IP Library Granted Patent US 12,401,657
Granted Patent B2
US 12,401,657 · App. 18/466,447 · Granted Aug 26, 2025

Aggregating certificate authority certificates for authenticating network entities located in different trust zones

Inventors: Haya Majeed (Mill Creek, WA); Tony Long (Edmonds, WA); Mauruthi Geetha Mohan (Seattle, WA)
Assignee: Oracle International Corporation
H04L63/105H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,657
App. No.
18/466,447
Granted
Aug 26, 2025
Kind
B2
Abstract

Operations of a certificate authority (CA) service may include aggregating in a certificate repository, a plurality of sets of CA certificates, in which each set of CA certificates is issued by a particular CA that is associated with a particular trust zone and that is trusted by a particular set of network entities located in the particular trust zone. The operations may further include distributing for access by an additional set of network entities, an aggregate set of CA certificates that includes the plurality of sets of CA certificates. The additional set of network entities may utilize the plurality of sets of CA certificates to authenticate network entities located in different trust zones.

Claims (115)

1. One or more non-transitory computer-readable media storing instructions, which when executed by one or more hardware processors, cause performance of operations comprising:

receiving, from a first certificate authority (CA) service associated with a first CA, a first set of one or more CA certificates issued by the first CA, wherein the first CA service is located in a first trust zone, and wherein the first CA is trusted by a first set of one or more network entities;

receiving, from a second CA service associated with a second CA, a second set of one or more CA certificates issued by the second CA, wherein the second CA service is located in a second trust zone, and wherein the second CA is trusted by a second set of one or more network entities;

aggregating in a first certificate repository, the first set of one or more CA certificates and the second set of one or more CA certificates;

distributing for access by a third set of one or more network entities, an aggregate set of CA certificates comprising the first set of one or more CA certificates and the second set of one or more CA certificates,

wherein the third set of one or more network entities access the aggregate set of CA certificates, and (a) use the first set of one or more CA certificates of the aggregate set of CA certificates to authenticate a first set of one or more entity certificates issued by the first CA to the first set of one or more network entities and (b) use the second set of one or more CA certificates of the aggregate set of CA certificates to authenticate a second set of one or more entity certificates issued by the second CA to the second set of one or more network entities.

2. The media of claim 1 , wherein the first set of one or more network entities are located in the first trust zone, and the second set of one or more network entities are located in the second trust zone.

3. The media of claim 1 , wherein the third set of one or more network entities are located in at least one of: the first trust zone, or a third trust zone.

4. The media of claim 1 , wherein the first trust zone comprises a home region, and wherein the second trust zone comprises an ancillary region.

5. The media of claim 1 , wherein the first CA is untrusted by the second set of one or more network entities, and wherein the second CA is untrusted by the first set of one or more network entities.

6. The media of claim 1 , wherein the third set of one or more network entities (a) use the first set of one or more CA certificates in the aggregate set of CA certificates to establish trust with the first CA, and (b) use the second set of one or more CA certificates in the aggregate set of CA certificates to establish trust with the second CA.

7. The media of claim 1 , wherein the third set of one or more network entities comprises an intermediate service host, and

wherein, subsequent to the intermediate service host authenticating the first set of one or more entity certificates and the second set of one or more entity certificates, the first set of one or more network entities and the second set of one or more network entities communicate and/or exchange data across at least one trust zone boundary via the intermediate service host.

8. The media of claim 1 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a second certificate repository accessible, directly or indirectly, by the third set of one or more network entities.

9. The media of claim 8 , wherein the second certificate repository is located in a different trust zone relative to one or more of: the first set of one or more network entities and the second set of one or more network entities.

10. The media of claim 9 , wherein the second certificate repository and the third set of one or more network entities are respectively located in a third trust zone.

11. The media of claim 8 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

transmitting a notification to the third set of one or more network entities, the notification indicating that the aggregate set of CA certificates is available in the second certificate repository for distribution to the third set of one or more network entities.

