IP Library › Granted Patent US 12,519,770
Granted Patent B2
US 12,519,770 · App. 17/246,970 · Granted Jan 6, 2026

Intelligent certificate discovery in physical and virtualized networks

Inventors: Thomas H. Benjamin (Cedar Park, TX); Steven E.T. Hikida (Markham, CA); John T. Peck (Liberty Hill, TX); Bruce A. Rich (Cedar Park, TX); Richard L. Robinson (Broomfield, CO)
Assignee: Edison Vault, LLC
H04L63/0823H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,770
App. No.
17/246,970
Granted
Jan 6, 2026
Kind
B2
Abstract

Mechanisms are provided, in a communication device associated with a first computing device, for capturing security data exchanged between the first computing device and a second computing device. The mechanisms receive a data message from either the first computing device or the second computing device. The data message is part of an operation for establishing a secure communication connection between the first computing device and the second computing device. The mechanisms filter the received data message for security data passed in the received data message and mirror the security data to an analysis port of the communication device. Moreover, the mechanisms output, via the analysis port, the security data to a data collection and analysis system that analyzes the security data with regard to security requirement compliance.

Claims (51)

1 . A method, in a switch associated with a first computing device, for capturing security data exchanged between the first computing device and a second computing device, the method comprising:

in a first port of the switch, receiving data messages from either the first computing device or the second computing device to be passed from the first port of the switch to a second port of the switch;

by a switch port analyzer of the switch, identifying from the data messages a handshake operation or other negotiation to establish a secure communication connection between the first computing device and the second computing device;

by the switch port analyzer, after identifying the handshake operation or the other negotiation, monitoring the data messages between the first computing device and the second computing device for security certificate data;

by the switch port analyzer of the switch, responsive to monitoring the one or more additional data messages, identifying one of the data messages as including security certificate data and extracting the security certificate data from the one of the data messages;

after identifying the one of the data messages, by the switch port analyzer, mirroring at least the extracted security certificate data to an analysis port of the switch;

after mirroring the extracted security certificate data, by the switch via the analysis port, outputting the mirrored extracted security data to a data collection and analysis system that is distinct from the switch.

2 . The method of claim 1 , wherein identifying the one of the data messages as including security certificate data and extracting the security certificate data from the one of the data messages comprises analyzing a traffic flow of data traffic through the switch by implementing logic to identify patterns of the data messages passed between the first computing device and the second computing device, field values in headers of data messages in the traffic flow, tags in data messages in the traffic flow, or communication identifiers corresponding to types of communications used to establish secure communication connections; and

identifying the received data message as a message that is part of the operation for establishing a secure communication connection in response to the received data messages being identified by the logic as being a communication used to establish the secure communication connection.

3 . The method of claim 1 , wherein the extracted security certificate data comprises an unencrypted security certificate.

4 . The method of claim 3 , wherein the unencrypted security certificate is a security certificate of the second computing device passed in the received data message as part of a traffic flow from the second computing device to the first computing device.

5 . The method of claim 1 , further comprising analyzing the extracted security certificate data with regard to security requirement compliance.

6 . The method of claim 1 , further comprising determining whether or not one or more security compliance requirements are met by a secure communication connection.

7 . The method of claim 1 , further comprising:

analyzing, by the data collection and analysis system, the security data to identify at least one of certificate usage trends, risky certificate analytics, or security alert trigger analytics;

comparing results of the analysis with one or more security compliance requirements; and

determining whether or not the one or more security compliance requirements are met by the secure communication connection.

8 . The method of claim 1 , wherein the switch is a physically coupled to one of the first computing device or the second computing device.

9 . The method of claim 1 , wherein the analysis port is a physical port of the switch.

10 . The method of claim 1 , wherein the analysis port is a virtualized port of the switch.

11 . The method of claim 1 , wherein the first computing device is a server computing device and the second computing device is a client computing device.

12 . The method of claim 11 , wherein the data messages is part of an ingress traffic flow from the client computing device to the server computing device.

13 . A computer program product comprising a computer readable storage medium having a computer readable program stored therein, wherein the computer readable program, when executed on a switch associated with a first computing device, causes the switch to perform a method including:

in a first port of the switch, receive data messages from either the first computing device or a second computing device;

by a switch port analyzer of the switch, identify from the data messages a handshake operation or other negotiation to establish a secure communication connection between the first computing device and the second computing device;

by the switch port analyzer, after the handshake operation or the other negotiation is identified, monitoring the data messages between the first computing device and the second computing device for security certificate data;

by the switch port analyzer of the switch, responsive to monitoring the data messages, identifying one of the data messages as including security certificate data and extracting the security certificate data from the one of the data messages;

after the one of the data messages is identified, by the switch port analyzer, mirror at least the extracted security certificate data to an analysis port of the switch; and

after the extracted security certificate data is mirrored, by the switch via the analysis port, output, via the analysis port, output the mirrored extracted security certificate data to a data collection and analysis system that is distinct from the switch.

14 . The computer program product of claim 13 , wherein the extracted security certificate data comprises an unencrypted security certificate.

15 . The computer program product of claim 14 , wherein the unencrypted security certificate is a security certificate of the second computing device passed in the received data message as part of a traffic flow from the second computing device to the first computing device.

16 . The computer program product of claim 13 , wherein the computer readable program, when executed on the switch, causes the switch to analyze the extracted security certificate data with regard to security requirement compliance.

17 . The computer program product of claim 13 , wherein the computer readable program, when executed on the switch, causes the switch to determine whether or not one or more security compliance requirements are met by the secure communication connection.

18 . The computer program product of claim 13 , wherein the first computing device is a server computing device and the second computing device is a client computing device.

