IP Library › Granted Patent US 11,153,099
Granted Patent B2
US 11,153,099 · App. 16/539,372 · Granted Oct 19, 2021

Reestablishing secure communication with a server after the server's certificate is renewed with a certificate authority unknown to the client

Inventors: Ngoc Pham (San Jose, CA); Satya Mylvara (Sunnyvale, CA)
Assignee: Dell Products L.P.
H04L9/3268G06F21/575H04L9/3213G06F2221/032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,099
App. No.
16/539,372
Filed
Aug 13, 2019
Granted
Oct 19, 2021
Kind
B2
Art Unit
2498
USPC
713/158
Abstract

Secure communication with a server can be reestablished after the server's certificate is renewed with a certificate authority unknown to a client. When a server's certificate is renewed with a CA whose certificate does not exist in a client's certificate store, the client will not be able to authenticate the server using SSL unless the CA's certificate is added to the certificate store. When a client is not updated to include the CA's certificate and therefore fails to authenticate the server, a web-based application on the client can perform a fallback authentication process to securely and automatically add any necessary CA certificates to the certificate store thereby eliminating the need for an administrator to manually install the necessary CA certificates.

Claims (61)

1. A method, implemented on a client, for reestablishing secure communication with a server after verification of the server's certificate failed due to the client not having one or more certificate authority (CA) certificates that are necessary to verify the server's certificate, the method comprising:

storing, on the client, a first server token that was received from the server;

receiving, from the server, a current server certificate;

attempting to verify the current server certificate;

in response to failing to verify the current server certificate, sending, to the server, a fallback authentication request;

in response to sending the fallback authentication request, receiving, from the server, a second server token and one or more CA certificates;

performing fallback authentication to authenticate the server, the fallback authentication including comparing the second server token to the first server token to determine that the second server token matches the first server token; and

in response to authenticating the server via the fallback authentication, adding the one or more CA certificates to a certificate store on the client.

2. The method of claim 1 , wherein comparing the second server token to the first server token includes comparing a second token identifier contained in the second server token to a first token identifier contained in the first server token, wherein the second server token is determined to match the first server token when the second token identifier matches the first token identifier.

3. The method of claim 2 , wherein the first server token stored on the client is mapped to a domain name, and wherein performing the fallback authentication further includes determining that a domain name included in the current server certificate matches the domain name to which the first server token is mapped.

4. The method of claim 1 , wherein performing the fallback authentication further includes:

identifying a URL of the server; and

comparing the URL of the server to a list of trusted URLs to determine that the URL of the server is included in the list of trusted URLs.

5. The method of claim 1 , wherein performing the fallback authentication further includes:

identifying an IP address of the server; and

comparing the IP address of the server to a list of trusted IP addresses to determine that the IP address of the server is included in the list of trusted IP addresses.

6. The method of claim 5 , wherein the list of trusted IP addresses only includes IP addresses of servers with which the client has previously established secure communication.

7. The method of claim 1 , further comprising:

after the one or more CA certificates are added to the certificate store on the client, again receiving, from the server, the current server certificate;

again attempting to verify the current server certificate;

based on the one or more CA certificates having been added to the certificate store, verifying the current server certificate; and

communicating securely with the server.

8. The method of claim 1 , further comprising:

prior to sending the fallback authentication request, causing the client to reboot into safe mode such that the fallback authentication is performed while the client is in safe mode.

9. The method of claim 1 , wherein the first server token is received from the server and stored on the client in response to and after verifying a previous server certificate.

10. The method of claim 1 , wherein the method is performed by a device agent that executes on the client and the server is part of a device management suite.

11. One or more non-transitory computer storage media storing computer executable instructions which when executed on a client implement a method for reestablishing secure communication with a server after verification of the server's certificate failed due to the client not having one or more certificate authority (CA) certificates that are necessary to verify the server's certificate, the method comprising:

storing, on the client, a first server token that was received from the server;

receiving, from the server, a current server certificate;

attempting to verify the current server certificate;

in response to failing to verify the current server certificate, sending, to the server, a fallback authentication request;

in response to sending the fallback authentication request, receiving, from the server, a second server token and one or more CA certificates;

performing fallback authentication to authenticate the server, the fallback authentication including comparing the second server token to the first server token to determine that the second server token matches the first server token; and

in response to authenticating the server via the fallback authentication, adding the one or more CA certificates to a certificate store on the client.

12. The computer storage media of claim 11 , wherein comparing the second server token to the first server token includes comparing a second token identifier contained in the second server token to a first token identifier contained in the first server token, wherein the second server token is determined to match the first server token when the second token identifier matches the first token identifier.

13. The computer storage media of claim 12 , wherein the first server token stored on the client is mapped to a domain name, and wherein performing the fallback authentication further includes determining that a domain name included in the current server certificate matches the domain name to which the first server token is mapped.

14. The computer storage media of claim 11 , wherein performing the fallback authentication further includes:

identifying a URL of the server; and

comparing the URL of the server to a list of trusted URLs to determine that the URL of the server is included in the list of trusted URLs.

15. The computer storage media of claim 11 , wherein performing the fallback authentication further includes:

identifying an IP address of the server; and

comparing the IP address of the server to a list of trusted IP addresses to determine that the IP address of the server is included in the list of trusted IP addresses.

16. The computer storage media of claim 15 , wherein the list of trusted IP addresses only includes IP addresses of servers with which the client has previously established secure communication.

17. The computer storage media of claim 11 , further comprising:

after the one or more CA certificates are added to the certificate store on the client, again receiving, from the server, the current server certificate;

again attempting to verify the current server certificate;

based on the one or more CA certificates having been added to the certificate store, verifying the current server certificate; and

communicating securely with the server.

18. The computer storage media of claim 11 , further comprising:

prior to sending the fallback authentication request, causing the client to reboot into safe mode such that the fallback authentication is performed while the client is in safe mode.

19. The computer storage media of claim 11 , wherein the first server token is received from the server and stored on the client in response to and after verifying a previous server certificate.

20. A client comprising:

one or more hardware processors; and

computer storage media storing computer executable instructions which when executed by the one or more processors implement a method for reestablishing secure communication with a server after verification of the server's certificate failed due to the client not having one or more certificate authority (CA) certificates that are necessary to verify the server's certificate, the method comprising:

storing, on the client, a first server token that was received from the server;

receiving, from the server, a current server certificate;

attempting to verify the current server certificate;

in response to failing to verify the current server certificate, sending, to the server, a fallback authentication request;

in response to sending the fallback authentication request, receiving, from the server, a second server token and one or more CA certificates;

performing fallback authentication to authenticate the server, the fallback authentication including comparing the second server token to the first server token to determine that the second server token matches the first server token; and

in response to authenticating the server via the fallback authentication, adding the one or more CA certificates to a certificate store on the client.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2019
From: PHAM, NGOC; MYLVARA, SATYA
To: DELL PRODUCTS L.P.
Reel/Frame 050039/0423 →
Continuity (1)
Related Publication 20210051029A1 · Feb 18, 2021