12. The media of claim 8 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

determining that the aggregate set of CA certificates is available in the second certificate repository; and

responsive to determining that the aggregate set of CA certificates is available in the second certificate repository:

downloading the aggregate set of CA certificates from the second certificate repository; and

storing the aggregate set of CA certificates in a third certificate repository accessible, directly or indirectly, by the third set of one or more network entities, wherein the third certificate repository is located in a different trust zone relative to the second certificate repository.

13. The media of claim 1 ,

wherein the first trust zone comprises a first ancillary trust zone, wherein the first CA is a first intrazone CA of the first ancillary trust zone, and wherein the first set of one or more network entities are located in the first ancillary trust zone; and

wherein the second trust zone comprises a second ancillary trust zone, wherein the second CA is a second intrazone CA of the second ancillary trust zone, and wherein the second set of one or more network entities are located in the second ancillary trust zone.

14. The media of claim 13 , wherein the operations further comprise:

initially provisioning or updating the third set of one or more network entities, wherein initially provisioning or updating the third set of one or more network entities comprises:

receiving, from the first set of one or more network entities, the first set of one or more entity certificates, and authenticating the first set of one or more entity certificates via the first set of one or more CA certificates;

receiving, from the second set of one or more network entities, the second set of one or more entity certificates, and authenticating the second set of one or more entity certificates via the second set of one or more CA certificates.

15. The media of claim 14 , wherein initially provisioning or updating the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a third certificate repository accessible by the third set of one or more network entities.

16. The media of claim 1 ,

wherein the first trust zone comprises an ancillary trust zone, wherein the first CA is an intrazone CA of the ancillary trust zone, and wherein the first set of one or more network entities are located in the ancillary trust zone; and

wherein the second trust zone is a home trust zone, wherein the second CA is a home CA of the home trust zone, wherein the second set of one or more network entities are located in the home trust zone.

17. The media of claim 16 , wherein the operations further comprise:

initially provisioning or updating the third set of one or more network entities, wherein initially provisioning or updating the third set of one or more network entities comprises:

receiving, from the first set of one or more network entities, the first set of one or more entity certificates, and authenticating the first set of one or more entity certificates via the first set of one or more CA certificates;

receiving, from the second set of one or more network entities, the second set of one or more entity certificates, and authenticating the second set of one or more entity certificates via the second set of one or more CA certificates.

18. The media of claim 17 , wherein initially provisioning or updating the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a third certificate repository accessible by the third set of one or more network entities.

19. The media of claim 1 ,

wherein a first network entity, of the first set of one or more network entities, is a first intrazone network entity;

wherein a second network entity, of the second set of one or more network entities, is a second intrazone network entity;

wherein a third network entity, of the third set of one or more network entities, is an interzone network entity located in a third trust zone;

wherein the first intrazone network entity and the second intrazone network entity communicate and/or exchange data directly or indirectly with one another across a trust zone boundary in accordance with an interzone security protocol, wherein the interzone security protocol comprises the interzone network entity (a) authenticating the first intrazone network entity based at least in part on a first CA certificate, of the first set of one or more CA certificates, and (b) authenticating the second intrazone network entity based at least in part on a second CA certificate, of the second set of one or more CA certificates.

20. The media of claim 1 ,

wherein the first set of one or more network entities comprises an interzone network entity;

wherein the second set of one or more network entities comprises a first intrazone network entity;

wherein the third set of one or more network entities comprises a second intrazone network entity located in the second trust zone;

wherein the second intrazone network entity and the interzone network entity communicate and/or exchange data with one another across a first trust zone boundary in accordance with an interzone security protocol, wherein the interzone security protocol comprises the second intrazone network entity authenticating the interzone network entity based at least in part on a first CA certificate, of the first set of one or more CA certificates;

wherein the first intrazone network entity and the second intrazone network entity communicate and/or exchange data with one another across a second trust zone boundary in accordance with an intrazone security protocol, wherein the intrazone security protocol comprises (a), the second intrazone network entity authenticating the interzone network entity based at least in part on the first CA certificate, of the first set of one or more CA certificates and (b) the second intrazone network entity authenticating the first intrazone network entity based at least in part on a second CA certificate, of the second set of one or more CA certificates.

