IP Library › Granted Patent US 11,366,914
Granted Patent B2
US 11,366,914 · App. 16/498,984 · Granted Jun 21, 2022

Authenticating access of service of service entity to application of client device based on whether root certificate corresponding to application is installed in service entity

Inventor: Surender Panuganti (Bangalore, IN)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/608H04L63/0823H04L63/166H04W36/0005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,366,914
App. No.
16/498,984
Granted
Jun 21, 2022
Kind
B2
Abstract

Examples for authenticating applications to allow access to a service being offered by a service entity, are described. In one example, a request from an application for accessing services is received over a handshake session adhering to a security protocol. It is determined whether a root certificate corresponding to the application is installed in the service entity. Based on the determination, the request is authenticated to allow access to the services. The authenticating is performed in the handshake session.

Claims (52)

1. A service entity comprising:

a service engine to provide a service in response to request from an application installed on a client device, wherein the service engine is to:

receive a request from the application for accessing the service;

determine whether a root certificate corresponding to the application is installed in the service entity; and

authenticate the request based on the determining, by:

providing access of the service to the application on determining that the root certificate is installed in the service entity; and

denying the access of the service to the application on determining that the root certificate is not installed in the service entity,

wherein the authenticating is performed in a handshake session between the service entity and the client device, with the handshake session adhering to a security protocol.

2. The service entity as claimed in claim 1 , wherein the service engine, to determine whether the root certificate is installed, is to:

request a client certificate from the client device, with the client certificate corresponding to the application, wherein the client certificate is signed by the root certificate;

retrieve information associated with the root certificate from the client certificate; and

based on the information, identify whether the root certificate is installed on the service entity.

3. The service entity as claimed in claim 1 , wherein the security protocol is one of Transport Layer Security (TLS) and Secure Sockets Layer (SSL).

4. The service entity as claimed in claim 3 , wherein the handshake session is a TLS handshake session between the service entity and the client device.

5. The service entity as claimed in claim 1 , wherein the root certificate specifies a unique application identifier for the application which may access the service provided by the service entity,

and wherein the root certificate is generated for the application prior to development of the application being completed.

6. The service entity as claimed in claim 1 , wherein the root certificate is uninstallable to subsequently deny the application access to the service.

7. A method comprising:

obtaining by a service entity, a root certificate from a source repository, wherein the root certificate corresponds to an application installed on a client device;

receiving command to enable client authentication on the service entity, wherein the client authentication is based on the root certificate;

monitoring incoming requests for a service being provided by the service entity from the application over a handshake session adhering to a security protocol;

determining whether the root certificate corresponding to the application is installed within the service entity; and

authenticating the incoming requests based on the root certificate, by:

determining whether the root certificate corresponding to the application is installed in the service entity;

providing access of the service to the application on determining that the root certificate is installed in the service entity; and

denying the access of the service to the application on determining that the root certificate is not installed in the service entity.

8. The method as claimed in claim 7 , wherein the root certificate is a public key certificate to identify a root certificate authority and a unique application identification,

and wherein the root certificate is generated for the application prior to development of the application being completed.

9. The method as claimed in claim 7 , wherein the method comprises enabling client authentication conforming to the security protocol.

10. The method as claimed in claim 7 , wherein determining whether the root certificate is installed comprises:

requesting a client certificate from the client device, with the client certificate corresponding to the application, wherein the client certificate is signed by the root certificate;

retrieving information associated with the root certificate from the client certificate; and

based on the information, identify whether the root certificate is installed on the service entity.

11. The method as claimed in claim 10 , the method further comprising:

uninstalling the root certificate from the service entity;

monitoring incoming requests from the application to access the service; and

denying access to the incoming request.

12. The method as claimed in claim 7 , wherein the service entity is a print device.

13. A non-transitory computer-readable medium comprising instructions executable by a processing resource to:

import a root certificate into a service entity providing a service, wherein the root certificate corresponds to the application installed on a client device;

enable client authentication on the service entity;

receive a request from the application for accessing the service;

determine whether the root certificate corresponding to the application is installed within the service entity; and

authenticate the incoming requests based on the root certificate, by:

determining whether the root certificate corresponding to the application is installed in the service entity;

providing access of the service to the application on determining that the root certificate is installed in the service entity; and

denying the access of the service to the application on determining that the root certificate is not installed in the service entity.

14. The non-transitory computer-readable medium as claimed in claim 13 , wherein the instructions are executable by the processing resource to determine whether the root certificate is installed by:

requesting a client certificate from the client device, with the client certificate corresponding to the application, wherein the client certificate is signed by the root certificate;

retrieving information associated with the root certificate from the client certificate; and

based on the information, identify whether the root certificate is installed on the service entity.

15. The non-transitory computer-readable medium as claimed in claim 13 , wherein the root certificate is generated for the application prior to development of the application being completed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2020
From: PANUGANTI, SURENDER
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 052252/0444 →
Priority Claims (1)
IN IN201741013410 · Apr 14, 2017 · national
Continuity (1)
Related Publication 20210089666A1 · Mar 25, 2021