IP Library Granted Patent US 11,595,358
Granted Patent B2
US 11,595,358 · App. 17/224,630 · Granted Feb 28, 2023

Two-way secure channels with certification by one party

Inventors: Anurag Sharma (Cedar Park, TX); Yedidia Atzmony (Zichron Yaakov, IL); Shoham Levy (Ra'anana, IL); Joji John (Bangalore, IN); Eric Dequin (Montigny le Bretonneux, FR)
Assignee: EMC IP Holding Company LLC
H04L63/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,358
App. No.
17/224,630
Granted
Feb 28, 2023
Kind
B2
Abstract

Two-way secure channels are provided between two parties to a communication with certification being provided by one party. One method comprises providing, by a first entity that provides a certificate authority, a first signed certificate to a second entity, wherein the first signed certificate is signed by the certificate authority and wherein the second entity generates a first request to sign a second certificate generated by the second entity, wherein the first request is generated by the second entity using a first credential generated by the second entity; receiving, from the second entity, (i) the first request to sign the second certificate, and (ii) the first signed certificate; and providing, in response to the certificate authority verifying the first signed certificate, a second signed certificate, signed by the certificate authority, to the second entity; wherein one or more additional communications between the first entity and the second entity use the two-way channel.

Claims (35)

1. A method, comprising:

providing, by a first entity of a communication, wherein the first entity provides a certificate authority for the communication, a first signed certificate to a second entity of the communication, wherein the first signed certificate is signed by the certificate authority and wherein the second entity generates a first certificate signing request to sign a second certificate generated by the second entity, wherein the first certificate signing request is generated by the second entity using at least a portion of a first credential generated by the second entity;

receiving, by the first entity from the second entity over a two-way channel, (i) the first certificate signing request to sign the second certificate, and (ii) the first signed certificate; and

providing, by the first entity, in response to the certificate authority verifying the first signed certificate, a second signed certificate, signed by the certificate authority, to the second entity;

wherein one or more additional communications between the first entity and the second entity use the two-way channel;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 , wherein the first signed certificate is based at least in part on a private key shared by the first entity and the second entity, and wherein the second signed certificate is based at least in part on a private key of the second entity.

3. The method of claim 1 , wherein the providing the first signed certificate to the second entity further comprises generating a second certificate signing request for the second entity; providing the second certificate signing request to the certificate authority; and obtaining the first signed certificate for the second entity from the certificate authority.

4. The method of claim 1 , wherein the providing the first signed certificate to the second entity further comprises providing one or more of a one-time credential of the second entity, a certificate of the first entity and a network address of the first entity to the second entity.

5. The method of claim 1 , wherein the first signed certificate for the second entity comprises one or more of (i) a revocable certificate, (ii) a limited purpose certificate that may only be used for one or more defined operations, and (iii) a certificate that expires in response to a predefined expiration time or a predefined expiration event.

6. The method of claim 1 , further comprising performing one or more remedial actions in response to detecting an anomalous use of the first signed certificate.

7. The method of claim 1 , wherein the first credential comprises one or more of a public key/private key pair, an authentication token, and a username/password pair.

8. The method of claim 1 , further comprising revoking, by the first entity, the first signed certificate in response to the providing the second signed certificate to the second entity.

9. The method of claim 1 , wherein the first credential is not communicated between the first entity and the second entity.

10. The method of claim 1 , wherein the first entity and the second entity are part of a cluster having a dynamically changing number of members.

11. The method of claim 1 , wherein the first signed certificate is based at least in part on a one-time secret of the second entity and wherein the second certificate is based at least in part on a second secret of the second entity.

12. An apparatus comprising:

at least one processing device of a first entity of a communication that provides a certificate authority for the communication, wherein the at least one processing device comprises a processor coupled to a memory;

the at least one processing device of the first entity being configured to implement the following steps:

providing a first signed certificate to a second entity of the communication, wherein the first signed certificate is signed by the certificate authority and wherein the second entity generates a first certificate signing request to sign a second certificate generated by the second entity, wherein the first certificate signing request is generated by the second entity using at least a portion of a first credential generated by the second entity;

receiving, from the second entity over a two-way channel, (i) the first certificate signing request to sign the second certificate, and (ii) the first signed certificate; and

providing, in response to the certificate authority verifying the first signed certificate, a second signed certificate, signed by the certificate authority, to the second entity;

wherein one or more additional communications between the first entity and the second entity use the two-way channel.

13. The apparatus of claim 12 , wherein the providing the first signed certificate to the second entity further comprises generating a second certificate signing request for the second entity; providing the second certificate signing request to the certificate authority; and obtaining the first signed certificate for the second entity from the certificate authority.

14. The apparatus of claim 12 , wherein the first signed certificate for the second entity comprises one or more of (i) a revocable certificate, (ii) a limited purpose certificate that may only be used for one or more defined operations, and (iii) a certificate that expires in response to a predefined expiration time or a predefined expiration event.

15. The apparatus of claim 12 , further comprising revoking, by the first entity, the first signed certificate in response to the providing the second signed certificate to the second entity.

16. The apparatus of claim 12 , wherein the first credential is not communicated between the first entity and the second entity.

17. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device, of a first entity of a communication that provides a certificate authority for the communication, causes the at least one processing device to perform the following steps:

providing, by a first entity of a communication that provides a certificate authority for the communication, a first signed certificate to a second entity of the communication, wherein the first signed certificate is signed by the certificate authority and wherein the second entity generates a first certificate signing request to sign a second certificate generated by the second entity, wherein the first certificate signing request is generated by the second entity using at least a portion of a first credential generated by the second entity;

receiving, from the second entity over a two-way channel, (i) the first certificate signing request to sign the second certificate, and (ii) the first signed certificate; and

providing, in response to the certificate authority verifying the first signed certificate, a second signed certificate, signed by the certificate authority, to the second entity;

wherein one or more additional communications between the first entity and the second entity use the two-way channel.

18. The non-transitory processor-readable storage medium of claim 17 , wherein the first signed certificate for the second entity comprises one or more of (i) a revocable certificate, (ii) a limited purpose certificate that may only be used for one or more defined operations, and (iii) a certificate that expires in response to a predefined expiration time or a predefined expiration event.

19. The non-transitory processor-readable storage medium of claim 17 , further comprising revoking, by the first entity, the first signed certificate in response to the providing the second signed certificate to the second entity.

20. The non-transitory processor-readable storage medium of claim 17 , wherein the first credential is not communicated between the first entity and the second entity.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2021
From: SHARMA, ANURAG; ATZMONY, YEDIDIA; LEVY, SHOHAM; JOHN, JOJI; DEQUIN, ERIC
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055854/0590 →