21. A method, comprising:

receiving, from a first certificate authority (CA) service associated with a first CA, a first set of one or more CA certificates issued by the first CA, wherein the first CA service is located in a first trust zone, and wherein the first CA is trusted by a first set of one or more network entities;

receiving, from a second CA service associated with a second CA, a second set of one or more CA certificates issued by the second CA, wherein the second CA service is located in a second trust zone, and wherein the second CA is trusted by a second set of one or more network entities;

aggregating in a first certificate repository, the first set of one or more CA certificates and the second set of one or more CA certificates;

distributing for access by a third set of one or more network entities, an aggregate set of CA certificates comprising the first set of one or more CA certificates and the second set of one or more CA certificates,

wherein the third set of one or more network entities access the aggregate set of CA certificates, and (a) use the first set of one or more CA certificates of the aggregate set of CA certificates to authenticate a first set of one or more entity certificates issued by the first CA to the first set of one or more network entities and (b) use the second set of one or more CA certificates of the aggregate set of CA certificates to authenticate a second set of one or more entity certificates issued by the second CA to the second set of one or more network entities;

wherein the method is performed by at least one device including a hardware processor.

22. The method of claim 21 , wherein the first set of one or more network entities are located in the first trust zone, and the second set of one or more network entities are located in the second trust zone.

23. The method of claim 21 , wherein the third set of one or more network entities are located in at least one of: the first trust zone, or a third trust zone.

24. The method of claim 21 , wherein the first trust zone comprises a home region, and wherein the second trust zone comprises an ancillary region.

25. The method of claim 21 , wherein the first CA is untrusted by the second set of one or more network entities, and wherein the second CA is untrusted by the first set of one or more network entities.

26. The method of claim 21 , wherein the third set of one or more network entities (a) use the first set of one or more CA certificates in the aggregate set of CA certificates to establish trust with the first CA, and (b) use the second set of one or more CA certificates in the aggregate set of CA certificates to establish trust with the second CA.

27. The method of claim 21 , wherein the third set of one or more network entities comprises an intermediate service host, and

wherein, subsequent to the intermediate service host authenticating the first set of one or more entity certificates and the second set of one or more entity certificates, the first set of one or more network entities and the second set of one or more network entities communicate and/or exchange data across at least one trust zone boundary via the intermediate service host.

28. The method of claim 21 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a second certificate repository accessible, directly or indirectly, by the third set of one or more network entities.

29. The method of claim 28 , wherein the second certificate repository is located in a different trust zone relative to one or more of: the first set of one or more network entities and the second set of one or more network entities.

30. The method of claim 29 , wherein the second certificate repository and the third set of one or more network entities are respectively located in a third trust zone.

31. The method of claim 28 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

transmitting a notification to the third set of one or more network entities, the notification indicating that the aggregate set of CA certificates is available in the second certificate repository for distribution to the third set of one or more network entities.

32. The method of claim 28 , wherein distributing the aggregate set of CA certificates for access by the third set of one or more network entities comprises:

determining that the aggregate set of CA certificates is available in the second certificate repository; and

responsive to determining that the aggregate set of CA certificates is available in the second certificate repository:

downloading the aggregate set of CA certificates from the second certificate repository; and

storing the aggregate set of CA certificates in a third certificate repository accessible, directly or indirectly, by the third set of one or more network entities, wherein the third certificate repository is located in a different trust zone relative to the second certificate repository.

