IP Library Granted Patent US 9,729,321
Granted Patent B2
US 9,729,321 · App. 14/699,712 · Granted Aug 8, 2017

Autonomous private key recovery

Inventor: Christopher Morgan Mayers (Histon, GB)
Assignee: CITRIX SYSTEMS, INC.
H04L9/0894H04L63/0407H04L63/0807H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,729,321
App. No.
14/699,712
Granted
Aug 8, 2017
Kind
B2
Abstract

Approaches described herein allow a stateless device to recover at least one private key. In particular, a stateless device can provide service-account credentials to a directory service to establish a first session and acquire a certificate and private key using information associated with the stateless device. The stateless device can store its private key before the first session ends. A stateless device can then provide user-account credentials to the directory service to establish a second session. After the second session begins, a private key can be acquired by the stateless device.

Claims (37)

1. A device having one or more processors, the device comprising:

a memory configured to store account credentials; and

a stateless machine comprising one or more certificate-using services and a certificate distributor that is configured to:

provide a directory service with the account credentials associated with the one or more certificate-using services for establishing a first session;

acquire a certificate and a private key using the account credentials and information associated with the stateless machine;

store the private key in the directory service before the first session ends;

provide the directory service with user-account credentials for establishing a second session, wherein the user-account credentials are associated with a device hosting the stateless machine; and

acquire the private key, using credential roaming, after the second session begins.

2. The device of claim 1 , wherein the account credentials are provided to log on to a domain that includes the directory service.

3. The device of claim 1 , wherein the user-account credentials are provided to log on to a domain that includes the directory service.

4. The device of claim 1 , wherein the private key is stored in the directory service using a credential roaming mechanism, and wherein the private key is acquired after the second session begins using the credential roaming mechanism.

5. The device of claim 1 , wherein the certificate distributor is included in the stateless machine.

6. The device of claim 1 , wherein the memory configured to store account credentials is persistent.

7. The device of claim 1 , wherein the certificate distributor is further configured to receive the private key before an autoenrollment mechanism is executed on the certificate distributor.

8. A method for recovering a private key, the method being performed by one or more processors associated with a stateless machine and comprising:

providing a directory service with account credentials associated with one or more certificate-using services of the stateless machine for establishing a first session;

acquiring a certificate and a private key using the account credentials and information associated with the stateless machine;

storing the private key in the directory service before the first session ends;

providing the directory service with user-account credentials for establishing a second session, wherein the user-account credentials are associated with a device hosting the stateless machine; and

acquiring the private key, using credential roaming, after the second session begins.

9. The method of claim 8 , wherein the account credentials are provided to log on to a domain that includes the directory service.

10. The method of claim 8 , wherein the user-account credentials are provided to log on to a domain that includes the directory service.

11. The method of claim 8 , wherein the private key is stored in the directory service using a credential roaming mechanism, and wherein the private key is acquired after the second session begins using the credential roaming mechanism.

12. The method of claim 8 , wherein providing the directory service with account credentials is performed by a certificate distributor included in the stateless machine.

13. The method of claim 8 , wherein memory is configured to store account credentials and is persistent.

14. The method of claim 8 , wherein a certificate distributor is configured to receive the private key before an autoenrollment mechanism is executed on the certificate distributor.

15. A nontransitory computer readable storage medium storing a set of instructions that are executable by at least one processor associated with a stateless machine, to cause the stateless machine to perform a method for recovering a private key, the method comprising:

providing a directory service with account credentials associated with the one or more certificate-using services of the stateless machine for establishing a first session;

acquiring a certificate and a private key using the account credentials and information associated with the stateless machine;

storing the private key in the directory service before the first session ends;

providing the directory service with user-account credentials for establishing a second session, wherein the user-account credentials are associated with a device hosting the stateless machine; and

acquiring the private key, using credential roaming, after the second session begins.

16. The nontransitory computer readable storage medium of claim 15 , wherein the account credentials are provided to log on to a domain that includes the directory service.

17. The nontransitory computer readable storage medium of claim 15 , wherein the user-account credentials are provided to log on to a domain that includes the directory service.

18. The nontransitory computer readable storage medium of claim 15 , wherein the private key is stored in the directory service using a credential roaming mechanism, and wherein the private key is acquired after the second session begins using the credential roaming mechanism.

19. The nontransitory computer readable storage medium of claim 15 , wherein memory configured to store account credentials is persistent.

20. The nontransitory computer readable storage medium of claim 15 , wherein a certificate distributor of the stateless machine is configured to receive the private key before an autoenrollment mechanism is executed on the certificate distributor.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2015
From: MAYERS, CHRISTOPHER MORGAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 035529/0265 →
Continuity (1)
Related Publication 20160323104A1 · Nov 3, 2016