IP Library › Granted Patent US 8,776,192
Granted Patent B2
US 8,776,192 · App. 12/619,899 · Granted Jul 8, 2014

Methods, systems, and computer program products for automatically verifying and populating digital certificates in an encryption keystore

Inventor: Andrew Schiefelbein (St. Louis, MO)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/0823H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,776,192
App. No.
12/619,899
Granted
Jul 8, 2014
Kind
B2
Abstract

Methods for automatically verifying and populating an encryption keystore are provided. Pursuant to these methods, the keystore may be automatically checked to determine if it is missing a required digital certificate; if so, the missing required digital certificate may be automatically inserted into the keystore. The methods may also include automatically obtaining the required digital certificates and a list of the required digital certificates, and automatically comparing the list of required digital certificates with the digital certificates in the keystore to determine if the keystore is missing a required digital certificate. The methods may further include sending an informational alert if a missing required digital certificate was automatically inserted into the keystore, and may include checking the keystore to determine if any required digital certificates have expired, will expire within a predetermined time period, or are inoperative. Related keystore verification and population systems and computer program products are also provided.

Claims (47)

1. A method of verifying and populating an encryption keystore, comprising:

performing operations as follows on a processor;

verifying the encryption keystore by automatically repeatedly checking the encryption keystore to determine if the encryption keystore is missing a required digital certificate;

wherein verifying the encryption keystore comprises:

automatically obtaining digital certificates present in the encryption keystore and a list of required digital certificates, the list of required digital certificates comprising both root certificate authority certificates and server digital certificates; and

automatically comparing the list of required digital certificates with the digital certificates present in the encryption keystore to determine whether a minimum number of required root certificate authority certificates and a minimum number of required server digital certificates are present in the encryption keystore;

determining that the encryption keystore is missing the required digital certificate;

populating the encryption keystore by automatically inserting into the encryption keystore the required digital certificate that is missing from the encryption keystore;

automatically repeatedly checking the encryption keystore to determine if any of the required digital certificates that are present in the encryption keystore are not operating properly; and

automatically issuing a warning alert when any of the required digital certificates that are present in the encryption keystore are determined to not be operating properly.

2. The method of claim 1 , wherein the required digital certificate is one of the root certificate authority certificates and the server digital certificates.

3. The method of claim 1 , further comprising automatically issuing an informational alert when one of the required digital certificates is missing from the encryption keystore but is automatically inserted into the encryption keystore.

4. The method of claim 3 , further comprising:

automatically repeatedly checking the encryption keystore to determine when any of the required digital certificates that are present in the encryption keystore have expired; and

automatically issuing a warning alert when any of the required digital certificates that are present in the encryption keystore have expired.

5. The method of claim 3 , wherein the encryption keystore comprises a certificate management system provider keystore, the method further comprising:

automatically repeatedly checking the certificate management system provider keystore to determine if a password for the certificate management system provider keystore has expired; and

automatically issuing a warning alert when the password for the certificate management system provider keystore has expired.

6. A verification and population system for an encryption keystore that contains a plurality of digital certificates, comprising:

a processor; and

a memory connected to the processor, the memory comprising:

a verifier, when executed by the processor, to automatically repeatedly check the encryption keystore to determine if the encryption keystore is missing a required digital certificate, to automatically obtain digital certificates present in the encryption keystore and a list of required digital certificates, the list of required digital certificates comprising both root certificate authority certificates and server digital certificates, to automatically compare the list of required digital certificates with the digital certificates present in the encryption keystore to determine whether a minimum number of required root certificate authority certificates and a minimum number of required server digital certificates are present in the encryption keystore, to automatically repeatedly check the encryption keystore to determine if any of the required digital certificates that are present in the encryption keystore are not operating properly, and to automatically issue a warning alert when any of the required digital certificates that are present in the encryption keystore are determined to not be operating properly; and

a populator, when executed by the processor, to automatically insert into the encryption keystore the required digital certificate that is missing from the encryption keystore, in response to the verifier verifying that the encryption keystore is missing the required digital certificate.

7. The system of claim 6 , wherein the required digital certificate is one of the root certificate authority certificates and the server digital certificates.

8. The system of claim 6 , wherein the verifier is further, when executed by the processor, to automatically issue an informational alert when one of the required digital certificates is missing from the encryption keystore but is automatically inserted into the encryption keystore.

9. The system of claim 8 , wherein the verifier is further, when executed by the processor, to:

automatically repeatedly check the encryption keystore to determine when any of the required digital certificates that are present in the encryption keystore have expired; and

automatically issue a warning alert when any of the required digital certificates that are present in the encryption keystore have expired.

10. The system of claim 8 , wherein the encryption keystore comprises a certificate management system provider keystore; and

wherein the verifier is further, when executed by the processor, to:

automatically repeatedly check the certificate management system provider keystore to determine if a password for the certificate management system provider keystore has expired; and

automatically issue a warning alert when the password for the certificate management system provider keystore has expired.

11. A computer program product for verifying and populating an encryption keystore, the computer readable program product comprising a non-transitory computer readable storage medium having computer readable program code embodied in the medium, the computer readable program code comprising:

computer readable program code to verify the encryption keystore by automatically repeatedly checking the encryption keystore to determine if the encryption keystore is missing a required digital certificate;

computer readable program code to populate the encryption keystore by automatically inserting into the encryption keystore the required digital certificate that is missing from the encryption keystore, in response to a determination that the encryption keystore is missing the required digital certificate;

computer readable program code to automatically obtain digital certificates present in the encryption keystore and a list of required digital certificates, the list of required digital certificates comprising both root certificate authority certificates and server digital certificates;

computer readable program code to automatically compare the list of required digital certificates with the digital certificates present in the encryption keystore to determine whether a minimum number of required root certificate authority certificates and a minimum number of required server digital certificates are present in the encryption keystore;

computer readable program code to automatically repeatedly check the encryption keystore to determine if any of the required digital certificates that are present in the encryption keystore are not operating properly; and

computer readable program code to automatically issue a warning alert when any of the required digital certificates that are present in the encryption keystore are determined to not be operating properly.

12. The computer program product of claim 11 , wherein the required digital certificate is one of the root certificate authority certificates and the server digital certificates.

13. The computer program product of claim 11 , further comprising computer readable program code to automatically issue an informational alert when one of the required digital certificates is missing from the encryption keystore but is automatically inserted into the encryption keystore.

14. The computer program product of claim 11 , further comprising:

computer readable program code to automatically repeatedly check the encryption keystore to determine when any of the required digital certificates that are present in the encryption keystore have expired; and

computer readable program code to automatically issue a warning alert when any of the required digital certificates that are present in the encryption keystore have expired.

15. The computer program product of claim 13 , wherein the encryption keystore comprises a certificate management system provider keystore, and further comprising:

computer readable program code to automatically repeatedly check the certificate management system provider keystore to determine if a password for the certificate management system provider keystore has expired; and

computer readable program code to automatically issue a warning alert when the password for the certificate management system provider keystore has expired.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2009
From: SCHIEFELBEIN, ANDREW
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 023528/0264 →
Continuity (1)
Related Publication 20110116637A1 · May 19, 2011