33. The method of claim 21 ,

wherein the first trust zone comprises a first ancillary trust zone, wherein the first CA is a first intrazone CA of the first ancillary trust zone, and wherein the first set of one or more network entities are located in the first ancillary trust zone; and

wherein the second trust zone comprises a second ancillary trust zone, wherein the second CA is a second intrazone CA of the second ancillary trust zone, and wherein the second set of one or more network entities are located in the second ancillary trust zone.

34. The method of claim 21 , wherein the method further comprises:

initially provisioning or updating the third set of one or more network entities, wherein initially provisioning or updating the third set of one or more network entities comprises:

receiving, from the first set of one or more network entities, the first set of one or more entity certificates, and authenticating the first set of one or more entity certificates via the first set of one or more CA certificates;

receiving, from the second set of one or more network entities, the second set of one or more entity certificates, and authenticating the second set of one or more entity certificates via the second set of one or more CA certificates.

35. The method of claim 34 , wherein initially provisioning or updating the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a third certificate repository accessible by the third set of one or more network entities.

36. The method of claim 21 ,

wherein the first trust zone comprises an ancillary trust zone, wherein the first CA is an intrazone CA of the ancillary trust zone, and wherein the first set of one or more network entities are located in the ancillary trust zone; and

wherein the second trust zone comprises a home trust zone, wherein the second CA is a home CA of the home trust zone, wherein the second set of one or more network entities are located in the home trust zone.

37. The method of claim 36 , wherein the method further comprises:

initially provisioning or updating the third set of one or more network entities, wherein initially provisioning or updating the third set of one or more network entities comprises:

receiving, from the first set of one or more network entities, the first set of one or more entity certificates, and authenticating the first set of one or more entity certificates via the first set of one or more CA certificates;

receiving, from the second set of one or more network entities, the second set of one or more entity certificates, and authenticating the second set of one or more entity certificates via the second set of one or more CA certificates.

38. The method of claim 37 , wherein initially provisioning or updating the third set of one or more network entities comprises:

storing the aggregate set of CA certificates in a third certificate repository accessible by the third set of one or more network entities.

39. The method of claim 21 ,

wherein a first network entity, of the first set of one or more network entities, is a first intrazone network entity;

wherein a second network entity, of the second set of one or more network entities, is a second intrazone network entity;

wherein a third network entity, of the third set of one or more network entities, is an interzone network entity located in a third trust zone;

wherein the first intrazone network entity and the second intrazone network entity communicate and/or exchange data directly or indirectly with one another across a trust zone boundary in accordance with an interzone security protocol, wherein the interzone security protocol comprises the interzone network entity (a) authenticating the first intrazone network entity based at least in part on a first CA certificate, of the first set of one or more CA certificates, and (b) authenticating the second intrazone network entity based at least in part on a second CA certificate, of the second set of one or more CA certificates.

40. The method of claim 21 ,

wherein the first set of one or more network entities comprises an interzone network entity;

wherein the second set of one or more network entities comprises a first intrazone network entity;

wherein the third set of one or more network entities comprises a second intrazone network entity located in the second trust zone;

wherein the second intrazone network entity and the interzone network entity communicate and/or exchange data with one another across a first trust zone boundary in accordance with an interzone security protocol, wherein the interzone security protocol comprises the second intrazone network entity authenticating the interzone network entity based at least in part on a first CA certificate, of the first set of one or more CA certificates;

wherein the first intrazone network entity and the second intrazone network entity communicate and/or exchange data with one another across a second trust zone boundary in accordance with an intrazone security protocol, wherein the intrazone security protocol comprises (a), the second intrazone network entity authenticating the interzone network entity based at least in part on the first CA certificate, of the first set of one or more CA certificates and (b) the second intrazone network entity authenticating the first intrazone network entity based at least in part on a second CA certificate, of the second set of one or more CA certificates.

