IP Library Granted Patent US 12,149,639
Granted Patent B2
US 12,149,639 · App. 18/178,349 · Granted Nov 19, 2024

Securely rotating a server certificate

Inventors: Jeromy Scott Statia (Arlington, WA); Chunsheng Yang (Bellevue, WA); Priyanka Vilas Deo (Redmond, WA); Elizabeth Anne Phippen (Bothell, WA); Bradley Scott Turner (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L9/3268H04L9/3265H04L63/08H04L67/51
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,149,639
App. No.
18/178,349
Granted
Nov 19, 2024
Kind
B2
Abstract

The present disclosure relates to systems, methods, and computer-readable media for enhancing security of communications between instances of clients and servers while enabling rotation of server certificates (e.g., X.509 certificates). The systems described herein involve updating a client list of server certificates (e.g., a certificate thumbprint) without reconfiguring or re-installing a client and/or server application, starting a new session (e.g., a hypertext transfer protocol secure (HTTPS) session), or deploying new code. The systems described herein may passively or actively update a client list of certificates to enable a client to security verify an identity of a server instance in a non-invasive way that boosts security from man-in-the-middle types of attacks.

Claims (35)

1. A method performed by a discovery endpoint on a computing device, the method comprising:

providing, from the discovery endpoint to a client, an initial client list of one or more server certificates associated with verifying an identify of a server instance;

generating, at the discovery endpoint, a current list of server certificates based on the initial client list and a new server certificate received from the server instance, the new server certificate being a server certificate currently in use by the server instance;

receiving, at the discovery endpoint from the client, a request for the current list of server certificates associated with verifying the identity of the server instance; and

providing, from the discovery endpoint to the client responsive to the request for the current list, a data object including the current list of server certificates, the data object being cryptographically signed by a server certificate from the one or more server certificates of the initial client list.

2. The method of claim 1 , wherein the initial client list corresponds to a list of valid server certificates for the server instance corresponding to an initiation of a session between the client and the server instance.

3. The method of claim 1 , wherein the initial client list corresponds to a previous iteration of the current list of server certificates prior to generating the current list of server certificates.

4. The method of claim 1 , wherein the new server certificate is a server certificate issued to the server instance by a certificate authority.

5. The method of claim 1 , wherein the request for the current list is based on the client device receiving the new server certificate from the server instance and failing to identify the new server certificate within the initial client list previously provided to the client.

6. The method of claim 1 , further comprising generating the data object by cryptographically signing the data object with the server certificate included within the initial client list.

7. The method of claim 1 , wherein the request for the current list is a hypertext transfer protocol secure (HTTPS) call, and wherein the data object is provided in response to the HTTPS call.

8. The method of claim 1 , wherein the initial client list includes a root list of one or more X.509 v3 digital certificates owned or previously owned by the server instance, and wherein the updated client list includes the root list of one or more X.509 v3 digital certificates and one or more additional X.509 v3 digital certificates associated with the server instance.

9. A method performed by a server device having a discovery endpoint and a server instance implemented thereon, the method comprising:

providing, from the server device to a client, an initial client list of one or more server certificates trusted by the client and associated with verifying an identity of a server instance;

providing, from the server device to the client responsive to a session initiation request, a session request response including a current server certificate currently in use by the server instance, the current server certificate being associated with verifying the identity of the server instance;

receiving, at the server device from the client, a request for a current list of server certificates associated with verifying the identity of the server instance, the current list of server certificates being an updated list of server certificates; and

providing, from the server device to the client, a data object including the current list of server certificates, the data object being cryptographically signed by a server certificate from the one or more server certificates from the initial client list.

10. The method of claim 9 , wherein the initial client list corresponds to a list of valid server certificates for the server instance corresponding to an initiation of a session between the client and the server instance.

11. The method of claim 9 , wherein the initial client list corresponds to a previous iteration of the current list of server certificates prior to updating the current list of server certificates to include the current server certificate.

12. The method of claim 9 , wherein the current server certificate is a server certificate issued to the server instance by a certificate authority.

13. The method of claim 9 , wherein the request for the current list is based on the client device receiving the current certificate within the session request response and failing to identify the current certificate within the initial client list previously provided to the client.

14. The method of claim 9 , further comprising generating the data object by cryptographically signing the data object with the certificate included within the initial client list.

15. The method of claim 9 , wherein the request for the current list is a hypertext transfer protocol secure (HTTPS) call, and wherein the data object is provided in response to the HTTPS call.

16. The method of claim 9 , wherein the initial client list includes a root list of one or more X.509 v3 digital certificates owned or previously owned by the server instance, and wherein the current list of server certificates includes the root list of one or more X.509 v3 digital certificates and one or more additional X.509 v3 digital certificates associated with the server instance.

17. A system, comprising:

at least one processor;

memory in electronic communication with the at least one processor; and

instructions stored in the memory, the instructions being executable by the at least one processor to cause a discovery endpoint to:

provide, to a client, an initial client list of one or more server certificates associated with verifying an identify of a server instance;

generate a current list of server certificates based on the initial client list and a new server certificate received from the server instance, the new server certificate being a server certificate currently in use by the server instance;

receiver, from the client, a request for the current list of server certificates associated with verifying the identity of the server instance; and

provide, to the client responsive to the request for the current list, a data object including the current list of server certificates, the data object being cryptographically signed by a server certificate from the one or more server certificates of the initial client list.

18. The system of claim 17 , wherein the initial client list corresponds to a list of valid server certificates for the server instance corresponding to an initiation of a session between the client and the server instance.

19. The system of claim 17 , further comprising instructions being executable by the at least one processor to cause the discover endpoint to generate the data object by cryptographically signing the data object with the server certificate included within the initial client list.

20. The system of claim 17 , wherein the request for the current list is a hypertext transfer protocol secure (HTTPS) call, and wherein the data object is provided in response to the HTTPS call.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2023
From: STATIA, JEROMY SCOTT; YANG, CHUNSHENG; DEO, PRIYANKA VILAS; PHIPPEN, ELIZABETH ANNE; TURNER, BRADLEY SCOTT
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 062880/0734 →
Continuity (2)
Continuation 16736758 · Jan 7, 2020
Related Publication 20230208655A1 · Jun 29, 2023