IP Library Granted Patent US 12,401,526
Granted Patent B2
US 12,401,526 · App. 18/354,498 · Granted Aug 26, 2025

Updating digital certificates associated with a virtual cloud network

Inventors: Tony Long (Edmonds, WA); Sneha Sudhakaran Nair (Burnaby, CA); Burak Uzun (London, GB)
Assignee: Oracle International Corporation
H04L9/3268H04L9/3073H04L9/3247H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,526
App. No.
18/354,498
Granted
Aug 26, 2025
Kind
B2
Abstract

Techniques for updating certificate bundles may include receiving, at an entity associated with a virtual cloud network, a certificate bundle that includes an updated set of certificate authority (CA) certificates. The techniques may include applying a validation process to an entity certificate based on the certificate bundle, with the entity certificate having been issued to the entity prior to the entity receiving the certificate bundle. The validation process may include validating, by the entity, a certificate chain that includes the entity certificate and a CA certificate included in the updated set of CA certificates. The techniques may include, responsive to validating the certificate chain, installing the certificate bundle in a storage medium associated with the entity, and utilizing, by the entity, the certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

Claims (301)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

receiving, at a first entity associated with a virtual cloud network, a first certificate bundle comprising a first updated set of certificate authority (CA) certificates;

applying a validation process to a first entity certificate based on the first certificate bundle, the first entity certificate being issued to the first entity prior to the first entity receiving the first certificate bundle, wherein the validation process comprises:

validating, by the first entity, a first certificate chain comprising the first entity certificate, and a first CA certificate included in the first updated set of CA certificates;

responsive to validating the first certificate chain, installing the first certificate bundle in a first storage medium associated with the first entity, and utilizing, by the first entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

2. The medium of claim 1 ,

wherein validating the first certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is the first CA certificate from among the updated set of CA certificates.

3. The medium of claim 2 ,

wherein the set of signature-key pairs comprises a first signature-key pair and a second signature-key pair;

wherein for the first signature-key pair, the recipient certificate is the first entity certificate and the issuer certificate is a first intermediate CA certificate; and

wherein for the second signature-key pair, the recipient certificate is the first intermediate CA certificate, and the issuer certificate is one of: a first root CA certificate or a second intermediate CA certificate.

4. The medium of claim 3 ,

wherein the set of signature-key pairs comprises the first signature-key pair, the second signature-key pair, and a third signature-key pair;

wherein for the second signature-key pair, the issuer certificate is the second intermediate CA certificate; and

wherein for the third signature-key pair, the recipient certificate is the second intermediate CA certificate, and the issuer certificate is the first CA certificate.

5. The medium of claim 1 , wherein the operations further comprise:

subsequent to validating the first certificate chain, receiving, at the first entity, a second entity certificate issued to the first entity, and installing the second entity certificate in the first storage medium associated with the first entity;

receiving, at the first entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first CA certificate;

validating, by the first entity, a second certificate chain, wherein the second certificate chain comprises the second entity certificate, and a second CA certificate of the second updated set of CA certificates;

responsive to validating the second certificate chain, installing the second certificate bundle in the first storage medium associated with the first entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

6. The medium of claim 5 ,

wherein validating the second certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is the second CA certificate from among the second updated set of CA certificates.

7. The medium of claim 6 , wherein the operations further comprise:

transmitting, to a certificate bundle distribution service, a first update request;

receiving the first certificate bundle comprising the first updated set of CA certificates in response to the first update request;

subsequent to validating the first certificate chain, transmitting, to the certificate bundle distribution service, a second update request; and

receiving the second certificate bundle comprising the second updated set of CA certificates in response to the second update request.

8. The medium of claim 6 , wherein the operations further comprise:

subsequent to validating the second certificate chain, uninstalling the first entity certificate from the first storage medium associated with the first entity.

9. The medium of claim 1 , wherein the operations further comprise:

prior to receiving the first certificate bundle, receiving, at the first entity, the first entity certificate, and installing the first entity certificate in the first storage medium associated with the first entity.

10. The medium of claim 1 ,

wherein the first certificate chain comprises one or more signature-key pairs, wherein each signature-key pair of the one or more signature-key pairs respectively comprises a public key and a digital signature, and

wherein validating the first certificate chain comprises, for each signature-key pair of the one or more signature-key pairs:

computing a decryption hash value at least by decrypting the digital signature of the signature-key pair with the public key of the signature-key pair;

computing a signature hash value at least by applying a hash function to the digital signature of the signature-key pair;

comparing the decryption hash value to the signature hash value;

determining a match between the decryption hash value and the signature hash value; and

designating the first certificate chain as valid based at least in part on having determined the match between the decryption hash value and the signature hash value for each signature-key pair of the one or more signature-key pairs.

11. The medium of claim 10 , wherein the one or more signature-key pairs comprises:

an intermediate signature-key pair comprising an intermediate public key and an intermediate digital signature of an intermediate CA, the intermediate public key corresponding to an intermediate CA certificate, and the first entity certificate including the intermediate digital signature of the intermediate CA; and

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the intermediate CA certificate including the root digital signature of the root CA.

