Identifying and Maintaining Secure Communications

US2016373263A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016373263-A1
Application numberUS-201514743674-A
CountryUS
Kind codeA1
Filing dateJun 18, 2015
Priority dateJun 18, 2015
Publication dateDec 22, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one embodiment, a system for managing secure communications includes an interface that may receive communication between a first endpoint and a second endpoint. A processor may identify a security certificate included in the communication and determine whether the identified security certificate has previously been stored in a certificate database. If the security certificate has not been previously stored in a certificate database, the processor may store the identified security certificate in the certificate database. The processor may also analyze parameters of the identified security certificate including a host device using the certificate, a network administrator responsible for the host device, an expiration date of the security certificate, and a certification authority issuing the security certificate.

First claim

Opening claim text (preview).

1 . A system for managing secure communications, comprising: an interface operable to: receive a communication between a first endpoint and a second endpoint; a processor communicatively coupled to the interface and operable to: identify a security certificate included in the communication; analyze parameters of the identified security certificate, wherein the parameters comprise: a host device using the security certificate; a network administrator responsible for the host device; an expiration date of the security certificate; and a certification authority issuing the security certificate; determine whether the identified security certificate has previously been stored in a certificate database; and in response to determining that the identified security certificate has not been previously stored in a certificate database, store the identified security certificate in the certificate database. 2 . The system of claim 1 , wherein: the interface is further operable to receive an alert indicating that a first security certificate stored in the certificate database has a first expiration date that is set to expire within a predetermined time period; and the processor is further operable to: identify the host server using the first security certificate; and identify the network administrator responsible for the host server, wherein the interface is further operable to communicate the alert message to the network administrator. 3 . The system of claim 2 , wherein the predetermined time period is one selected from the group consisting of: twenty-four hours, one week, one month, and three months. 4 . The system of claim 1 , wherein the security certificate is a security sockets layer (SSL) certificate selected from the group consisting of: an extended validation SSL certificate, an organization validation SSL certificate, and a domain validation SSL certificate. 5 . The system of claim 1 , wherein the first endpoint is a web browser and the second endpoint is a web server. 6 . The system of claim 1 , wherein the first endpoint is a first server and the second endpoint is a second server, wherein the first and second servers are associated with an enterprise. 7 . The system of claim 1 , wherein: the processor is further operable to determine that the certification authority issuing the security certificate is an unapproved certification authority; and the interface is further operable to communicate a message to the network administrator responsible for the host device, wherein the message indicates that the security certificate is from an unapproved certification authority. 8 . A method for managing secure communications, comprising: receiving, at an interface, a communication between a first endpoint and a second endpoint; identifying, using a processor communicatively coupled to the interface, a security certificate included in the communication; analyzing, using the processor, parameters of the identified security certificate, wherein the parameters comprise: a host device using the certificate; a network administrator responsible for the host device; an expiration date of the security certificate; and a certification authority issuing the security certificate; determining, using the processor, whether the identified security certificate has previously been stored in a certificate database; and in response to determining that the identified security certificate has not been previously stored in a certificate database, storing, using the processor, the identified security certificate in the certificate database. 9 . The method of claim 8 , further comprising: receiving an alert indicating that a first security certificate stored in the certificate database has an first expiration date that is set to expire within a predetermined time period; identifying the host server using the first security certificate; identifying the network administrator responsible for the host server; and communicating the alert message to the network administrator. 10 . The method of claim 9 , wherein the predetermined time period is one selected from the group consisting of: twenty-four hours, one week, one month, and three months. 11 . The method of claim 8 , wherein the security certificate is a secure sockets layer (SSL) certificate selected from the group consisting of: an extended validation SSL certificate, an organization validation SSL certificate, and a domain validation SSL certificate. 12 . The method of claim 8 , wherein the first endpoint is a web browser and the second endpoint is a web server. 13 . The method of claim 8 , wherein the first endpoint is a first server and the second endpoint is a second server, wherein the first and second servers are part of associated with an enterprise. 14 . The method of claim 8 , further comprising: determining that the certification authority issuing the security certificate is an unapproved certification authority; and communicating a message to the network administrator responsible for the host device, wherein the message indicates that the security certificate is from an unapproved certification authority. 15 . A non-transitory computer readable medium comprising logic, the logic operable, when executed by a processor, to: receive a communication between a first endpoint and a second endpoint; identify a security certificate included in the communication; analyze parameters of the identified security certificate, wherein the parameters comprise: a host device using the certificate; a network administrator responsible for the host device; an expiration date of the security certificate; and a certification authority issuing the security certificate; determine whether the identified security certificate has previously been stored in a certificate database; and in response to determining that the identified security certificate has not been previously stored in a certificate database, store the identified security certificate in the certificate database. 16 . The non-transitory medium of claim 15 , wherein the logic is further operable to: receive an alert indicating that a first security certificate stored in the certificate database has an first expiration date that is set to expire within a predetermined time period; identify the host server using the first security certificate; identify the network administrator responsible for the host server; and communicate the alert message to the network administrator. 17 . The non-transitory medium of claim 16 , wherein the predetermined time period is one selected from the group consisting of: twenty-four hours, one week, one month, and three months. 18 . The non-transitory medium of claim 15 , wherein the security certificate is an secure sockets layer (SSL) certificate selected from the group consisting of: an extended validation SSL certificate, an organization validation SSL certificate, and a domain validation SSL certificate. 19 . The non-transitory medium of claim 15 , wherein the first endpoint is a web browser and the second endpoint is a web server; 20 . The non-transitory medium of claim 15 , wherein the first endpoint is a first server and the second endpoint is a second server, wherein the first and second servers are part of an enterprise.

Assignees

Inventors

Classifications

  • above the transport layer · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using certificate chains, trees or paths; Hierarchical trust model · CPC title

  • H04L9/3268Primary

    using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016373263A1 cover?
In one embodiment, a system for managing secure communications includes an interface that may receive communication between a first endpoint and a second endpoint. A processor may identify a security certificate included in the communication and determine whether the identified security certificate has previously been stored in a certificate database. If the security certificate has not been pr…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L9/3268. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 22 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).