IP Library Granted Patent US 12,418,521
Granted Patent B2
US 12,418,521 · App. 18/243,992 · Granted Sep 16, 2025

Systems and methods for distributed agent-based monitoring of cryptographic key stores

Inventor: Ashutosh Bajpai (Haryana, IN)
Assignee: BANK OF AMERICA CORPORATION
H04L63/0823H04L9/0877
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,521
App. No.
18/243,992
Granted
Sep 16, 2025
Kind
B2
Abstract

Systems, computer program products, and methods are described herein for agent-based monitoring of cryptographic key stores. The present disclosure is configured for receiving a digital certificate request from a requesting entity, interfacing with a certificate manager service configured to store a database for tracking lifecycle of digital certificates, generating and disseminating a notification of a certificate event to designated recipients via real-time communication mechanisms, utilizing a specialized engine as an agent to capture and analyze events related to certificate requests and generate alerts via a specified communication medium, integrating the specialized engine and enterprise infrastructure units via a series of remote procedure calls and secure file transfers, transmitting serialized data packets to an incident response management (IRM) system, noting security parameters and interpreting incoming data for potential anomalies; and sending a process requests to an end user interface.

Claims (41)

1. A system for agent-based monitoring of cryptographic key stores, the system comprising:

a processing device;

a non-transitory storage device containing instructions when executed by the processing device, causes the processing device to perform the steps of:

receiving a digital certificate request from a requesting entity;

interfacing with a certificate manager service configured to store a database for tracking lifecycle of digital certificates;

generating and disseminating a notification of a certificate event to designated recipients via real-time communication mechanisms;

utilizing a specialized engine as an agent to capture and analyze events related to certificate requests and generate alerts via a specified communication medium;

integrating the specialized engine and enterprise infrastructure units via a series of remote procedure calls and secure file transfers, wherein integrating the specialized engine and the enterprise infrastructure units further comprises utilizing a hardware security module (HSM), application server, and web server, via the series of remote procedure calls and secure file transfers;

transmitting serialized data packets to an incident response management (IRM) system noting security parameters and interpreting incoming data for potential anomalies; and

sending a process request to an end user interface, allowing for an end user to engage in certificate installations and configurations.

2. The system of claim 1 , wherein sending a process request to the end user interface, allowing for the end user to engage in certificate installations and configurations further comprises communicating feedback or alterations back to the specialized engine, closing a loop on automated certificate management flow.

3. The system of claim 1 , wherein the certificate event further comprises a certificate expiration.

4. The system of claim 1 , wherein the specialized engine utilizes a containerized microservices architecture.

5. The system of claim 1 , wherein the specialized engine is further configured to direct the digital certificate request to one of an internal certificate authority and an external certificate authority via secure communication channels.

6. The system of claim 1 , further comprising allowing the end user to engage with the specialized engine through an adaptable web interface.

7. A computer program product for agent-based monitoring of cryptographic key stores, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to:

receive a digital certificate request from a requesting entity;

interface with a certificate manager service configured to store a database for tracking lifecycle of digital certificates;

generate and disseminate a notification of a certificate event to designated recipients via real-time communication mechanisms;

utilize a specialized engine as an agent to capture and analyze events related to certificate requests and generate alerts via a specified communication medium;

facilitate integration and communication between the specialized engine and enterprise infrastructure units via a series of remote procedure calls and secure file transfers, wherein integrating the specialized engine and the enterprise infrastructure units further comprises utilizing a hardware security module (HSM), application server, and web server, via the series of remote procedure calls and secure file transfers;

transmit serialized data packets to an incident response management (IRM) system noting security parameters and interpreting incoming data for potential anomalies; and

send a process request to an end user interface, allowing for an end user to engage in certificate installations and configurations.

8. The computer program product of claim 7 , wherein sending a process request to the end user interface, allowing for the end user to engage in certificate installations and configurations further comprises communicating feedback or alterations back to the specialized engine, closing a loop on automated certificate management flow.

9. The computer program product of claim 7 , wherein the certificate event further comprises a certificate expiration.

10. The computer program product of claim 7 , wherein the specialized engine utilizes a containerized microservices architecture.

