IP Library › Granted Patent US 12,726,368
Granted Patent B2
US 12,726,368 · App. 18/466,466 · Granted Sep 1, 2026

Validating certificate bundles with asymmetric keys

Inventors: Burak Uzun (London, GB); Mauruthi Geetha Mohan (Seattle, WA); Tony Long (Edmonds, WA); Owen Cliffe (Bath, GB)
Assignee: Oracle International Corporation
H04L9/3268H04L9/0825H04L9/3236H04L9/3247H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,368
App. No.
18/466,466
Filed
Sep 13, 2023
Granted
Sep 1, 2026
Kind
B2
Art Unit
2435
USPC
713/156
Abstract

Operations of a certificate bundle validation service may include receiving a first certificate bundle that includes a first set of one or more digital certificates, and a digital signature, associated with the first certificate bundle; determining, using a public key of an asymmetric key pair associated with a second set of one or more digital certificates, that the digital signature is generated using a private key of the asymmetric key pair; and responsive to determining that the digital signature is generated using the private key, storing the first certificate bundle in a certificate repository as a trusted certificate bundle.

Claims (110)

1 . One or more non-transitory computer-readable media storing instructions, which when executed by one or more hardware processors, cause performance of operations comprising:

receiving a first certificate bundle and a digital signature associated with the first certificate bundle,

wherein the first certificate bundle comprises a first set of one or more digital certificates;

determining, using a public key of an asymmetric key pair associated with a second certificate bundle comprising a second set of one or more digital certificates, that the digital signature is generated using a private key of the asymmetric key pair;

responsive to determining that the digital signature is generated using the private key:

storing the first certificate bundle in a certificate repository as a trusted certificate bundle, and

updating a data structure associated with the certificate repository to identify the first certificate bundle as a current certificate bundle and the second certificate bundle as a first untrusted certificate bundle;

based on the first certificate bundle being identified in the data structure as the current certificate bundle, distributing the first certificate bundle to one or more network entities associated with a virtual cloud network.

2 . The media of claim 1 , wherein the operations further comprise:

receiving a first public key of a first asymmetric key pair associated with a first digital certificate of the first set of one or more digital certificates,

wherein the public key associated with the second set of one or more digital certificates is a second public key, and wherein the private key used to generate the digital signature is a second private key; and

responsive to determining that the digital signature is generated using the second private key, storing the first public key in a public key repository, wherein the public key repository comprises a first data structure that identifies the first public key as being associated with the first digital certificate of the first set of one or more digital certificates,

wherein prior to storing the first public key in the public key repository, the second public key is stored in the public key repository, wherein the public key repository comprises a second data structure that identifies the second public key as being associated with the second set of one or more digital certificates.

3 . The media of claim 2 , wherein storing the first public key in the public key repository comprises replacing the second public key with the first public key.

4 . The media of claim 2 , wherein the first public key is included in the first digital certificate, and wherein the operations further comprise:

prior to storing the first public key in the public key repository, extracting the first public key from the first digital certificate.

5 . The media of claim 2 , wherein the operations further comprise:

prior to determining that the digital signature is generated using the second private key, identifying a file pointer in a public key configuration file, wherein the file pointer points to the second public key in the public key repository, and retrieving, based on the file pointer, the second public key from the public key repository; and

subsequent to determining that the digital signature is generated using the second private key, storing the first public key in the public key repository and updating the public key configuration file and/or the file pointer in the public key configuration file, to point to the first public key in the public key repository.

6 . The media of claim 2 , wherein the operations further comprise:

receiving a third certificate bundle and a third digital signature associated with the third certificate bundle,

wherein the third certificate bundle comprises (i) a third set of one or more digital certificates and (ii) a third public key of a third asymmetric key pair associated with a third digital certificate of the third set of one or more digital certificates, and

wherein the third digital signature is generated using a first private key of the first asymmetric key pair associated with the first set of one or more digital certificates;

identifying a file pointer in a public key configuration file, wherein the file pointer points to the first public key in the public key repository;

retrieving, based on the file pointer, the first public key from the public key repository;

determining, using the first public key, that the third digital signature is generated using the first private key;

responsive to determining that the third digital signature is generated using the first private key:

storing the third certificate bundle in the certificate repository as the trusted certificate bundle;

storing the third public key in the public key repository, wherein the public key repository comprises a third data structure that identifies the third public key as being associated with the third digital certificate of the third set of one or more digital certificates, wherein storing the third public key in the public key repository comprises replacing the first public key with the third public key; and

updating the public key configuration file and/or the file pointer in the public key configuration file, to point to the third public key in the public key repository;

wherein the certificate repository comprises a fourth data structure, wherein prior to storing the third certificate bundle in the certificate repository, the fourth data structure identifies the first certificate bundle as the trusted certificate bundle, and wherein storing the third certificate bundle in the certificate repository as the trusted certificate bundle comprises:

updating the fourth data structure to identity the first certificate bundle as a second untrusted certificate bundle and to identify the third certificate bundle as the trusted certificate bundle.

