IP Library › Granted Patent US 12,615,247
Granted Patent B2
US 12,615,247 · App. 18/230,920 · Granted Apr 28, 2026

Wildcard-free certificates for network address domains

Inventor: Yogesh Patil (Davis, CA)
Assignee: eBay Inc.
H04L63/0823H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,247
App. No.
18/230,920
Granted
Apr 28, 2026
Kind
B2
Abstract

Generating an access point certificate based on a graph that defines relationships between an access point and at least one domain is described. Relationship data describing how data is to be routed between an access point and domains is received by a certificate management system. The certificate management system generates a graph representing an access point and associated domains as nodes, with edges connecting various nodes to model relationships between the access point and the associated domains. Based on the graph, a certificate is generated that individually lists each domain associated with the access point and includes information describing data routing for the domain via the access point. The certificate excludes wildcard entries that represent multiple domains via a single entry. The certificate is used to control data communication traffic via the access point and is updated responsive to changes in in domain relationship data for the access point.

Claims (36)

1 . A method comprising:

generating, by a computing device, a graph that defines relationships between a network address and a plurality of different domains, the graph comprising a plurality of nodes that each represent a corresponding one of the plurality of different domains or the network address;

generating, by the computing device, a first certificate for the network address based on the graph, the first certificate listing each of the plurality of nodes in the graph that identify corresponding ones of the plurality of different domains as separate certificate entries;

controlling access to the network address using the first certificate;

detecting, by the computing device, a change to at least one of the relationships between the network address and one or more of the plurality of different domains;

generating, by the computing device, a modified graph based on the change to the at least one of the relationships;

generating, by the computing device, a second certificate for the network address based on the modified graph, the second certificate listing individual nodes in the modified graph as separate certificate entries; and

controlling access to the network address using the second certificate instead of the first certificate.

2 . The method of claim 1 , wherein generating the first certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.

3 . The method of claim 1 , wherein generating the second certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.

4 . The method of claim 1 , wherein the network address is served by multiple providers that comprise a first provider hosted by an entity and a second provider hosted by a content delivery network that is different than the entity, wherein the first provider is represented in the graph by a first node and the second provider is represented in the graph by a second node.

5 . The method of claim 4 , wherein each of the plurality of nodes that represent the plurality of different domains is connected by a link to the first node or the second node in the graph.

6 . The method of claim 1 , wherein the network address is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.

7 . The method of claim 1 , wherein detecting the change to the at least one of the relationships is performed based on data received from a listener at the network address that describes at least one configuration change for one or more of the plurality of different domains.

8 . The method of claim 1 , wherein detecting the change to the at least one of the relationships is performed in response to detecting expiration of the first certificate.

9 . A system comprising:

at least one processor; and

a computer-readable storage medium storing instructions that are executable by the at least one processor to perform operations comprising:

generating a graph that defines relationships between a network address and at least one domain, the graph comprising a plurality of nodes that each represent a corresponding domain of the at least one domain or the network address;

generating a first certificate for the network address using the graph, the first certificate listing each of the plurality of nodes in the graph that identify corresponding ones of the at least one domain as separate certificate entries;

responsive to a change to a relationship between the network address and the at least one domain, generating a modified graph based on the change to the relationship between the network address and the at least one domain; and

generating a second certificate for the network address using the modified graph, the second certificate listing individual nodes in the modified graph as separate certificate entries.

10 . The system of claim 9 , wherein generating the first certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.

11 . The system of claim 9 , wherein generating the second certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.

12 . The system of claim 9 , wherein the network address is served by multiple providers that comprise a first provider hosted by a first entity and a second provider hosted by a second entity that is different than the first entity, wherein the first provider is represented in the graph by a first node and the second provider is represented in the graph by a second node.

13 . The system of claim 12 , wherein the graph further comprises at least one node that represents a corresponding one of the at least one domain associated with the first entity or the second entity, wherein each node of the at least one node is connected by a link to the first node or the second node in the graph.

14 . The system of claim 9 , wherein the network address is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.

15 . The system of claim 9 , the operations further comprising detecting the change to the relationship based on data, generated by a listener at the network address, that describes at least one configuration change for the at least one domain.

16 . The system of claim 9 , the operations further comprising detecting the change to the relationship responsive to an expiration of the first certificate.

17 . The system of claim 9 , the operations further comprising controlling access to the network address using the second certificate instead of the first certificate.

18 . A method comprising:

receiving, at an access point, a certificate generated from a graph that defines relationships between the access point and a plurality of domains, each of the plurality of domains being represented as a separate node in the graph and being listed in the certificate as a separate certificate entry;

receiving, from a device, a request to access data via at least one of the plurality of domains; and

responsive to authenticating the device using the certificate, controlling data transfer between the at least one of the plurality of domains and the device based on the relationships between the access point and the at least one of the plurality of domains.

19 . The method of claim 18 , wherein the certificate does not include a single certificate entry that comprises a character indicating multiple subdomains as being valid.