12. The medium of claim 10 , wherein the one or more signature-key pairs comprises:

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the first entity certificate including the root digital signature of the root CA.

13. The medium of claim 1 , wherein the operations further comprise:

receiving, at a second entity associated with the virtual cloud network, a second certificate bundle comprising a second updated set of CA certificates;

determining that a second certificate chain is invalid, wherein the second certificate chain comprises a second entity certificate, having been issued to the second entity, and at least one second CA certificate of the second updated set of CA certificates;

responsive to determining that the second certificate chain is invalid, rejecting the second certificate bundle, and utilizing an earlier certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

14. The medium of claim 1 , wherein the operations further comprise:

subsequent to validating the first certificate chain, receiving, at the first entity, a first certificate bundle request from an overlay entity associated with the virtual cloud network, the virtual cloud network comprising a substrate network and an overlay network, wherein the overlay entity resides on the overlay network, and wherein the first entity comprises an interface entity that provides a communication interface between the substrate network and the overlay entity;

responsive to the first certificate bundle request, transmitting from the interface entity to the overlay entity, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the overlay entity, a second certificate chain, wherein the second certificate chain comprises a first instance principal certificate, having been issued to the overlay entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the overlay entity, and utilizing, by the overlay entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

15. The medium of claim 14 , wherein the operations further comprise:

subsequent to validating the second certificate chain, receiving, at the overlay entity, a second instance principal certificate issued to the overlay entity, and installing the second instance principal certificate in the second storage medium associated with the overlay entity;

receiving, at the first entity, a second certificate bundle request from the overlay entity;

responsive to the second certificate bundle request, transmitting from the interface entity to the overlay entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second instance principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the overlay entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

16. The medium of claim 15 , wherein the operations further comprise:

subsequent to validating the third certificate chain, uninstalling the first instance principal certificate from the second storage medium associated with the overlay entity.

17. The medium of claim 15 , wherein the operations further comprise at least one of:

the first entity utilizing the second certificate bundle to authenticate the overlay entity; or

the overlay entity utilizing the second certificate bundle to authenticate the first entity.

18. The medium of claim 1 , wherein the operations further comprise:

receiving, at a substrate entity associated with the virtual cloud network, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the substrate entity, a second certificate chain, wherein the second certificate chain comprises a first service principal certificate, having been issued to the substrate entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the substrate entity, and utilizing, by the substrate entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

19. The medium of claim 18 , wherein the operations further comprise:

subsequent to validating the second certificate chain, receiving, at the substrate entity, a second service principal certificate issued to the substrate entity, and installing the second service principal certificate in the second storage medium associated with the substrate entity;

receiving, at the substrate entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the second CA certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second service principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the substrate entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

20. The medium of claim 19 , wherein the operations further comprise:

subsequent to validating the third certificate chain, uninstalling the first service principal certificate from the second storage medium associated with the substrate entity.

21. The medium of claim 19 , wherein the operations further comprise at least one of:

the first entity utilizing the second certificate bundle to authenticate the substrate entity; or

the substrate entity utilizing the second certificate bundle to authenticate the first entity.

22. The medium of claim 1 , wherein the first updated set of CA certificates further comprises a second CA certificate, wherein the first CA certificate is a prior CA certificate and the second CA certificate is a subsequent CA certificate.

23. The medium of claim 22 , wherein the first CA certificate is issued by a first CA certificate authority, and the second CA certificate is issued by a second CA certificate authority.

24. The medium of claim 1 , wherein the first entity comprises one of:

a substrate entity, an overlay entity, or an interface entity.

25. A method, comprising:

receiving, at a first entity associated with a virtual cloud network, a first certificate bundle comprising a first updated set of certificate authority (CA) certificates;

applying a validation process to a first entity certificate based on the first certificate bundle, the first entity certificate being issued to the first entity prior to the first entity receiving the first certificate bundle, wherein the validation process comprises:

validating, by the first entity, a first certificate chain comprising the first entity certificate, having been issued to the first entity, and a first CA certificate included in the first updated set of CA certificates;

responsive to validating the first certificate chain, installing the first certificate bundle in a first storage medium associated with the first entity, and utilizing, by the first entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network;

wherein the method is performed using at least one hardware device.

26. A system, comprising:

at least one hardware processor;

the system being configured to execute operations, using the at least one hardware processor, the operations comprising:

receiving, at a first entity associated with a virtual cloud network, a first certificate bundle comprising a first updated set of certificate authority (CA) certificates;

applying a validation process to a first entity certificate based on the first certificate bundle, the first entity certificate being issued to the first entity prior to the first entity receiving the first certificate bundle, wherein the validation process comprises:

validating, by the first entity, a first certificate chain comprising the first entity certificate, having been issued to the first entity, and a first CA certificate included in the first updated set of CA certificates;

responsive to validating the first certificate chain, installing the first certificate bundle in a first storage medium associated with the first entity, and utilizing, by the first entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

27. The system of claim 26 ,

wherein validating the first certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is the first CA certificate from among the updated set of CA certificates.