7 . The media of claim 1 , wherein the private key is held by a certificate authority (CA), and wherein the trusted certificate bundle comprises one or more CA certificates issued by the CA.

8 . The media of claim 1 , wherein the trusted certificate bundle comprises one or more certificate authority (CA) certificates, and wherein a first network entity trusts a second network entity based on an authentication operation performed by the first network entity, wherein the authentication operation comprises validating a certificate chain that includes (a) an entity certificate presented by the second network entity and (b) at least one CA certificate of the one or more CA certificates.

9 . The media of claim 1 , wherein the operations further comprise:

prior to receiving the first certificate bundle and the digital signature associated with the first certificate bundle:

polling a pending certificate repository for a pending certificate bundle; and

downloading the first certificate bundle and the digital signature associated with the first certificate bundle responsive to polling the pending certificate repository for the pending certificate bundle, wherein the first certificate bundle is the pending certificate bundle.

10 . The media of claim 1 , wherein the operations further comprise:

prior to receiving the first certificate bundle and the digital signature associated with the first certificate bundle:

receiving a notification that a pending certificate bundle is available in a pending certificate repository; and

responsive to receiving the notification, downloading the first certificate bundle and the digital signature associated with the first certificate bundle from the pending certificate repository, wherein the first certificate bundle is the pending certificate bundle.

11 . The media of claim 1 , wherein the operations further comprise:

updating the data structure to identity the second certificate bundle as a previous certificate bundle.

12 . The media of claim 1 , wherein the first set of one or more digital certificates comprises a first set of one or more first CA certificates, and wherein the second set of one or more digital certificates comprise a second set of one or more second CA certificates.

13 . The media of claim 12 , wherein subsequent to distributing the current certificate bundle to the one or more network entities associated with the virtual cloud network, (a) a first network entity of the one or more network entities determines that a first CA certificate, of the first set of one or more first CA certificates, is a trusted CA certificate, or (b) a second network entity of the one or more network entities determines that a second CA certificate, of the second set of one or more second CA certificates, is an untrusted CA certificate.

14 . The media of claim 1 , wherein the digital signature is generated by (a) applying a hash function to the first certificate bundle to obtain a first hash value and (b) digitally signing the first hash value using the private key of the asymmetric key pair associated with the second set of one or more digital certificates.

15 . The media of claim 14 , wherein determining that the digital signature is generated using the private key comprises:

generating a second hash value by applying the hash function to the first certificate bundle;

generating a third hash value by decrypting the digital signature using the public key; and

determining that the third hash value matches the second hash value.

16 . The media of claim 1 , wherein prior to receiving the first certificate bundle, the second set of one or more digital certificates are currently or previously trusted.

17 . A method, comprising:

receiving a first certificate bundle and a digital signature associated with the first certificate bundle,

wherein the first certificate bundle comprises a first set of one or more digital certificates, and

wherein the digital signature is generated using a private key of an asymmetric key pair associated with a second certificate bundle comprising a second set of one or more digital certificates;

determining, using a public key of the asymmetric key pair associated with the second certificate bundle comprising the second set of one or more digital certificates, that the digital signature is generated using the private key;

responsive to determining that the digital signature is generated using the private key:

storing the first certificate bundle in a certificate repository as a trusted certificate bundle, and

updating a data structure associated with the certificate repository to identify the first certificate bundle as a current certificate bundle and the second certificate bundle as an untrusted certificate bundle;

based on the first certificate bundle being identified in the data structure as the current certificate bundle, distributing the first certificate bundle to one or more network entities associated with a virtual cloud network;

wherein the method is performed by at least one device including a hardware processor.

18 . The method of claim 17 , further comprising:

receiving a first public key of a first asymmetric key pair associated with a first digital certificate of the first set of one or more digital certificates,

wherein the public key associated with the second set of one or more digital certificates is a second public key, and wherein the private key used to generate the digital signature is a second private key; and

responsive to determining that the digital signature is generated using the second private key, storing the first public key in a public key repository, wherein the public key repository comprises a first data structure that identifies the first public key as being associated with the first digital certificate of the first set of one or more digital certificates,

wherein prior to storing the first public key in the public key repository, the second public key is stored in the public key repository, wherein the public key repository comprises a second data structure that identifies the second public key as being associated with the second set of one or more digital certificates.