41. A system comprising:

at least one hardware processor;

the system being configured to execute operations, using the at least one hardware processor, the operations comprising:

receiving, from a first certificate authority (CA) service associated with a first CA, a first set of one or more CA certificates issued by the first CA, wherein the first CA service is located in a first trust zone, and wherein the first CA is trusted by a first set of one or more network entities;

receiving, from a second CA service associated with a second CA, a second set of one or more CA certificates issued by the second CA, wherein the second CA service is located in a second trust zone, and wherein the second CA is trusted by a second set of one or more network entities;

aggregating in a first certificate repository, the first set of one or more CA certificates and the second set of one or more CA certificates;

distributing for access by a third set of one or more network entities, an aggregate set of CA certificates comprising the first set of one or more CA certificates and the second set of one or more CA certificates,

wherein the third set of one or more network entities access the aggregate set of CA certificates, and (a) use the first set of one or more CA certificates of the aggregate set of CA certificates to authenticate a first set of one or more entity certificates issued by the first CA to the first set of one or more network entities and (b) use the second set of one or more CA certificates of the aggregate set of CA certificates to authenticate a second set of one or more entity certificates issued by the second CA to the second set of one or more network entities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2023
From: MAJEED, HAYA; LONG, TONY; GEETHA MOHAN, MAURUTHI
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 064915/0947 →
Continuity (1)
Related Publication 20250088514A1 · Mar 13, 2025
References Cited (143)
US 5699431A · Van Oorschot et al. · 1997 [cited by applicant]
US 7272714B2 · Nagaratnam · 2007 [cited by examiner]
US 7644270B1 · Cherukumudi · 2010 [cited by examiner]
US 8452958B2 · Sun et al. · 2013 [cited by applicant]
US 9172543B2 · Wnuk · 2015 [cited by applicant]
US 9197630B2 · Sharif et al. · 2015 [cited by applicant]
US 9231933B1 · Shenoy et al. · 2016 [cited by applicant]
US 9485101B2 · Bowen · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9680813B2 · Sade et al. · 2017 [cited by applicant]
US 9794249B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9882727B1 · Veladanda et al. · 2018 [cited by applicant]
US 10021084B2 · Matthews et al. · 2018 [cited by applicant]
US 10212147B2 · Buendgen et al. · 2019 [cited by applicant]
US 10652030B1 · Levy et al. · 2020 [cited by applicant]
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10771261B1 · Lazar et al. · 2020 [cited by applicant]
US 10812276B2 · Bojjireddy et al. · 2020 [cited by applicant]
US 10848323B2 · Barr, III et al. · 2020 [cited by applicant]
US 11153103B2 · Fynaardt et al. · 2021 [cited by applicant]
US 11196570B2 · Borne-Pons et al. · 2021 [cited by applicant]
US 11310059B2 · Leibmann et al. · 2022 [cited by applicant]
US 11362843B1 · Jiang et al. · 2022 [cited by applicant]
US 11368314B2 · Ray et al. · 2022 [cited by applicant]
US 11388594B2 · Uy · 2022 [cited by examiner]
US 11438325B2 · Begun · 2022 [cited by examiner]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11706038B1 · Thakore · 2023 [cited by examiner]
