IP Library Granted Patent US 12,323,407
Granted Patent B2
US 12,323,407 · App. 18/402,842 · Granted Jun 3, 2025

Client certificates to communicate trusted information

Inventors: Derk Norton (Pleasanton, CA); Tushar Vaish (Milpitas, CA); Jeff Webb (Pleasanton, CA)
Assignee: Blackhawk Network, Inc.
H04L63/0807H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,407
App. No.
18/402,842
Granted
Jun 3, 2025
Kind
B2
Abstract

A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.

Claims (21)

1. A device comprising a processor implemented on one or more computer chips configured to:

authenticate a client certificate, wherein the client certificate is signed by a private certificate authority associated with the device,

extract, in response to the authentication, attributes from the client certificate, and

create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes comprise a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, wherein the certificate ID attribute identifies the client and uniquely identifies the client certificate, wherein the tenant ID attribute is associated with partner data and specifies which partner data is client accessible, wherein the role ID attribute helps to implement role-based access control, and wherein the reformatted attributes can be trusted.

2. The device of claim 1 , wherein the device is a gateway server and wherein the gateway server is configured to receive the client certificate from a client.

3. The device of claim 1 , wherein the reformatted attributes can be trusted because of the authentication.

4. The device of claim 1 , wherein the reformatted attributes can be trusted because the processor created the message comprising the reformatted attributes.

5. The device of claim 1 , wherein the reformatted attributes are included in Hypertext Transfer Protocol (HTTP) or HTTP Secure (HTTPS) headers.

6. The device of claim 1 , wherein the message is in an Extensible Markup Language (XML) or JavaScript Object Notation (JSON) format.

7. A device comprising a processor implemented on one or more computer chips configured to:

process a client certificate's attributes to produce reformatted attributes comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and include the client certificate in a request for a shared service, wherein the certificate identifier (ID) attribute identifies a client and uniquely identifies the device, wherein the device is the client, wherein the tenant ID attribute specifies which partner data is device accessible, and wherein the role ID attribute helps to implement role-based access control.

8. The device of claim 7 , wherein the certificate identifier (ID) attribute, the tenant ID attribute, and the role ID attribute are globally unique identifiers (GUIDs) that are unique and cannot be forged.

9. The device of claim 7 , wherein the client certificate is signed by a private certificate authority associated with a gateway server.

10. The device of claim 7 , wherein the request is in an Extensible Markup Language (XML) or JavaScript Object Notation (JSON) format.

11. A method comprising:

authenticating a client certificate based on a signature in the client certificate;

authorizing, in response to the authenticating, access to a shareable service;

extracting, in response to the authenticating, attributes from the client certificate; and

creating, in response to the extracting, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes comprise a certificate identifier (ID) attribute, a tenant identifier attribute, and a role ID attribute, wherein the reformatted attributes can be trusted based on the authentication and wherein the reformatted attributes are globally unique identifiers (GUIDs) that are unique and cannot be forged, and wherein the certificate ID attribute uniquely identifies the device, the tenant ID attribute specifies which partner data is device accessible, and the role ID attribute specifies a role of the device.

12. The method of claim 11 , further comprising transmitting the message.

13. The method of claim 12 , further comprising receiving, in response to the transmitting, a resource associated with the shareable service.

Assignments (2)
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Mar 10, 2026
From: BLACKHAWK NETWORK, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 075070/0347 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2024
From: NORTON, DERK; VAISH, TUSHAR; WEBB, JEFF
To: BLACKHAWK NETWORK, INC.
Reel/Frame 066990/0229 →
Continuity (5)
Continuation 17192705 · Mar 4, 2021
Continuation 16227147 · Dec 20, 2018
Continuation 14211640 · Mar 14, 2014
Provisional Application 61800548 · Mar 15, 2013
Related Publication 20240187394A1 · Jun 6, 2024
References Cited (47)
US 1429347A · Hough · 1922 [cited by applicant]
US 6944761B2 · Wood et al. · 2005 [cited by applicant]
US 7117359B2 · Wood et al. · 2006 [cited by applicant]
US 7325128B2 · Wood et al. · 2008 [cited by applicant]
US 7430755B1 · Hughes et al. · 2008 [cited by applicant]
US 7506368B1 · Kersey et al. · 2009 [cited by applicant]
US 7716077B1 · Mikurak · 2010 [cited by examiner]
US 8104075B2 · Spector · 2012 [cited by examiner]
US 8230505B1 · Ahrens · 2012 [cited by examiner]
US 8291490B1 · Ahmed et al. · 2012 [cited by applicant]
US 8452956B1 · Kersey et al. · 2013 [cited by applicant]
US 8548467B2 · Vanderveen · 2013 [cited by examiner]
US 8826010B2 · Rescorla · 2014 [cited by examiner]
US 8843997B1 · Hare · 2014 [cited by examiner]
US 9521119B2 · Leibovitz · 2016 [cited by examiner]
US 10382202B1 · Ohsie et al. · 2019 [cited by applicant]
US 11936639B2 · Norton · 2024 [cited by examiner]
US 20020016777A1 · Seamons · 2002 [cited by examiner]
US 20030046586A1 · Bheemarasetti · 2003 [cited by examiner]
US 20030073406A1 · Benjamin · 2003 [cited by examiner]
US 20040225897A1 · Norton · 2004 [cited by applicant]
US 20050050362A1 · Peles · 2005 [cited by applicant]
US 20060259762A1 · Tanimoto · 2006 [cited by examiner]
US 20070150737A1 · Parupudi et al. · 2007 [cited by applicant]
US 20070192557A1 · Kezuka · 2007 [cited by examiner]
US 20070288247A1 · Mackay · 2007 [cited by examiner]
US 20080046987A1 · Spector · 2008 [cited by examiner]
US 20090198651A1 · Shiffer · 2009 [cited by examiner]
US 20090198670A1 · Shiffer · 2009 [cited by examiner]
US 20090198689A1 · Frazier · 2009 [cited by examiner]
US 20100017859A1 · Kelly et al. · 2010 [cited by applicant]
US 20100132016A1 · Ferris · 2010 [cited by examiner]
US 20100306393A1 · Appiah et al. · 2010 [cited by applicant]
US 20110126002A1 · Fu · 2011 [cited by examiner]
US 20110289581A1 · Gourevitch et al. · 2011 [cited by applicant]
US 20120266231A1 · Spiers · 2012 [cited by examiner]
US 20140052877A1 · Mao · 2014 [cited by examiner]
US 20140068743A1 · Marcus · 2014 [cited by examiner]
US 20140075501A1 · Srinivasan et al. · 2014 [cited by applicant]
US 20140075565A1 · Srinivasan et al. · 2014 [cited by applicant]
US 20140101299A1 · Cherel et al. · 2014 [cited by applicant]
US 20140164776A1 · Hook · 2014 [cited by examiner]
US 20160044035A1 · Huang · 2016 [cited by applicant]
US 20210194865A1 · Norton · 2021 [cited by examiner]
WO WO03021464A2 · 2003 [cited by examiner]
Merriam-Webster, “Can I Definition of Can by Merriam-Webster”, viewed on Mar. 2, 2016, https://www.merriam-webster.com/dictionary/can. [cited by applicant]
Merriam-Webster, “May I Definition of May by Merriam-Webster”, viewed on Mar. 2, 2016, https://www.merriam-webster.com/dictionary/may. [cited by applicant]