19 . The method of claim 18 , wherein storing the first public key in the public key repository comprises replacing the second public key with the first public key.

20 . The method of claim 18 , wherein the first public key is included in the first digital certificate, and wherein the method further comprises:

prior to storing the first public key in the public key repository, extracting the first public key from the first digital certificate.

21 . The method of claim 18 , further comprising:

prior to determining that the digital signature is generated using the second private key, identifying a file pointer, wherein the file pointer points to the second public key in the public key repository, and retrieving, based on the file pointer, the second public key from the public key repository; and

subsequent to determining that the digital signature is generated using the second private key, storing the first public key in the public key repository and updating the file pointer to point to the first public key in the public key repository.

22 . The method of claim 18 , further comprising:

receiving a third certificate bundle and a third digital signature associated with the third certificate bundle,

wherein the third certificate bundle comprises (i) a third set of one or more digital certificates and (ii) a third public key of a third asymmetric key pair associated with a third digital certificate of the third set of one or more digital certificates, and

wherein the third digital signature is generated using a first private key of the first asymmetric key pair associated with the first set of one or more digital certificates;

identifying a file pointer, wherein the file pointer points to the first public key in the public key repository;

retrieving, based on the file pointer, the first public key from the public key repository;

determining, using the first public key, that the third digital signature is generated using the first private key;

responsive to determining that the third digital signature is generated using the first private key:

storing the third certificate bundle in the certificate repository, wherein the certificate repository comprises a third data structure that identifies the third certificate bundle as an additional trusted certificate bundle;

storing the third public key in the public key repository, wherein the public key repository comprises a fourth data structure that identifies the third public key as being associated with the third digital certificate of the third set of one or more digital certificates, wherein storing the third public key in the public key repository comprises replacing the first public key with the third public key; and

updating the file pointer to point to the third public key in the public key repository.

23 . The method of claim 17 , wherein the private key is held by a certificate authority (CA), and wherein the trusted certificate bundle comprises one or more CA certificates issued by the CA.

24 . The method of claim 17 , wherein the trusted certificate bundle comprises one or more certificate authority (CA) certificates, and wherein a first network entity trusts a second network entity based on an authentication operation performed by the first network entity, wherein the authentication operation comprises validating a certificate chain that includes (a) an entity certificate presented by the second network entity and (b) at least one CA certificate of the one or more CA certificates.

25 . The method of claim 17 , further comprising:

prior to receiving the first certificate bundle and the digital signature associated with the first certificate bundle:

polling a pending certificate repository for a pending certificate bundle; and

downloading the first certificate bundle and the digital signature associated with the first certificate bundle responsive to polling the pending certificate repository for the pending certificate bundle, wherein the first certificate bundle is the pending certificate bundle.

26 . The method of claim 17 , further comprising:

prior to receiving the first certificate bundle and the digital signature associated with the first certificate bundle:

receiving a notification that a pending certificate bundle is available from a pending certificate repository; and

responsive to receiving the notification, downloading the first certificate bundle and the digital signature associated with the first certificate bundle from the pending certificate repository, wherein the first certificate bundle is the pending certificate bundle.

27 . The method of claim 17 , wherein the method further comprises:

updating the data structure to identity the second certificate bundle as a previous certificate bundle.

28 . The method of claim 17 , wherein the first set of one or more digital certificates comprises a first set of one or more first CA certificates, and wherein the second set of one or more digital certificates comprise a second set of one or more second CA certificates.

29 . The method of claim 28 , wherein subsequent to distributing the current certificate bundle to the one or more network entities associated with the virtual cloud network, (a) a first network entity of the one or more network entities determines that a first CA certificate, of the first set of one or more first CA certificates, is a trusted CA certificate, or (b) a second network entity of the one or more network entities determines that a second CA certificate, of the second set of one or more second CA certificates, is an untrusted CA certificate.

30 . The method of claim 17 , wherein prior to receiving the first certificate bundle, the second set of one or more digital certificates are currently or previously trusted.

