Systems and methods to rotate security assets used for secure communications

    公开(公告)号:US11265349B2

    公开(公告)日:2022-03-01

    申请号:US16507812

    申请日:2019-07-10

    Applicant: eBay Inc.

    Abstract: Systems and methods to rotate security assets used to for secure communications are disclosed. The system includes receiving a first certificate that includes a first subject name for the remote servers. The first certificate further includes a first public key. Next, the system receives a second certificate that includes the first subject name for the remote servers. The second certificate further includes a second public key that is different from the first public key. Next, the system stores the first and second certificates in a trust module. Next, the system receive a third certificate from a first server included in the plurality of remote servers. Next, the system identifies the first server is trusted. The identifying is based on the third certificate matching any one of the first certificate and the second certificate. Finally, the system establishes a secure communication session with the first server based on the identifying the first server is trusted.

    Systems and methods to rotate security assets used for secure communications

    公开(公告)号:US10389758B2

    公开(公告)日:2019-08-20

    申请号:US15840702

    申请日:2017-12-13

    Applicant: eBay Inc.

    Abstract: Systems and methods to rotate security assets used for secure communication are described. The system retrieves security assets from a security asset repository, the security assets including a first version of the certificate and a second version of the certificate. Further, the system receives, over a network, a third certificate, at a client machine, the third certificate being received from the first remote server machine of the plurality of remote server machines. Further, the system identifies, at the client machine, whether a first remote server machine associated with the first subject name is trusted by identifying whether the third certificate matches any one of the first version of the certificate and the second version of the certificate. Finally, the system establishes a secure communication session with the first remote server machine based on identifying that the first remote server is trusted.

    System and method for pool-based identity authentication for service access without use of stored credentials
    3.
    发明授权
    System and method for pool-based identity authentication for service access without use of stored credentials 有权
    用于服务访问的基于池的身份认证的系统和方法,而不使用存储的凭据

    公开(公告)号:US09319394B2

    公开(公告)日:2016-04-19

    申请号:US14290823

    申请日:2014-05-29

    Applicant: eBay Inc.

    CPC classification number: H04L63/08 H04L9/321 H04L63/0823 H04L63/10

    Abstract: A computer-implemented system and method for pool-based identity authentication for service access without use of stored credentials is disclosed. The method in an example embodiment includes providing provisioning information for storage in a provisioning repository; receiving a service request from a service consumer, the service request including requestor identifying information; generating an authentication request to send to an authentication authority, the authentication request including requestor identifying information; receiving validation of an authenticated service request from the authentication authority; and providing the requested service to the service consumer.

    Abstract translation: 公开了一种用于基于池的身份认证的计算机实现的系统和方法,用于不使用存储的凭证的服务访问。 示例实施例中的方法包括提供用于存储在供应存储库中的供应信息; 从服务消费者接收服务请求,所述服务请求包括请求者识别信息; 生成认证请求发送给认证机构,认证请求包括请求者识别信息; 从认证机构接收认证服务请求的验证; 并向服务消费者提供所请求的服务。

    SYSTEM AND METHOD FOR POOL-BASED IDENTITY AUTHENTICATION FOR SERVICE ACCESS WITHOUT USE OF STORED CREDENTIALS

    公开(公告)号:US20200014676A1

    公开(公告)日:2020-01-09

    申请号:US16556624

    申请日:2019-08-30

    Applicant: eBay Inc.

    Abstract: A computer-implemented system and method for pool-based identity authentication for service access without use of stored credentials is disclosed. The method in an example embodiment includes providing provisioning information for storage in a provisioning repository; receiving a service request from a service consumer, the service request including requestor identifying information; generating an authentication request to send to an authentication authority, the authentication request including requestor identifying information; receiving validation of an authenticated service request from the authentication authority; and providing the requested service to the service consumer.

    SYSTEM AND METHOD FOR POOL-BASED IDENTITY AUTHENTICATION FOR SERVICE ACCESS WITHOUT USE OF STORED CREDENTIALS
    7.
    发明申请
    SYSTEM AND METHOD FOR POOL-BASED IDENTITY AUTHENTICATION FOR SERVICE ACCESS WITHOUT USE OF STORED CREDENTIALS 有权
    不使用存储凭证的服务访问的基于池的身份认证的系统和方法

    公开(公告)号:US20140282980A1

    公开(公告)日:2014-09-18

    申请号:US14290823

    申请日:2014-05-29

    Applicant: eBay Inc.

    CPC classification number: H04L63/08 H04L9/321 H04L63/0823 H04L63/10

    Abstract: A computer-implemented system and method for pool-based identity authentication for service access without use of stored credentials is disclosed. The method in an example embodiment includes providing provisioning information for storage in a provisioning repository; receiving a service request from a service consumer, the service request including requestor identifying information; generating an authentication request to send to an authentication authority, the authentication request including requestor identifying information; receiving validation of an authenticated service request from the authentication authority; and providing the requested service to the service consumer.

    Abstract translation: 公开了一种用于基于池的身份认证的计算机实现的系统和方法,用于不使用存储的凭证的服务访问。 示例实施例中的方法包括提供用于存储在供应存储库中的供应信息; 从服务消费者接收服务请求,所述服务请求包括请求者识别信息; 生成认证请求发送给认证机构,认证请求包括请求者识别信息; 从认证机构接收认证服务请求的验证; 并向服务消费者提供所请求的服务。

    System and method for pool-based identity authentication for service access without use of stored credentials

    公开(公告)号:US10887298B2

    公开(公告)日:2021-01-05

    申请号:US16556624

    申请日:2019-08-30

    Applicant: eBay Inc.

    Abstract: A computer-implemented system and method for pool-based identity authentication for service access without use of stored credentials is disclosed. The method in an example embodiment includes providing provisioning information for storage in a provisioning repository; receiving a service request from a service consumer, the service request including requestor identifying information; generating an authentication request to send to an authentication authority, the authentication request including requestor identifying information; receiving validation of an authenticated service request from the authentication authority; and providing the requested service to the service consumer.

    SYSTEMS AND METHODS TO ROTATE SECURITY ASSETS USED FOR SECURE COMMUNICATIONS

    公开(公告)号:US20200084240A1

    公开(公告)日:2020-03-12

    申请号:US16507812

    申请日:2019-07-10

    Applicant: eBay Inc.

    Abstract: Systems and methods to rotate security assets used to for secure communications are disclosed. The system includes receiving a first certificate that includes a first subject name for the remote servers. The first certificate further includes a first public key. Next, the system receives a second certificate that includes the first subject name for the remote servers. The second certificate further includes a second public key that is different from the first public key. Next, the system stores the first and second certificates in a trust module. Next, the system receive a third certificate from a first server included in the plurality of remote servers. Next, the system identifies the first server is trusted. The identifying is based on the third certificate matching any one of the first certificate and the second certificate. Finally, the system establishes a secure communication session with the first server based on the identifying the first server is trusted.

Patent Agency Ranking