28. The system of claim 27 ,

wherein the set of signature-key pairs comprises a first signature-key pair and a second signature-key pair;

wherein for the first signature-key pair, the recipient certificate is the first entity certificate and the issuer certificate is a first intermediate CA certificate; and

wherein for the second signature-key pair, the recipient certificate is the first intermediate CA certificate, and the issuer certificate is one of: a first root CA certificate or a second intermediate CA certificate.

29. The system of claim 28 ,

wherein the set of signature-key pairs comprises the first signature-key pair, the second signature-key pair, and a third signature-key pair;

wherein for the second signature-key pair, the issuer certificate is the second intermediate CA certificate; and

wherein for the third signature-key pair, the recipient certificate is the second intermediate CA certificate, and the issuer certificate is the first CA certificate.

30. The system of claim 26 , wherein the operations further comprise:

subsequent to validating the first certificate chain, receiving, at the first entity, a second entity certificate issued to the first entity, and installing the second entity certificate in the first storage medium associated with the first entity;

receiving, at the first entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first CA certificate;

validating, by the first entity, a second certificate chain, wherein the second certificate chain comprises the second entity certificate, and a second CA certificate of the second updated set of CA certificates;

responsive to validating the second certificate chain, installing the second certificate bundle in the first storage medium associated with the first entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

31. The system of claim 30 ,

wherein validating the second certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is a second CA certificate from among the set of CA certificates.

32. The system of claim 31 , wherein the operations further comprise:

transmitting, to a certificate bundle distribution service, a first update request;

receiving the first certificate bundle comprising the first updated set of CA certificates in response to the first update request;

subsequent to validating the first certificate chain, transmitting, to the certificate bundle distribution service, a second update request; and

receiving the second certificate bundle comprising the second updated set of CA certificates in response to the second update request.

33. The system of claim 31 , wherein the operations further comprise:

subsequent to validating the second certificate chain, uninstalling the first entity certificate from the first storage medium associated with the first entity.

34. The system of claim 26 , wherein the operations further comprise:

prior to receiving the first certificate bundle, receiving, at the first entity, the first entity certificate, and installing the first entity certificate in the first storage medium associated with the first entity.

35. The system of claim 26 ,

wherein the first certificate chain comprises one or more signature-key pairs, wherein each signature-key pair of the one or more signature-key pairs respectively comprises a public key and a digital signature, and

wherein validating the first certificate chain comprises, for each signature-key pair of the one or more signature-key pairs:

computing a decryption hash value at least by decrypting the digital signature of the signature-key pair with the public key of the signature-key pair;

computing a signature hash value at least by applying a hash function to the digital signature of the signature-key pair;

comparing the decryption hash value to the signature hash value;

determining a match between the decryption hash value and the signature hash value; and

designating the first certificate chain as valid based at least in part on having determined the match between the decryption hash value and the signature hash value for each signature-key pair of the one or more signature-key pairs.

36. The system of claim 35 , wherein the one or more signature-key pairs comprises:

an intermediate signature-key pair comprising an intermediate public key and an intermediate digital signature of an intermediate CA, the intermediate public key corresponding to an intermediate CA certificate, and the first entity certificate including the intermediate digital signature of the intermediate CA; and

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the intermediate CA certificate including the root digital signature of the root CA.

37. The system of claim 35 , wherein the one or more signature-key pairs comprises:

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the first entity certificate including the root digital signature of the root CA.

38. The system of claim 26 , wherein the operations further comprise:

receiving, at a second entity associated with the virtual cloud network, a second certificate bundle comprising a second updated set of CA certificates;

determining that a second certificate chain is invalid, wherein the second certificate chain comprises a second entity certificate, having been issued to the second entity, and at least one second CA certificate of the second updated set of CA certificates;

responsive to determining that the second certificate chain is invalid, rejecting the second certificate bundle, and utilizing an earlier certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

39. The system of claim 26 , wherein the operations further comprise:

subsequent to validating the first certificate chain, receiving, at the first entity, a first certificate bundle request from an overlay entity associated with the virtual cloud network, the virtual cloud network comprising a substrate network and an overlay network, wherein the overlay entity resides on the overlay network, and wherein the first entity comprises an interface entity that provides a communication interface between the substrate network and the overlay entity;

responsive to the first certificate bundle request, transmitting from the interface entity to the overlay entity, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the overlay entity, a second certificate chain, wherein the second certificate chain comprises a first instance principal certificate, having been issued to the overlay entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the overlay entity, and utilizing, by the overlay entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

40. The system of claim 39 , wherein the operations further comprise:

subsequent to validating the second certificate chain, receiving, at the overlay entity, a second instance principal certificate issued to the overlay entity, and installing the second instance principal certificate in the second storage medium associated with the overlay entity;

receiving, at the first entity, a second certificate bundle request from the overlay entity;

responsive to the second certificate bundle request, transmitting from the interface entity to the overlay entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second instance principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the overlay entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

41. The system of claim 40 , wherein the operations further comprise:

subsequent to validating the third certificate chain, uninstalling the first instance principal certificate from the second storage medium associated with the overlay entity.