31 . A system comprising:

at least one hardware processor;

the system being configured to execute operations, using the at least one hardware processor, the operations comprising:

receiving a first certificate bundle and a digital signature associated with the first certificate bundle,

wherein the first certificate bundle comprises a first set of one or more digital certificates, and

wherein the digital signature is generated using a private key of an asymmetric key pair associated with a second certificate bundle comprising a second set of one or more digital certificates;

determining, using a public key of the asymmetric key pair associated with the second certificate bundle comprising the second set of one or more digital certificates, that the digital signature is generated using the private key;

responsive to determining that the digital signature is generated using the private key:

storing the first certificate bundle in a certificate repository as a trusted certificate bundle, and

updating a data structure associated with the certificate repository to identify the first certificate bundle as a current certificate bundle and the second certificate bundle as an untrusted certificate bundle;

based on the first certificate bundle being identified in the data structure as the current certificate bundle, distributing the first certificate bundle to one or more network entities associated with a virtual cloud network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2023
From: UZUN, BURAK; GEETHA MOHAN, MAURUTHI; LONG, TONY; CLIFFE, OWEN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 064916/0037 →
Continuity (1)
Related Publication 20250088373A1 · Mar 13, 2025
References Cited (223)
US 5671279A · Elgamal · 1997 [cited by applicant]
US 5699431A · Van Oorschot et al. · 1997 [cited by applicant]
US 7272714B2 · Nagaratnam et al. · 2007 [cited by applicant]
US 7644270B1 · Cherukumudi et al. · 2010 [cited by applicant]
US 8176328B2 · Chen et al. · 2012 [cited by applicant]
US 8452958B2 · Sun et al. · 2013 [cited by applicant]
US 9172543B2 · Wnuk · 2015 [cited by applicant]
US 9197630B2 · Sharif et al. · 2015 [cited by applicant]
US 9231933B1 · Shenoy et al. · 2016 [cited by applicant]
US 9252958B1 · Tempel · 2016 [cited by examiner]
US 9485101B2 · Bowen · 2016 [cited by applicant]
US 9660978B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9680813B2 · Sade et al. · 2017 [cited by applicant]
US 9794249B1 · Truskovsky et al. · 2017 [cited by applicant]
US 9882727B1 · Veladanda et al. · 2018 [cited by applicant]
US 10021084B2 · Matthews et al. · 2018 [cited by applicant]
US 10212147B2 · Buendgen et al. · 2019 [cited by applicant]
US 10425401B1 · Pecen et al. · 2019 [cited by applicant]
US 10439825B1 · Meyer et al. · 2019 [cited by applicant]
US 10447683B1 · Loladia et al. · 2019 [cited by applicant]
US 10469518B1 · Natanzon et al. · 2019 [cited by applicant]
US 10621577B2 · Castinado et al. · 2020 [cited by applicant]
US 10652030B1 · Levy et al. · 2020 [cited by applicant]
US 10764263B2 · Rossi · 2020 [cited by applicant]
US 10771261B1 · Lazar et al. · 2020 [cited by applicant]
US 10812276B2 · Bojjireddy et al. · 2020 [cited by applicant]
US 10848323B2 · Barr, III et al. · 2020 [cited by applicant]
US 11153103B2 · Fynaardt et al. · 2021 [cited by applicant]
US 11190504B1 · Ah Kun et al. · 2021 [cited by applicant]
US 11196570B2 · Borne-Pons et al. · 2021 [cited by applicant]
US 11310059B2 · Leibmann et al. · 2022 [cited by applicant]
US 11362843B1 · Jiang et al. · 2022 [cited by applicant]
US 11368314B2 · Ray et al. · 2022 [cited by applicant]
US 11388594B2 · Uy et al. · 2022 [cited by applicant]
US 11438325B2 · Begun et al. · 2022 [cited by applicant]
US 11477011B1 · Pelton et al. · 2022 [cited by applicant]
US 11533185B1 · Sharma et al. · 2022 [cited by applicant]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11706038B1 · Thakore et al. · 2023 [cited by applicant]
US 11706207B1 · Fynaardt · 2023 [cited by applicant]
