IP Library Granted Patent US 11,477,011
Granted Patent B1
US 11,477,011 · App. 16/529,185 · Granted Oct 18, 2022

Distributed cryptographic management for computer systems

Inventors: Douglas Pelton (Richmond, CA); Waeed Sherzai (Martinez, CA); Catherine Li (Corte Madera, CA); Ruven Schwartz (Minneapolis, MN)
Assignee: Wells Fargo Bank, N.A.
H04L9/08H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,011
App. No.
16/529,185
Granted
Oct 18, 2022
Kind
B1
Abstract

An administrator installs a key management agent on a previously approved client machine. The agent is started on the client machine, which posts requests for keys to a central key management service. The central key management service logs requests posted to it by clients, and checks for existing pre-approval records. If none are found, a message is typically sent to an approver for the requesting client machine. When a request is verified as approved, the request is flagged for further processing. The supported systems continuously or periodically look for records flagged for processing, use requests to generate keys and other appropriate elements for the requesting client machine, and post keys and other elements to the key management database. The key management agent polls the central key management service periodically until finding the expected key file, which it downloads and installs into a protected file location on the client machine. The key management agent periodically sends status messages to the central key management service, which tracks expected behavior of the client machine and/or key management agent.

Claims (48)

1. A system for managing digital certificates, comprising:

a plurality of client devices, with each of the plurality of client devices being connected to a network and having a digital certificate to encrypt communications;

a certificate authority device programmed to issue digital certificates; and

a central enrollment device, the central enrollment device being in communication with the plurality of client devices through the network, the central enrollment device including a processor and memory encoding instructions which, when executed by the processor, causes the central enrollment device to:

monitor a status of the digital certificate for each of the plurality of client devices;

obtain new digital certificates from the certificate authority device;

pursuant to the central enrollment device automatically determining that the digital certificate is expiring, allow the central enrollment device to initiate issue or update of the digital certificate on each of the plurality of client devices upon expiration with one of the new digital certificates, thereby automating certificate management through centralization to minimize undesired expiration;

at a pre-assigned schedule based on rules set forth by the central enrollment device, receive requests for a renewal key from a key management agent associated with at least one of the plurality of client devices; and

when the renewal key is available and upon request from the key management agent, transmit the renewal key to the key management agent for download.

2. The system of claim 1 , further comprising a registration authority programmed to provide verification services for the certificate authority.

3. The system of claim 2 , wherein the verification services include authentication information and audit information for the system.

4. The system of claim 1 , further comprising a database storing a keystore profile for one or more of the plurality of client devices.

5. The system of claim 1 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to communicate with the key management agent on each of the plurality of client devices to delete, revoke, suspend, or reissue the digital certificate.

6. The system of claim 1 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to:

receive status messages relating to the status of the digital certificate for each of the plurality of client devices; and

track expected behavior of the plurality of client devices.

7. The system of claim 6 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to revoke the digital certificate based upon unexpected behavior.

8. The system of claim 1 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to receive a hypertext transfer protocol request through the network to issue or update the digital certificate from one of the plurality of client devices.

9. A system for managing digital certificates, comprising:

a plurality of client devices, with each of the plurality of client devices being connected to a network and having a digital certificate to encrypt communications; and

a central enrollment device, the central enrollment device being in communication with the plurality of client devices through the network, the central enrollment device including a processor and memory encoding instructions which, when executed by the processor, causes the central enrollment device to:

monitor a status of the digital certificate for each of the plurality of client devices;

obtain new digital certificates from a certificate authority device;

pursuant to the central enrollment device automatically determining that the digital certificate is expiring, allow the central enrollment device to initiate issue or update of the digital certificate on each of the plurality of client devices upon expiration with one of the new digital certificates, thereby automating certificate management through centralization to minimize undesired expiration;

at a pre-assigned schedule based on rules set forth by the central enrollment device, receive requests for a renewal key from a key management agent associated with at least one of the plurality of client devices; and

when the renewal key is available and upon request from the key management agent, transmit the renewal key to the key management agent for download.

10. The system of claim 9 , further comprising a registration authority programmed to provide verification services for the certificate authority.

11. The system of claim 10 , wherein the verification services include authentication information and audit information for the system.

12. The system of claim 9 , further comprising a database storing a keystore profile for one or more of the plurality of client devices.

13. The system of claim 9 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to communicate with the key management agent on each of the plurality of client devices to delete, revoke, suspend, or reissue the digital certificate.

14. The system of claim 9 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to:

receive status messages relating to the status of the digital certificate for each of the plurality of client devices; and

track expected behavior of the plurality of client devices.

15. The system of claim 14 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to revoke the digital certificate based upon unexpected behavior.

16. The system of claim 9 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to receive a hypertext transfer protocol request through the network to issue or update the digital certificate from one of the plurality of client devices.

17. A system for managing digital certificates, comprising:

a plurality of client devices, with each of the plurality of client devices being connected to a network and having a digital certificate to encrypt communications;

a certificate authority device programmed to issue digital certificates;

a registration authority programmed to provide verification services for the certificate authority;

a database storing a keystore profile for one or more of the plurality of client devices; and

a central enrollment device, the central enrollment device being in communication with the plurality of client devices through the network, the central enrollment device including a processor and memory encoding instructions which, when executed by the processor, causes the central enrollment device to:

communicate with a key management agent on each of the plurality of client devices;

monitor a status of the digital certificate for each of the plurality of client devices;

obtain new digital certificates from the certificate authority device;

pursuant to the central enrollment device automatically determining that the digital certificate is expiring, allow the central enrollment device to initiate issue or update of the digital certificate on each of the plurality of client devices upon expiration with one of the new digital certificates, thereby automating certificate management through centralization to minimize undesired expiration;

at a pre-assigned schedule based on rules set forth by the central enrollment device, receive requests for a renewal key from the key management agent associated with at least one of the plurality of client devices; and

when the renewal key is available and upon request from the key management agent, transmit the renewal key to the key management agent for download.

18. The system of claim 17 , wherein the memory encodes further instructions which, when executed by the processor, causes the central enrollment device to communicate with the key management agent on each of the plurality of client devices to delete, revoke, suspend, or reissue the digital certificate.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071657/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2019
From: PELTON, DOUGLAS; SHERZAI, WAEED; LI, CATHERINE; SCHWARTZ, RUVEN
To: WELLS FARGO BANK, N.A.
Reel/Frame 049935/0654 →
Continuity (5)
Continuation 15461724 · Mar 17, 2017
Continuation 14158513 · Jan 17, 2014
Division 13612355 · Sep 12, 2012
Division 11270788 · Nov 8, 2005
Provisional Application 60667186 · Mar 30, 2005
Cited By (3)
US 12,418,521 US 12,562,966 US 12,719,850