11. The computer program product of claim 7 , wherein the specialized engine is further configured to direct the digital certificate request to one of an internal certificate authority and an external certificate authority via secure communication channels.

12. The computer program product of claim 7 , further comprising allowing the end user to engage with the specialized engine through an adaptable web interface.

13. A method for agent-based monitoring of cryptographic key stores, the method comprising:

receiving a digital certificate request from a requesting entity;

interfacing with a certificate manager service configured to store a database for tracking lifecycle of digital certificates;

generating and disseminating a notification of a certificate event to designated recipients via real-time communication mechanisms;

utilizing a specialized engine as an agent to capture and analyze events related to certificate requests and generate alerts via a specified communication medium;

integrating the specialized engine and enterprise infrastructure units via a series of remote procedure calls and secure file transfers, wherein integrating the specialized engine and the enterprise infrastructure units further comprises utilizing a hardware security module (HSM), application server, and web server, via the series of remote procedure calls and secure file transfers;

transmitting serialized data packets to an incident response management (IRM) system noting security parameters and interpreting incoming data for potential anomalies; and

sending a process request to an end user interface, allowing for an end user to engage in certificate installations and configurations.

14. The method of claim 13 , wherein the method further comprises:

sending a process request to the end user interface, allowing for the end user to engage in certificate installations and configurations further comprises communicating feedback or alterations back to the specialized engine, closing a loop on automated certificate management flow.

15. The method of claim 13 , wherein the certificate event further comprises a certificate expiration.

16. The method of claim 13 , wherein the specialized engine utilizes a containerized microservices architecture.

17. The method of claim 13 , wherein the specialized engine is further configured to direct the digital certificate request to one of an internal certificate authority and an external certificate authority via secure communication channels.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: BAJPAI, ASHUTOSH
To: BANK OF AMERICA CORPORATION
Reel/Frame 064848/0086 →
Continuity (1)
Related Publication 20250088497A1 · Mar 13, 2025
References Cited (32)
US 6934393B2 · Aull · 2005 [cited by applicant]
US 7493486B1 · Jacobs · 2009 [cited by applicant]
US 7647494B2 · Wray · 2010 [cited by applicant]
US 8767965B2 · Di Crescenzo · 2014 [cited by applicant]
US 9614833B1 · Rao · 2017 [cited by examiner]
US 9954848B1 · Stoica · 2018 [cited by examiner]
US 10326754B2 · Newton · 2019 [cited by applicant]
US 10380362B2 · Nix · 2019 [cited by applicant]
US 10547457B1 · Duccini · 2020 [cited by examiner]
US 10764313B1 · Mushtaq · 2020 [cited by examiner]
US 11477011B1 · Pelton · 2022 [cited by examiner]
US 11930123B2 · Simplicio, Jr. · 2024 [cited by examiner]
US 20020178354A1 · Ogg · 2002 [cited by applicant]
US 20040111607A1 · Yellepeddy · 2004 [cited by applicant]
US 20050114367A1 · Serebrennikov · 2005 [cited by applicant]
US 20070214357A1 · Baldus · 2007 [cited by applicant]
US 20110167258A1 · Schibuk · 2011 [cited by applicant]
US 20110197061A1 · Chou · 2011 [cited by applicant]
US 20120331288A1 · Kapoor · 2012 [cited by applicant]
US 20130339743A1 · Hada · 2013 [cited by applicant]
US 20140325231A1 · Hook · 2014 [cited by applicant]
US 20140351581A1 · Pritikin · 2014 [cited by applicant]
US 20200028842A1 · Leiserson · 2020 [cited by examiner]
US 20200044869A1 · Lutz · 2020 [cited by applicant]
US 20200235939A1 · Obaidi · 2020 [cited by examiner]
US 20210006417A1 · Pala · 2021 [cited by applicant]
US 20210029151A1 · Brooks · 2021 [cited by examiner]
US 20210209593A1 · Trujillo · 2021 [cited by applicant]
US 20210306156A1 · Madineni · 2021 [cited by applicant]
US 20240291865A1 · Mikolajczyk · 2024 [cited by examiner]
US 20240380745A1 · Patil · 2024 [cited by examiner]
US 20240414144A1 · Chirala · 2024 [cited by examiner]