
Continuation 15594806 · May 15, 2017
Division 14282034 · May 20, 2014
Related Publication 20190312722A1 · Oct 10, 2019