42. The system of claim 40 , wherein the operations further comprise at least one of:

the first entity utilizing the second certificate bundle to authenticate the overlay entity; or

the overlay entity utilizing the second certificate bundle to authenticate the first entity.

43. The system of claim 26 , wherein the operations further comprise:

receiving, at a substrate entity associated with the virtual cloud network, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the substrate entity, a second certificate chain, wherein the second certificate chain comprises a first service principal certificate, having been issued to the substrate entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the substrate entity, and utilizing, by the substrate entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

44. The system of claim 43 , wherein the operations further comprise:

subsequent to validating the second certificate chain, receiving, at the substrate entity, a second service principal certificate issued to the substrate entity, and installing the second service principal certificate in the second storage medium associated with the substrate entity;

receiving, at the substrate entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the second CA certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second service principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the substrate entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

45. The system of claim 44 , wherein the operations further comprise:

subsequent to validating the third certificate chain, uninstalling the first service principal certificate from the second storage medium associated with the substrate entity.

46. The system of claim 44 , wherein the operations further comprise at least one of:

the first entity utilizing the second certificate bundle to authenticate the substrate entity; or

the substrate entity utilizing the second certificate bundle to authenticate the first entity.

47. The system of claim 26 , wherein the first updated set of CA certificates further comprises a second CA certificate, wherein the first CA certificate is a prior CA certificate and the second CA certificate is a subsequent CA certificate.

48. The system of claim 47 , wherein the first CA certificate is issued by a first CA certificate authority, and the second CA certificate is issued by a second CA certificate authority.

49. The system of claim 26 , wherein the first entity comprises one of: a substrate entity, an overlay entity, or an interface entity.

50. The method of claim 25 ,

wherein validating the first certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is the first CA certificate from among the updated set of CA certificates.

51. The method of claim 50 ,

wherein the set of signature-key pairs comprises a first signature-key pair and a second signature-key pair;

wherein for the first signature-key pair, the recipient certificate is the first entity certificate and the issuer certificate is a first intermediate CA certificate; and

wherein for the second signature-key pair, the recipient certificate is the first intermediate CA certificate, and the issuer certificate is one of: a first root CA certificate or a second intermediate CA certificate.

52. The method of claim 51 ,

wherein the set of signature-key pairs comprises the first signature-key pair, the second signature-key pair, and a third signature-key pair;

wherein for the second signature-key pair, the issuer certificate is the second intermediate CA certificate; and

wherein for the third signature-key pair, the recipient certificate is the second intermediate CA certificate, and the issuer certificate is the first CA certificate.

53. The method of claim 25 , further comprising:

subsequent to validating the first certificate chain, receiving, at the first entity, a second entity certificate issued to the first entity, and installing the second entity certificate in the first storage medium associated with the first entity;

receiving, at the first entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first CA certificate;

validating, by the first entity, a second certificate chain, wherein the second certificate chain comprises the second entity certificate, and a second CA certificate of the second updated set of CA certificates;

responsive to validating the second certificate chain, installing the second certificate bundle in the first storage medium associated with the first entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

54. The method of claim 53 ,

wherein validating the second certificate chain comprises validating a set of signature-key pairs;

wherein each signature-key pair, of the set of signature-key pairs, respectively comprises a public key corresponding to an issuer certificate and a digital signature corresponding to a recipient certificate;

wherein validating the set of signature-key pairs comprises:

for a respective signature-key pair of the set of signature-key pairs:

(a) computing a decryption hash value at least by using the public key to decrypt the digital signature,

(b) computing a signature hash value at least by applying a hash function to the digital signature,

(c) comparing the decryption hash value to the signature hash value, and

(d) determining a match between the decryption hash value and the signature hash value, and

repeating elements (a), (b), (c), and (d) for each signature-key pair of the set of signature-key pairs;

wherein for at least one signature-key pair of the set of signature-key pairs, the recipient certificate is the first entity certificate, and wherein for at least one signature-key pair of the set of signature-key pairs, the issuer certificate is a second CA certificate from among the set of CA certificates.

55. The method of claim 54 , further comprising:

transmitting, to a certificate bundle distribution service, a first update request;

receiving the first certificate bundle comprising the first updated set of CA certificates in response to the first update request;

subsequent to validating the first certificate chain, transmitting, to the certificate bundle distribution service, a second update request; and

receiving the second certificate bundle comprising the second updated set of CA certificates in response to the second update request.

