IP Library Granted Patent US 11,764,979
Granted Patent B2
US 11,764,979 · App. 17/334,375 · Granted Sep 19, 2023

Customer-controlled authentication

Inventor: Ashton Mozano (San Diego, CA)
Assignee: ServiceNow, Inc.
H04L9/3268G06F21/33H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,764,979
App. No.
17/334,375
Granted
Sep 19, 2023
Kind
B2
Abstract

A certificate credential and an associated signature is received. The certificate credential and the associated signature are authenticated at an operating system level. Whether the certificate credential has expired is validated at an application level via an external certificate authority. Access to encrypted data is allowed based at least in part on the authentication and the validation of the certificate credential.

Claims (39)

1. A method, comprising:

receiving a certificate credential of a client and an associated signature;

authenticating the certificate credential and the associated signature at an operating system level using a private key of the client and using a listing of approved clients, each client of the approved clients having corresponding specified one or more allowed level of application service access;

in response to the authentication of the certificate credential, triggering an application level validation of the certificate credential;

validating at an application level via an external certificate authority whether the certificate credential has expired; and

allowing access to encrypted data allowed by the corresponding specified one or more allowed level of application service access associated with the certificate credential of the client based at least in part on the authentication and the validation of the certificate credential.

2. The method of claim 1 , wherein the certificate credential identifies a client Internet Protocol (IP) address or client hostname.

3. The method of claim 1 , wherein the associated signature includes a digital signature of the external certificate authority.

4. The method of claim 1 , wherein authenticating the certificate credential and the associated signature at the operating system level is performed as part of establishing a network connection with the client.

5. The method of claim 4 , wherein the certificate credential and the associated signature are received from the client via the network connection with the client.

6. The method of claim 1 , wherein an application system performs the validating of whether the certificate credential has expired.

7. The method of claim 6 , wherein the application system is a database system, an email system, or a file sharing system.

8. The method of claim 1 , further comprising configuring at the operating system level a requirement that authentication is performed using a client certificate.

9. The method of claim 1 , further comprising configuring at the application level a requirement that authentication is performed at the operating system level using a client certificate.

10. The method of claim 1 , wherein validating at the application level via the external certificate authority whether the certificate credential has expired includes receiving at the application level the certificate credential and the associated signature from a security module implemented at the operating system level.

11. A system, comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

receive a certificate credential of a client and an associated signature;

authenticate the certificate credential and the associated signature at an operating system level using a private key of the client and using a listing of approved clients, each client of the approved clients having corresponding specified one or more allowed level of application service access;

in response to the authentication of the certificate credential, trigger an application level validation of the certificate credential;

validate at an application level via an external certificate authority whether the certificate credential has expired; and

allow access to encrypted data allowed by the corresponding specified one or more allowed level of application service access associated with the certificate credential of the client based at least in part on the authentication and the validation of the certificate credential.

12. The system of claim 11 , wherein the certificate credential identifies a client Internet Protocol (IP) address or client hostname.

13. The system of claim 11 , wherein the associated signature includes a digital signature of the external certificate authority.

14. The system of claim 11 , wherein causing the one or more processors to authenticate the certificate credential and the associated signature at the operating system level includes establishing a network connection with the client.

15. The system of claim 14 , wherein the certificate credential and the associated signature are received from the client via the network connection with the client.

16. The system of claim 11 , wherein an application system causes the one or more processors to validate at the application level via the external certificate authority whether the certificate credential has expired.

17. The system of claim 16 , wherein the application system is a database system, an email system, or a file sharing system.

18. The system of claim 11 , wherein the memory is further configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

configure at the operating system level a requirement that authentication is performed using a client certificate.

19. The system of claim 11 , wherein the memory is further configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

configure at the application level a requirement that authentication is performed at the operating system level using a client certificate.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a certificate credential of a client and an associated signature;

authenticating the certificate credential and the associated signature at an operating system level using a private key of the client and using a listing of approved clients, each client of the approved clients having corresponding specified one or more allowed level of application service access;

in response to the authentication of the certificate credential, triggering an application level validation of the certificate credential;

validating at an application level via an external certificate authority whether the certificate credential has expired; and

allowing access to encrypted data allowed by the corresponding specified one or more allowed level of application service access associated with the certificate credential of the client based at least in part on the authentication and the validation of the certificate credential.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2021
From: MOZANO, ASHTON
To: SERVICENOW, INC.
Reel/Frame 057107/0659 →
Continuity (1)
Related Publication 20220385482A1 · Dec 1, 2022