US 11888997B1 · Bowen et al. · 2024 [cited by applicant]
US 12088738B2 · Rosenthol et al. · 2024 [cited by applicant]
US 12323466B1 · Miseiko et al. · 2025 [cited by applicant]
US 12361110B1 · Subramanian et al. · 2025 [cited by applicant]
US 12380443B1 · Edwards et al. · 2025 [cited by applicant]
US 20020007346A1 · Qiu et al. · 2002 [cited by applicant]
US 20020029200A1 · Dulin et al. · 2002 [cited by applicant]
US 20020174066A1 · Kleckner et al. · 2002 [cited by applicant]
US 20030037234A1 · Fu et al. · 2003 [cited by applicant]
US 20060047965A1 · Thayer · 2006 [cited by applicant]
US 20060101510A1 · Kadyk et al. · 2006 [cited by applicant]
US 20070005956A1 · Zilinskas et al. · 2007 [cited by applicant]
US 20070016782A1 · Crall et al. · 2007 [cited by applicant]
US 20070147619A1 · Bellows et al. · 2007 [cited by applicant]
US 20100030897A1 · Stradling · 2010 [cited by applicant]
US 20100325429A1 · Saha et al. · 2010 [cited by applicant]
US 20110113239A1 · Fu et al. · 2011 [cited by applicant]
US 20110238986A1 · Kherani et al. · 2011 [cited by applicant]
US 20120036220A1 · Dare et al. · 2012 [cited by applicant]
US 20120240192A1 · Orazi et al. · 2012 [cited by applicant]
US 20120246466A1 · Salvarani et al. · 2012 [cited by applicant]
US 20120278614A1 · Choi · 2012 [cited by applicant]
US 20130086642A1 · Resch et al. · 2013 [cited by applicant]
US 20130179676A1 · Hamid · 2013 [cited by applicant]
US 20130262857A1 · Neuman et al. · 2013 [cited by applicant]
US 20140298419A1 · Boubez et al. · 2014 [cited by applicant]
US 20140354405A1 · Kocher · 2014 [cited by examiner]
US 20150095995A1 · Bhalerao · 2015 [cited by applicant]
US 20150135299A1 · Liang et al. · 2015 [cited by applicant]
US 20150215308A1 · Manolov et al. · 2015 [cited by applicant]
US 20150279132A1 · Perotti · 2015 [cited by applicant]
US 20150288528A1 · Cho et al. · 2015 [cited by applicant]
US 20150334110A1 · Bishop et al. · 2015 [cited by applicant]
US 20150381374A1 · Lszlo · 2015 [cited by applicant]
US 20160277923A1 · Steffey et al. · 2016 [cited by applicant]
US 20160352521A1 · Choi · 2016 [cited by examiner]
US 20170039373A1 · Sasin et al. · 2017 [cited by applicant]
US 20170126667A1 · Bishop et al. · 2017 [cited by applicant]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170177324A1 · Frank et al. · 2017 [cited by applicant]
US 20170222981A1 · Srivastav et al. · 2017 [cited by applicant]
US 20170279807A1 · Bermdez · 2017 [cited by applicant]
US 20170317837A1 · Alrawais et al. · 2017 [cited by applicant]
US 20170338967A1 · Lewison et al. · 2017 [cited by applicant]
US 20170373860A1 · Kshirsagar et al. · 2017 [cited by applicant]
US 20180019993A1 · Kravitz et al. · 2018 [cited by applicant]
US 20180083966A1 · Zhou et al. · 2018 [cited by applicant]
US 20180102904A1 · Lin et al. · 2018 [cited by applicant]
US 20180287804A1 · Geisbush · 2018 [cited by applicant]
US 20190026804A1 · Yin · 2019 [cited by applicant]
US 20190149342A1 · Fynaardt et al. · 2019 [cited by applicant]
US 20190165950A1 · Ibrahim · 2019 [cited by applicant]
US 20190166635A1 · Mccolgan et al. · 2019 [cited by applicant]
US 20190347406A1 · Lev-Ran et al. · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190356494A1 · Chmara et al. · 2019 [cited by applicant]
US 20190356817A1 · Bush et al. · 2019 [cited by applicant]
US 20190363895A1 · Barr et al. · 2019 [cited by applicant]
US 20190372783A1 · Martinez et al. · 2019 [cited by applicant]
US 20200021575A1 · Rezvani et al. · 2020 [cited by applicant]
US 20200092095A1 · Yang et al. · 2020 [cited by applicant]
US 20200150972A1 · Ketkar et al. · 2020 [cited by applicant]
US 20200274718A1 · Hwang et al. · 2020 [cited by applicant]
US 20200274862A1 · Varvarezis et al. · 2020 [cited by applicant]
US 20200382323A1 · Keselman et al. · 2020 [cited by applicant]
US 20200396089A1 · Guo et al. · 2020 [cited by applicant]
US 20210034767A1 · Free et al. · 2021 [cited by applicant]
US 20210051028A1 · Kapon et al. · 2021 [cited by applicant]