56. The method of claim 54 , further comprising:

subsequent to validating the second certificate chain, uninstalling the first entity certificate from the first storage medium associated with the first entity.

57. The method of claim 25 , further comprising:

prior to receiving the first certificate bundle, receiving, at the first entity, the first entity certificate, and installing the first entity certificate in the first storage medium associated with the first entity.

58. The method of claim 25 ,

wherein the first certificate chain comprises one or more signature-key pairs, wherein each signature-key pair of the one or more signature-key pairs respectively comprises a public key and a digital signature, and

wherein validating the first certificate chain comprises, for each signature-key pair of the one or more signature-key pairs:

computing a decryption hash value at least by decrypting the digital signature of the signature-key pair with the public key of the signature-key pair;

computing a signature hash value at least by applying a hash function to the digital signature of the signature-key pair;

comparing the decryption hash value to the signature hash value;

determining a match between the decryption hash value and the signature hash value; and

designating the first certificate chain as valid based at least in part on having determined the match between the decryption hash value and the signature hash value for each signature-key pair of the one or more signature-key pairs.

59. The method of claim 58 , wherein the one or more signature-key pairs comprises:

an intermediate signature-key pair comprising an intermediate public key and an intermediate digital signature of an intermediate CA, the intermediate public key corresponding to an intermediate CA certificate, and the first entity certificate including the intermediate digital signature of the intermediate CA; and

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the intermediate CA certificate including the root digital signature of the root CA.

60. The method of claim 58 , wherein the one or more signature-key pairs comprises:

a root signature-key pair comprising a root public key and a root digital signature of a root CA, the root public key corresponding to the first CA certificate, and the first entity certificate including the root digital signature of the root CA.

61. The method of claim 25 , further comprising:

receiving, at a second entity associated with the virtual cloud network, a second certificate bundle comprising a second updated set of CA certificates;

determining that a second certificate chain is invalid, wherein the second certificate chain comprises a second entity certificate, having been issued to the second entity, and at least one second CA certificate of the second updated set of CA certificates;

responsive to determining that the second certificate chain is invalid, rejecting the second certificate bundle, and utilizing an earlier certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

62. The method of claim 25 , further comprising:

subsequent to validating the first certificate chain, receiving, at the first entity, a first certificate bundle request from an overlay entity associated with the virtual cloud network, the virtual cloud network comprising a substrate network and an overlay network, wherein the overlay entity resides on the overlay network, and wherein the first entity comprises an interface entity that provides a communication interface between the substrate network and the overlay entity;

responsive to the first certificate bundle request, transmitting from the interface entity to the overlay entity, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the overlay entity, a second certificate chain, wherein the second certificate chain comprises a first instance principal certificate, having been issued to the overlay entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the overlay entity, and utilizing, by the overlay entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

63. The method of claim 62 , further comprising:

subsequent to validating the second certificate chain, receiving, at the overlay entity, a second instance principal certificate issued to the overlay entity, and installing the second instance principal certificate in the second storage medium associated with the overlay entity;

receiving, at the first entity, a second certificate bundle request from the overlay entity;

responsive to the second certificate bundle request, transmitting from the interface entity to the overlay entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the first certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second instance principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the overlay entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

64. The method of claim 63 , further comprising:

subsequent to validating the third certificate chain, uninstalling the first instance principal certificate from the second storage medium associated with the overlay entity.

65. The method of claim 63 , further comprising at least one of:

the first entity utilizing the second certificate bundle to authenticate the overlay entity; or

the overlay entity utilizing the second certificate bundle to authenticate the first entity.

66. The method of claim 25 , further comprising:

receiving, at a substrate entity associated with the virtual cloud network, the first certificate bundle comprising the first updated set of CA certificates;

validating, by the substrate entity, a second certificate chain, wherein the second certificate chain comprises a first service principal certificate, having been issued to the substrate entity, and a second CA certificate of the first updated set of CA certificates;

responsive to validating the second certificate chain, installing the first certificate bundle in a second storage medium associated with the substrate entity, and utilizing, by the substrate entity, the first certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

67. The method of claim 66 , further comprising:

subsequent to validating the second certificate chain, receiving, at the substrate entity, a second service principal certificate issued to the substrate entity, and installing the second service principal certificate in the second storage medium associated with the substrate entity;

receiving, at the substrate entity, a second certificate bundle comprising a second updated set of CA certificates, the second updated set of CA certificates reflecting an update from the first updated set of CA certificates, wherein the update comprises removing the second CA certificate;

validating a third certificate chain, wherein the third certificate chain comprises the second service principal certificate, and a third CA certificate of the second updated set of CA certificates;

responsive to validating the third certificate chain, installing the second certificate bundle in the second storage medium associated with the substrate entity, and utilizing the second certificate bundle to authenticate at least one additional entity associated with the virtual cloud network.

68. The method of claim 67 , further comprising:

subsequent to validating the third certificate chain, uninstalling the first service principal certificate from the second storage medium associated with the substrate entity.