19 . A switch, comprising:

a switch port analyzer;

a first port communicably couplable to a first computing device and a second computing device; and

an analysis port communicably couplable to a data collection and analysis system that is distinct from the switch;

wherein the switch port analyzer comprises logic configured to:

in the first port, receive data messages from either the first computing device or the second computing device;

identify from the data messages a handshake operation or other negotiation to establish a secure communication connection between the first computing device and the second computing device;

after the handshake operation or the other negotiation is identified, monitor the data messages between the first computing device and the second computing device for security certificate data;

responsive to monitoring the data messages, identify one of the data messages as including security certificate data and extract the security certificate data from the one of the data messages;

after the filtered, by the switch the one of the data messages is identified, mirror at least the extracted security certificate data to an analysis port of the switch; and

after the extracted security certificate data is mirrored, by the switch via the analysis port, output, via the analysis port, output the mirrored extracted security certificate data to a data collection and analysis system that is distinct from the switch.

20 . A system, comprising

the switch of claim 19 ;

the first computing device communicably coupled to the first port of the switch;

the second computing device communicably coupled to the first port of the switch; and

the data collection and analysis system communicably coupled to the analysis port.

21 . The method of claim 1 , wherein identifying from the data messages the handshake operation or other negotiation includes identifying from the data messages the handshake operation.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Mar 28, 2025
From: BLUE OWL CREDIT INCOME CORP (F/K/A OWL ROCK CORE INCOME CORP.), AS COLLATERAL AGENT
To: AVALARA, INC.; EDISON VAULT, LLC
Reel/Frame 070671/0486 →
SECURITY INTEREST Recorded Mar 28, 2025
From: AVALARA, INC.; EDISON VAULT, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 070671/0097 →
SECURITY INTEREST Recorded Oct 20, 2022
From: AVALARA, INC.; EDISON VAULT, LLC
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 061728/0201 →
Continuity (3)
Continuation 16403778 · May 6, 2019
Continuation 14832250 · Aug 21, 2015
Related Publication 20210258301A1 · Aug 19, 2021
References Cited (40)
US 6351812B1 · Datar et al. · 2002 [cited by applicant]
US 7778194B1 · Yung · 2010 [cited by examiner]
US 8380259B2 · Jain et al. · 2013 [cited by applicant]
US 8584215B2 · Narasimha et al. · 2013 [cited by applicant]
US 8683052B1 · Brinskelle · 2014 [cited by examiner]
US 8793361B1 · Riddle · 2014 [cited by applicant]
US 8813189B2 · Li et al. · 2014 [cited by applicant]
US 8856869B1 · Brinskelle · 2014 [cited by applicant]
US 8935525B2 · Xiao · 2015 [cited by applicant]
US 9338147B1 · Rothstein et al. · 2016 [cited by applicant]
US 10284542B2 · Benjamin et al. · 2019 [cited by applicant]
US 20040054885A1 · Bartram et al. · 2004 [cited by applicant]
US 20040181665A1 · Houser · 2004 [cited by applicant]
US 20070245401A1 · Brabson · 2007 [cited by examiner]
US 20080025322A1 · Tadimeti · 2008 [cited by examiner]
US 20080175245A1 · Beam et al. · 2008 [cited by applicant]
US 20090300762A1 · Yalakanti · 2009 [cited by applicant]
US 20090328194A1 · Kim et al. · 2009 [cited by applicant]
US 20120002679A1 · Kenigsberg · 2012 [cited by examiner]
US 20130173913A1 · Kocsis · 2013 [cited by examiner]
US 20130191628A1 · Nedeltchev · 2013 [cited by applicant]
US 20140196108A1 · Barr · 2014 [cited by examiner]
US 20140269777A1 · Rothstein · 2014 [cited by examiner]
US 20140280889A1 · Nispel et al. · 2014 [cited by applicant]
US 20150372821A1 · Deschenes · 2015 [cited by examiner]
US 20160119374A1 · Williams et al. · 2016 [cited by applicant]
US 20160269482A1 · Jamjoom · 2016 [cited by examiner]
US 20160308766A1 · Register · 2016 [cited by examiner]
US 20160373433A1 · Rivers · 2016 [cited by examiner]
US 20170026186A1 · Gu · 2017 [cited by applicant]
EP 1267516A2 · 2002 [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/403,778 mailed Sep. 1, 2020. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/403,778 mailed Feb. 4, 2021. [cited by applicant]
U.S. Appl. No. 14/832,250, filed Aug. 21, 2015. [cited by applicant]
U.S. Appl. No. 16/403,778, filed May 6, 2019. [cited by applicant]
List of IBM Patents or Patent Applications Treated as Related, May 6, 2019, 2 pages. [cited by applicant]
“High Performance Browser Networking: Chapter 4. Transport Layer Security (TLS)”, O'Reilly Media, Inc.,, http://chimera.labs.oreilly.com/books/1230000000545/ch04.html#TLS_HANDSHAKE, accessed on the internet on Jun. 3, 2… [cited by applicant]
Singh, “Catalyst Switched Port Analyzer (SPAN) Configuration Example”, Cisco, Document ID: 10570, Apr. 21, 2014, accessed on the internet on Aug. 20, 2015; http://www.cisco.com/c/en/us/support/docs/switches/catalyst-650… [cited by applicant]
Thompson, et al., “Certificate-Based Authorization Policy in a PKI Environment”, ACM Transactions on Information and System Security, vol. 6, No. 4, Nov. 2003, pp. 566-588. [cited by applicant]
Issue Notification for U.S. Appl. No. 16/403,778 mailed May 12, 2021. [cited by applicant]