IP Library Granted Patent US 9,032,499
Granted Patent B2
US 9,032,499 · App. 13/454,600 · Granted May 12, 2015

System and method for providing a certificate to a user request

Inventors: Kevin Lee Koster (Westminster, CO); Roger Lynn Haney (Denver, CO)
Assignee: Cloudpath Neworks, Inc.
H04L63/0823H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,032,499
App. No.
13/454,600
Granted
May 12, 2015
Kind
B2
Abstract

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system based on at least one criteria and an established identity with a first system. The method includes receiving criteria, such as at least one predefined attribute. Also received from a user known to a first system is a request for network access to a second system, the request having at least one identifier. The first system is then queried with the identifier for attributes associated with the user. The attributes associated with the user are evaluated to the predefined attribute(s). In response to at least one attribute associated with the user correlating to the predefined attribute(s), providing a certificate with at least one characteristic for network access on the second system to the user. An associated system for providing a Certificate is also provided.

Claims (62)

1. A method of providing a certificate for certificate based wireless network access comprising:

receiving from a user by way of a computing device authenticated to a remote first system a request for access to a second system remote from the first system, the request having at least one identifier, wherein the access is certificate based wireless network access;

receiving at an authorizing system from a third party at least one predefined attribute as criteria for receiving a certificate;

querying, by the authorizing system, the first system with the at least one identifier for attributes associated with the user;

evaluating, by the authorizing system, the attributes associated with the user to the at least one predefined attribute;

providing the user with an X.509 certificate with at least one characteristic derived from the attributed associated with the user for certificate based wireless network access on a secured wireless network of the second system in response to at least one attribute associated with the user correlating to at least one predefined attribute, wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute; and

enabling a level of access to the secured wireless network of the second system based on the certificate.

2. The method of claim 1 , wherein the at least one predefined attribute is user information.

3. The method of claim 2 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

4. The method of claim 1 , wherein the at least one predefined attribute is an association.

5. The method of claim 4 , wherein the association is selected from the group consisting of: membership in a group, subscribing to another user, being a friend of another user, listing a school/company/employer, likes.

6. The method of claim 1 , wherein the at least one predefined attribute is an action taken by the user.

7. The method of claim 1 , wherein the predefined attribute is received from the second system.

8. The method of claim 1 , wherein the predefined attribute is received from a third party.

9. The method of claim 1 , wherein the first system is a federated web service.

10. The method of claim 1 , wherein the third party is the second system.

11. The method of claim 1 , wherein the characteristic of the certificate is selected from the group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

12. The method of claim 1 , wherein the querying of the first system is focused based on the at least one identifier and the at least one predefined attribute.

13. The method of claim 1 , further including:

subsequently querying the first system with the at least one identifier for attributes associated with the user;

evaluating the attributes associated with the user to the at least one predefined attribute; and

in response to at least one prior correlation between an attribute associated with the user and a predefined attribute failing, revoking the certificate.

14. The method of claim 1 , wherein providing the user with a certificate further includes providing the user with a token to generate a certificate.

15. The method of claim 1 , wherein providing the user with a certificate further includes providing the user with instructions to generate a certificate.

16. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for certificate based wireless network access, the computer program comprising instructions which when executed by a computer system having at least one processor performs the steps of:

receiving from a user by way of a computing device authenticated to a remote first system a request for access to a second system remote from the first system, the request having at least one identifier, wherein the access is certificate based wireless network access;

receiving at an authorizing system from a third party at least one predefined attribute as criteria for receiving a certificate;

querying, by the authorizing system, the first system with the at least one identifier for attributes associated with the user;

evaluating, by the authorizing system, the attributes associated with the user to the at least one predefined attribute;

providing the user with an X.509 certificate with at least one characteristic derived from the attributes associated with the user for certificate based wireless network access on a secured wireless network of the second system in response to at least one attribute associated with the user correlating to at least one predefined attribute, wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute; and

enabling a level of access to the secured wireless network of the second system based on the certificate.

17. The non-transitory machine readable medium of claim 16 , wherein the at least one predefined attribute is user information.