69. The method of claim 67 , further comprising at least one of:

the first entity utilizing the second certificate bundle to authenticate the substrate entity; or

the substrate entity utilizing the second certificate bundle to authenticate the first entity.

70. The method of claim 25 , wherein the first updated set of CA certificates further comprises a second CA certificate, wherein the first CA certificate is a prior CA certificate and the second CA certificate is a subsequent CA certificate.

71. The method of claim 70 , wherein the first CA certificate is issued by a first CA certificate authority, and the second CA certificate is issued by a second CA certificate authority.

72. The method of claim 25 , wherein the first entity comprises one of: a substrate entity, an overlay entity, or an interface entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: LONG, TONY; NAIR, SNEHA SUDHAKARAN; UZUN, BURAK
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 064410/0823 →
Continuity (1)
Related Publication 20250030561A1 · Jan 23, 2025
References Cited (142)
US 5699431A · Van Oorschot et al. · 1997 [cited by applicant]
US 7272714B2 · Nagaratnam et al. · 2007 [cited by applicant]
US 7644270B1 · Cherukumudi et al. · 2010 [cited by applicant]
US 8452958B2 · Sun et al. · 2013 [cited by applicant]
US 9172543B2 · Wnuk · 2015 [cited by applicant]
US 9197630B2 · Sharif et al. · 2015 [cited by applicant]
US 9231933B1 · Shenoy et al. · 2016 [cited by applicant]
US 9485101B2 · Bowen · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9680813B2 · Sade et al. · 2017 [cited by applicant]
US 9794249B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9882727B1 · Veladanda et al. · 2018 [cited by applicant]
US 10021084B2 · Matthews et al. · 2018 [cited by applicant]
US 10212147B2 · Buendgen et al. · 2019 [cited by applicant]
US 10652030B1 · Levy et al. · 2020 [cited by applicant]
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10771261B1 · Lazar et al. · 2020 [cited by applicant]
US 10812276B2 · Bojjireddy et al. · 2020 [cited by applicant]
US 10848323B2 · Barr, III et al. · 2020 [cited by applicant]
US 11153103B2 · Fynaardt et al. · 2021 [cited by applicant]
US 11196570B2 · Borne-Pons et al. · 2021 [cited by applicant]
US 11310059B2 · Leibmann et al. · 2022 [cited by applicant]
US 11362843B1 · Jiang et al. · 2022 [cited by applicant]
US 11368314B2 · Ray et al. · 2022 [cited by applicant]
US 11388594B2 · Uy et al. · 2022 [cited by applicant]
US 11438325B2 · Begun et al. · 2022 [cited by applicant]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11706038B1 · Thakore et al. · 2023 [cited by applicant]
US 11888997B1 · Bowen et al. · 2024 [cited by applicant]
US 12088738B2 · Rosenthol et al. · 2024 [cited by applicant]
US 20020007346A1 · Qiu et al. · 2002 [cited by applicant]
US 20020174066A1 · Kleckner et al. · 2002 [cited by applicant]
US 20030037234A1 · Fu et al. · 2003 [cited by applicant]
US 20060047965A1 · Thayer · 2006 [cited by applicant]
US 20060101510A1 · Kadyk et al. · 2006 [cited by applicant]
US 20070005956A1 · Zilinskas et al. · 2007 [cited by applicant]
US 20070147619A1 · Bellows · 2007 [cited by examiner]
US 20100030897A1 · Stradling · 2010 [cited by examiner]
US 20100325429A1 · Saha et al. · 2010 [cited by applicant]
US 20110113239A1 · Fu et al. · 2011 [cited by applicant]
US 20120036220A1 · Dare et al. · 2012 [cited by applicant]
US 20120246466A1 · Salvarani et al. · 2012 [cited by applicant]
US 20140298419A1 · Boubez et al. · 2014 [cited by applicant]
US 20150135299A1 · Liang et al. · 2015 [cited by applicant]
US 20170039373A1 · Sasin et al. · 2017 [cited by applicant]
US 20170126667A1 · Bishop · 2017 [cited by examiner]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170317837A1 · Alrawais et al. · 2017 [cited by applicant]
US 20170338967A1 · Lewison et al. · 2017 [cited by applicant]
US 20180083966A1 · Zhou et al. · 2018 [cited by applicant]
US 20180102904A1 · Lin et al. · 2018 [cited by applicant]
US 20180287804A1 · Geisbush · 2018 [cited by applicant]
US 20190149342A1 · Fynaardt et al. · 2019 [cited by applicant]
US 20190165950A1 · Ibrahim · 2019 [cited by applicant]
US 20190347406A1 · Lev-Ran · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190363895A1 · Barr et al. · 2019 [cited by applicant]
US 20200021575A1 · Rezvani et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang · 2020 [cited by examiner]