US 20210126801A1 · Nix · 2021 [cited by applicant]
US 20210144017A1 · Li · 2021 [cited by examiner]
US 20210152547A1 · Barhudarian et al. · 2021 [cited by applicant]
US 20210211307A1 · Statia et al. · 2021 [cited by applicant]
US 20210218723A1 · Lekov et al. · 2021 [cited by applicant]
US 20210274348A1 · Yoon et al. · 2021 [cited by applicant]
US 20210297259A1 · Rahn et al. · 2021 [cited by applicant]
US 20210328814A1 · Wei et al. · 2021 [cited by applicant]
US 20210392002A1 · Gray et al. · 2021 [cited by applicant]
US 20210409403A1 · Lewin et al. · 2021 [cited by applicant]
US 20210409409A1 · Palanisamy · 2021 [cited by applicant]
US 20220014522A1 · Thomas et al. · 2022 [cited by applicant]
US 20220029988A1 · Levin et al. · 2022 [cited by applicant]
US 20220038894A1 · Yoon et al. · 2022 [cited by applicant]
US 20220116229A1 · Jones et al. · 2022 [cited by applicant]
US 20220123951A1 · Lutz et al. · 2022 [cited by applicant]
US 20220141004A1 · Murray · 2022 [cited by applicant]
US 20220141085A1 · Singhal et al. · 2022 [cited by applicant]
US 20220150238A1 · Bhalerao · 2022 [cited by applicant]
US 20220239503A1 · Mallikarjuna et al. · 2022 [cited by applicant]
US 20220264301A1 · Martinez et al. · 2022 [cited by applicant]
US 20220393886A1 · Williams et al. · 2022 [cited by applicant]
US 20230007474A1 · Ni et al. · 2023 [cited by applicant]
US 20230032867A1 · Peddada et al. · 2023 [cited by applicant]
US 20230049095A1 · Rangaraj · 2023 [cited by applicant]
US 20230062888A1 · Colombano · 2023 [cited by applicant]
US 20230109231A1 · Adogla et al. · 2023 [cited by applicant]
US 20230121514A1 · Smith · 2023 [cited by applicant]
US 20230208655A1 · Statia et al. · 2023 [cited by applicant]
US 20230237155A1 · Jacquin et al. · 2023 [cited by applicant]
US 20230239163A1 · Liu · 2023 [cited by examiner]
US 20230291574A1 · Held et al. · 2023 [cited by applicant]
US 20230291577A1 · Thai et al. · 2023 [cited by applicant]
US 20230401307A1 · Pop et al. · 2023 [cited by applicant]
US 20230412397A1 · Gollent et al. · 2023 [cited by applicant]
US 20240015508A1 · Yoon et al. · 2024 [cited by applicant]
US 20240020373A1 · Ivanov et al. · 2024 [cited by applicant]
US 20240031146A1 · Marosi-Bauer et al. · 2024 [cited by applicant]
US 20240097919A1 · Qiu et al. · 2024 [cited by applicant]
US 20240104192A1 · Kalle et al. · 2024 [cited by applicant]
US 20240106886A1 · Roy et al. · 2024 [cited by applicant]
US 20240121603A1 · Yoon et al. · 2024 [cited by applicant]
US 20240146543A1 · Sahoo et al. · 2024 [cited by applicant]
US 20240333640A1 · Shevade et al. · 2024 [cited by applicant]
US 20240356763A1 · Goldberg et al. · 2024 [cited by applicant]
US 20240364540A1 · Sai et al. · 2024 [cited by applicant]
US 20240372731A1 · Kobel et al. · 2024 [cited by applicant]
US 20240388510A1 · Madtha et al. · 2024 [cited by applicant]
US 20240427642A1 · Punreddy et al. · 2024 [cited by applicant]
US 20240430249A1 · Singh et al. · 2024 [cited by applicant]
US 20250030561A1 · Long et al. · 2025 [cited by applicant]
US 20250097211A1 · Uzun et al. · 2025 [cited by applicant]
US 20250133401A1 · Lee et al. · 2025 [cited by applicant]
CN 112019477A · 2020 [cited by applicant]
CN 114884963A · 2022 [cited by applicant]
EP 1251670A2 · 2002 [cited by applicant]
EP 2267970A2 · 2010 [cited by applicant]
EP 2854349A1 · 2015 [cited by applicant]
EP 4000296A1 · 2022 [cited by applicant]
EP 3772208B1 · 2024 [cited by applicant]
KR 1020110045459A · 2011 [cited by applicant]
WO 2006122024A2 · 2006 [cited by applicant]
WO 2007117293A2 · 2007 [cited by applicant]
WO 2022103890A1 · 2022 [cited by applicant]
WO 2022121461A1 · 2022 [cited by applicant]
WO 2022133026A1 · 2022 [cited by applicant]
WO 2023240360A1 · 2023 [cited by applicant]
WO 2025059187A1 · 2025 [cited by applicant]
“What is Certificate Lifecycle Management”, Retrieved from https://www.encryptionconsulting.com/different-phases-of-a-certificate-lifecycle-management-process/, Aug. 1, 2024, pp. 1-12. [cited by applicant]
