IP Library Granted Patent US 8,606,875
Granted Patent B1
US 8,606,875 · App. 10/882,719 · Granted Dec 10, 2013

Method and system for automatic distribution and installation of a client certificate in a secure manner

Inventors: Jean Chouanard (Redwood City, CA); Craig A. Vosburgh (Colorado Springs, CO)
Assignee: Oracle America, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,606,875
App. No.
10/882,719
Granted
Dec 10, 2013
Kind
B1
Abstract

A method for distributing and installing a digital certificate is provided. In this method, an object is accessed. The object is used for requesting a new digital certificate from a remote server. The object comprises a request for the new digital certificate, validity scope information, and an address associated with a controlled access point through which the object is transmitted when requesting the new digital certificate. Thereafter, the object is sent to the remote server on a communication path that includes the controlled access point. Subsequently, the new digital certificate is received from the remote server after the remote server verifies the validity scope information and verifies that the object was transmitted through the address associated with the controlled access point.

Claims (27)

1. A method for distributing and installing a digital certificate comprising:

accessing an object, the object being used for requesting a new digital certificate from a remote server, the object comprising a request for the new digital certificate, validity scope information, and an address associated with a controlled access point through which the object is transmitted when requesting the new digital certificate;

specifying through the object a network path to be used to send the request for the new digital certificate;

sending the object to the remote server on a communication path that includes the controlled access point; and

receiving the new digital certificate from the remote server after the remote server verifies the validity scope information and verifies that the object was transmitted through the address associated with the controlled access point.

2. The method of claim 1 , further comprising:

limiting access to the controlled access point.

3. The method of claim 1 , further comprising:

digitally signing the object by the new digital certificate.

4. The method of claim 1 , wherein the validity scope information further comprises an expiration date.

5. The method of claim 1 , further comprising:

receiving a new object from the remote server with updated validity scope information and an updated controlled access point.

6. The method of claim 1 , further comprising:

storing the object in a local network upon installation of a proxy server.

7. The method of claim 1 , wherein the remote server is located outside a local network.

8. A computer system comprising a processor and a computer readable memory coupled to the processor and comprising program instructions that, when executed, implement a method for distributing and installing a digital certificate comprising:

creating an object signed by a root signing authority, the object being stored within a local network and being used for requesting a new digital certificate from a remote server, the object comprising a request for the new digital certificate, validity scope information, and an address associated with a controlled access point through which the object is transmitted when requesting the new digital certificate;

specifying through the object a network path to be used to send the request for the new digital certificate;

sending the object to the remote server located outside the local network on a communication path that includes the controlled access point to request the new digital certificate; and

receiving the new digital certificate from the remote server after the remote server verifies the validity scope information and verifies that the object was transmitted through the address associated with the controlled access point.

9. The computer system of claim 8 , wherein the method further comprises:

limiting access to the controlled access point.

10. The computer system of claim 8 , wherein the method further comprises:

digitally signing the object by the root signing authority.

11. The computer system of claim 8 , wherein the validity scope information further comprises an expiration date.

12. The computer system of claim 8 , wherein the method further comprises:

receiving a new object from the remote server with updated validity scope information and an updated controlled access point.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037311/0233 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2004
From: CHOUANARD, JEAN; VOSBURGH, CRAIG A.
To: SUN MICROSYSTEMS, INC.
Reel/Frame 015916/0368 →