US 11888997B1 · Bowen et al. · 2024 [cited by applicant]
US 12088738B2 · Rosenthol · 2024 [cited by examiner]
US 20020007346A1 · Qiu · 2002 [cited by examiner]
US 20020174066A1 · Kleckner et al. · 2002 [cited by applicant]
US 20030037234A1 · Fu et al. · 2003 [cited by applicant]
US 20060047965A1 · Thayer · 2006 [cited by applicant]
US 20060101510A1 · Kadyk et al. · 2006 [cited by applicant]
US 20070005956A1 · Zilinskas et al. · 2007 [cited by applicant]
US 20070147619A1 · Bellows et al. · 2007 [cited by applicant]
US 20100030897A1 · Stradling · 2010 [cited by applicant]
US 20100325429A1 · Saha et al. · 2010 [cited by applicant]
US 20110113239A1 · Fu et al. · 2011 [cited by applicant]
US 20120036220A1 · Dare et al. · 2012 [cited by applicant]
US 20120246466A1 · Salvarani et al. · 2012 [cited by applicant]
US 20140298419A1 · Boubez · 2014 [cited by examiner]
US 20150135299A1 · Liang et al. · 2015 [cited by applicant]
US 20170039373A1 · Sasin et al. · 2017 [cited by applicant]
US 20170126667A1 · Bishop et al. · 2017 [cited by applicant]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170317837A1 · Alrawais et al. · 2017 [cited by applicant]
US 20170338967A1 · Lewison et al. · 2017 [cited by applicant]
US 20180083966A1 · Zhou et al. · 2018 [cited by applicant]
US 20180102904A1 · Lin et al. · 2018 [cited by applicant]
US 20180287804A1 · Geisbush · 2018 [cited by applicant]
US 20190149342A1 · Fynaardt et al. · 2019 [cited by applicant]
US 20190165950A1 · Ibrahim · 2019 [cited by applicant]
US 20190347406A1 · Lev-Ran · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190363895A1 · Barr et al. · 2019 [cited by applicant]
US 20200021575A1 · Rezvani et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang et al. · 2020 [cited by applicant]
US 20200150972A1 · Ketkar et al. · 2020 [cited by applicant]
US 20200274718A1 · Hwang · 2020 [cited by examiner]
US 20200274862A1 · Varvarezis et al. · 2020 [cited by applicant]
US 20210034767A1 · Free et al. · 2021 [cited by applicant]
US 20210126801A1 · Nix · 2021 [cited by applicant]
US 20210152547A1 · Barhudarian et al. · 2021 [cited by applicant]
US 20210211307A1 · Statia et al. · 2021 [cited by applicant]
US 20210218723A1 · Lekov et al. · 2021 [cited by applicant]
US 20210392002A1 · Gray et al. · 2021 [cited by applicant]
US 20210409403A1 · Lewin et al. · 2021 [cited by applicant]
US 20210409409A1 · Palanisamy · 2021 [cited by applicant]
US 20220038894A1 · Yoon et al. · 2022 [cited by applicant]
US 20220123951A1 · Lutz et al. · 2022 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220239503A1 · Mallikarjuna et al. · 2022 [cited by applicant]
US 20220393886A1 · Williams et al. · 2022 [cited by applicant]
US 20230032867A1 · Peddada et al. · 2023 [cited by applicant]
US 20230109231A1 · Adogla et al. · 2023 [cited by applicant]
US 20230208655A1 · Statia et al. · 2023 [cited by applicant]
US 20230237155A1 · Jacquin et al. · 2023 [cited by applicant]
US 20230291577A1 · Thai et al. · 2023 [cited by applicant]
US 20230401307A1 · Pop et al. · 2023 [cited by applicant]
US 20230412397A1 · Gollent et al. · 2023 [cited by applicant]
US 20240015508A1 · Yoon et al. · 2024 [cited by applicant]
US 20240020373A1 · Ivanov et al. · 2024 [cited by applicant]
US 20240031146A1 · Marosi-Bauer et al. · 2024 [cited by applicant]
US 20240106886A1 · Roy et al. · 2024 [cited by applicant]
US 20240121603A1 · Yoon et al. · 2024 [cited by applicant]
US 20240146543A1 · Sahoo · 2024 [cited by examiner]
US 20240333640A1 · Shevade et al. · 2024 [cited by applicant]