Yi, Seunghee, (WO2023/227228 , “Method and Apparatus for Canary deployment in Gnodeb,”), Nov. 30. 2023. pp. 1-17. (Year: 2023). [cited by applicant]
“About Azure Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/about-certificates, Feb. 8, 2023, pp. 1-8. [cited by applicant]
“About the Expressway”, Aug. 17, 2022. pp. 1-12. [cited by applicant]
“Automated certificate management for TLS certificates”, Retrieved from https://docs.servicenow.com/en-US/bundle/utah-it-operations-management/page/product/discovery/concept/automated-cert-requests.html, Retrieved on Ma… [cited by applicant]
“AWS Certificate Manager FAQs”, Retrieved from https://aws.amazon.com/certificate-manager/faqs/, Retrieved on Mar. 24, 2023, pp. 1-17. [cited by applicant]
“Azure Instance Metadata Service”, Retrieved from https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=windows, Mar. 15, 2023, pp. 1-42. [cited by applicant]
“Cisco Expressway Certificate Creation and Use Deployment Guide”, Feb. 23, 2021, p. 10. [cited by applicant]
“Deploying the CA bundle iApp”, Retrieved from https://www.f5.com/pdf/deployment-guides/f5-ca-bundle-dg.pdf, Dec. 14, 2017, pp. 1-9. [cited by applicant]
“DigiCert Public Key Infrastructure (PKI) Platform”, 2019, p. 15. [cited by applicant]
“Get started with Key Vault certificates”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/certificate-scenarios, Retrieved on Feb. 1, 2023, pp. 1-6. [cited by applicant]
“High Availability using Patching and Rolling AP Upgrade on Cisco Catalyst 9800 Wireless Controllers”, Copyright 2020, pp. 1-41. [cited by applicant]
“Manage Certificate Revocation Lists (CRLs)”, Jul. 23, 2021, pp. 1-4. [cited by applicant]
“PKI secrets engine”, Retrieved from https://developer.hashicorp.com/vault/docs/secrets/pki, Retrieved on May 4, 2023, pp. 1-3. [cited by applicant]
“Planning a certificate revocation list (CRL)”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/crl-planning.html, Retrieved on Jul. 28, 2023, p. 11. [cited by applicant]
“Release app updates with staged rollouts”, Retrieved from https://support.google.com/googleplay/android-developer/answer/6346149?hl=en#zippy=%2Crelease-a-staged-rollout-to-specific-countries, Retrieved on Apr. 27, 2023… [cited by applicant]
“Release Your App Update in a Staged Rollout”, Retrieved from https://developer.amazon.com/docs/app-submission/release-updates-in-staged-rollouts.html, Retrieved on Apr. 27, 2023, pp. 1-18. [cited by applicant]
“Rotate Security Certificates”, Retrieved from https://www.cockroachlabs.com/docs/stable/rotate-certificates, Retrieved on May 4, 2023, pp. 1-6. [cited by applicant]
“Rotating the Root CA and Leaf Certificates”, Retrieved from https://docs.pivotal.io/ops-manager/2-4/security/pcf-infrastructure/rotate-cas-and-leaf-certs.html, Nov. 5, 2020, pp. 1-9. [cited by applicant]
“Staged upgrade”, Retrieved from https://www.ibm.com/docs/en/order-management-sw/9.4.0?topic=migrating-staged-upgrade, Mar. 2, 2021, pp. 1-3. [cited by applicant]
“Troubleshoot SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/troubleshooting, Retrieved on Mar. 24, 2023, pp. 1-8. [cited by applicant]
“Tutorial: Configure certificate auto-rotation in Key Vault”, Retrieved from https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-rotate-certificates, Feb. 27, 2023, pp. 1-6. [cited by applicant]
“Updating the CA bundle”, Retrieved from https://docs.openshift.com/container-platform/4.9/security/certificates/updating-ca-bundle.html#ca-bundle-understanding_updating-ca-bundle, Retrieved on Mar. 24, 2023, pp. 1-2. [cited by applicant]
“Updating your private CA”, Retrieved from https://docs.aws.amazon.com/privateca/latest/userguide/PCAUpdateCA.html, Retrieved on Mar. 24, 2023, pp. 1-4. [cited by applicant]
“Use self-managed SSL certificates”, Retrieved from https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs, Aug. 15, 2023, p. 13. [cited by applicant]
“vSphere Security”, vmware, Update 3, Mar. 21, 2023, pp. 1-426. [cited by applicant]