US 20200150972A1 · Ketkar et al. · 2020 [cited by applicant]
US 20200274718A1 · Hwang et al. · 2020 [cited by applicant]
US 20200274862A1 · Varvarezis et al. · 2020 [cited by applicant]
US 20210126801A1 · Nix · 2021 [cited by applicant]
US 20210152547A1 · Barhudarian et al. · 2021 [cited by applicant]
US 20210211307A1 · Statia et al. · 2021 [cited by applicant]
US 20210218723A1 · Lekov et al. · 2021 [cited by applicant]
US 20210392002A1 · Gray et al. · 2021 [cited by applicant]
US 20210409403A1 · Lewin et al. · 2021 [cited by applicant]
US 20210409409A1 · Palanisamy · 2021 [cited by applicant]
US 20220038894A1 · Yoon · 2022 [cited by examiner]
US 20220123951A1 · Lutz et al. · 2022 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220239503A1 · Mallikarjuna Durga Lokanath · 2022 [cited by examiner]
US 20220393886A1 · Williams et al. · 2022 [cited by applicant]
US 20230032867A1 · Peddada et al. · 2023 [cited by applicant]
US 20230109231A1 · Adogla et al. · 2023 [cited by applicant]
US 20230208655A1 · Statia et al. · 2023 [cited by applicant]
US 20230237155A1 · Jacquin et al. · 2023 [cited by applicant]
US 20230291577A1 · Thai · 2023 [cited by examiner]
US 20230401307A1 · Pop · 2023 [cited by examiner]
US 20230412397A1 · Gollent · 2023 [cited by examiner]
US 20240015508A1 · Yoon · 2024 [cited by examiner]
US 20240020373A1 · Ivanov · 2024 [cited by examiner]
US 20240031146A1 · Marosi-Bauer et al. · 2024 [cited by applicant]
US 20240106886A1 · Roy et al. · 2024 [cited by applicant]
US 20240121603A1 · Yoon · 2024 [cited by examiner]
US 20240146543A1 · Sahoo et al. · 2024 [cited by applicant]
US 20240333640A1 · Shevade · 2024 [cited by examiner]
US 20240356763A1 · Goldberg et al. · 2024 [cited by applicant]
US 20240388510A1 · Madtha · 2024 [cited by examiner]
US 20250030561A1 · Long · 2025 [cited by examiner]
US 20250088373A1 · Uzun · 2025 [cited by examiner]
US 20250097211A1 · Uzun · 2025 [cited by examiner]
US 20250133401A1 · Lee · 2025 [cited by examiner]
CN 112019477A · 2020 [cited by applicant]
CN 114884963A · 2022 [cited by applicant]
EP 1251670A2 · 2002 [cited by applicant]
EP 2267970A2 · 2010 [cited by applicant]
EP 2854349A1 · 2015 [cited by applicant]
EP 3772208B1 · 2024 [cited by examiner]
KR 1020110045459A · 2011 [cited by applicant]
WO WO2006122024A2 · 2006 [cited by examiner]
WO 2022121461A1 · 2022 [cited by applicant]
WO 2022133026A1 · 2022 [cited by applicant]
WO WO2023240360A1 · 2023 [cited by examiner]
WO WO2025059187A1 · 2025 [cited by examiner]
“What is Certificate Lifecycle Management”, Retrieved from https://www.encryptionconsulting.com/different-phases-of-a-certificate-lifecycle-management-process/, Aug. 1, 2024, pp. 1-12. [cited by applicant]
“About Azure Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/about-certificates, Feb. 8, 2023, pp. 1-8. [cited by applicant]
“About the Expressway”, Aug. 17, 2022. pp. 1-12. [cited by applicant]
“Automated certificate management for TLS certificates”, Retrieved from https://docs.servicenow.com/en-US/bundle/utah-it-operations-management/page/product/discovery/concept/automated-cert-requests.html, Retrieved on Ma… [cited by applicant]
“AWS Certificate Manager FAQs”, Retrieved from https://aws.amazon.com/certificate-manager/faqs/, Retrieved on Mar. 24, 2023, pp. 1-17. [cited by applicant]
“Azure Instance Metadata Service”, Retrieved from https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows, Mar. 15, 2023, pp. 1-42. [cited by applicant]
“Cisco Expressway Certificate Creation and Use Deployment Guide”, Feb. 23, 2021, pp. 10. [cited by applicant]
“Deploying the CA bundle iApp”, Retrieved from https://www.f5.com/pdf/deployment-guides/f5-ca-bundle-dg.pdf, Dec. 14, 2017, pp. 1-9. [cited by applicant]
“DigiCert Public Key Infrastructure (PKI) Platform”, 2019, pp. 15. [cited by applicant]
“Get started with Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios, Retrieved on Feb. 1, 2023, pp. 1-6. [cited by applicant]
“High Availability using Patching and Rolling AP Upgrade on Cisco Catalyst 9800 Wireless Controllers”, Copyright 2020, pp. 1-41. [cited by applicant]
“Manage Certificate Revocation Lists (CRLs)”, Jul. 23, 2021, pp. 1-4. [cited by applicant]
“PKI secrets engine”, Retrieved from https://developer.hashicorp.com/vault/docs/secrets/pki, Retrieved on May 4, 2023, pp. 1-3. [cited by applicant]