US 20240356763A1 · Goldberg et al. · 2024 [cited by applicant]
US 20240388510A1 · Madtha et al. · 2024 [cited by applicant]
US 20250030561A1 · Long et al. · 2025 [cited by applicant]
US 20250088373A1 · Uzun et al. · 2025 [cited by applicant]
US 20250097211A1 · Uzun et al. · 2025 [cited by applicant]
US 20250133401A1 · Lee et al. · 2025 [cited by applicant]
CN 112019477A · 2020 [cited by applicant]
CN 114884963A · 2022 [cited by applicant]
EP 1251670A2 · 2002 [cited by applicant]
EP 2267970A2 · 2010 [cited by applicant]
EP 2854349A1 · 2015 [cited by applicant]
EP 3772208B1 · 2024 [cited by applicant]
KR 1020110045459A · 2011 [cited by applicant]
WO 2006122024A2 · 2006 [cited by applicant]
WO 2022121461A1 · 2022 [cited by applicant]
WO 2022133026A1 · 2022 [cited by applicant]
WO 2023240360A1 · 2023 [cited by applicant]
WO 2025059187A1 · 2025 [cited by applicant]
“What is Certificate Lifecycle Management”, Retrieved from https://www.encryptionconsulting.com/different-phases-of-a-certificate-lifecycle-management-process/, Aug. 1, 2024, pp. 1-12. [cited by applicant]
“About Azure Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/about-certificates, Feb. 8, 2023, pp. 1-8. [cited by applicant]
“About the Expressway”, Aug. 17, 2022. pp. 1-12. [cited by applicant]
“Automated certificate management for TLS certificates”, Retrieved from https://docs.servicenow.com/en-us/bundle/utah-it-operations-management/page/product/discovery/concept/automated-cert-requests.html, Retrieved on Ma… [cited by applicant]
“AWS Certificate Manager FAQs”, Retrieved from https://aws.amazon.com/certificate-manager/faqs/, Retrieved on Mar. 24, 2023, pp. 1-17. [cited by applicant]
“Azure Instance Metadata Service”, Retrieved from https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows, Mar. 15, 2023, pp. 1-42. [cited by applicant]
“Cisco Expressway Certificate Creation and Use Deployment Guide”, Feb. 23, 2021, pp. 10. [cited by applicant]
“Deploying the CA bundle iApp”, Retrieved from https://www.f5.com/pdf/deployment-guides/f5-ca-bundle-dg.pdf, Dec. 14, 2017, pp. 1-9. [cited by applicant]
“DigiCert Public Key Infrastructure (PKI) Platform”, 2019, pp. 15. [cited by applicant]
“Get started with Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios, Retrieved on Feb. 1, 2023, pp. 1-6. [cited by applicant]
“High Availability using Patching and Rolling AP Upgrade on Cisco Catalyst 9800 Wireless Controllers”, Copyright 2020, pp. 1-41. [cited by applicant]
“Manage Certificate Revocation Lists (CRLs)”, Jul. 23, 2021, pp. 1-4. [cited by applicant]
“PKI secrets engine”, Retrieved from https://developer.hashicorp.com/vault/docs/secrets/pki, Retrieved on May 4, 2023, pp. 1-3. [cited by applicant]
“Planning a certificate revocation list (CRL)”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/crl-planning.html, Retrieved on Jul. 28, 2023, pp. 11. [cited by applicant]
“Release app updates with staged rollouts”, Retrieved from https://support.google.com/googleplay/android-developer/answer/6346149?hl=en#zippy=%2Crelease-a-staged-rollout-to-specific-countries, Retrieved on Apr. 27, 2023… [cited by applicant]
“Release Your App Update in a Staged Rollout”, Retrieved from https://developer.amazon.com/docs/app-submission/release-updates-in-staged-rollouts.html, Retrieved on Apr. 27, 2023, pp. 1-18. [cited by applicant]
“Rotate Security Certificates”, Retrieved from https://www.cockroachlabs.com/docs/stable/rotate-certificates, Retrieved on May 4, 2023, pp. 1-6. [cited by applicant]