18. The non-transitory machine readable medium of claim 16 , wherein the at least one predefined attribute is an association.

19. The non-transitory machine readable medium of claim 16 , wherein the at least one predefined attribute is a user action.

20. The non-transitory machine readable medium of claim 16 , wherein the predefined attribute is received from the second system.

21. The non-transitory machine readable medium of claim 16 , wherein the predefined attribute is received from a third party.

22. The non-transitory machine readable medium of claim 16 , wherein the first system is a federated web service.

23. The non-transitory machine readable medium of claim 16 , wherein the characteristic of the certificate is selected from the group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

24. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for certificate based wireless network access, the computer program comprising instructions which when executed by a computer system having at least one processor performs the steps of:

an input routine operative associated with an input device to receive from a user by way of a computing device authenticated to a remote first system a request for access to a second system remote from the first system, the request having at least one identifier, wherein the access is certificate based wireless network access;

a receiving routine to receive at an authorizing system from a third party at least one predefined attribute as criteria for receiving a certificate;

a query routine to query, by the authorizing system, the first system with the at least one identifier for attributes associated with the user;

an evaluating routine to evaluate, by the authorizing system, the attributes associated with the user to the at least one predefined attribute;

an output routine to provide the user with an X.509 certificate with at least one characteristic derived from the attributes associated with the user for certificate based wireless network access on a secured wireless network of the second system in response to at least one attribute associated with the user correlating to at least one predefined attribute, wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute, the output routine enabling a level of access to the secured wireless network of the second system based on the certificate.

25. The non-transitory machine readable medium of claim 24 , wherein the at least one predefined attribute is user information.

26. The non-transitory machine readable medium of claim 24 , wherein the at least one predefined attribute is an association.

27. The non-transitory machine readable medium of claim 24 , wherein the at least one predefined attribute is a user action.

28. The non-transitory machine readable medium of claim 24 , wherein the predefined attribute is received from the second system.

29. The non-transitory machine readable medium of claim 24 , wherein the predefined attribute is received from a third party.

30. The non-transitory machine readable medium of claim 24 , wherein the first system is a federated web service.

31. The non-transitory machine readable medium of claim 24 , wherein the characteristic of the certificate is selected from the group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

32. A system for providing a certificate for certificate based wireless network access comprising:

a first system having a processor structured and arranged as a single sign on system having a plurality of user accounts for remote users;

a third party system having a processor structured and arranged to establish at least one predefined attribute for receiving a certificate permitting certificate based wireless network access on a second system remote from the first hardware or software system;

an authorizing hardware system having at least one processor structured and arranged to receive from the third party the at least one predefined attribute, and in response to a request by way of a computing device from a user of the first system for a certificate for certificate based wireless network access to the remote second system the authorizing system further structured and arranged to access the first system to query the remote user accounts for attributes associated with at least one user, the authorizing system providing an X.509 certificate with at least one characteristic derived from the attributes associated with the user for certificate based wireless network access on a secured wireless network of the second system to at least one user having at least one attribute associated with the user correlated to the at least one predefined attribute, wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute, the authorizing system enabling a level of access to the secured wireless network of the second system based on the certificate.

33. The system of claim 32 , wherein the at least one predefined attribute is user information.

34. The system of claim 32 , wherein the at least one predefined attribute is an association.

35. The system of claim 32 , wherein the at least one predefined attribute is a user action.

36. The system of claim 32 , wherein the third party is the second system.

37. The system of claim 32 , wherein the third party is distinct from the second system.

38. The system of claim 32 , wherein the first system is a federated web service.

39. The system of claim 32 , wherein the characteristic of the certificate is selected from the group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

Assignments (14)
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 2, 2026
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075892/0107 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2016
From: CLOUDPATH NETWORKS, INC.
To: RUCKUS WIRELESS, INC.
Reel/Frame 037679/0278 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: KOSTER, KEVIN LEE; HANEY, ROGER LYNN
To: CLOUDPATH NETWORKS, INC.
Reel/Frame 028098/0111 →
Continuity (2)
Provisional Application 61614990 · Mar 23, 2012
Related Publication 20130254864A1 · Sep 26, 2013