“Working with Hosts”, Retrieved from https://docs.cloudstack.apache.org/projects/archived-cloudstack-administration/en/latest/hosts.html, Retrieved on Mar. 24, 2023, pp. 1-7. [cited by applicant]
Atutxa et al., “Improving efficiency and security of IIoT communications using in-network validation of server certificate”, Computers in Industry, vol. 144, Jan. 2023, 103802, p. 30. [cited by applicant]
Bigelow S.J., “Rolling deployment”, Retrieved from https://www.techtarget.com/searchitoperations/definition/rolling-deployment, Jan. 2023, p. 4. [cited by applicant]
Este-Gracias S., “Rotate your CA seamlessly using a Vault PKI”, Retrieved from https://sestegra.medium.com/rotate-your-ca-seamlessly-using-a-vault-pki-9262228b4afb Sep. 29, 2022, pp. 1-49. [cited by applicant]
Ghanmi et al., “A Secure Data Storage in Multi-cloud Architecture Using Blowfish Encryption Algorithm”, Advanced Information Networking and Applications, Mar. 2022, pp. 398-408. [cited by applicant]
Jamal F., “Zero Trust for SSH—Secure One-click Server Access for Software Engineering Teams”, Retrieved from https://www.banyansecurity.io/blog/zero-trust-for-ssh/, Oct. 28, 2020, pp. 1-7. [cited by applicant]
Manjusha R. et al., “Secure Authentication and Access System for Cloud Computing Auditing Services Using Associated Digital Certificate”, Indian Journal of Science and Technology, vol. 8 (S7), Apr. 2015, pp. 220-227. [cited by applicant]
Nexthop Team, “Updated: Creating a Certificate Revocation List Distribution Point for Your Internal Certification Authority”, Retrieved from https://techcommunity.microsoft.com/t5/skype-for-business-blog/updated-creatin… [cited by applicant]
Rowley J., “Google's Moving Forward Together Proposals for Root CA Policy: Rotating ICAS More Frequently”, Retrieved from https://www.digicert.com/blog/googles-moving-forward-together-proposals-for-root-ca-policy, Mar. … [cited by applicant]
Subhayu, “Different Phases of a Certificate Lifecycle Management Process for a secure WPA2-Enterprise network”, Certificate Lifecycle Management Oct. 6, 2022, p. 16. [cited by applicant]
Ylonen et al., “Security of Automated Access Management Using Secure Shell (SSH)”, NISTIR 7966 (Draft), Aug. 2014, p. 43. [cited by applicant]
Bingyu Li et al., Locally-Centralized Certificate Validation and Its Application in Desktop Virtualization Systems, Nov. 2, 2020, IEEE, vol. 16, pp. 1380-1395. (Year: 2020). [cited by applicant]
Jude Nelson et al., Syndicate: Virtual Cloud Storage through Provider Composition, Jun. 23, 2014, ACM, pp. 1-8. (Year: 2014). [cited by applicant]
Kathleen Nichols et al., Trust Schemas and ICN: Key to Secure Home IoT, Sep. 22, 2021, ACM, pp. 95-106. (Year: 2021). [cited by applicant]
Albert Wasef et al., DCS: An Efficient Distributed-Certificate-Service Scheme for Vehicular Networks, Feb. 2010, IEEE, vol. 59, Issue: 2, pp. 533-549. (Year: 2010). [cited by applicant]
Artem Dinaburg et al., Ether: Malware Analysis via Hardware Virtualization Extensions, Oct. 27, 2008, ACM, pp. 51-62. (Year: 2008). [cited by applicant]
Capt James M. Hayes, Secure In-band Update of Trusted Certificates, Aug. 6, 2002, IEEE, pp. 1-6. (Year: 2002). [cited by applicant]
Kumagai et al., “Distributed Public Key Certificate-Issuing Infrastructure for Consortium Certificate Authority Using Distributed Ledger Technology”, Security and Communication Networks, vol. 2023, Article ID 9559439, J… [cited by applicant]
Marco Anisetti et al., Test-Based Security Certification of Composite Services, Dec. 4, 2018, vol. 13, Issue 1, pp. 1-43. (Year: 2018). [cited by applicant]
Yu et al., “A Cloud Certificate Authority Architecture for Virtual Machines with Trusted Platform Module”, 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th Internat… [cited by applicant]
M. S. Zefreh, A. Fanian, S. M. Sajadieh, M. Berenjkoub and p. Khadivi, “A Distributed Certificate Authority and Key Establishment Protocol for Mobile Ad Hoc Networks,” 2008 10th International Conference on Advanced Comm… [cited by applicant]