“Planning a certificate revocation list (CRL)”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/crl-planning.html, Retrieved on Jul. 28, 2023, pp. 11. [cited by applicant]
“Release app updates with staged rollouts”, Retrieved from https://support.google.com/googleplay/android-developer/answer/6346149?hl=en#zippy=%2Crelease-a-staged-rollout-to-specific-countries, Retrieved on Apr. 27, 2023… [cited by applicant]
“Release Your App Update in a Staged Rollout”, Retrieved from https://developer.amazon.com/docs/app-submission/release-updates-in-staged-rollouts.html, Retrieved on Apr. 27, 2023, pp. 1-18. [cited by applicant]
“Rotate Security Certificates”, Retrieved from https://www.cockroachlabs.com/docs/stable/rotate-certificates, Retrieved on May 4, 2023, pp. 1-6. [cited by applicant]
“Rotating the Root CA and Leaf Certificates”, Retrieved from https://docs.pivotal.io/ops-manager/2-4/security/pcf-infrastructure/rotate-cas-and-leaf-certs.html, Nov. 5, 2020, pp. 1-9. [cited by applicant]
“Staged upgrade”, Retrieved from https://www.ibm.com/docs/en/order-management-sw/9.4.0?topic=migrating-staged-upgrade, Mar. 2, 2021, pp. 1-3. [cited by applicant]
“Troubleshoot SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/troubleshooting, Retrieved on Mar. 24, 2023, pp. 1-8. [cited by applicant]
“Tutorial: Configure certificate auto-rotation in Key Vault”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-rotate-certificates, Feb. 27, 2023, pp. 1-6. [cited by applicant]
“Updating the CA bundle”, Retrieved from https://docs.openshift.com/container-platform/4.9/security/certificates/updating-ca-bundle.html#ca-bundle-understanding_updating-ca-bundle, Retrieved on Mar. 24, 2023, pp. 1-2. [cited by applicant]
“Updating your private CA”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/PCAUpdateCA.html, Retrieved on Mar. 24, 2023, pp. 1-4. [cited by applicant]
“Use self-managed SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs, Aug. 15, 2023, pp. 13. [cited by applicant]
“VSphere Security”, vmware, Update 3, Mar. 21, 2023, pp. 1-426. [cited by applicant]
“Working with Hosts”, Retrieved from https://docs.cloudstack.apache.org/projects/archived-cloudstack-administration/en/latest/hosts.html, Retrieved on Mar. 24, 2023, pp. 1-7. [cited by applicant]
Atutxa et al., “Improving efficiency and security of IIoT communications using in-network validation of server certificate”, Computers in Industry, vol. 144, Jan. 2023, 103802, pp. 30. [cited by applicant]
Bigelow S.J., “Rolling deployment”, Retrieved from https://www.techtarget.com/searchitoperations/definition/rolling-deployment, Jan. 2023, pp. 4. [cited by applicant]
Este-Gracias S., “Rotate your CA seamlessly using a Vault PKI”, Retrieved from https://sestegra.medium.com/rotate-your-ca-seamlessly-using-a-vault-pki-9262228b4afb Sep. 29, 2022, pp. 1-49. [cited by applicant]
Ghanmi et al., “A Secure Data Storage in Multi-cloud Architecture Using Blowfish Encryption Algorithm”, Advanced Information Networking and Applications, Mar. 2022, pp. 398-408. [cited by applicant]
Jamal F., “Zero Trust for SSH—Secure One-click Server Access for Software Engineering Teams”, Retrieved from https://www.banyansecurity.io/blog/zero-trust-for-ssh/, Oct. 28, 2020, pp. 1-7. [cited by applicant]
Manjusha R. et al., “Secure Authentication and Access System for Cloud Computing Auditing Services Using Associated Digital Certificate”, Indian Journal of Science and Technology, vol. 8 (S7), Apr. 2015, pp. 220-227. [cited by applicant]
Nexthop Team, “Updated: Creating a Certificate Revocation List Distribution Point for Your Internal Certification Authority”, Retrieved from https://techcommunity.microsoft.com/t5/skype-for-business-blog/updated-creatin… [cited by applicant]
Rowley J., “Google's Moving Forward Together Proposals for Root CA Policy: Rotating ICAS More Frequently”, Retrieved from https://www.digicert.com/blog/googles-moving-forward-together-proposals-for-root-ca-policy, Mar. … [cited by applicant]
Subhayu, “Different Phases of a Certificate Lifecycle Management Process for a secure WPA2-Enterprise network”, Certificate Lifecycle Management Oct. 6, 2022, pp. 16. [cited by applicant]
Ylonen et al., “Security of Automated Access Management Using Secure Shell (SSH)”, NISTIR 7966 (Draft), Aug. 2014, pp. 43. [cited by applicant]