“Rotating the Root CA and Leaf Certificates”, Retrieved from https://docs.pivotal.io/ops-manager/2-4/security/pcf-infrastructure/rotate-cas-and-leaf-certs.html, Nov. 5, 2020, pp. 1-9. [cited by applicant]
“Staged upgrade”, Retrieved from https://www.ibm.com/docs/en/order-management-sw/9.4.0?topic=migrating-staged-upgrade, Mar. 2, 2021, pp. 1-3. [cited by applicant]
“Troubleshoot SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/troubleshooting, Retrieved on Mar. 24, 2023, pp. 1-8. [cited by applicant]
“Tutorial: Configure certificate auto-rotation in Key Vault”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-rotate-certificates, Feb. 27, 2023, pp. 1-6. [cited by applicant]
“Updating the CA bundle”, Retrieved from https://docs.openshift.com/container-platform/4.9/security/certificates/updating-ca-bundle.html#ca-bundle-understanding_updating-ca-bundle, Retrieved on Mar. 24, 2023, pp. 1-2. [cited by applicant]
“Updating your private CA”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/PCAUpdateCA.html, Retrieved on Mar. 24, 2023, pp. 1-4. [cited by applicant]
“Use self-managed SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs, Aug. 15, 2023, pp. 13. [cited by applicant]
“VSphere Security”, vmware, Update 3, Mar. 21, 2023, pp. 1-426. [cited by applicant]
“Working with Hosts”, Retrieved from https://docs.cloudstack.apache.org/projects/archived-cloudstack-administration/en/latest/hosts.html, Retrieved on Mar. 24, 2023, pp. 1-7. [cited by applicant]
Atutxa et al., “Improving efficiency and security of IIoT communications using in-network validation of server certificate”, Computers in Industry, vol. 144, Jan. 2023, 103802, pp. 30. [cited by applicant]
Bigelow S.J., “Rolling deployment”, Retrieved from https://www.techtarget.com/searchitoperations/definition/rolling-deployment, Jan. 2023, pp. 4. [cited by applicant]
Este-Gracias S., “Rotate your CA seamlessly using a Vault PKI”, Retrieved from https://sestegra.medium.com/rotate-your-ca-seamlessly-using-a-vault-pki-9262228b4afb Sep. 29, 2022, pp. 1-49. [cited by applicant]
Ghanmi et al., “A Secure Data Storage in Multi-cloud Architecture Using Blowfish Encryption Algorithm”, Advanced Information Networking and Applications, Mar. 2022, pp. 398-408. [cited by applicant]
Jamal F., “Zero Trust for SSH—Secure One-click Server Access for Software Engineering Teams”, Retrieved from https://www.banyansecurity.io/blog/zero-trust-for-ssh/, Oct. 28, 2020, pp. 1-7. [cited by applicant]
Manjusha R. et al., “Secure Authentication and Access System for Cloud Computing Auditing Services Using Associated Digital Certificate”, Indian Journal of Science and Technology, vol. 8 (S7), Apr. 2015, pp. 220-227. [cited by applicant]
Nexthop Team, “Updated: Creating a Certificate Revocation List Distribution Point for Your Internal Certification Authority”, Retrieved from https://techcommunity.microsoft.com/t5/skype-for-business-blog/updated-creatin… [cited by applicant]
Rowley J., “Google's Moving Forward Together Proposals for Root CA Policy: Rotating ICAS More Frequently”, Retrieved from https://www.digicert.com/blog/googles-moving-forward-together-proposals-for-root-ca-policy, Mar. … [cited by applicant]
Subhayu, “Different Phases of a Certificate Lifecycle Management Process for a secure WPA2-Enterprise network”, Certificate Lifecycle Management Oct. 6, 2022, pp. 16. [cited by applicant]
Ylonen et al., “Security of Automated Access Management Using Secure Shell (SSH)”, NISTIR 7966 (Draft), Aug. 2014, pp. 43. [cited by applicant]