IP Library Granted Patent US 11,722,477
Granted Patent B2
US 11,722,477 · App. 16/747,792 · Granted Aug 8, 2023

Automated renewal of certificates across a distributed computing security system

Inventors: Luis Diogo Monteiro Duarte Couto (Cork, IE); Ciarán James Dorney (Cork, IE); Ralph Hans Depping (Cork, IE); Jordan Smith (Cork, IE); Finbar O'Mahony (Cork, IE)
Assignee: FORCEPOINT LLC
H04L63/0823H04L9/3263H04L63/0281H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,477
App. No.
16/747,792
Granted
Aug 8, 2023
Kind
B2
Abstract

A system for data processing, comprising a plurality of data processing systems, each associated with a user and having an anchor certificate, a proxy system operating on a processor and configured to determine whether an expiration associated with the anchor certificate for each data processing system is within a predetermined time of expiration and a certificate expiration monitor operating on the processor and configured to generate a certificate signing request in response to the determination that the expiration associated with the anchor certificate for each data processing system is within the predetermined time of expiration.

Claims (26)

1. A system for data processing, comprising:

a plurality of data processing systems, each associated with a user and having an anchor certificate;

a proxy system operating on a processor and configured to interact with each of the plurality of data processing systems to provide a firewall function to allow each of the plurality of data processing systems to access a public network, the proxy system further configured to determine whether an expiration associated with the anchor certificate for each data processing system is within a predetermined time of expiration as part of the firewall function, wherein the proxy system is configured to determine a validity of the anchor certificate for each data processing system, to automatically renew the anchor certificate for each data processing system, to replace a previous anchor certificate with the renewed anchor certificate after determining the validity of the anchor certificate and to provide a firewall function; and

a certificate expiration monitor operating on the processor and configured to generate a certificate signing request in response to the determination that the expiration associated with the anchor certificate for each data processing system is within the predetermined time of expiration.

2. The system of claim 1 wherein each data processing system is configured to receive a new anchor certificate from a firewall system and to replace a previous anchor certificate with the new anchor certificate.

3. The system of claim 1 wherein the proxy system comprises means to receive a new anchor certificate from a firewall system for each data processing system and to replace a previous anchor certificate with the new anchor certificate to perform a firewall function.

4. The system of claim 1 wherein the proxy system is operated by a firewall system and controls access to the plurality of data processing systems, and the proxy system is configured to determine a validity of the anchor certificate for each data processing system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate prior to allowing data communications with each data processing system.

5. The system of claim 1 wherein the proxy system is configured to determine a validity of the anchor certificate for each data processing system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate and a Certificate Revocation List (CRL) Profile.

6. A method for data processing, comprising:

receiving an anchor certificate from each of a plurality of data processing systems as part of a firewall function, wherein each data processing system is associated with a user, determining a validity of the anchor certificate for each data processing system and automatically renewing the anchor certificate for each data processing system;

determining with a proxy system operating on a processor whether an expiration associated with the anchor certificate for each data processing system is within a predetermined time of expiration prior to performing the firewall function; and

generating a certificate signing request with a certificate expiration monitor operating on the processor in response to the determination that the expiration associated with the anchor certificate for each data processing system is within the predetermined time of expiration prior to allowing each data processing system to access a public network, to replace a previous anchor certificate with the renewed anchor certificate after determining the validity of the anchor certificate.

7. The method of claim 6 further comprising:

preventing access by each data processing system to an external network if the expiration associated with the anchor certificate for each data processing system is within the predetermined time of expiration; and

allowing access by each data processing system to the external network after replacing the previous anchor certificate with the renewed anchor certificate.

8. The method of claim 6 further comprising:

preventing access to one of the data processing systems if the anchor certificate for that data processing system is invalid.

9. The method of claim 6 further comprising determining a validity of the anchor certificate for each data processing system using the proxy system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate and preventing access to one of the data processing systems if the anchor certificate for that data processing system is invalid until a new anchor certificate is received.

10. The method of claim 6 further comprising determining a validity of the anchor certificate for each data processing system wherein the proxy system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate and a Certificate Revocation List (CRL) Profile.

11. A data memory device storing algorithmic instructions that cause a processor to perform the steps of:

receiving an anchor certificate from each of a plurality of data processing systems prior to allowing access to a public network for each of the plurality of data processing systems, wherein each data processing system is associated with a user, determining a validity of the anchor certificate for each data processing system and automatically renewing the anchor certificate for each data processing system;

determining with a proxy system operating on a processor whether an expiration associated with the anchor certificate for each data processing system is within a predetermined time of expiration prior to allowing access to the public network for each of the plurality of data processing systems; and

generating a certificate signing request with a certificate expiration monitor operating on the processor in response to the determination that the expiration associated with the anchor certificate for each data processing system is within the predetermined time of expiration prior to allowing access to the public network for each of the plurality of data processing systems, to replace a previous anchor certificate with the renewed anchor certificate after determining the validity of the anchor certificate.

12. The data memory device of claim 11 wherein the algorithmic instructions further comprise determining a validity of the anchor certificate for each data processing system using the proxy system as part of firewall processing for each data processing system.

13. The data memory device of claim 11 wherein the algorithmic instructions further comprise determining a validity of the anchor certificate for each data processing system using the proxy system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate.

14. The data memory device of claim 11 wherein the algorithmic instructions further comprise determining a validity of the anchor certificate for each data processing system wherein the proxy system in accordance with RFC 5280 Internet X.509 Public Key Infrastructure Certificate and a Certificate Revocation List (CRL) Profile.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2020
From: COUTO, LUIS DIOGO MONTEIRO DUARTE; DORNEY, CIARÁN JAMES; DEPPING, RALPH HANS; SMITH, JORDAN; O'MAHONY, FINBAR
To: FORCEPOINT LLC
Reel/Frame 051567/0623 →