20 . The method of claim 18 , wherein the access point is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2023
From: PATIL, YOGESH
To: EBAY INC.
Reel/Frame 064510/0929 →
Continuity (1)
Related Publication 20250055839A1 · Feb 13, 2025
References Cited (58)
US 7272714B2 · Nagaratnam · 2007 [cited by examiner]
US 8977265B2 · Lee et al. · 2015 [cited by applicant]
US 9104836B2 · Burstein · 2015 [cited by examiner]
US 10389528B2 · Moysi et al. · 2019 [cited by applicant]
US 10581829B1 · Don et al. · 2020 [cited by applicant]
US 10673716B1 · Sethuramalingam et al. · 2020 [cited by applicant]
US 10681035B1 · Kincaid · 2020 [cited by examiner]
US 11204961B1 · Farber et al. · 2021 [cited by applicant]
US 11206275B2 · Nabeel et al. · 2021 [cited by applicant]
US 11425114B2 · Shubin et al. · 2022 [cited by applicant]
US 11444931B1 · Quevedo · 2022 [cited by applicant]
US 11743282B1 · Torkamani et al. · 2023 [cited by applicant]
US 20020087859A1 · Weeks · 2002 [cited by examiner]
US 20030070070A1 · Yeager et al. · 2003 [cited by applicant]
US 20030233543A1 · Nagaratnam et al. · 2003 [cited by applicant]
US 20040264697A1 · Gavrilescu et al. · 2004 [cited by applicant]
US 20110210973A1 · Di Crescenzo · 2011 [cited by examiner]
US 20120047394A1 · Jain et al. · 2012 [cited by applicant]
US 20140092726A1 · Khan et al. · 2014 [cited by applicant]
US 20150213131A1 · Styler et al. · 2015 [cited by applicant]
US 20160330164A1 · Bellan et al. · 2016 [cited by applicant]
US 20170236079A1 · Venna et al. · 2017 [cited by applicant]
US 20190044815A1 · Rosh · 2019 [cited by examiner]
US 20190205773A1 · Ackerman · 2019 [cited by examiner]
US 20200007666A1 · Amin et al. · 2020 [cited by applicant]
US 20200137094A1 · Janakiraman · 2020 [cited by applicant]
US 20200334365A1 · Buck et al. · 2020 [cited by applicant]
US 20210119962A1 · Ramia et al. · 2021 [cited by applicant]
US 20210258299A1 · Bruckner et al. · 2021 [cited by applicant]
US 20210266185A1 · Konda et al. · 2021 [cited by applicant]
US 20220103525A1 · Shribman et al. · 2022 [cited by applicant]
US 20220131852A1 · Sharma et al. · 2022 [cited by applicant]
US 20220182246A1 · Murphy et al. · 2022 [cited by applicant]
US 20220201036A1 · Nabeel et al. · 2022 [cited by applicant]
US 20220210146A1 · Dhanabalan et al. · 2022 [cited by applicant]
US 20220239696A1 · Konda et al. · 2022 [cited by applicant]
US 20220247624A1 · Johnson et al. · 2022 [cited by applicant]
US 20230179429A1 · Rosenthol · 2023 [cited by examiner]
US 20230409215A1 · Kohli et al. · 2023 [cited by applicant]
US 20240039732A1 · Luo · 2024 [cited by examiner]
US 20240106861A1 · Ahn et al. · 2024 [cited by applicant]
US 20240283809A1 · Sinha et al. · 2024 [cited by applicant]
US 20250220011A1 · Patil · 2025 [cited by applicant]
CN 106470191A · 2019 [cited by applicant]
CN 110225013A · 2021 [cited by applicant]
CN 114422170A · 2023 [cited by applicant]
CN 110537346A · 2023 [cited by applicant]
CN 120223349A · 2025 [cited by applicant]
EP 4580124A1 · 2025 [cited by applicant]
“Automated Certificate Management”, Oracle [retrieved Jun. 19, 2023]. Retrieved from the Internet <https://docs.oracle.com/en/cloud/saas/marketing/eloqua-user/Help/CertificateManagement/AutoSSLCert.htm>., 5 Pages. [cited by applicant]
“EP Search Report”, European Application No. 24220460.0, Mar. 31, 2025, 12 pages. [cited by applicant]
Anderson, et al., “Assessing and Exploiting Domain Name Misinformation”, 2023 IEEE European Symposium on Security and Privacy Workshops, 2023, 12 pages. [cited by applicant]
Shobiri, et al., “CDN's Dark Side Security Problems in CDN-to-Origin Connections”, Digital Threats: Research and Practice, vol. 4, No. 1, Articles 3, Mar. 2023, 22 pages. [cited by applicant]
Amarnani, et al., “Pursuant to MPEP § 2001.06(b) the applicant brings the following co-pending application to the Examiner's attention:”, U.S. Appl. No. 19/002,294, filed Dec. 26, 2024, 60 pages. [cited by applicant]
Das, Arindam, “Azure Front Door: Enhancing Global Application Delivery and Security”, Medium, Jul. 1, 2023, 12 pages. [cited by applicant]
Microsoft, “Mission-critical global HTTP ingress”, Apr. 19, 2023, 6 pages. [cited by applicant]
Patil, “Pursuant to MPEP § 2001.06(b) the applicant brings the following co-pending application to the Examiner's attention:”, U.S. Appl. No. 18/397,189, Dec. 27, 2023, 69 pages. [cited by applicant]
“Non-Final Office Action”, U.S. Appl. No. 18/397,189, Sep. 11, 2025, 32 pages. [cited by applicant]